At full delivery capacity until the end of 2026.
Blog
Articles
Your First Security Hire Should Not Be Full-Time
Small companies handling sensitive data need real security. A full-time senior hire is usually the wrong first move, and here is why.
You Spent on Security. Did It Work? Metrics Every SME Should Track
Most SMEs buy security without knowing whether it worked. A small, decision-focused set of metrics that shows if you are harder to attack.
The EU AI Act for Small Companies: What You Actually Have to Do
A plain-English starter on the EU AI Act for SMEs. If your company uses AI tools rather than builds them, here is what actually applies.
How to Scope a REST API Penetration Test (and Pay Less for a Better One)
What your API pentest actually needs from you. Bring two documents and the test gets cheaper, faster and more useful. Skip them and you pay for guesswork.
What Security Actually Is: A Guide for People Who Never Wanted to Learn It (Part 1)
Information security, cyber security, the CIA triad and CIS Controls, explained for business owners with no IT background.
Insider Risk for SMEs: You Don’t Have to Be Hacked to Lose Data
Staff, contractors, suppliers and leavers can expose company data by mistake or misuse. How SMEs cut insider risk with better access controls.
Your Enterprise Customer Will Not Wait Until Your Security Is Ready
Enterprise customers ask small vendors for security evidence long before there is a security team. How a retained advisor closes that gap.
Leaving Microsoft 365 for Proton: A Practical Sovereign Stack Test
Why I am testing Proton as a more sovereign European workspace: what improves, what may hurt, and how SMEs should approach migrations.
Shadow AI: The Risk Is Secrecy, Not AI Itself
Employees use AI because it helps them work faster. The security risk starts when policies are unclear and usage goes underground.