Security Notes & Case Studies
Write-ups from real engagements, and practical guidance on the threats actually hitting small and mid-sized businesses right now.
Incident Response Posts
Case Study: Recovering a Business After a Publicly Exposed RDP Server Was Taken Over and Wiped
A publicly forwarded RDP port, no other way in needed, and the client’s only backup living on the exact machine that got wiped. Here’s how the recovery actually went.
Incident ResponseCase Study: Removing a ClickFix Malware Infection From a Compromised WordPress Site
A walkthrough of a real WordPress clean-up: ClickFix-style fake-verification malware, multiple malicious plugins, hidden backdoors, a rogue admin account, and the hardening that stopped it from coming back.
Incident ResponseIncident Response: What Should Actually Happen in the First 24 Hours
The first 24 hours after discovering a breach determine most of what happens next — here’s the order that actually reduces damage.
Incident ResponseWhy We Run Tabletop Exercises Before a Business Ever Needs Incident Response for Real
A written incident response plan and a team that’s actually rehearsed it are two very different levels of preparedness.
Incident ResponseCase Study: How a Business Email Compromise Almost Redirected a $40,000 Wire Transfer
A convincing email, a legitimate-looking invoice, and one habit that stopped a $40,000 wire transfer from going to the wrong account.
Incident ResponseRansomware: Should You Ever Pay? What We Tell Clients Facing That Decision
There’s no universally correct answer to "should we pay the ransom" — but there are specific factors that should actually drive the decision, and a few myths worth clearing up first.
Dealing with something right now?
If this is an active incident, don't wait on a blog post — our response team is on call 24/7.