Security analysis for businesses that need to know what matters
Relevant threat developments, plain-English explanations of attack methods and sector-specific guidance — written for business owners and busy IT leads, not security specialists.
Why supplier compromise matters for small and medium businesses
A large share of breaches at small and medium businesses involve a supplier or another third party. We explain how attackers move from a supplier into a customer's systems and what to ask your suppliers.
Coming soonWhy supplier compromise matters for small and medium businesses
A large share of breaches at small and medium businesses involve a supplier or another third party. We explain how attackers move from a supplier into a customer's systems and what to ask your suppliers.
Stolen passwords and why multi-factor authentication helps
Credential abuse remains a common way criminals breach small and medium businesses. A plain-English explanation of how stolen passwords are used and what MFA actually does.
Unpatched software: where to focus first
Many attacks start with software that had not been updated. A practical look at which updates matter most and how to prioritise them without an enterprise budget.
Understanding MITRE ATT&CK without the jargon
MITRE ATT&CK is a knowledge base of techniques observed in real attacks. Here is what it is, why analysts use it, and what it can and cannot tell you about your own security.
Email authentication (DMARC, DKIM and SPF) explained
Your domain can be used to phish your customers even when you are not breached. What these three records actually do and how to read a DMARC report.
Phishing: where to focus training and controls
Phishing is a smaller slice of the breach picture than many assume, but it is high-impact. Where to focus for real risk reduction rather than box-ticking.
The Lowside threat brief
One short email when we publish, plus the occasional note on what attackers are doing to small organisations right now. No noise. You can unsubscribe at any time.