Fifteen minutes for Microsoft 365. Fifteen for your firewall. Thirty for a weekly review process. Here is the practical logging guide your IT provider should have given you.
Two financially-motivated threat groups are running active campaigns that should concern every UK business with a helpdesk, a SaaS stack, or customers whose data you hold.
Blockchain-based C2 infrastructure, an actively exploited cPanel flaw, and an extortion gang that now shows up in person. Mauven explains what the advisories are not telling you.
Three separate threats with direct SMB exposure landed today. One targets Microsoft 365 credentials, one hits developers and their clients, and one is already being exploited in the wild.
You do not need a six-figure SOC to spot attackers. You need the same thing Clifford Stoll had in 1986: curiosity, logs, and a refusal to ignore what looks wrong.
A 75-cent billing error. One stubborn astronomer. A KGB spy ring. The Cuckoo's Egg is 37 years old and its lessons still embarrass most UK small businesses.
Vendors want to sell you fear. Consultancies want to sell you compliance. The most effective security tool costs nothing. It is the willingness to say: that looks wrong.
Active exploitation of Drupal's SQL injection flaw began within 48 hours of disclosure. If your website or your supplier's runs Drupal, this is not a drill.
A social engineering phone call. A password reset. £300 million in losses. The M&S DragonForce attack is the most expensive lesson in UK retail cyber security history.
A malware-signing service is making ransomware harder to detect. npm packages with millions of downloads are compromised. And Cisco just patched a perfect-10 vulnerability.
TPM plus PIN BitLocker is one Group Policy change, one command per device, and a Tuesday of user communication. The whole job fits in two weeks. Here is how.