Notes from
the field.
Practical writing on testing, compliance and defence, plus the threats and trends worth your attention, for people who make real security decisions.
Vulnerability management vs pentesting
Why scanning and pentesting answer different questions — and why you need both.
Security for startups: what to do first
A pragmatic priority list before you have a security team.
Red team vs penetration test
Goals, scope, cost — and which one your organisation actually needs right now.
API security: the forgotten attack surface
Why APIs are the most-attacked, least-tested part of modern apps.
Phishing simulations without wrecking trust
Run them so they build security culture instead of humiliating staff.
Cloud misconfigurations that cause breaches
Public buckets, over-broad IAM, exposed metadata — find them first.
Zero trust, without the buzzwords
What it actually means, and pragmatic first steps for smaller teams.
How much does a penetration test cost?
Real price drivers, and how to avoid paying for a scanner report dressed as a pentest.
SOC 2 Type I vs Type II
Which report enterprise clients actually accept, and the pragmatic path to get there.
Securing AI chatbots: an LLM checklist
Prompt injection, data leakage, excessive agency — what to test before launch.
The first 24 hours of an incident
A calm playbook: containment, evidence, communication — and the mistakes to avoid.
The OWASP Top 10, for business leaders
What the most-cited list in appsec actually means for your risk, in plain language.
What a penetration test actually is
The difference between a real pentest and an automated scan, and how to prepare for one.
ISO 27001 vs SOC 2: which first?
A plain-language guide to choosing the right standard when clients start asking for proof.
Prompt injection, explained for builders
Why the newest attack surface bypasses traditional testing, and what to do about it.