Security Insights

admin

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

What a Penetration Test Actually Involves, Step by Step

Tabletop Exercises: Practicing Incident Response Before You Need It

Businesses considering a penetration test for the first time often have a vague sense of what the engagement will involve day to day, which can make it harder to prepare internally or set realistic expectations for what a completed engagement will deliver. Understanding the real phases of a typical penetration test helps demystify the process. … Read more

Bring Your Own Device Policies: Balancing Security and Convenience

SOC 2 Type I vs Type II: What the Difference Actually Means

Bring your own device policies, letting employees use personal smartphones and laptops for work purposes, offer convenience and cost savings. They also introduce security risk. Organizations need to manage that risk through thoughtful policy design instead of reaching for either extreme – banning personal devices outright, or permitting them with no security guardrails at all. … Read more

Security Awareness Training That Employees Do Not Tune Out

Security Awareness Training That Employees Do Not Tune Out

Security awareness training has a reputation problem – many employees experience it as a boring, easily forgotten annual obligation rather than useful, actionable guidance, undermining the very real security value effective awareness training could otherwise provide across an organization. Why Traditional Awareness Training Fails to Land Annual, lengthy, generic security awareness training sessions struggle to … Read more

Log Management Fundamentals for Growing Companies

Shared Responsibility Model: Where Cloud Provider Security Ends

Log management, the practice of collecting and analyzing the log data generated across an organization’s systems, becomes more complex and more important as a company grows, and organizations that build solid log management fundamentals early avoid the considerably more painful process of retrofitting log management onto an already-large, established environment later. Why Logs Are Foundational … Read more

What Cyber Insurance Actually Requires From Policyholders

Continuous Compliance Monitoring: Moving Beyond the Annual Audit

Cyber insurance has become standard practice for many businesses, but policyholders are often surprised to discover that cyber insurance carries real, specific security requirements they must maintain to keep coverage valid – requirements that go well beyond simply paying the actual policy premium itself. Why Cyber Insurers Require Specific Security Controls Cyber insurers have learned, … Read more

Understanding SSRF Vulnerabilities in Modern Applications

CSRF Attacks Explained: Why They Still Work in 2026

Server-side request forgery vulnerabilities have become more significant as applications increasingly integrate with cloud services and internal microservices, creating opportunity for attackers to exploit a server’s own network position rather than attacking through a more traditional, direct external path. What SSRF Allows an Attacker to Do SSRF vulnerabilities occur when an application accepts an user-influenced … Read more

Cloud Native Security Tools: CSPM, CWPP, and CNAPP Explained

Shared Responsibility Model: Where Cloud Provider Security Ends

Cloud security tooling has developed its own dense acronym landscape – CSPM, CWPP, CNAPP among others – that can obscure the actual practical purpose each tool category serves. Understanding what each does, and how they relate to each other, helps organizations build a coherent cloud security tooling strategy. It also helps them avoid accumulating overlapping … Read more

How Attackers Actually Use Leaked Credentials

Physical Penetration Testing: Why Digital Security Is Not Enough

Credential leaks from third-party data breaches have become so common that understanding exactly how attackers exploit this leaked information matters considerably for building appropriately proportionate defenses. Treating credential leaks as an abstract concern, without understanding the specific, practical exploitation techniques involved, leaves those defenses incomplete. Credential Stuffing: The Most Common Exploitation Path Credential stuffing attacks … Read more

Building an Effective Bug Bounty Program

API Discovery: Why You Probably Have More APIs Than You Think

Bug bounty programs offer organizations access to a considerably broader pool of security researchers than any internal security team alone could realistically provide, but building an effective program requires more careful, deliberate thought than simply offering a reward and waiting for reports to start arriving. Why Bug Bounty Programs Complement Internal Security Testing Internal security … Read more

Understanding SBOM: Software Bill of Materials Explained

How to Prepare for a SOC 2 Audit Without the Panic

Software Bill of Materials requirements have moved from a niche security practice to an increasingly common regulatory and contractual requirement, particularly for organizations selling software to government agencies or operating in regulated industries. Understanding what a SBOM is, and what value it provides, matters for organizations navigating these emerging, increasingly common requirements. What a SBOM … Read more