Insights
Practical security writing.
Notes on how security operations, detection and offensive testing actually work — written for people who have to make decisions, not for search engines.
Topics
- SOC & MDR
- Threat Detection
- Active Directory Security
- Penetration Testing
- Cloud Security
- Incident Response
- Compliance
- Cybersecurity Strategy
Published articles
In progress
Topics currently being written. These are listed rather than linked — we don't publish placeholder pages.
Threat Detection
Detecting Identity Attacks in Microsoft 365
Most intrusions into mid-market organisations begin with an identity, not an exploit. Here is what to watch.
Incident Response
The First Hour of an Incident
What to do, what to avoid, and which decisions made in the first sixty minutes determine how the rest of the response goes.
Cloud Security
Cloud Attack Paths Start With Identity
Why cloud compromise is usually a permissions problem, and how to assess it before it becomes an incident.
Compliance
ISO 27001 Readiness: What to Expect
A realistic view of the work involved between deciding to certify and being ready for an external audit.
Next step
Prefer a conversation to an article?
If something here maps to a problem you're actually facing, a scoping call will get you further than another blog post.