Security Insights

admin

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

Attack Surface Management: Why You Cannot Secure What You Cannot See

Tabletop Exercises: Practicing Incident Response Before You Need It

Attack surface management, the ongoing discipline of identifying and monitoring every actual externally exposed system and service an organization operates, has become essential as organizations discover that their real attack surface is often considerably larger, and considerably less well understood, than security teams originally assumed. Why Organizations Underestimate Their Own Attack Surface Organizations accumulate externally … Read more

HIPAA Compliance for Healthcare Technology Vendors

How to Prepare for a SOC 2 Audit Without the Panic

Technology vendors serving healthcare organizations face distinct HIPAA compliance obligations that differ meaningfully from compliance obligations facing the healthcare providers themselves, and vendors new to the healthcare space often underestimate what actual HIPAA compliance as a business associate requires. Understanding the Business Associate Relationship Technology vendors handling protected health information on behalf of a healthcare … Read more

Cloud Encryption: What Is Actually Protected and What Is Not

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud encryption provides real, important data protection, but organizations frequently misunderstand exactly what specific encryption protects against, leading to dangerous gaps where organizations mistakenly believe encryption addresses a security risk that, in reality, it honestly does not address at all. The Distinction Between Encryption at Rest and in Transit Cloud encryption operates in two distinct … Read more

Business Logic Vulnerabilities: The Flaws Scanners Cannot Find

OWASP Top 10 Explained for Non-Security Teams

Business logic vulnerabilities – flaws in an application’s actual intended workflow and rules, rather than in its underlying technical implementation – represent a significant application security blind spot, since automated vulnerability scanners are honestly fundamentally poorly suited to detecting this distinct vulnerability category. What Distinguishes Business Logic Vulnerabilities From Technical Vulnerabilities Technical vulnerabilities involve flaws … Read more

Kubernetes Secrets Management: Why the Default Approach Is Not Enough

Kubernetes Secrets Management: Why the Default Approach Is Not Enough

Kubernetes native secrets provide a convenient built-in mechanism for managing sensitive configuration data, but security-conscious organizations increasingly recognize that the default Kubernetes secrets approach carries real limitations that make it insufficient for security-sensitive production use without additional, deliberate hardening. What Kubernetes Native Secrets Provide Kubernetes secrets offer a built-in mechanism for storing and injecting sensitive … Read more

Red Team vs Penetration Test: What Is Actually Different

Physical Penetration Testing: Why Digital Security Is Not Enough

Organizations new to offensive security testing frequently use “red team” and “penetration test” interchangeably, when these represent distinct engagement types with real different objectives, scope, and methodology that organizations should understand clearly before commissioning either type of engagement. The Core Objective Difference Penetration testing aims to identify as many actual exploitable vulnerabilities as possible within … Read more

ISO 27001 Certification: What the Process Actually Involves

ISO 27001 Certification: What the Process Actually Involves

Organizations pursuing ISO 27001 certification for the first time often have a vague understanding of what the actual certification process involves beyond a general awareness that it demonstrates real information security management maturity. Understanding the actual process helps organizations prepare more realistically and avoid common, avoidable certification delays. What ISO 27001 Actually Certifies ISO 27001 … Read more

Shared Responsibility Model: Where Cloud Provider Security Ends

Shared Responsibility Model: Where Cloud Provider Security Ends

Organizations migrating to cloud infrastructure frequently misunderstand the shared responsibility model – the division of security responsibility between cloud provider and customer – leading to dangerous security gaps where each party mistakenly assumes the other is handling a particular security responsibility that, in reality, honestly nobody is actively addressing. What the Shared Responsibility Model Establishes … Read more

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure Direct Object References: A Common but Overlooked Flaw

Insecure direct object references, commonly abbreviated IDOR, represent a common but often overlooked application security vulnerability class, where an application exposes internal object references – database IDs, file paths – without adequately verifying that the actual requesting user has authorization to access that specific referenced object. How IDOR Vulnerabilities Work IDOR vulnerabilities occur when an … Read more

Kubernetes RBAC Misconfigurations That Quietly Grant Too Much Access

Kubernetes RBAC Misconfigurations That Quietly Grant Too Much Access

Kubernetes role-based access control, commonly known as RBAC, provides powerful, granular access management capability, but its own flexibility and complexity make RBAC misconfiguration a common source of Kubernetes clusters quietly granting considerably more access than administrators intended or realized. Why Kubernetes RBAC Complexity Invites Misconfiguration Kubernetes RBAC offers considerable configuration flexibility – roles, cluster roles, … Read more