Long-form. Technical. Every Wednesday. The things you already know you should be doing.
-
Everyone collects logs; almost nobody reads them, and the gap between compliance logging and operational detection is where breaches live undetected for months.
-
A patching policy is a document; patching is a measurable outcome, and the gap between the two is where most organizations quietly live.
-
Everyone writes a least-privilege policy and almost no one enforces it; here's the gap between the document and an access review that actually revokes something.
-
Push-based MFA was supposed to kill phishing and credential reuse, but by turning authentication into a single fatigued tap, it became a new attack surface, and NIST has been quietly telling you to fix it for years.