Insights

The TechBiz blog

Research, write-ups, and practical guidance from the team — straight from the field.

Password Policy: What NIST Actually Recommends
Compliance & GRC Sep 6, 2026

Password Policy: What NIST Actually Recommends

Most corporate password policies still enforce rules that current guidance explicitly advises against — and those rules measurably reduce security.

Read more
How a Ransomware Attack Actually Unfolds
Threat Intelligence Sep 6, 2026

How a Ransomware Attack Actually Unfolds

By the time files are encrypted, the attacker has usually been inside for days or weeks. Every one of those days was an opportunity…

Read more
Software Supply Chain Attacks: Trusting What You Did Not Write
Threat Intelligence Sep 6, 2026

Software Supply Chain Attacks: Trusting What You Did Not Write

Modern software is assembled more than written. Every dependency, build tool and pipeline credential is a path into your product — and into your…

Read more
Business Email Compromise: The Attack That Needs No Malware
Threat Intelligence Sep 6, 2026

Business Email Compromise: The Attack That Needs No Malware

No malware, no exploit, no alert. Business email compromise succeeds through patience and social engineering — and causes losses that dwarf many technical attacks.

Read more
Insider Threats: Malice, Negligence and Compromised Accounts
Threat Intelligence Sep 6, 2026

Insider Threats: Malice, Negligence and Compromised Accounts

The insider threat is rarely a disgruntled employee stealing secrets. Far more often it is an ordinary person making an ordinary mistake — or…

Read more
Social Engineering Beyond Phishing: Vishing, Pretexting and Help-Desk Attacks
Threat Intelligence Sep 6, 2026

Social Engineering Beyond Phishing: Vishing, Pretexting and Help-Desk Attacks

Organisations train relentlessly on suspicious emails, then hand over an account reset to a confident voice on the phone that answers three questions found…

Read more