Latest analysis
Articles from the field, not the marketing deck.
Direct cyber security and infrastructure commentary based on operational reality, implementation quality and what happens when the policy slide deck meets the actual environment.
-

You Cannot Report Your Way Out of Poor Security
Metrics matter. Stats-for-stats’-sake is where cyber work goes todie. There is nothing wrong with measuring cyber security. A serious security function needs evidence. It needs to know whether alerts arebeing handled, whether vulnerabilities are being remediated,…
-

Cornflake Box Cyber Degrees, when speed becomes a security risk
“Cornflake box degrees” is a rude little phrase, but it points at a real pattern, credentials that look respectable on a CV, yet represent far less learning than the label implies. In UK cyber security, where…
-

The CrowdStrike Patch Problem: A Cautionary Tale
(Moved from old site: Originally published 22 Nov 2024) In the fast-paced world of cybersecurity, even industry leaders can occasionally stumble. In 2024, CrowdStrike—a company renowned for its cutting-edge endpoint security—faced an unexpected issue with a…
-

The Double-Edged Sword of Security Scorecards
(Moved from old site. Originally posted June 23, 2025) Transparency or Reconnaissance-as-a-Service? In today’s hyperconnected digital ecosystem, security scorecards have emerged as tools for evaluating and publicising an organisation’s cybersecurity posture. Built on publicly accessible data,…
-

When Companies Ignore Their Security Teams: A Costly Disconnect
(Moved from old site. Originally posted June 25, 2025) Organisations often treat cybersecurity as an afterthought, especially if it conflicts with business goals. This can create a dangerous disconnect between security operations (SecOps) teams and management. Instead of…
-

Riding the Cybersecurity Startup Bandwagon: Half-Baked Products and Unintended Risks.
The cybersecurity market has become a hotbed of venture investment and hype, spurring a flood of startups pursuing the latest trends, from AI-powered detection to Extended Detection and Response (XDR) platforms. In 2020 alone, investors poured…
-

Certifiably Secure? “Tick-box tooling” and the Illusion of Compliance in Modern Cybersecurity Certification
(Moved from old site. Originally posted 26 June 2025) IntroductionAcross the UK, and globally, organisations increasingly pursue certifications such as ISO/IEC 27001 and Cyber Essentials as visible signals of trust. In theory, that is sensible. Buyers…
-

ManageEngine Log360, From Clunky Beginnings to a Respectable SIEM Solution
(Moved from old site. Originally posted June 23, 2025, with Updated content December 18, 2025) I first started using ManageEngine products after a job change around 2021. Log360 was part of the toolset I inherited, and…
