Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
7 results for “risk” · Clear
EPSS vs CVSS vs KEV: Building a Data-Driven Patch Prioritisation Model
CVSS measures severity, EPSS estimates exploitation likelihood, and KEV records confirmed exploitation. Here is how to combine all three into a defensible patching queue — and why a CVSS-only backlog is unpatchable by design.
Govern Microsoft 365 Copilot with Purview DSPM: Stop Oversharing Before You Deploy
Microsoft 365 Copilot governance means controlling what Copilot can surface, not just who can use it. Copilot does not break your permissions — it exposes them, turning a decade of overshared SharePoint sites into plain-English answers. This guide walks the actual Purview and SharePoint controls that fix it, in the order a security team should apply them: DSPM for AI to find overshared data, sensitivity labels plus DLP to stop Copilot processing it, and SharePoint Restricted Content Discovery to keep high-risk sites out of Copilot answers. Licence and GA/preview status validated against Microsoft Learn, August 2026.
Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026
Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.
NIST CSF 2.0 Explained: The Six Functions, Tiers, and Profiles — A Practical Guide
The NIST Cybersecurity Framework 2.0, released in February 2024, is a voluntary framework for organising, assessing and communicating cybersecurity risk. Version 2.0 added a sixth function — Govern — and widened the framework beyond critical infrastructure to organisations of every size. This guide explains the six Functions and their Categories, the Core / Tiers / Profiles structure, how to run a Current-to-Target gap assessment, the new Govern function and CSF Tiers, and how CSF maps to ISO 27001 and SOC 2 so it becomes the connective tissue of a single compliance programme.
ISO 27001 Explained: A Complete Guide to the ISMS and Certification in 2026
ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a risk-based, auditable way to prove you manage security as a system, not a checklist. This guide covers what the standard actually requires (Clauses 4–10 plus the 93 Annex A controls of the 2022 revision), the 2024 climate amendment, how certification works, a realistic timeline and cost, the evidence auditors expect, and how ISO 27001 maps to SOC 2 and NIST CSF so you can satisfy more than one framework at once.
Third-Party Risk Management: From Onboarding to Offboarding (With Continuous Monitoring)
A practical, end-to-end guide to managing third-party and vendor risk across the full lifecycle — intake and tiering, due-diligence assessment, contracting, secure onboarding, continuous monitoring, periodic review, and secure offboarding — mapped to NIST SP 800-161, ISO 27036, the Shared Assessments SIG, and SOC 2.
Entra ID Conditional Access Gaps: 10 Misconfigurations That Quietly Defeat MFA
The most common Entra ID Conditional Access gaps are policies that exclude too much, sit in report-only forever, ignore legacy authentication, skip device and risk signals, and leave break-glass accounts unmanaged. Here's how to find and close each one.