Security writing for people who have to fix things.
Plain writing on application security, testing and the frameworks behind audits — what actually goes wrong, and what to do about it. Written from the work, by the people who do it.
A scan is not a penetration test
Scanners find what everyone already knows about. The flaws that actually expose customer data usually need a person who understands what the application is for.
The OWASP Top 10:2025, for owners
The new edition keeps broken access control at number one, folds SSRF into it, and adds two categories that say a lot about where attacks are coming from now.
SOC 2, before the auditor arrives
For a small software company, the first SOC 2 feels enormous. Most of the work is evidence of habits you already have, plus a short list of gaps you would want to fix anyway.
The endpoints nobody listed
Mobile back ends, partner integrations, old versions still running. The endpoints that cause breaches are often the ones missing from the spec you handed the tester.
NIST CSF 2.0 and the board
The 2024 update added a sixth function, Govern. It is the most useful change for smaller organisations, because it answers the question boards actually ask: who owns this?
Every script on your checkout
Since 31 March 2025, merchants have had to inventory, justify and monitor the scripts on their payment pages. The tag manager your marketing team loves is now a compliance question.