Security,
without the smoke.
Practical ideas for protecting the systems and people you rely on. No panic. No magic bullet. Just a little more signal in the noise.
The first 30 minutes after a suspicious login
A calm, practical response sequence for when an account may be compromised—and a reminder of what not to do first.
Read the field note →Useful by design.
Solid enough to use.
The first 30 minutes after a suspicious login
A measured checklist for validating the alert, containing access, and preserving useful evidence.
Passkeys at work: a rollout that people can live with
How to introduce phishing-resistant sign-in without locking out the people who keep things running.
Make reporting a phish the easiest thing someone does all day
Good reporting is a product decision. Make the safe choice obvious, quick, and blame-free.
No notes in this topic yet. Try another filter.
Less theater.
More security.
Security advice should help you make a better decision—not make you feel worse about the last one. This is an independent collection of practical notes for IT teams, curious builders, and anyone responsible for keeping a system safe.
We favor clear language, proportionate controls, and ideas you can actually put into practice. Every environment is different; adapt the guidance to your risks, obligations, and users.
Say hello ↗