What a security assessment actually finds

It is rarely anything exotic. It is almost always something ordinary that nobody owned.

People imagine a security review as somebody clever finding an ingenious flaw. In practice the findings are dull and they repeat: software two years out of date, an account belonging to somebody who left, a password reused from a service that was breached, a folder the web server can write to that it has no business writing to.

Dull does not mean harmless. Nearly every compromise of a small business site comes through one of those, because attackers are not looking for you specifically. They are scanning everyone for the same handful of known holes.

The pattern behind all of them is ownership. Somebody installed a plugin for a campaign in 2023 and nobody owned it afterwards. An administrator account was created for a contractor and nobody owned closing it.

So an assessment worth paying for produces two things: a list of what is wrong, ranked by what an attacker would actually reach first, and a shorter list of who now owns each thing that has to keep being true.

The second list is the one that prevents the next incident. The first only fixes this one.

Everything

One feed with all of it - requests, prayers and news, as they are posted.

Or choose a section

Follow the blogs

Every blog is filed under one of four sections. Take the lot, or just the ones you want.

What would you like to be sent?

One confirmation email, then only the posts.

Feed readers: RSS Atom JSON

Subscribe to the blogs

Choose which blogs you want. Every post in a section you pick reaches you by email.

What would you like to hear about?

Comments and reactions 0

No comments yet. Yours would be the first.

Add emoji to your comment (optional, as many as you like)