What's new

Everything that changed here, newest first: research, patents, portfolio works, books, and the site itself.

September 2026

  • NewResearch & IP

    Adversarial simulation may replace part of annual training

    Generated, varied, current scenarios delivered continuously and measured behaviourally are a plausible substitute for a yearly module. Plausible is not proven.

    Read more

  • NewResearch & IP

    Backups are usually out of scope, and usually full of the data

    Retention and deletion policies often exclude backups for practical reasons. The exclusion is defensible. Leaving it unstated in the notice is not.

    Read more

  • NewResearch & IP

    Consent language without enforcement is a claim about intent

    If withholding consent does not change what a system does with a record, the consent mechanism only keeps a record of the choice. It does not enforce it.

    Read more

  • NewResearch & IP

    Credential reset at scale is required and almost never rehearsed

    Serious intrusions usually end with rotating every credential, key, token, certificate, and service account. Most organisations have never attempted this even partially.

    Read more

  • NewResearch & IP

    Deletion is the sharpest privacy test

    A verified end-to-end deletion exercises the data map, the vendor list, the backup policy, and the derived-data problem at once. Few organisations pass it on the first attempt.

    Read more

  • NewResearch & IP

    Design out the memory dependency

    For each control that depends on a person recalling guidance under pressure, look for a technical arrangement that makes the safe action the default or the only one.

    Read more

  • NewResearch & IP

    Do not publish a resilience formula yet

    People often ask for one weighted score. Publishing it before the measures are validated would give an untested formula the look of certainty.

    Read more

  • NewResearch & IP

    Escalation paths decay quietly

    Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.

    Read more

  • NewResearch & IP

    Fluent output is not evidence

    A generated security assessment reads better than a human one and is harder to doubt. Readability and correctness are unrelated properties.

    Read more

  • NewResearch & IP

    Generate the policy from the enforced rule

    Where a platform enforces a setting, produce the written policy from that configuration. Then the rule and the document cannot drift apart.

    Read more

  • NewResearch & IP

    Governance runs short of time for judgment

    When collecting and formatting evidence takes most GRC hours, little time remains for decisions. Automating the clerical work may give that time back.

    Read more

  • NewResearch & IP

    Keep evidence that can be reproduced

    A screenshot is a claim about a moment. A stored query with provenance can be re-run by the reader, which changes what the evidence is worth.

    Read more

  • NewResearch & IP

    Let machines watch; keep consequential decisions with people

    Machines can watch systems and prepare evidence. People remain responsible for decisions that cannot be reversed.

    Read more

  • NewResearch & IP

    Measure the time between each response step

    Incident counts depend on how hard an organisation looks. Detection, containment, and recovery intervals can be generated on demand and compared over time.

    Read more

  • NewResearch & IP

    Phishing resistance belongs in the credential

    Origin-bound, hardware-backed authentication removes a whole class of failure regardless of how convincing the message was. This is the clearest available example of design beating vigilance.

    Read more

  • NewResearch & IP

    Put the last demonstrated RTO beside the target

    A recovery objective is a statement of intent written during planning. The useful number is the one produced by the last real restore, with the date attached.

    Read more

  • NewResearch & IP

    Requirements with no evidence source are more common than failed controls

    When requirements are mapped to operational data sources, the largest category is usually requirements that no system can currently answer at all.

    Read more

  • NewResearch & IP

    The audit passed and the network was flat

    Certification scope is negotiated. A clean report describes the environment that was examined against the controls that were selected, at the time of the examination.

    Read more

  • NewResearch & IP

    The restore worked and took four days

    A restore can return all the data and still come too late. Time, sequence, and hidden dependencies often cause the loss.

    Read more

  • NewResearch & IP

    The tool was purchased. Was it tested?

    Procurement produces a deployment date. Nothing in the ordinary purchase process produces evidence that the tool changes an attack outcome in this environment.

    Read more