CyberSafe LogoCyberSafe

Threat Research · Security Guides

Security Guides you can
run as procedures.

Step-by-step checklists, owners, and verification — not another essay. Download the ransomware 72-hour path and the identity baseline, or read the field notes on the blog.

Planning documents on a table
Guide workbook

What you'll find

Procedures, not opinion pieces

Security Guides are how-to artifacts: baseline hardening, phishing response drills, access reviews, and recovery checklists. Commentary and strategic framing live under Insights. Keeping those channels separate means an engineer can open a guide and execute without hunting for the actionable part.

Published guides sit below as printable procedures. Blog field notes in the Guide category unpack the same topics when you need the argument, not just the checklist. Commentary lives under Insights.

  • Cloud
  • Traffic
  • Contain
Cloud & network graph

Published guides

guide

Aug 2026

Ransomware: first 72 hours checklist

Printable procedure: contain, preserve, communicate, recover.

guide

Jul 2026

Identity hardening baseline (MFA, admin, email)

A procedure for IT leads: privileged accounts, MFA, and mailbox controls.

Field notes

Capabilities

Guide categories

Lanes for practical content as publications land.

Baseline hardening

Identity, endpoint, email, and network controls ordered by risk reduction.

01

Incident readiness

Playbooks, contact trees, evidence handling, and tabletop agendas.

02

People & process

Awareness cadences, access reviews, and change control that staff can sustain.

03

Assurance checklists

Self-checks before audits, vendor reviews, or board reporting cycles.

04

Process

How a guide is structured

Every guide should be usable under pressure — clear steps, clear done criteria.

  1. 01

    Purpose

    What outcome the guide produces and who owns it.

  2. 02

    Prerequisites

    Access, tools, and approvals needed before step one.

  3. 03

    Steps

    Numbered actions with expected results — no buried critical detail.

  4. 04

    Verify

    How to confirm the control or process actually works.

  5. 05

    Escalate

    When to stop DIY and bring in assessment or response support.

At a glance

Who should use Security Guides

Primary readers

  • IT admins implementing baseline controls
  • Security generalists running first-time playbooks
  • Ops leads coordinating access and change reviews
  • Smaller teams without a full-time procedure writer

What “done” looks like

  • Named owner and last-run date on the procedure
  • Evidence or screenshot trail where verification matters
  • Exceptions documented instead of silently skipped
  • Link into Insights or Advisories when context is needed

Capabilities

Guides vs. Insights

Pick the channel that matches the job.

Guides = execute

Follow steps, verify, close the ticket or control gap.

01

Insights = decide

Understand trade-offs and programme direction before you spend.

02

Together = durable

Decide with Insights, implement with Guides, validate with assessment.

03

Threat landscape

The surface does not sit still.

Cloud estates, identities, vendors, and employee devices shift every week. A once-a-year assessment is a snapshot. CyberSafe treats the attack surface as a live model — continuously scanned, ranked by business consequence, and tied to the work of closing what actually matters.

  • Internet-facing services, identity paths, and cloud defaults mapped as one surface
  • Automated probing tropes — phishing, credential stuffing, unpatched CVEs — ranked by impact
  • A continuous scan model so new exposure is seen before it becomes an incident
Scanning · Cloud
Live threat surface · continuous scan model

Need a guide tailored to your stack?

Tell us your environment and the control you need to stand up. We can point you to published guides as they ship — or scope a hands-on engagement to build procedures with your team.

Talk about security procedures