-
ICS Tabletop Exercises: Why the Lessons Never Transfer to the Plant Floor
An IT tabletop finds a process gap and the team rewrites the runbook. An ICS tabletop finds the same gap and the team can do nothing with it, because the person who would have to act on the gap is two floors down, on a different shift, under a different chain of command.
-
How to Threat-Model a System You Have Never Seen Before
Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does
-
What a CISO Actually Does on a Tuesday Afternoon
The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice
-
How to Run a Purple Team Exercise When Nobody Has Done One Before
Most purple team advice is written for teams that have done several. Here is the version for the team that is about to do their first one, in order, with the parts that most programmes get wrong
-
Tabletop Exercises That Actually Prepare You for an Incident
Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says 'we are well prepared.' Here is how to run one that is not theatre
-
Why Most Threat Intelligence Programmes Are Not Worth the Money
Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work
-
The Red Team Engagement That Changed How I Think About Risk
There is one engagement in my career that genuinely changed how I think about cybersecurity risk. It was not the most sophisticated operation I have run. It was not the most expensive. It was the one that taught me the most. Here is what it was and what it taught me
-
What I Look For in a Red Team Report
Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong
-
Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts
Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not
-
Adversary Emulation vs Penetration Testing: Why the Distinction Matters
You paid €80,000 for a \"red team engagement.\" The report arrived with 47 findings, a 12-page executive summary, and a heat map of your network that looked like something out of a disaster movie
-
How to Write a Purple Team Report That Actually Gets Read
You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…
-
The 7 Most Pointless Findings in OT Pen Tests
If you run enough OT pen tests, you start to notice a pattern. The report arrives, the client is confused, and the findings have a peculiar quality: technically correct, operationally impossible to remediate, and…
-
Purple Teaming OT: Why \"We Can't Test That\" Is No Longer Acceptable
I keep hearing the same thing in conversations about operational technology security
-
How to Scope a Red Team Engagement That Tells You Something Real
Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent
-
Purple Teaming That Actually Works: A Framework for Real Collaboration
You've got a red team and a blue team. They hate each other
-
Why Your Red Team Tests Are Designed to Fail, And You Don't Know It
Red team comes in on Monday. They've got a scope, a timeline, and a list of techniques to test. By Friday, they've \"successfully executed\" initial access, lateral movement, persistence, and exfiltration
-
Detection Engineering in a Real Environment: Why Generic Rules Fail
I walked into a SOC last month where they'd deployed 847 Sigma rules
-
Your Purple Team Test Failed Because Your Threat Model Is Wrong
You ran a purple team exercise last week. Your red team executed a flawless attack chain: initial access via phishing, lateral movement via Kerberos relay, privilege escalation, and data exfiltration. Picture perfect