Engineering notes
Notes fromthe engine room.
Practical write-ups from our engineers: what we check, what tends to break and what we would do differently. No client is named or identifiable.
Preparing for a CREST internal pen test
An internal test shows what an attacker could do once inside your network. Prepared well, it tells you something new. Prepared badly, it charges you to rediscover what you already knew.
Least privilege for AI agents in Microsoft 365
An agent that can read every mailbox is one malicious email away from a breach. The answer isn't to avoid agents. It's to give each one exactly the access its job needs, and nothing it could be talked into misusing.
What a DR test should actually prove
A green backup report proves a job ran. It doesn't prove you can run the business on what it saved. A disaster recovery test should answer five questions, with a stopwatch running.