SITEY Blog

Security insights & guides

Patch Exceptions and Risk Acceptance Without the Spreadsheet

How to design a patch exception process: who approves risk acceptance, required compensating controls, expiry rules, and audit-ready reporting.

Vulnerability Exception Management Without the Rubber Stamp

A vulnerability exception process needs dated expiry, review board quorum, capped renewals, and verified compensating controls, not a rubber stamp signoff.

Orphaned Assets: What Happens When No One Owns a Server

Why servers lose their owners, how orphaned assets decay into breach points, and the DNS, billing, code and network techniques to reclaim…

PCI DSS ROC vs AOC: Which Document Your Partners Need

PCI DSS ROC vs AOC explained: what each document contains, who can legally request the ROC, and how to review a vendor's…

Backported Patches: Why Scanners Flag Patched Servers

Why RHEL, Debian and SUSE backports trigger a backported patch false positive, and the changelog and package evidence that proves a CVE…

ASR Rules: Moving From Audit Mode to Block Mode Safely

A staged plan for moving Microsoft Defender ASR rules from audit to block mode: telemetry sizing, rule ranking, exclusions, and enforcement verification.

CVSS 4.0 Supplemental Metrics: Safety, Recovery, Automatable

CVSS v4.0 Supplemental metrics (Safety, Automatable, Recovery, Value Density, Provider Urgency) never change the score. Here is how to route on them…

Risk Acceptance Tracking: Managing Exceptions Without Chaos

How to run a defensible security risk acceptance process: record fields, approval authority by residual risk, expiry rules, and exception metrics.

CSPM vs CWPP vs CNAPP: Choosing the Right Cloud Layer

CSPM, CWPP, and CNAPP answer different questions. Compare configuration, workload, and correlated risk with a coverage matrix and buying decision guide.

LLM-Generated Remediation Steps: How Accurate Are They?

How accurate are LLM generated remediation steps for CVEs, where version and vendor specific syntax breaks them, and how to verify a…