Blog
Field notes,
with sources.
Operator writing from the CyberSafe desk. We attribute CISA and ENISA when we brief their numbers. We do not invent campaigns for traffic.


Advisory · 18 Aug 2026 · 6 min
Four KEVs in one day: patch SharePoint and vCenter before the rest
CISA added four exploited CVEs on 18 August 2026. For most estates the consequence order is SharePoint, vCenter, IKE/VPN, then macOS endpoints.

Insight · 4 Aug 2026 · 7 min
ENISA still puts phishing at ~60% of initial access. That should change your spend.
The ENISA Threat Landscape 2025 analysed 4,875 incidents. Ransomware remains the most damaging crime. Phishing is still how most of it starts.

Insight · 22 Jul 2026 · 5 min
A platform plan is not a pentest. Stop buying the wrong thing first.
Individual, CyberLink, and Enterprise are coverage. Assessments and tests are scoped work. Mixing them is how buyers get a bundle they cannot run.

Guide · 9 Jul 2026 · 8 min
Zero Trust for a mid-market estate: identity first, network later
You do not need a greenfield network. You need verified access to the paths that actually matter.

Guide · 18 Jun 2026 · 9 min
Ransomware: the first 72 hours if you do not have a SOC
Contain, preserve, communicate, recover. In that order. Print the checklist before you need it.

Insight · 2 Jun 2026 · 6 min
What a good cybersecurity assessment actually delivers
Not a 200-page PDF. A ranked list, owners, and a 90-day ladder you can fund.
Get advisories when they publish
The blog is public. If you want the same notes routed to your sector, say so on the contact form.
Request updates