Independent IT security notes

Security,
without the smoke.

Practical ideas for protecting the systems and people you rely on. No panic. No magic bullet. Just a little more signal in the noise.

Field notes  ·  Vol. 001 / 2026
Start here  ·  Security foundations

A calm, practical response sequence for when an account may be compromised—and a reminder of what not to do first.

Incident response8 min readOct 7, 2026
Read the field note →
The library / 03 notes

Useful by design.

Short enough to read.
Solid enough to use.

The first 30 minutes after a suspicious login

A measured checklist for validating the alert, containing access, and preserving useful evidence.

Passkeys at work: a rollout that people can live with

How to introduce phishing-resistant sign-in without locking out the people who keep things running.

Make reporting a phish the easiest thing someone does all day

Good reporting is a product decision. Make the safe choice obvious, quick, and blame-free.

No notes in this topic yet. Try another filter.

A note on the approach

Less theater.
More security.

Security advice should help you make a better decision—not make you feel worse about the last one. This is an independent collection of practical notes for IT teams, curious builders, and anyone responsible for keeping a system safe.

We favor clear language, proportionate controls, and ideas you can actually put into practice. Every environment is different; adapt the guidance to your risks, obligations, and users.

Say hello ↗