Security writing
Notes from breaking into things.
What we find, how we find it, and what a security review is actually worth to someone about to sign a deal.
All posts
01
2026-08-06
What security due diligence should tell an investment committee
Not a severity distribution. Three things: does this change the price, does this change the plan, and what does it cost to fix. If the report cannot answer those, it was written for the wrong reader.
2026-07-16
A current ISO 27001 certificate is not evidence that you are secure
We have found production databases on the open internet at companies holding current certifications. The certificate was not fraudulent. It was answering a different question from the one the buyer thought it answered.
2026-06-24
What two hours of testing actually buys you
A Flash Review is not a pentest and we do not pretend otherwise. Here is what fits in two hours, what does not, and why the constraint produces better results than it sounds like it should.