Security insights & guides
Change Windows and Auto-Patching Without Causing Outages
How to design maintenance windows, handle no-window assets, queue reboots, encode freeze calendars, and align automated patching with CAB approval.
Choosing Pilot Devices for Patch Testing Without Angering Users
How to build a patch pilot group that actually catches breakages: hardware and role diversity, volunteer incentives, roster upkeep, and rollout signals.
12 Vulnerability Management Metrics That Actually Matter
A practical breakdown of 12 vulnerability management metrics that survive leadership scrutiny, with formulas, thresholds, and a one-page scorecard template.
Forgotten Domains: Auditing a Sprawling Domain Portfolio
Learn how domain portfolios sprawl, how to inventory every registration, why expired domains enable phishing and mail spoofing, and how to govern…
GDPR Article 32: What “State of the Art” Security Means
GDPR Article 32 never defines "state of the art." Here is how regulators read it, what enforcement decisions reveal, and what evidence…
Scanning Fragile Devices: OT, Printers and Embedded Hosts
How to scan PLCs, printers and embedded hosts without crashing them: safe-check profiles, passive discovery, rate limits and OT sign-off procedure.
SeImpersonate and Potato Attacks: Blocking Token Abuse
How SeImpersonatePrivilege turns a compromised IIS or SQL service account into SYSTEM through Potato attacks, and the concrete steps that close the…
Where EPSS Falls Short: Blind Spots in Exploit Prediction
EPSS misses internal-only bugs, targeted exploitation and brand-new CVEs. Where its blind spots are, and how to compensate with exposure and KEV…
Translating CVSS Scores Into Business Risk That Executives Get
A practical method for turning CVSS scores into business risk language executives can act on, with a rubric, likelihood scale, and rewrite…
How to Scan Docker Images for Vulnerabilities in CI
A concrete guide to scanning Docker images for vulnerabilities in CI: pipeline placement, severity thresholds, base image findings, caching, and exports.