Editorial Policy

Last updated: 18 July 2026

MarcoWeb publishes analysis of cybersecurity incidents, threat actors, and IT General Controls for auditors, security professionals, and the organisations they protect. This page explains who writes that content, the standards we hold it to, and how to flag a correction. We publish it because trustworthy security guidance depends on knowing where it comes from.

Who writes and reviews this content

All content on this site is written and reviewed by Marco Cavani, a cybersecurity professional and IT governance specialist who works in IT audit and information security. Marco specialises in IT governance, threat intelligence, and information security risk management, and built the ITGC Audit Tool used in IT audit and compliance engagements. Every article and report carries his byline because he stands behind its technical accuracy.

Where a post covers a control area or framework, it is written from the perspective of how an IT auditor would actually assess it in practice, not as abstract theory.

Sourcing standards

Our breach case studies and control analyses are built on publicly available, reputable primary sources. Where we describe an incident or cite a standard, we draw on authorities such as:

  • Government and law enforcement, the FBI, CISA, the Australian Cyber Security Centre (ACSC), and equivalent agencies;
  • Standards and frameworks, NIST, ISO/IEC 27001, COBIT, and the Australian Government's PSPF;
  • Industry research, vendor and analyst reporting such as IBM Security's Cost of a Data Breach, and other well-documented, verifiable research;
  • Official disclosures, regulatory findings, court records, and public statements from the affected organisations.

We prioritise primary and official sources over second-hand reporting, and we describe incidents based on what has been publicly established rather than speculation.

Accuracy and review

Draft articles are reviewed for technical accuracy before publication. Because security details matter, we aim to represent how attacks actually happened and how controls are genuinely tested. Where the full picture of an incident is contested or still emerging, we say so rather than presenting uncertainty as fact.

Corrections policy

We correct errors promptly and transparently. If you believe something we have published is inaccurate, incomplete, or out of date, email marco@marcoweb.org with the page and the specifics. Substantive corrections that change the meaning of a piece are noted on the article itself; minor fixes (typos, broken links) are made without a formal note.

Independence and advertising

Editorial decisions are made independently of any advertising shown on this site. This site displays advertising through Google AdSense and links to the author's own ITGC Audit Tool; neither of these influences the analysis or conclusions in our content. Where a post references our own tool, we say so plainly. We do not accept payment to alter the findings of a report or case study.

A note on our breach reporting

Our incident case studies exist to help defenders and auditors learn from what went wrong. They explain the governance and control failures behind real breaches so that others can avoid them. They are written for defence, not offence, and are consistent with our Terms of Service.

Contact

Questions about our editorial standards, or a correction to raise?

Marco Cavani

MarcoWeb.org

marco@marcoweb.org