Skip to content
Cyber Security Firms

Cyber security resources

Every article on the site, grouped by topic. Each one answers a single question completely, so you are not stitching an answer together from four half-pages.

39 resources across 7 topics

3 resources

14 resources

Cyber Security Threats: The 12 That Actually Cause Breaches
Beginner

Cyber Security Threats: The 12 That Actually Cause Breaches

Every list of cyber threats has twenty entries and no sense of proportion. These are the twelve that account for nearly all real breaches, in the order the evidence ranks them, with the mechanism of each drawn out.

13 min read
Business Email Compromise: How It Works and How to Stop It
Beginner

Business Email Compromise: How It Works and How to Stop It

Business email compromise is the fraud that arrives with no malware, no link and no obvious lie: a real invoice from a real supplier, with the bank details changed. It is the second most expensive crime reported to the FBI.

18 min read
Credential Stuffing: How the Attack Works and How to Stop It
Beginner

Credential Stuffing: How the Attack Works and How to Stop It

Credential stuffing does not guess your password. It already has one, taken from a site you forgot you signed up for, and it is trying that exact password everywhere else you might have used it.

12 min read
Insider Threat: Definition, Types, Examples and Controls
Beginner

Insider Threat: Definition, Types, Examples and Controls

An insider threat is not a kind of person you can pick out of a room. It is a piece of access doing something it was never meant to do, and most of the time nobody involved meant any harm at all.

16 min read
What Is a Data Breach? How They Happen and How to Check
Beginner

What Is a Data Breach? How They Happen and How to Check

A data breach is an event about data, not about damage, and the two get confused constantly. Here is what the word actually covers, how one unfolds, and where to look to find out whether your information is already in one.

19 min read
What Is a DDoS Attack? How It Works and How to Stop It
Beginner

What Is a DDoS Attack? How It Works and How to Stop It

A DDoS attack does not break into anything. It buries a website in traffic until nobody else can reach it, and the defense has to sit upstream of the thing being buried.

15 min read
What Is a Man-in-the-Middle Attack? Types and Signs
Beginner

What Is a Man-in-the-Middle Attack? Types and Signs

The version everyone pictures, a stranger reading your email over the cafe Wi-Fi, mostly stopped working. The idea underneath it moved to the login page, where it works better than ever.

11 min read
What Is a Zero Day? Vulnerabilities, Exploits, Attacks
Beginner

What Is a Zero Day? Vulnerabilities, Exploits, Attacks

Zero day is three different things wearing one name, and the difference decides what you can do about it. Here is what the clock is counting, how many are really out there, and what protects a system that has no patch available.

14 min read
What Is Malware? Types, Signs and How to Remove It
Beginner

What Is Malware? Types, Signs and How to Remove It

Malware is not one attack, it is the whole category, which is why the word feels vague right up until something on your machine starts behaving oddly. Here is what it covers, how it arrives, and what actually gets it off.

18 min read
What Is Phishing? How It Works and How to Spot It
Beginner

What Is Phishing? How It Works and How to Spot It

Phishing is the attack everyone has seen and most people still fall for, because the good ones do not look like the bad ones. Here is how it works, what gives it away, and what to do when you have already clicked.

10 min read
What Is Ransomware? How It Works and How to Stop It
Beginner

What Is Ransomware? How It Works and How to Stop It

The ransom note is the last thing that happens, not the first. By the time it appears the attackers have usually been inside for days, taken a copy of everything worth taking, and deleted the backups. The week before the note is where this is won or lost.

16 min read
What Is Social Engineering? How These Attacks Work
Beginner

What Is Social Engineering? How These Attacks Work

Social engineering is the attack that never touches your software, because it does not have to. It asks a person, politely and plausibly, and the person says yes.

15 min read
What Is a Supply Chain Attack? Examples and Defenses
Intermediate

What Is a Supply Chain Attack? Examples and Defenses

A supply chain attack does not start with you. It starts with a company you bought something from, and it arrives signed, expected and trusted.

17 min read
What Is SQL Injection? How It Works and How to Stop It
Intermediate

What Is SQL Injection? How It Works and How to Stop It

SQL injection turns a form field into an instruction the database obeys. It is one of the oldest flaws on the web, second on the latest list of the most dangerous software weaknesses, and one of the very few problems in security with a complete fix.

18 min read

11 resources

How to Create a Strong Password That Actually Holds Up
Beginner

How to Create a Strong Password That Actually Holds Up

Most password advice is a decade out of date. The rules that replaced it are shorter, easier to follow, and written down in a federal standard you can check.

14 min read
Two-Factor Authentication: How 2FA Works and Which to Use
Beginner

Two-Factor Authentication: How 2FA Works and Which to Use

A password is one secret, and secrets travel. Two-factor authentication adds a second proof that whoever stole the first one does not have, and which kind of second factor you pick matters more than anyone tells you.

14 min read
What Is a Firewall? How It Works and What It Misses
Beginner

What Is a Firewall? How It Works and What It Misses

A firewall decides which network traffic gets through and which does not. That is a narrower job than most people assume, and knowing exactly where the line falls is what tells you which other defenses you still need.

14 min read
What Is a Password Manager? How It Works and the Catch
Beginner

What Is a Password Manager? How It Works and the Catch

A password manager is an encrypted vault that invents a different password for every account and types it for you. The reason to use one is arithmetic, and the reasons not to are worth hearing before you commit.

20 min read
What Is Encryption? How It Works and the Two Types
Beginner

What Is Encryption? How It Works and the Two Types

Encryption is running on almost everything you touch, and the only decision that ever matters is who holds the key. Here is how it works, what the two types are for, and where it quietly stops protecting you.

13 min read
What Is a SOC? Inside a Security Operations Center
Intermediate

What Is a SOC? Inside a Security Operations Center

A security operations center is the team that answers the alert, not the software that raised it. The distinction decides almost everything about what one costs and whether yours works.

14 min read
What Is EDR? Endpoint Detection and Response Explained
Intermediate

What Is EDR? Endpoint Detection and Response Explained

An EDR agent watches every process that starts on a laptop or a server, keeps the record, and can cut the machine off the network. The part nobody sells you is that someone still has to read what it finds.

16 min read
What Is Penetration Testing? The Phases, Types and Limits
Intermediate

What Is Penetration Testing? The Phases, Types and Limits

A penetration test is an authorized attack on your own systems, run by someone you pay to succeed. What varies enormously is the scope, the skill and what you get back, which is why three quotes for the same request arrive at three prices.

13 min read
What Is SIEM? How Log Data Becomes a Security Alert
Intermediate

What Is SIEM? How Log Data Becomes a Security Alert

Every system you run is already writing down what it did. A SIEM is the product that reads all of it at once and tells you which three lines out of nine million belong together.

15 min read
What Is Vulnerability Scanning? Types and How It Works
Intermediate

What Is Vulnerability Scanning? Types and How It Works

A vulnerability scan tells you what is wrong with your systems in a few hours. Working out which of the four hundred findings an attacker would actually use is the part that decides whether the scan was worth running.

16 min read
What Is Zero Trust? The Principles, Pillars and Limits
Intermediate

What Is Zero Trust? The Principles, Pillars and Limits

Zero trust is a set of design principles, not a category of software, and the distance between those two things is where most security budgets go wrong. Here is what the model actually says, who defines it, and what it does not solve.

12 min read

4 resources

3 resources

2 resources

2 resources