Security Insights

Security Assessments

Thinking on cybersecurity, compliance, and managed defence - from the CyberCheck team.

How Attackers Actually Use Leaked Credentials

Physical Penetration Testing: Why Digital Security Is Not Enough

Credential leaks from third-party data breaches have become so common that understanding exactly how attackers exploit this leaked information matters considerably for building appropriately proportionate defenses. Treating credential leaks as an abstract concern, without understanding the specific, practical exploitation techniques involved, leaves those defenses incomplete. Credential Stuffing: The Most Common Exploitation Path Credential stuffing attacks … Read more

What a Real Cybersecurity Assessment Actually Covers

Kubernetes Admission Controllers: Enforcing Policy Before Deployment

Ask a business owner what a “security assessment” involves and you will usually get a vague answer about scanning for vulnerabilities. That is part of it, but a thorough assessment covers far more ground than an automated scanner report – and the gap between a real assessment and a superficial one is exactly where the … Read more

Why Rotating a Leaked API Key Quickly Is Not the Same as Rotating It Safely

Physical Penetration Testing: Why Digital Security Is Not Enough

A company discovers a leaked API key during a routine security review, rotates it within the hour, and treats the incident as genuinely closed – until a follow-up investigation reveals that key had been embedded in a genuinely large number of downstream integrations and cached configurations, several of which quietly broke the moment rotation happened, … Read more