Threat Intel
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
6 min read
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
How to Read a CVE (and What to Do About It)
6 min read
Stop chasing every ‘Critical’ alert. Learn how to decode CVEs and prioritize patches based on actual risk to your SMB environment.
-
Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline
6 min read
Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.
-
PCI DSS Targeted Risk Analysis: A Template an SMB Can Actually Fill
6 min read
PCI DSS v4.0.1 requires a targeted risk analysis (requirement 12.3.1) wherever a control’s frequency is flexible. Here are the elements the standard requires, a fill-in template, and a worked example for the 11.6.1 payment-page tamper-detection frequency.
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
6 min read
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
How to Read a CVE (and What to Do About It)
6 min read
Stop chasing every ‘Critical’ alert. Learn how to decode CVEs and prioritize patches based on actual risk to your SMB environment.
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
6 min read
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
Comment lire un CVE (et que faire ensuite)
6 min read
Arrêtez de courir après chaque alerte « Critique ». Apprenez à décoder un CVE et à prioriser les correctifs en fonction du risque réel pour votre environnement PME.
-
A Practical SMB Patch Cadence: Risk-Based Triage Without a SOC
6 min read
A one- to three-person IT team cannot patch every CVE. Here is a risk-based cadence using CISA KEV and EPSS, mapped to ISO 27001:2022 controls A.8.8 and A.8.9, that keeps the business stable and the auditor satisfied.
-
Building a Vulnerability Intake Workflow That Works
6 min read
Set up repeatable triage, severity mapping, and remediation tracking for faster risk reduction.
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
How to Read a CVE (and What to Do About It)
Stop chasing every ‘Critical’ alert. Learn how to decode CVEs and prioritize patches based on actual risk to your SMB environment.
-
Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline
Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.
-
PCI DSS Targeted Risk Analysis: A Template an SMB Can Actually Fill
PCI DSS v4.0.1 requires a targeted risk analysis (requirement 12.3.1) wherever a control’s frequency is flexible. Here are the elements the standard requires, a fill-in template, and a worked example for the 11.6.1 payment-page tamper-detection frequency.
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
How to Read a CVE (and What to Do About It)
Stop chasing every ‘Critical’ alert. Learn how to decode CVEs and prioritize patches based on actual risk to your SMB environment.
-
How to Run Your First Tabletop Exercise: An SMB Walkthrough
ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.
-
Comment lire un CVE (et que faire ensuite)
Arrêtez de courir après chaque alerte « Critique ». Apprenez à décoder un CVE et à prioriser les correctifs en fonction du risque réel pour votre environnement PME.
-
A Practical SMB Patch Cadence: Risk-Based Triage Without a SOC
A one- to three-person IT team cannot patch every CVE. Here is a risk-based cadence using CISA KEV and EPSS, mapped to ISO 27001:2022 controls A.8.8 and A.8.9, that keeps the business stable and the auditor satisfied.
-
Building a Vulnerability Intake Workflow That Works
Set up repeatable triage, severity mapping, and remediation tracking for faster risk reduction.