Blog

Cybersecurity analysis, threat intelligence, and IT governance insights.

Network Segmentation and VPN for Critical Infrastructure
Cybersecurity8 min read

Network Segmentation and VPN for Critical Infrastructure

In critical infrastructure a network breach is not a data problem, it is a physical one. Here is why segmentation is the control that keeps a compromised laptop away from a turbine, and why the VPN meant to protect the network is so often the way in.

Read more →
Critical InfrastructureNetwork SegmentationVPN
LastPass Proves That Penetration Testing Must Cover Your Cloud Environment
IT Audit8 min read

LastPass Proves That Penetration Testing Must Cover Your Cloud Environment

LastPass was breached twice in 2022. The second breach exploited a DevOps engineer's home computer to reach cloud backups that held encrypted vaults for 33 million users. Periodic security assessments of the cloud environment should have identified the path. They did not.

Read more →
Periodic Security AssessmentITGCPenetration Testing
How a Flat Network Let Attackers Hide in Marriott for Four Years
IT Audit8 min read

How a Flat Network Let Attackers Hide in Marriott for Four Years

When Marriott acquired Starwood in 2016, they inherited a compromised network. Because the two environments were poorly segmented, attackers moved freely for four years. Network Architecture is the control that determines how far a breach can travel.

Read more →
Network ArchitectureITGCNetwork Segmentation
SolarWinds and the Firewall Rules Nobody Reviewed
IT Audit8 min read

SolarWinds and the Firewall Rules Nobody Reviewed

The SolarWinds SUNBURST attack compromised 18,000 organisations. The malware called home for months. Egress filtering and network security controls should have caught it. Here is what was missing and what auditors check.

Read more →
Network Security ControlsITGCFirewall
Understanding the Cost of Data Breaches
Cybersecurity6 min read

Understanding the Cost of Data Breaches

Key insights from IBM's Cost of a Data Breach report: healthcare leads at $10.1M per breach, while AI platforms, DevSecOps, and incident response teams can significantly cut costs.

Read more →
Data BreachIBMCost Analysis
Boss of The SOC V3 Timeline
Tutorial6 min read

Boss of The SOC V3 Timeline

A chronological account of the BOTSv3 security incident on 20 August 2018, categorised by MITRE ATT&CK tactics, from initial access and phishing through to exfiltration and a Memcached DDoS attack.

Read more →
MITRE ATT&CKBOTSv3Incident Response
Exploring Zero-Day Vulnerabilities
Cybersecurity5 min read

Exploring Zero-Day Vulnerabilities

A vendor-based analysis of zero-day vulnerabilities from 2006 to 2023, revealing which companies are most associated with exploitable weaknesses, and what organisations can learn from the patterns.

Read more →
Zero-DayVulnerabilitiesMicrosoft
Governance: A Cybersecurity Lifeline for SMEs
Cybersecurity4 min read

Governance: A Cybersecurity Lifeline for SMEs

How cybersecurity governance frameworks help small and medium enterprises identify, assess, and manage risks, and why the most impacted businesses in Australia are often the ones with the least protection.

Read more →
GovernanceSMECybersecurity
ITGC Audit Tool

Streamline Your IT General Controls Audits

The RACM ITGC SaaS platform helps audit professionals manage IT General Controls assessments, from risk and control mapping to workpaper generation and evidence tracking.