Skip to main content

Insights

Practical security writing.

Notes on how security operations, detection and offensive testing actually work — written for people who have to make decisions, not for search engines.

Topics

  • SOC & MDR
  • Threat Detection
  • Active Directory Security
  • Penetration Testing
  • Cloud Security
  • Incident Response
  • Compliance
  • Cybersecurity Strategy

In progress

Topics currently being written. These are listed rather than linked — we don't publish placeholder pages.

  • Threat Detection

    Detecting Identity Attacks in Microsoft 365

    Most intrusions into mid-market organisations begin with an identity, not an exploit. Here is what to watch.

  • Incident Response

    The First Hour of an Incident

    What to do, what to avoid, and which decisions made in the first sixty minutes determine how the rest of the response goes.

  • Cloud Security

    Cloud Attack Paths Start With Identity

    Why cloud compromise is usually a permissions problem, and how to assess it before it becomes an incident.

  • Compliance

    ISO 27001 Readiness: What to Expect

    A realistic view of the work involved between deciding to certify and being ready for an external audit.

Next step

Prefer a conversation to an article?

If something here maps to a problem you're actually facing, a scoping call will get you further than another blog post.