Everything we have written on cyber security

Phishing Training That Actually Changes Behaviour
The yearly video and the multiple choice quiz are gone from memory by the following week. Here is what does move behaviour, and why punishing people who click makes you less safe.
9 min read

The First Hour After You Find a Breach
Preserve, contain, then investigate. The first hour decides how much you will ever know about what happened, and the costliest mistake is usually the well meant clean up.
10 min read

Rolling Out Multi Factor Authentication Without a Revolt
Switching it on takes an afternoon. Getting a whole company through it without a queue at the help desk and without exceptions that never expire is the part nobody plans for.
9 min read

Ransomware, and What Actually Stops It
Encryption is the last step, not the first. Most of what saves you happens in the quiet days before it, and the control that does the most work costs nothing but an argument about admin rights.
10 min read

What a Security Audit Actually Checks
Audit is one word for four different jobs. Knowing which one you are buying is the difference between a useful report and an expensive PDF.
9 min read

Getting a Small Team Onto a Password Manager
The shared spreadsheet works until somebody leaves. Here is how to move a small team across in one push, structure the vaults so they survive growth, and handle the founder who will not budge.
8 min read

Securing a Team That Works From Anywhere
The office network stopped being the boundary a while ago. What matters now is the account and the device, and a fair amount of what gets enforced on remote staff is theatre.
9 min read

What a Penetration Test Tells You, and What It Does Not
A test answers one bounded question: could this tester, in this window, inside this scope, reach this goal. Everything you get out of the report depends on understanding that sentence.
9 min read

The Access Someone Keeps After They Leave
Disabling the email account is the easy part. What survives an exit is the access nobody ever wrote down, and a good deal of it is still working a year later.
9 min read

What to Put in an Incident Plan
A plan that only exists as a document is a plan nobody follows at two in the morning. Here is what makes one usable while everything is on fire.
9 min read

The Security Questions to Ask a Supplier
Their breach becomes your incident. Here are the questions that get real answers, the reassuring phrases that mean nothing, and the part of the risk you control whatever they say.
9 min read

Patching Without Breaking the Thing That Pays the Bills
Nobody argues that updates matter. The argument is about the machine that cannot be restarted and the vendor who forbids patching, and both of those have real answers.
9 min read
Other things we write about
Tell Us What You Need Built Or Fixed
Write down what you are dealing with, in your own words. We will tell you whether it is work we do and what it would take.
What You Get
- Scope agreed before we start
- One team, not three suppliers
- You own the code and the accounts
- Plain answers about cost
- Support after it goes live
- Work you can hand to someone else
What Happens Next
- 1We call you at a time that suits you
- 2We ask what you have now and what is going wrong
- 3We send back a scope and a price
Tell Us About Your Project
Every enquiry gets a reply within one working day.
