Long-form. Technical. Every Wednesday. The things you already know you should be doing.
-
You cannot defend infrastructure you've never counted, and the assets that get you owned are almost always the ones nobody remembered existed.
-
Annual phishing-quiz compliance training teaches people to pass quizzes, not to resist attacks, and CIS Control 14 asks for something far harder: role-specific skills that hold up under pressure.
-
The admin/admin problem never dies; it just migrates to whatever new class of infrastructure you weren't watching, and CIS Control 4 is the map you keep refusing to read.
-
Every organization claims it has backups, but far fewer can prove those backups restore under pressure, and ransomware crews have built a business model on the difference.
-
A ready incident response plan that has never been exercised isn't a capability at all, just a document waiting to fail you in the worst possible way.
-
Segmentation isn't a diagram you draw once and file away, it's an assumption you have to prove every time it matters, and flat networks that pass audits still collapse the moment an attacker gets a foothold.
-
Your vendors inherit your trust and export their weaknesses to you, and NIST's GV.SC exists precisely because almost nobody manages that relationship past the initial questionnaire.
-
Everyone collects logs; almost nobody reads them, and the gap between compliance logging and operational detection is where breaches live undetected for months.
-
A patching policy is a document; patching is a measurable outcome, and the gap between the two is where most organizations quietly live.
-
Everyone writes a least-privilege policy and almost no one enforces it; here's the gap between the document and an access review that actually revokes something.
-
Push-based MFA was supposed to kill phishing and credential reuse, but by turning authentication into a single fatigued tap, it became a new attack surface, and NIST has been quietly telling you to fix it for years.