Writing and thinking about information security. Helping organizations build resilient security postures through assessment, architecture, and compliance.
Comprehensive security solutions tailored to your organization.
Know where you stand before an attacker shows you. Our assessments go beyond automated scans to uncover real risks in your environment.
Build security into your infrastructure from the ground up. We design network architectures that are secure by default and resilient by design.
Compliance does not have to be painful. We help you meet regulatory requirements efficiently while building a governance program that adds real value.
Control who has access to what and when. We help you implement IAM frameworks that balance security with usability.
Thinking out loud about security, risk, and what it means to protect systems.
The Network Management Plane Just Became the Most Exploitable Surface You Own Between Tuesday and Thursday of last week, three vendors told the world that the systems meant to control your network are now the easiest way into it. Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine that attackers are using right […]
The Patch Is Out. You Are Probably Still Exposed. Last Tuesday, Microsoft patched 974 vulnerabilities in one go. It was the largest Patch Tuesday in history: 723 flaws in Windows, 111 in Office, 62 in SQL, 22 in developer tools, and over 110 rated critical. Two of those flaws were already being exploited before the […]
A finance employee at a multinational engineering firm joined a video call last year expecting to see his company’s UK-based CFO and a handful of other colleagues. Every face on that call looked right.
Ready to get serious about security? Tell me about your situation.