Blog
The working out, left in.
Findings, methods and the parts that did not work. If we claim a technique detects something, the piece says what it misses.
Arguments
What we end up saying out loud in a buying conversation, usually more than once.
- Security5 min read
You do not have four thousand critical vulnerabilities
A scanner sorted by severity produces a backlog nobody can work and everybody feels bad about. The federal government stopped prioritizing that way in June 2026, and the reasoning behind the change is worth borrowing whoever you are.
- Security4 min read
Most tabletop exercises are designed not to find anything
An exercise everyone passes has told you nothing you did not already believe. The scenarios are free and published; what makes an exercise worth the room is the two decisions nobody wants to make in it.
- Engineering5 min read
Whether you can investigate a breach was decided months ago
The questions asked after an incident are answerable only if somebody made specific, unglamorous logging decisions long before it happened. Almost nobody does.
- Security7 min read
CMMC on the shop floor: scope is the only lever that matters
A prime asked for your certification status and now the plant network is the problem. Almost all of the cost in a Level 2 assessment is decided before a single control is implemented, and since Phase 2 was suspended in July 2026, the person asserting your posture is you.
- Security6 min read
Four breach clocks, and the one you budgeted for is not running
Almost every incident-response plan we read commits to notifying somebody within 72 hours, and cites a federal rule that has never taken effect. Meanwhile the obligations that do bind you start on a trigger nobody has written down.
- Security5 min read
What you are actually buying when you buy a penetration test
Two quotes for the same words can differ by a factor of six, and the cheap one is often a vulnerability scan with a title page. The difference is legible before you sign, if you ask four questions.
- Security6 min read
Your plant network is flat, and the drawing says otherwise
Every site we have assessed had a network diagram showing a segmented plant. On most of them the segmentation was a VLAN with a permissive rule, a vendor laptop, or a spreadsheet nobody had opened in three years.
Engineering write-ups
Systems we built end to end, walked through in full, with the parts that did not work left in.
- Security8 min read
In vulnerability research, most of the work is ruling things out
We hunt on public disclosure programs between engagements. The part that transfers to paid work is not the findings. It is the machinery for discarding the forty candidates that looked exactly like them.
- Security6 min read
Catching anomalies on OT networks with fuzzy hashing
Enterprise intrusion detection does not transfer to industrial control networks. The traffic is a different shape, and that turns out to be an advantage.
Next step
Disagree with any of this?
Good, that’s usually the start of a useful conversation. We’d rather argue with you before an engagement than during one.
- Phone
- (214) 723-2510
- Reply
- A person replies, not a sequence: within one business day, from someone who would be on the engagement.