Categories
837 sketches across 26 subjects.
- Identity & access66Who someone is, what they may do, and how both get proved. Most breaches start here.
- Vulnerability management58Finding weaknesses, ranking them honestly, and actually fixing some.
- Networks57Routing, naming, certificates and segmentation. The plumbing attackers move through.
- AI security52Models, agents and the pipelines around them. New surface, mostly old failure modes.
- Incident response50What you do once it has already happened, and what you wish you had done first.
- Data protection & privacy45Where data lives, who can read it, and what the law expects of you.
- Detection & SOC44Finding the thing. Telemetry, rules, and the gap between the two.
- Architecture & resilience35Designing so that failure is survivable rather than surprising.
- Application security34The flaws that come from how software is written, not how it is deployed.
- OT, ICS & cyber-physical34Estates you cannot take offline. Where a security decision has a physical consequence.
- Software supply chain & DevSecOps33Security in the pipeline, and in everything the pipeline pulls in.
- Governance & risk33Deciding what matters, writing it down, and proving it afterwards.
- Cloud security29Shared responsibility, and the parts of it people assume somebody else is holding.
- Human factors & social engineering29People are not the weakest link. They are the most targeted one.
- Cryptography25What the maths guarantees, and the far longer list of what it does not.
- Threat actors & ATT&CK25Who does this, how they work, and how to model it before they arrive.
- Containers & Kubernetes24Orchestration, isolation, and the defaults that are not safe ones.
- Malware & ransomware24How hostile code gets in, stays, and gets paid.
- API security23The interface is the product now, and the attack surface with it.
- Metrics, decisions & economics22Numbers that change a decision, and the many that do not.
- Supply chain & third parties21The risk you inherit from people you do not employ.
- Email & browser security19The two places most users meet an attacker.
- Frameworks & standards15ISO, NIST, Cyber Essentials and the rest. What they actually ask for.
- Everyday cyber & digital life15The advice worth giving people who do not do this for a living.
- Security fundamentals14The ideas everything else is built on. Get these and the rest starts to make sense.
- Security leadership & culture11Getting an organisation to care before it has to.
