Security Insights

All Articles

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Supply Chain Security: What SBOMs Actually Tell You and What They Do Not

Continuous Compliance Monitoring: Moving Beyond the Annual Audit

Software Bills of Materials have gone from a niche compliance artifact to something regulators and enterprise customers increasingly require by name, and that rapid mandate-driven adoption has outpaced a clear, shared understanding of what an SBOM actually tells you — and, just as importantly, what it structurally can’t. What an SBOM Genuinely Solves An SBOM’s … Read more

Identity and Access Management: Why Deprovisioning Is Where Programs Actually Fail

API Discovery: Why You Probably Have More APIs Than You Think

Identity and access management programs get evaluated heavily on how well provisioning works — how quickly and correctly a new employee gets access to what they need — while deprovisioning, the reverse process of removing access when it’s no longer needed, receives disproportionately less attention despite being where most real IAM program failures actually originate. … Read more

Zero Trust Architecture: What Changes Beyond the Marketing Slide

Shared Responsibility Model: Where Cloud Provider Security Ends

Zero trust has become one of the most overused terms in security marketing, applied to products that implement a narrow slice of the actual architecture while the phrase itself gets stretched to cover almost any access control improvement. Underneath the marketing noise, though, is a genuinely coherent architectural model with specific, identifiable requirements — and … Read more

Red Team vs Penetration Test: Choosing the Right Assessment for Your Maturity

Physical Penetration Testing: Why Digital Security Is Not Enough

“Should we get a penetration test or a red team engagement” is a question worth answering deliberately, because the two assessments measure genuinely different things, and buying the wrong one for an organization’s actual security maturity produces a report that either states the obvious or misses the point entirely. What a Penetration Test Actually Measures … Read more

Kubernetes Secrets Management: Why etcd Encryption Is Not Enough

Kubernetes Admission Controllers: Enforcing Policy Before Deployment

Enabling encryption at rest for etcd is a genuinely important Kubernetes security control, and it’s also frequently treated as a complete solution to Kubernetes secrets security when it addresses only one specific threat: someone gaining direct access to the etcd data store or its underlying disk. Most real-world Kubernetes secrets exposure happens through paths that … Read more

SOC 2 Readiness: The Gaps Most Teams Discover Too Late

Continuous Compliance Monitoring: Moving Beyond the Annual Audit

Organizations preparing for a first SOC 2 audit consistently underestimate one thing: not the technical controls themselves, which most reasonably mature companies already have in some form, but the evidence trail proving those controls operated consistently over the entire audit period. A control that exists but wasn’t documented as operating is, from an auditor’s perspective, … Read more

Cloud Security Posture Management: What CSPM Tools Actually Catch

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud Security Posture Management tools get sold on the promise of catching cloud misconfigurations automatically, and they genuinely do catch a real and important category of risk — but “catches misconfigurations” covers a wide range of actual capability, and teams that buy a CSPM tool expecting comprehensive cloud security coverage are usually disappointed by what … Read more

Secrets Sprawl: Why Your Codebase Has More Credentials Than You Think

API Discovery: Why You Probably Have More APIs Than You Think

Every codebase accumulates more credentials than anyone tracking access controls believes it has, and the gap between “credentials we know about” and “credentials that actually exist and work” is what security teams call secrets sprawl — a problem that grows quietly with every API integration, every CI pipeline, and every developer who hardcodes a token … Read more

Tabletop Exercises: Practicing Incident Response Before You Need It

Tabletop Exercises: Practicing Incident Response Before You Need It

Tabletop exercises are structured, discussion-based simulations that walk a team through a hypothetical security incident. They deliver real incident response practice at a fraction of the cost and disruption of a full technical simulation, yet most organizations still underuse them relative to their actual value. What a Tabletop Exercise Involves A tabletop exercise gathers the … Read more

Kubernetes Admission Controllers: Enforcing Policy Before Deployment

Kubernetes Admission Controllers: Enforcing Policy Before Deployment

Kubernetes admission controllers give teams a powerful mechanism for enforcing security and operational policy before resources are ever created in a cluster. Yet many organizations underuse this capability. They rely instead on after-the-fact detection and remediation for violations that admission control could have prevented entirely. What Admission Controllers Do Admission controllers intercept requests to the … Read more