Security Notes & Case Studies
Write-ups from real engagements, and practical guidance on the threats actually hitting small and mid-sized businesses right now.
All Posts
Secure Remote Access: What to Actually Set Up Instead of Forwarding RDP to the Internet
Needing to reach a machine remotely is normal. Forwarding RDP straight through your router so anyone on the internet can try to reach it isn’t — here’s what to do instead.
Incident ResponseCase Study: Recovering a Business After a Publicly Exposed RDP Server Was Taken Over and Wiped
A publicly forwarded RDP port, no other way in needed, and the client’s only backup living on the exact machine that got wiped. Here’s how the recovery actually went.
Incident ResponseCase Study: Removing a ClickFix Malware Infection From a Compromised WordPress Site
A walkthrough of a real WordPress clean-up: ClickFix-style fake-verification malware, multiple malicious plugins, hidden backdoors, a rogue admin account, and the hardening that stopped it from coming back.
WordPress Security9 Signs Your WordPress Site Has Been Hacked (and What to Do First)
From unfamiliar admin accounts to sudden search-engine warnings, here are the signs that mean your WordPress site needs an incident response, not just a quick fix.
Managed SecurityWhy Small Businesses Are Prime Ransomware Targets — Not Just Big Enterprises
The "we’re too small to be a target" assumption is exactly what makes small businesses an efficient target for ransomware operators.
Penetration TestingPenetration Testing vs. Vulnerability Scanning: What’s Actually the Difference
A scanner tells you what might be exploitable. A penetration test tells you what actually is — and the difference matters for budget and compliance decisions.
Incident ResponseIncident Response: What Should Actually Happen in the First 24 Hours
The first 24 hours after discovering a breach determine most of what happens next — here’s the order that actually reduces damage.
Email SecuritySPF, DKIM, and DMARC: What They Actually Do and Why Half of Small Business Email Is Still Unprotected
Three records that decide whether an attacker can send email that looks like it came from you — and why so many small businesses have them missing or misconfigured.
Identity SecurityMulti-Factor Authentication: Why SMS Codes Are the Weakest Option, Not the Safe Default
MFA dramatically cuts account-takeover risk, but not all MFA is equal — SMS codes are the version most vulnerable to interception and SIM-swap attacks.
Vulnerability ManagementPatch Management: Why "We Update on Patch Tuesday" Isn’t a Full Strategy
Patch Tuesday covers Windows and Microsoft products. It says nothing about your third-party software, network devices, or the servers running your business.
Network SecurityVPN vs. Zero Trust Network Access: What Actually Changes for a Small Business
Zero Trust is genuinely useful, but it’s not automatically the right move for every business still running a traditional VPN.
WordPress SecurityA WooCommerce Security Checklist That Goes Beyond "Install a Security Plugin"
WooCommerce security is WordPress security plus payment data, checkout flow, and PCI scope — a single security plugin doesn’t cover all of that.
Penetration TestingWhat a Phishing Simulation Actually Tests (and What It Doesn’t)
Click-rate is the number every phishing simulation report leads with, and it’s also the least useful metric in it.
Cloud SecurityThe Cloud Misconfigurations We Find Most Often in AWS and Azure Audits
Most cloud breaches aren’t sophisticated exploits — they’re a handful of recurring configuration mistakes we see across almost every audit.
Threat DetectionEDR vs. Traditional Antivirus: What the Upgrade Actually Buys You
Antivirus asks "is this file known-bad?" EDR asks "is this behavior suspicious?" — and that distinction is why modern attacks slip past antivirus alone.
Incident ResponseWhy We Run Tabletop Exercises Before a Business Ever Needs Incident Response for Real
A written incident response plan and a team that’s actually rehearsed it are two very different levels of preparedness.
Network SecurityDNS Security: The Infrastructure Layer Most Businesses Never Monitor
DNS decides where your traffic actually goes, and it’s one of the least monitored pieces of infrastructure in a typical small business setup.
Incident ResponseCase Study: How a Business Email Compromise Almost Redirected a $40,000 Wire Transfer
A convincing email, a legitimate-looking invoice, and one habit that stopped a $40,000 wire transfer from going to the wrong account.
Data ProtectionThe 3-2-1 Backup Rule, and Why "We Have Backups" Still Isn’t Enough
Having backups and having a backup strategy that actually survives ransomware are two different things.
CompliancePCI-DSS Basics for Small Retailers: What Actually Applies to You
PCI-DSS applies differently depending on how your business actually handles card data — and reducing scope is often more practical than trying to secure everything.
Penetration TestingSocial Engineering Beyond Phishing: Pretexting, Vishing, and Physical Tailgating
Phishing is the social engineering technique everyone trains for. It’s not the only one, and the others don’t show up in an email inbox at all.
Incident ResponseRansomware: Should You Ever Pay? What We Tell Clients Facing That Decision
There’s no universally correct answer to "should we pay the ransom" — but there are specific factors that should actually drive the decision, and a few myths worth clearing up first.
Dealing with something right now?
If this is an active incident, don't wait on a blog post — our response team is on call 24/7.