What's new
Everything that changed here, newest first: research, patents, portfolio works, books, and the site itself.
September 2026
NewResearch & IP
Adversarial simulation may replace part of annual training
Generated, varied, current scenarios delivered continuously and measured behaviourally are a plausible substitute for a yearly module. Plausible is not proven.
NewResearch & IP
Backups are usually out of scope, and usually full of the data
Retention and deletion policies often exclude backups for practical reasons. The exclusion is defensible. Leaving it unstated in the notice is not.
NewResearch & IP
Consent language without enforcement is a claim about intent
If withholding consent does not change what a system does with a record, the consent mechanism only keeps a record of the choice. It does not enforce it.
NewResearch & IP
Credential reset at scale is required and almost never rehearsed
Serious intrusions usually end with rotating every credential, key, token, certificate, and service account. Most organisations have never attempted this even partially.
NewResearch & IP
Deletion is the sharpest privacy test
A verified end-to-end deletion exercises the data map, the vendor list, the backup policy, and the derived-data problem at once. Few organisations pass it on the first attempt.
NewResearch & IP
Design out the memory dependency
For each control that depends on a person recalling guidance under pressure, look for a technical arrangement that makes the safe action the default or the only one.
NewResearch & IP
Do not publish a resilience formula yet
People often ask for one weighted score. Publishing it before the measures are validated would give an untested formula the look of certainty.
NewResearch & IP
Escalation paths decay quietly
Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.
NewResearch & IP
Fluent output is not evidence
A generated security assessment reads better than a human one and is harder to doubt. Readability and correctness are unrelated properties.
NewResearch & IP
Generate the policy from the enforced rule
Where a platform enforces a setting, produce the written policy from that configuration. Then the rule and the document cannot drift apart.
NewResearch & IP
Governance runs short of time for judgment
When collecting and formatting evidence takes most GRC hours, little time remains for decisions. Automating the clerical work may give that time back.
NewResearch & IP
Keep evidence that can be reproduced
A screenshot is a claim about a moment. A stored query with provenance can be re-run by the reader, which changes what the evidence is worth.
NewResearch & IP
Let machines watch; keep consequential decisions with people
Machines can watch systems and prepare evidence. People remain responsible for decisions that cannot be reversed.
NewResearch & IP
Measure the time between each response step
Incident counts depend on how hard an organisation looks. Detection, containment, and recovery intervals can be generated on demand and compared over time.
NewResearch & IP
Phishing resistance belongs in the credential
Origin-bound, hardware-backed authentication removes a whole class of failure regardless of how convincing the message was. This is the clearest available example of design beating vigilance.
NewResearch & IP
Put the last demonstrated RTO beside the target
A recovery objective is a statement of intent written during planning. The useful number is the one produced by the last real restore, with the date attached.
NewResearch & IP
Requirements with no evidence source are more common than failed controls
When requirements are mapped to operational data sources, the largest category is usually requirements that no system can currently answer at all.
NewResearch & IP
The audit passed and the network was flat
Certification scope is negotiated. A clean report describes the environment that was examined against the controls that were selected, at the time of the examination.
NewResearch & IP
The restore worked and took four days
A restore can return all the data and still come too late. Time, sequence, and hidden dependencies often cause the loss.
NewResearch & IP
The tool was purchased. Was it tested?
Procurement produces a deployment date. Nothing in the ordinary purchase process produces evidence that the tool changes an attack outcome in this environment.
