Active Directory: The 8 Most Common Attack Paths
Kerberoasting, AS-REP roasting, password spraying, ACL abuse and the rest. What an attacker looks for in AD, and how to take it away from them.
Read articleExpert perspectives on cybersecurity trends, NIS2 compliance, OT security and the evolving threat landscape, from the ARLITECH team.
Kerberoasting, AS-REP roasting, password spraying, ACL abuse and the rest. What an attacker looks for in AD, and how to take it away from them.
Read articleMost incident investigations fail because the decisive log is missing or already rotated. Which sources to collect from, what to capture, and how long to keep it.
Read articleA flat internal network is the most expensive legacy. Which four segments to start with, what client isolation means, and how to avoid the first outage.
Read articleHow large a fine the authority can impose for NIS2 failures, the escalation ladder an investigation follows, and the personal liability of the management body.
Read articleWhy mandatory 90-day rotation is wrong, what the right length rule is, and how to roll out a password manager people actually use.
Read articleHow a modern ransomware attack actually unfolds, which controls genuinely stop it, and what to do in the first hours once it has happened.
Read articleThe reference standard for industrial cybersecurity explained: what the zone-and-conduit model means, how to set Security Levels, and where a plant should start.
Read articleA classic VPN hands over the whole network. What Zero Trust Network Access does differently, what migration costs, and when it is not worth it.
Read articleHow to stop anyone sending mail in your company name. What each record does, the rollout order, and the most common mistakes.
Read articleWhy conventional antivirus and EDR fail on the plant floor, and the principles OT-specific endpoint protection is built on, illustrated with txOne Networks tooling.
Read articleWhat separates EDR from classic antivirus, what to look for when selecting, and why most deployments fail on operations rather than technology.
Read articleWhy the classic 3-2-1 rule is not enough against ransomware, what immutable backup means, and how to actually test restoration.
Read articleMost cloud incidents are not the provider failing but configuration. Exposed storage, over-broad permissions, missing logging.
Read articleHour by hour: what to do and what to avoid from discovery to regulatory notification, and why preserving evidence is the most important early decision.
Read articleAdmin accounts are the primary target. What PAM solves, when just-in-time access is enough, and where to start with no budget.
Read articleModern phishing is no longer given away by bad spelling. Which techniques work, what to teach staff, and which technical controls actually catch it.
Read articleWhich ten group policy settings deliver the most protection, what to disable immediately, and how to roll it out without breaking anything.
Read articleSSH configuration, privileges, service minimisation and logging. The eight steps that deliver the most protection on a server.
Read articleNIS2 measure area four extends your responsibility to your suppliers. How to build supplier risk assessment, contractual requirements and continuous oversight.
Read articleMost insider risk is not malice but negligence. What signals to watch, and how to address it without building distrust.
Read articleSMS, app codes, push, hardware keys: what each method protects against and what it does not, where to start rollout, and how to defeat MFA fatigue.
Read articleThe most important OWASP Top 10 items explained: broken access control, injection, authentication. What a pentester tests and what to fix first.
Read articleAPIs are more exposed than web applications because no interface constrains usage. Authorisation, rate limiting, version management.
Read articleWhy the CVSS score alone misleads, what EPSS and the KEV catalogue add, and how to build a working patch process including in OT environments.
Read articleMost of a modern application is third-party code. How to know what is in it, and what to do when a component vulnerability appears.
Read articleHow to turn Zero Trust principles into real steps: identity, device posture, micro-segmentation and least privilege, on a realistic timeline.
Read articlePrompt injection, data leakage, shadow AI and the privileges granted to the model: what to consider before letting AI into your processes.
Read articleThe types of denial-of-service attacks, what your provider handles, and what you must solve yourself. Preparation without a plan is not measurable.
Read articleData at rest, in transit and in use. What encryption protects against in each case, and what people commonly get wrong about it.
Read articleNetFlow, NDR and traffic analysis. Why network visibility is needed alongside endpoint protection, and where to start without a dedicated tool.
Read articleWhen an organisation needs a SIEM, which log sources to start with, how to avoid alert flooding, and what it really costs.
Read articleCorporate or personal device, MDM or application-level protection. Which model works when, and what to do when a device is lost.
Read articleYou do not need a full DevSecOps programme. Which five steps deliver the most protection in development, and what merely slows teams down.
Read articleThe difference between vulnerability scanning and penetration testing, how often to test, and how to recognise a report that is actually worth having.
Read articleWhy a shared password is not enough, what 802.1X provides, and how to separate guest, corporate and device networks.
Read articleImages, runtime privileges, network policies and secrets. The six settings that deliver the most protection in a containerised environment.
Read articleWhy the IT security toolkit does not work on the plant floor, and how to build an OT security programme around the IEC 62443 zone-and-conduit model.
Read articleA practical NIS2 checklist: determining whether you are in scope, the ten mandatory measures, incident reporting deadlines and management liability, step by step.
Read article