Filings tagged: Security
Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.
-
The ICO is becoming the Information Commission
· Security Commentary
The UK's data protection regulator is being restructured under the Data (Use and Access) Act 2025. New board, new CEO, new statutory objectives. The name is the least interesting part.
-
What the Cyber Security and Resilience Bill actually means
· Security Commentary
The biggest overhaul of UK security regulation since 2018 is in committee. MSPs are in scope, incident reporting gets a 24-hour clock, and fines go up to £17 million. Here's what it means in practice.
-
The free security awareness campaign you didn't know existed
· Security
The NPSA gives away a complete, professionally designed security awareness campaign kit. Posters, booklets, checklists, and a full starter guide. Most organisations don't know it exists.
-
Chrome's first zero-day of 2026: update now, don't wait
· Security Commentary
CVE-2026-2441 is actively being exploited in the wild. A use-after-free bug in CSS handling means a crafted webpage is all it takes. Push the update now.
-
Prompt injection is not the new SQL injection
· AI Security Commentary
Schneier and co have reframed prompt injection as 'promptware' — a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.
-
The first five minutes of incident response
· Security
Containment over correctness, reversibility over impact, protecting state before touching services. What your first five minutes should actually look like.
-
Patch your text editors
· Security Commentary
Notepad++ had its update service hijacked by state-sponsored attackers. Windows Notepad got a CVSS 8.8 command injection. Two editors, two attack vectors, same lesson.
-
Insecure defaults have a long half-life
· Security Commentary
Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass was disclosed. The protocol is old. The lesson is current.
-
What Cyber Essentials actually involves
· Security
A plain-English walkthrough of the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn't prove about your security.