Data on screens

Home / Insights

Guides & insights.

Practical writing on the things we actually get asked about — security decisions, compliance traps, and how to run IT that does not fall over. No thought-leadership fluff. If it will not help you make a better decision, we will not publish it.

Laptop with security lock symbol — penetration testing cost guide
Featured · Pricing

How much does a penetration test cost in 2026?

Real bands from our scoping: external $4–8k, web app $6–15k, combined $10–30k — what moves the number, and how to spot a scan sold as a test.

Read the article →
Compliance

SOC 2 for startups: real cost & timeline (2026)

What SOC 2 truly costs ($25k–$80k all-in), Type I vs II timelines, and the sequencing mistake that adds a quarter.

11 min read · July 2026
OPSEC

Personal OPSEC for crypto founders & executives

SIM-swap defense, persona separation, key custody and a duress plan — protecting the person, not just the platform.

11 min read · July 2026
Federal

FAR 52.204-21 in plain English: the 15 controls

Every basic safeguarding control a federal contractor needs, and how it maps to NIST 800-171 and CMMC Level 1.

11 min read · July 2026
Security ops

EDR vs. MDR vs. SIEM: what you actually need

Three acronyms, one budget decision — what each does and which you need at 20, 80, and 200 people.

10 min read · July 2026
Security testing

What a pen test report should include

The seven sections of a credible report, annotated good-vs-useless, and a two-minute test for a scan in disguise.

10 min read · July 2026
Backup

The 3-2-1 backup rule isn't enough anymore

Why ransomware beats classic 3-2-1, the 2026 evolution to 3-2-1-1-0, and a one-week upgrade path.

10 min read · July 2026
Healthcare

HIPAA IT requirements for small practices

What the Security Rule actually requires — safeguards and the mandatory risk analysis — without the vendor theatrics.

11 min read · July 2026
OSINT

What anyone can learn about your company in an afternoon

A defensive walkthrough of attacker reconnaissance — five public layers, how they combine, and how to shrink each.

10 min read · July 2026
Identity

Phishing-resistant MFA without a mutiny

Why most MFA is phishable, what passkeys change, and a wave-by-wave rollout that avoids the helpdesk revolt.

10 min read · July 2026
Buyer's guide

How to choose an IT company: 12 questions

Twelve questions that separate a real partner from a lock-in machine — including how to vet us.

10 min read · July 2026
Security testing

Pen test vs. vulnerability scan: which one do you need?

Different instruments for different questions — with a decision flowchart, honest costs, and the mislabeled-scan trap that fails audits.

9 min read · July 2026
Incident response

The first 24 hours after a ransomware attack

An engineer's hour-by-hour playbook from real 2 a.m. calls: contain, assess, eradicate, restore — and the mistakes that turn days into weeks.

11 min read · July 2026
Checklist

The 20-point IT security checklist for SMBs

A tickable baseline across identity, devices, network, data and operations — with the three items everyone skips.

12 min read · July 2026
Pricing

Managed IT pricing: what SMBs actually pay in 2026

Per-user rates by tier, the contract clauses that cost more than the invoice, and the honest in-house-vs-provider math.

10 min read · July 2026
Fintech & crypto

Crypto exchange security: what banks actually expect

The six-layer control stack — KYC, monitoring, Travel Rule, custody, platform security, governance — from an AML/MLRO practitioner who builds these systems.

14 min read · July 2026
Insurance

Cyber insurance requirements 2026: what insurers demand

The underwriting table, the attestation trap that voids claims, and a 30-day path to answering the questionnaire honestly.

10 min read · July 2026
Federal

The cheap camera that can cost you a federal contract

Section 889 bans covered Chinese-made gear from federal work — and it hides inside ordinary brands. How to run the audit in an afternoon.

5 min read · July 2026
In the pipeline

We publish weekly — when we have something worth your time, not to feed a calendar.

·

What a pen test report should include

An annotated example — what auditors and banking partners look for on page one. Coming soon.

·

The 3-2-1 backup rule isn't enough anymore

Why immutable copies and rehearsed restores are the real ransomware defence. Coming soon.

·

Phishing-resistant MFA without a mutiny

Rolling out passkeys and hardware keys across a small company, step by step. Coming soon.

Want an answer now, not next month?

The articles are useful, but a five-minute conversation with an engineer is faster. Tell us the actual problem and we will point you the right way.

Ask an engineer