SITEY Blog

Security insights & guides

Designing Maintenance Windows Across Global Time Zones

How to build a maintenance window schedule across time zones: system tolerance, follow-the-sun vs. global slots, blackout periods, and window length math.

Vulnerability Management Maturity Models: Levels 1 to 5

A five-level vulnerability management maturity model with observable behaviors, a 20-question self-assessment, and a 12-month roadmap to reach level 4.

Unknown Unknowns: The Assets Your Inventory Never Listed

A practical framework for finding unknown assets: the discovery matrix, where they come from, a 48 hour triage playbook, and the metric…

SOC 2 Type I vs Type II: Which Report Do Buyers Expect?

SOC 2 Type I vs Type II explained: what each report actually tests, typical observation windows, cost differences, and what procurement teams…

How a WAF Changes What Your Web Scanner Reports

A WAF between scanner and target can turn a real vulnerability into a clean result. How to detect the interference and separate…

RDP Hardening: NLA, Restricted Admin and Exposure Limits

A practical RDP hardening checklist: NLA and TLS settings, Restricted Admin vs Remote Credential Guard, session limits, deny logon rules and drift…

When NVD and the Vendor Disagree on a CVE’s Severity

NVD and vendor CVSS scores for the same CVE often diverge sharply. See documented cases and get a tiebreak policy your team…

16 Security KPIs Worth Reporting and 6 to Retire Today

A working list of 16 defensible security KPIs by category, 6 vanity metrics to cut, and a template for a one-page KPI…

Amazon Inspector: What It Finds and Where It Stops

What Amazon Inspector actually scans, how findings refresh, its coverage gaps, cost traps at scale, and when to add a second layer…

How to Verify an AI-Written Patch Script Before You Run It

A practical checklist for verifying an AI generated patch script before you run it: static review, dry runs, sandbox tests, snapshots, and…