cyber security Dealing with low hanging fruit Deal with the easy quick wins before you have an external testing team perform their audit.
cyber security My CISSP experience In early September 2020 I studied for the CISSP at an intensive six day course.
cyber security "We have conducted a review to ensure this never happens again" If you're going to claim to have "conducted a review" you need to make sure your response is appropriate and useful.
cyber security Dealing with Ransomware - a real life tale Thinking clearly during a ransomware attack is key, helping to save your data.
cyber security Permissions vs authority A discussion of the differences between "having permissions" and "having authority".
eVitabu Why we chose OAuth for eVitabu User authentication is an important consideration when designing any system. Here's how we decided to use OAuth for eVitabu.
conference Towards a safe and secure smart world (conference) A summary of my key take aways from January's conference.
cyber security Learning from cyber attacks Cyber attacks are a regular occurrence, and it's important that we learn from them.
cyber security Reusing paper - good for the environment, risky for privacy It's important to review the paper you re-use to avoid leaking confidential information.
cyber security Delegated trust vs Web of Trust The difference between the web of trust and delegating your trust to a third party.
cyber security Password cracking and how it can help your organisation Password cracking can be an invaluable tool when it comes to checking your organisation's password hygiene.
cyber security What is a Next Generation firewall? A look at Next Generation firewalls and the extra services they often provide.
cyber security Kent Cyber Security Forum 2019 A short write up following the Kent Cyber Security Forum 2019.
ethics A question of ethics: disclosing security vulnerabilities When you've found a vulnerability, bug or data leak how do you report it? This post looks at the considerations for disclosure.
ethics A question of ethics: investigating users Thoughts on being fair and considerate when investigating others.
System administration Logging: getting the right balance Logging: what's too much? Is there too little? How long should I keep them? This post discusses factors to consider when configuring logging.
development Avoiding direct object reference problems Discussing some of the ways to prevent insecure direct object reference issues.
cyber security Be wary of attackers bearing old emails Analysis of some obfuscated VBScript that a malicious email wanted us to download.
cyber security The threat of security knowledge gaps (conference slides) Slides from my recent conference talk on the threat of security knowledge gaps.
cyber security My journey (so far) to a cyber security career How I got into cybersecurity - the story so far.
cyber security What penetration tests have shown me Having worked with a few cyber security firms over the years, let's take a look at some of the findings.
forensics Show and tell: digital forensics and giving evidence After performing some forensics for the ICO I was called to give evidence in court. Here I discuss some basics of forensics before talking about my experience in court.
Google GSuite: Allowing users to publish files to the web (link sharing) Sharing files by link outside of your GSuite organisation can be restricted by GSuite administrators. This post shows how to do that.