Field notes from the offensive side.
Deep, practical writing on how systems actually get broken, and how to keep them whole. No filler, no vendor spin. Analysis you can cite, from a firm that does the work.
The cybersecurity challenge facing small island states
Concentrated high-value targets, thin connectivity, and a talent gap. Why the Indian Ocean faces a distinct threat, and what a proportionate response looks like.
Why "Welcome1" is still breaching banks in 2026
Vendor default credentials remain one of the most reliable ways into a critical system. Why they survive, and how to hunt them out of your estate.
Your API is a map. Stop handing it out.
Unauthenticated blueprints and over-sharing endpoints give an attacker the whole floor plan before they try a single door. What to lock down first.
A pentest report your board will actually read
Findings nobody acts on are wasted findings. How one document can serve both the engineer who fixes the issue and the board that funds the work.
The attacks that actually happen.
A plain-language field guide to the attack classes we hunt on every engagement, grounded in OWASP and MITRE ATT&CK.
How each attack works, what it costs, how we test for it, and how to defend. Written for the people who make the decisions.
Read the reference →