UK insurers increasingly ask for evidence of penetration testing before they will quote or pay out on cyber cover. Here is what they actually require and how to get ready …
Risk Management
-
-
A Microsoft-signed EDR killer driver evaded Microsoft’s own blocklist. Signed was never the same as safe, and this case is why the difference matters.
-
A cyber security risk assessment ranks your threats by likelihood and impact so security spending goes where it matters most. Here is what it covers, who needs one, and how …
-
An insider threat comes from someone who already has legitimate access to your systems. Here’s what the main types are, what they cost, and how to reduce your risk.
-
Banning shadow IT rarely works. Here’s why the NCSC recommends a no-blame approach, what actually reduces unsanctioned tech, and how it changes what your penetration test should cover.
-
CVE-2026-58048 is being downplayed as low risk because it needs an existing account. On shared hosting, that’s exactly the wrong conclusion to draw.
-
Citrix called CVE-2026-8452 a memory overflow. It turned out to be an unauthenticated root exploit, and that gap says something about how patch priority gets set.
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Threat modelling is how you work out where a system could be attacked before it’s built or tested. Here’s how it works, the main methodologies, and how it relates to …
-
A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.