Journal

TitleDateExcerpt
Using Threat Feeds to Update Remediation Playbooks in Real TimeThreat intelligence is most valuable when it changes what a security team does. A feed that merely adds indicators to a dashboard may improve awareness, yet it…
Building a Triage Protocol for Suspected Data ExfiltrationWhen an organisation suspects that sensitive records are leaving the network, the first hour shapes everything that follows. A triage protocol for suspected…
The Pitfalls of Manual Remediation in Large-Scale CyberattacksModern cyberattacks rarely stay contained to a single system. Once an adversary crosses the perimeter, they pivot through file shares, identity providers,…
Sorting the signal from the noise when every alert demands attentionAn Australian SOC analyst at 2am AEST in Sydney logs into the queue and sees 4,200 open alerts. Eight different sensors are firing - EDR, network detection,…
Securing Third-Party Access During Incident ResponseWhen a cyberattack is unfolding, outside specialists can provide the expertise and capacity an internal team lacks. A forensic investigator may need access to…
Credential theft and the limits of multi-factor authenticationAustralia's enterprise security teams have spent the better part of a decade rolling out multi-factor authentication as a frontline defence against stolen…
Deception technology and the post-breach detection gap in AustraliaWhen an adversary crosses the perimeter of a corporate network, the assumptions defenders relied on at design time stop holding. Firewalls, endpoint protection…
Threat hunting as a faster path to breach remediationA breach rarely follows a neat sequence from initial access to detection, investigation and recovery. Attackers may remain quiet for weeks, use legitimate…
Incident response runbook essentials for SaaS platformsWhen a security incident hits a software-as-a-service platform, the difference between a contained event and a front-page breach usually comes down to how well…
Reining in lateral movement across cloud-hybrid estatesWhen a finance team in Sydney signs into a SaaS workload at 8am local time and a sysadmin in Perth rotates a token for a Kubernetes cluster a few minutes…