Insights
Practical guidance from the people doing the work
Written by the engineers who run and defend production environments. We publish the things we find ourselves explaining repeatedly, in the detail we would want if we were the buyer.
Security Assessment
Cyber Insurance Controls Insurers Expec
Cyber insurers increasingly ask about practical security controls. Here is what businesses should have ready before applying, renewing or answering an insurer's questions.
8 min read
Read articleManaged IT
Patching in the Real World
Patching is more than installing updates. Learn how businesses should prioritise, test, deploy and verify patches without creating unnecessary disruption
8 min read
Read articleManaged IT
Questions to Ask Before Signing With an MSP
Choosing an MSP is not just about price. Ask these practical questions about responsibility, security, support, tools and contracts before you sign
8 min read
Read articleMicrosoft 365
Conditional Access Explained Simply
Conditional Access can turn Microsoft 365 sign-in rules into practical security controls. Here is what to configure, what to avoid and how to roll it out safely.
8 min read
Read articleAI Security
How to Secure AI Agents Before They Access Business Data
AI agents can now access files, applications and business systems. Learn the practical controls needed before giving an agent real permissions.
5 min read
Read articleManaged IT
What 24/7 Monitoring Really Means
True 24/7 monitoring is more than alert emails. Learn what continuous IT monitoring should include, where its limits are, and how to judge whether it is working
15 min read
Read articleManaged IT
What a Managed IT Contract Should Include
A managed IT contract should define responsibility, response times, security, maintenance and exclusions clearly. Here is what to check before signing an MSP agreement.
10 min read
Read articleData Protection
How Often Should You Test Your Backups?
A backup is only valuable if you can restore it. Learn how often to test backups, what to restore and the mistakes that cause recovery failures.
10 min read
Read articleEndpoint Security
EDR vs Traditional Antivirus: What's the Difference?
Antivirus alone no longer stops many modern attacks. Learn how EDR differs, what each tool does and which approach suits your business.
10 min read
Read articleMicrosoft 365
Why Your Microsoft 365 Security Still Has Gaps
Most Microsoft 365 compromises happen because security features are left unconfigured. Learn what to check first and what actually matters.
5 min read
Read articleMicrosoft 365
Why Microsoft 365 Still Needs Its Own Backup
Microsoft 365 includes resilience and recovery features, but they are not a complete backup strategy. Learn where the gaps are and how to reduce recovery risk.
8 min read
Read articleSecurity Assessment
Twelve questions to ask a penetration testing vendor before you sign
Penetration testing quality varies enormously and the reports look similar. These twelve questions separate genuine manual testing from an automated scan with a cover page.
8 min read
Read articleData Protection
What immutable backup actually stops, and what it does not
Immutable backup is the single most effective control against ransomware, but it is widely misunderstood. Here is what it genuinely prevents, where it fails, and how to verify yours works.
7 min read
Read articleIT Strategy
MSP vs in-house IT team: how to actually decide
A practical comparison of managed service providers and in-house IT teams, covering real cost, coverage, risk concentration and the co-managed middle ground most organisations end up choosing.
9 min read
Read article
Want this applied to your environment?
Most of what we write about started as a problem in a real client estate. If any of it sounds familiar, we can look at yours.
