$ ls writing/ -lt
writing.
Notes from the desk, not thought leadership. Specifics over slogans. If a piece couldn't earn its keep at a kitchen table, it didn't make it here.
Total · 155 pieces
Latest · 2026·08·18 Page · 2 / 7 Locale · en_GB
License · CC BY 4.0
2026·07·17
Patch FortiSandbox by Sunday: when the security appliance is the hole CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target. patching · vulnerability management · threat intel
7 min
2026·07·17
The TfL hackers were teenagers. Unusually, they were caught. Two young Britons — Thalha Jubair, 20, and Owen Flowers, 18 — jailed five and a half years each for the 2024 Transport for London attack: £29m of damage, 148 systems down, done with social engineering. The UK's largest cybercrime case — and, unusually, they were caught. threat intel · law enforcement · social engineering
8 min
2026·07·16
Children and social media in 2026: the conversation now Revisiting the 2023 post on social media. The platforms have changed. The Online Safety Act has taken effect. Australia banned under-16 social media. The Smartphone Free Childhood movement has changed what is socially possible. privacy · children · social media · update
8 min
2026·07·16
The Qantas breach was a phone call: what we know A living account of the Qantas breach, now pinned on a tech-support scam. No zero-day — a phone call to a contact centre exposed 5.7 million customers. What's confirmed, what's still unproven, and the help-desk controls that actually stop it. Updated as it develops. data breach · social engineering · incident response
10 min
2026·07·15
Six hundred patches, two emergencies, and one broken Dell Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic. patching · vulnerability management · craft
9 min
2026·07·11
It wasn't a misdirected email: the NHS Forth Valley breach The headlines called it an email blunder. It wasn't — a staff member moved a spreadsheet of 150 maternity patients' data to their own personal inbox. Why that distinction matters, where NHS Scotland keeps going wrong, and the controls that actually stop it. data protection · privacy · insider risk
10 min
2026·07·11
Quantum computing: the machine that doesn't exist yet Does quantum computing really work, is the threat real, and is any of it viable? A straight answer: real physics, a threat deferred but already forcing your hand through harvest-now-decrypt-later, and a defence that is standardised, hybrid, and already running in your browser. quantum · cryptography · craft
9 min
2026·07·11
The week in cyber — 6 to 10 July 2026 Whitehall credentials for sale after a Fortinet campaign that needed no zero-day, a voluntary pledge launched at Number 10 that most of the FTSE ignored, the Bank of England naming frontier AI as a stability risk, and npm about to break your build on purpose. weekly · governance · ned · board
7 min
2026·07·11
Three weeks with the door open A cybercrime crew backdoored 25,000 websites using nothing but public exploits — then left its own server open on the internet for three weeks. The exposed working directory shows an adversary far less polished, and far more industrialised, than its victims imagined. threat intel · web security · craft
8 min
2026·07·09
Five shifts for cyber resilience in an AI-driven world The long-form version of a panel talk — five shifts AI forces on cyber resilience and assurance: assure the model not just the infrastructure, AI as threat and shield, a supply chain reaching upstream into the model, the accountability gap, and sovereignty at the edge. AI · assurance · defence
8 min
2026·07·09
Ghosts and runners: living off GitHub Attackers have stopped bringing their own infrastructure and started borrowing GitHub's — dormant accounts aged for years to blend in, and CI runners turned into backdoors. A look at the ghost-account and hijacked-runner campaigns, and the dull controls that would stop them. supply chain · threat intel · craft
8 min
2026·07·06
Everyone in the shop is a suspect Sainsbury's is tripling its Facewatch facial recognition, scanning every shopper's face against a private watchlist to catch a few. It's biometric special-category data, the ICO's own guidance calls it the hardest case to justify, and 'it works' is not the same as 'it's lawful.' privacy · surveillance · data protection
11 min
2026·07·04
The week in cyber — 29 June to 3 July 2026 A CitrixBleed sequel exploited within a day, on-prem SharePoint on a patch clock that runs out today, the police pricing UK ransomware and asking you not to pay, and the Cyber Security and Resilience Bill heading for the Lords. weekly · governance · ned · board
6 min
2026·06·29
The week in cyber — 24 to 28 June 2026 Cisco phone systems, an engineering PLM vault and the Linux kernel each turned into a route to root in the same week — against a CISA patch deadline that fell on Sunday. weekly · governance · ned · board
5 min
2026·06·25
School edtech in 2026: the lay of the land Updating the 2023 post on school accounts and edtech, three years and one AI cycle later. What schools collect now, what the regulator has done, and the new category that did not exist in 2023 — AI tutors, AI markers, AI safeguarding tools. privacy · children · school · edtech · update
7 min
2026·06·23
Making it stick: the second-half-of-2026 roadmap Part four: making the strategy run — tested backups, a rehearsed incident plan, metrics a board will read, and a month-by-month roadmap to be certified and rehearsed by Christmas. cyber essentials · iso 27001 · small business
9 min
2026·06·21
Least certain exactly where it has to decide: the Home Office age guesser A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone. ai governance · privacy · data protection · biometrics
6 min
2026·06·20
FortiBleed: your firewall, turned into a wiretap An update on the FortiGate exploitation story. SOCRadar's dismantling of FortiBleed shows 430,000 firewalls targeted and 110 million credentials harvested — by turning the appliance's own diagnostics into a credential tap. A board read, then the technical detail. fortinet · credential theft · threat analysis · board
8 min
2026·06·20
Prinz Eugen: the ransomware that takes your newest work first A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown. ransomware · threat analysis · technical · board
15 min
2026·06·20
The week in cyber — 15 to 19 June 2026 The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account. weekly · governance · ned · board
6 min
2026·06·19
Breached without being touched: the Klue attack and the case for digital sovereignty Two security firms were caught in a data theft this week without an attacker going anywhere near their systems. The way in was a sales tool they had connected to their CRM themselves. This is the clearest argument I have for owning your stack that I have seen in a while. supply chain · saas · digital sovereignty · oauth
8 min
2026·06·19
The criminals have a product team now: The Gentlemen and the industrialised EDR-killer A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model. ransomware · byovd · endpoint · board
6 min
2026·06·16
From self-assessment to assurance: Cyber Essentials Plus and ISO 27001 Part three: turning a self-assessment into assurance. What Cyber Essentials Plus actually tests on your real machines, and how to build a proportionate ISO 27001 management system that keeps the controls alive. cyber essentials · iso 27001 · small business
8 min
2026·06·13
The week in cyber — 8 to 12 June 2026 Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other. weekly · governance · ned · board
6 min
2026·06·09
The five controls that do most of the work Part two: the five Cyber Essentials controls one by one, what the Danzell question set now demands of each, the mistakes that fail firms at assessment, and how each maps onto its ISO 27001 counterpart. cyber essentials · iso 27001 · small business
9 min
$ grep -l tag:* | sort | uniq
Browse by tag — filtering applies to the list above.