1. ICS Tabletop Exercises: Why the Lessons Never Transfer to the Plant Floor

    An IT tabletop finds a process gap and the team rewrites the runbook. An ICS tabletop finds the same gap and the team can do nothing with it, because the person who would have to act on the gap is two floors down, on a different shift, under a different chain of command.

    ICS OT Security Tabletop

  2. How to Threat-Model a System You Have Never Seen Before

    Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does

    Threat Modelling

  3. What a CISO Actually Does on a Tuesday Afternoon

    The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice

    Threat Modelling

  4. How to Run a Purple Team Exercise When Nobody Has Done One Before

    Most purple team advice is written for teams that have done several. Here is the version for the team that is about to do their first one, in order, with the parts that most programmes get wrong

  5. Tabletop Exercises That Actually Prepare You for an Incident

    Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says 'we are well prepared.' Here is how to run one that is not theatre

    Blue Team

  6. Why Most Threat Intelligence Programmes Are Not Worth the Money

    Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work

    Threat Modelling

  7. The Red Team Engagement That Changed How I Think About Risk

    There is one engagement in my career that genuinely changed how I think about cybersecurity risk. It was not the most sophisticated operation I have run. It was not the most expensive. It was the one that taught me the most. Here is what it was and what it taught me

    Red Team

  8. What I Look For in a Red Team Report

    Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong

    Red Team

  9. Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts

    Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not

    Detection Engineering

  10. Adversary Emulation vs Penetration Testing: Why the Distinction Matters

    You paid €80,000 for a \"red team engagement.\" The report arrived with 47 findings, a 12-page executive summary, and a heat map of your network that looked like something out of a disaster movie

    Red Team

  11. How to Write a Purple Team Report That Actually Gets Read

    You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…

    Red Team Blue Team

  12. The 7 Most Pointless Findings in OT Pen Tests

    If you run enough OT pen tests, you start to notice a pattern. The report arrives, the client is confused, and the findings have a peculiar quality: technically correct, operationally impossible to remediate, and…

    OT Security ICS Pen Testing

  13. Purple Teaming OT: Why \"We Can't Test That\" Is No Longer Acceptable

    I keep hearing the same thing in conversations about operational technology security

    OT Security ICS Critical Infrastructure

  14. How to Scope a Red Team Engagement That Tells You Something Real

    Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent

    Red Team Threat Modelling

  15. Purple Teaming That Actually Works: A Framework for Real Collaboration

    You've got a red team and a blue team. They hate each other

  16. Why Your Red Team Tests Are Designed to Fail, And You Don't Know It

    Red team comes in on Monday. They've got a scope, a timeline, and a list of techniques to test. By Friday, they've \"successfully executed\" initial access, lateral movement, persistence, and exfiltration

  17. Detection Engineering in a Real Environment: Why Generic Rules Fail

    I walked into a SOC last month where they'd deployed 847 Sigma rules

  18. Your Purple Team Test Failed Because Your Threat Model Is Wrong

    You ran a purple team exercise last week. Your red team executed a flawless attack chain: initial access via phishing, lateral movement via Kerberos relay, privilege escalation, and data exfiltration. Picture perfect