Resources
What we’re seeing, in plain English.
Threat landscape, security leadership and compliance — written for the people who sign the questionnaire, not the people who run the servers.
Threat landscapeComplianceSecurity leadershipTechnical explainer
Compliance
What a client security questionnaire actually asks — and why 'we have an IT company' won't answer it
"We've got forty questions from a client and eleven days." It's the most common reason a firm calls us. The questions are almost never about technology.
Security leadership
Your IT provider is not your CISO. That's not a criticism of them.
Firms with an MSP assume security is covered. The MSP assumes the firm knows the boundary. The scan usually proves neither is right — and the fix isn't to blame the IT company.
Technical explainer
DMARC, explained for managing partners: can someone send an invoice as your firm?
Three DNS records decide whether a fraudster can email your clients from your own domain and pass every check. Most firms have one of them, half-configured. Here's what each does, in plain English.