Blog
Straight-talking security and compliance writing.
No vendor fluff and no unsourced statistics — every figure is checked against a primary source before we publish it. 11 articles across 5 topics.
Your website’s busiest reader
We pulled a month of raw server logs to answer a boring question — how many people actually read this? — and needed three attempts, because the first two were wrong in ways most analytics setups are also wrong.
Penetration TestingThey do the homework
The first phase of a real attack leaves no trace on your side, because it never touches you. It is done entirely with public records — most of which you created on purpose.
ComplianceYour register says that control works.
A control marked verified and a Critical finding against that same control can coexist for months, in two systems, without anybody noticing. Not because either is wrong — because nothing is looking.
ComplianceFour regulators,
A bank subject to the RBI framework is often also subject to the CERT-In Directions. An insurer answers to IRDAI and CERT-In. Running these as separate programmes is how organisations end up with four binders and one unevidenced control.
ComplianceThe answer was true in March.
Automating questionnaire answers is easy. Keeping them true is the part nobody builds — and the part that turns a sales convenience into a contractual liability.
ComplianceThe DPDP Rules, 2025:
The Act was passed in 2023. The Rules are what made it operable. A clause-level read of what actually changed on 13 November 2025 — and why the commencement dates are written into rule 1.
ComplianceSOC 2 or ISO 27001?
Enterprise buyers demand proof of security before they sign. How SOC 2 and ISO 27001 compare in 2026, and which to choose first.
AI GovernanceThe $6 million blind spot:
IBM’s 2026 data shows one in four breaches are now AI-enabled, with shadow AI a top blind spot. What the numbers reveal, and how to govern AI.
CryptographyHarvest now, decrypt later:
Attackers steal encrypted data today to crack it with tomorrow’s quantum computers. What “harvest now, decrypt later” means, and how to start migrating.
AI SecuritySecuring the agents:
AI agents can act, not just answer — and that changes your attack surface. What the OWASP Top 10 for Agentic Applications 2026 means, and how to defend.
ComplianceIndia’s DPDP countdown:
India’s DPDP Rules 2025 are now law. Here’s the phased timeline, the ₹250-crore penalty risk, and a practical compliance checklist to be ready before May 2027.
Stay ahead
Have a question this didn’t answer?
Every article here started as a question a client asked us. If yours isn’t covered yet, ask us directly — thirty minutes, no charge, no obligation.