Filings
Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.
-
The ICO is becoming the Information Commission
19 February 2026 · Security Commentary
The UK's data protection regulator is being restructured under the Data (Use and Access) Act 2025. New board, new CEO, new statutory objectives. The name is the least interesting part.
-
What the Cyber Security and Resilience Bill actually means
19 February 2026 · Security Commentary
The biggest overhaul of UK security regulation since 2018 is in committee. MSPs are in scope, incident reporting gets a 24-hour clock, and fines go up to £17 million. Here's what it means in practice.
-
The free security awareness campaign you didn't know existed
18 February 2026 · Security
The NPSA gives away a complete, professionally designed security awareness campaign kit. Posters, booklets, checklists, and a full starter guide. Most organisations don't know it exists.
-
Chrome's first zero-day of 2026: update now, don't wait
17 February 2026 · Security Commentary
CVE-2026-2441 is actively being exploited in the wild. A use-after-free bug in CSS handling means a crafted webpage is all it takes. Push the update now.
-
AI just claimed your spinning disks too
16 February 2026 · Infrastructure Commentary
Western Digital's entire HDD capacity for 2026 is sold out. Cloud is 89% of their revenue. HDD prices are up 46% since September. The window for sensible storage pricing is closing.
-
Prompt injection is not the new SQL injection
16 February 2026 · AI Security Commentary
Schneier and co have reframed prompt injection as 'promptware' — a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.
-
The first five minutes of incident response
15 February 2026 · Security
Containment over correctness, reversibility over impact, protecting state before touching services. What your first five minutes should actually look like.
-
When your payment processor can't send a valid email
13 February 2026 · Infrastructure Commentary
Viva.com sends verification emails missing the Message-ID header. Google Workspace and Zoho reject them. The fix is one line of code.
-
Microsoft is a cloud company that also makes Windows
12 February 2026 · Commentary
Microsoft's FY2025 numbers tell a clear story. Azure and M365 are two-thirds of revenue. Windows is about 6%. This is a cloud and productivity company.
-
Patch your text editors
11 February 2026 · Security Commentary
Notepad++ had its update service hijacked by state-sponsored attackers. Windows Notepad got a CVSS 8.8 command injection. Two editors, two attack vectors, same lesson.
-
Insecure defaults have a long half-life
10 February 2026 · Security Commentary
Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass was disclosed. The protocol is old. The lesson is current.
-
What Cyber Essentials actually involves
7 February 2026 · Security
A plain-English walkthrough of the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn't prove about your security.