SITEY Blog

Security insights & guides

Patch Tuesday Planning: Building a Repeatable Monthly Cycle

A concrete monthly cycle for patch tuesday planning: triage windows, pilot rings, rollout gates, out-of-band handling, staffing, and closeout reporting.

What a Vulnerability Management Policy Must Include

A vulnerability management policy needs scope, severity SLAs, and exception rules that stay enforceable. Here is the section-by-section structure to copy.

Shadow IT: How Unsanctioned Systems Reach Production

Shadow IT security risk comes from microsites, demo environments and personal-card SaaS buys. How to find these assets, decide their fate, and…

ISO 27001 Nonconformities: Major vs Minor and How to Close

How ISO 27001 auditors classify major vs minor nonconformities, what closure deadlines apply, and how to write a root cause analysis that…

Setting Up SSH Credentials for Linux Authenticated Scans

Configure SSH key auth and scoped sudo for Linux vulnerability scans without granting root, and learn to catch silent partial-credential scan failures.

LSASS Protection: Credential Guard, RunAsPPL and Gaps

RunAsPPL and Credential Guard for LSASS: hardware prerequisites, enablement steps, what stays exposed, compatibility breakage, and how to verify it is really…

CVSS Threat Metrics and Exploit Code Maturity Explained

CVSS Exploit Code Maturity and v4 Threat Metrics decoded: value definitions, real score multipliers, evidence sources, and how often to re-score findings.

Scan Coverage Metrics: Proving You Can See Every Asset

Vulnerability scan coverage metrics mean nothing until you fix the denominator: CMDB, discovery, or cloud billing. Here is how auditors judge the…

How to Find Every Public Storage Bucket Across Your Accounts

A practical guide to enumerating public S3, Azure Blob, and GCS buckets across every account, with CLI recipes, diffable output, and prevention…

How to Measure and Reduce Your False Positive Rate

A concrete method for false positive rate: disposition codes, a sampling process, the formula, per-scanner breakdowns, and reporting it so it can't…