Skip to main content
ITSIGNSolutions
Insights

Security writing that is useful

Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.

Infrastructure2 min read

Why on-site still matters in Toronto and Vancouver

Remote fixes the tenant. Hands fix the switch, the backup appliance, and the room nobody labelled.

ITSIGN Administrator · December 24, 2025

Infrastructure2 min read

Your first IT hire vs an MSP

A generalist drowns in tickets and never does the project. An MSP without a named person feels like a queue. You can have both.

ITSIGN Administrator · December 17, 2025

Risk and Insurance2 min read

A board briefing that fits in ten minutes

Residual risk, open highs, last restore test, last simulation. Then stop talking.

ITSIGN Administrator · December 10, 2025

Risk and Insurance2 min read

Vendor questionnaires that waste a week

Keep a living packet: MFA, backup, pentest date, policies. Answer from the packet, not from memory.

ITSIGN Administrator · December 3, 2025

Risk and Insurance2 min read

SOC 2 readiness for a 40-person firm

You do not need a 20-person GRC team. You need owners, evidence locations, and a scope that matches the customer who asked.

ITSIGN Administrator · November 26, 2025

Risk and Insurance2 min read

Cyber insurance questions you will fail on a Thursday

MFA everywhere? Offline backups? EDR? Privileged access? If you cannot evidence it, the answer is no.

ITSIGN Administrator · November 19, 2025

Risk and Insurance2 min read

PIPEDA and a mailbox breach

If personal information left the building, you have a clock. Know who calls whom before it starts.

ITSIGN Administrator · November 12, 2025

Risk and Insurance2 min read

Multi-factor authentication is no longer optional

Most Canadian cyber-insurance policies now treat MFA as a precondition. Here is how to roll it out without a revolt.

ITSIGN Administrator · November 5, 2025

Email Security2 min read

Email retention, PIPEDA, and the mailbox you never deleted

Keeping everything forever is not a strategy. It is a larger breach waiting for a number.

ITSIGN Administrator · October 29, 2025

Email Security2 min read

When the phish comes from a vendor you trust

Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.

ITSIGN Administrator · October 22, 2025

Email Security2 min read

Turn off IMAP and POP before someone else uses them

Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.

ITSIGN Administrator · October 15, 2025

Email Security2 min read

External email banners that help instead of training people to ignore them

If every newsletter is tagged EXTERNAL, staff will stop reading the tag. Tune it.

ITSIGN Administrator · October 8, 2025

Email Security2 min read

Shared mailboxes are not a reason to skip MFA

info@ and ar@ without MFA are a BEC starter kit. Convert, licence, or stop using them for money.

ITSIGN Administrator · October 1, 2025

Email Security2 min read

A Microsoft 365 email security baseline that fits a 40-person firm

You do not need every blade in the portal. You need a short list that stays on.

ITSIGN Administrator · September 24, 2025

Email Security2 min read

SPF, DKIM and DMARC without the mystique

Three records. One policy you tighten over time. The cheapest email-forgery control you are not done with.

ITSIGN Administrator · September 17, 2025

Infrastructure2 min read

Capacity before the busy season, not after the outage

Retail in November. Accounting in April. Manufacturing when the line is booked. Size for that.

ITSIGN Administrator · September 10, 2025

Infrastructure2 min read

Privileged access on the LAN is still a gift

Local admin everywhere, shared jump boxes, and service accounts that never expire.

ITSIGN Administrator · September 3, 2025

Infrastructure2 min read

Ransomware and the copy they cannot reach

Immutable or offline. Tested. The rest is optimism.

ITSIGN Administrator · August 27, 2025

Infrastructure2 min read

Network documentation you can use at 2 a.m.

A diagram, a password path, and who to call. Not a 90-page binder from 2018.

ITSIGN Administrator · August 20, 2025

Infrastructure2 min read

End-of-life servers are a management decision

IT can flag them. Someone has to fund the move. Write the residual risk in business language.

ITSIGN Administrator · August 13, 2025

Infrastructure2 min read

Active Directory hygiene for firms that still have one

Stale admins, nested groups nobody can explain, and a domain that trusts too much.

ITSIGN Administrator · August 6, 2025

Infrastructure2 min read

Backups that restore, not backups that exist

A green job is not a company that can open on Monday. Test the restore. Time it.

ITSIGN Administrator · July 30, 2025

Infrastructure2 min read

Patching that actually happens

A window, an owner, an exception list. Without those you have a wish and a scanner.

ITSIGN Administrator · July 23, 2025

Security Awareness2 min read

Awareness training for hybrid and remote teams

Home routers, family PCs, and coffee-shop Wi-Fi are part of your estate whether you like it or not.

ITSIGN Administrator · July 16, 2025

Security Awareness2 min read

Building a report-it culture

The best control you do not have to licence: staff who forward the weird mail in under two minutes.

ITSIGN Administrator · July 9, 2025

Security Awareness2 min read

Why the annual security video fails

People click complete. Attackers do not wait for your LMS calendar.

ITSIGN Administrator · July 2, 2025

Security Awareness2 min read

Training finance is not training the shop floor

One module for everyone is how you waste the hour and miss the risk.

ITSIGN Administrator · June 25, 2025

Security Awareness2 min read

Measuring phishing click-through without lying to yourself

A 2% click rate on a cartoonish lure is not the same as 2% on a real invoice.

ITSIGN Administrator · June 18, 2025

Security Awareness2 min read

Security awareness that changes behaviour

Short, role-specific, measured. Annual videos are a compliance artefact, not a control.

ITSIGN Administrator · June 11, 2025

Email Security2 min read

QR-code phishing is email with extra steps

A poster in the lobby or a PDF in the inbox. The destination is still a credential farm.

ITSIGN Administrator · June 4, 2025

Email Security2 min read

Lookalike domains and your legal name

Register the obvious typos. Monitor the rest. Tell finance what your real sending domain is.

ITSIGN Administrator · May 28, 2025

Security Awareness2 min read

Reporting phishing without humiliating staff

Named-and-shamed click lists kill the programme. Report trends. Thank the people who forward mail.

ITSIGN Administrator · May 21, 2025

Email Security2 min read

Spear phishing executives is a process problem

Assistants, travel, and public speaking calendars are OSINT. Treat VIP mailboxes like privileged accounts.

ITSIGN Administrator · May 14, 2025

Email Security2 min read

Invoice fraud and the callback rule

The cheapest control in the building: call the number you already have, not the one on the invoice.

ITSIGN Administrator · May 7, 2025

Email Security2 min read

The first hour after someone clicks

Reset, revoke, hunt the rule, tell the right people. Do not start with a lecture.

ITSIGN Administrator · April 30, 2025

Email Security2 min read

Business email compromise is still the expensive one

In Canada this is still the claim that hurts: a changed bank detail, a rushed payment, a quiet mailbox rule.

ITSIGN Administrator · April 23, 2025

Email Security2 min read

What phishing emails actually look like in 2026

Fewer princes. More Microsoft 365 notices, freight invoices, and threads that were already in the mailbox.

ITSIGN Administrator · April 16, 2025

Network and Firewalls2 min read

Do you still need a perimeter firewall?

Yes, if you have an office. No, it is not your only control. Identity is the new edge, and both still matter.

ITSIGN Administrator · April 9, 2025

Network and Firewalls2 min read

Site-to-site VPN mistakes we still walk into

Overlapping subnets, stale tunnels, and a second office that was never documented.

ITSIGN Administrator · April 2, 2025

Network and Firewalls2 min read

Firewall change control that people will actually follow

If the process takes a week, someone will bypass it on a Friday. Make it short and recorded.

ITSIGN Administrator · March 26, 2025

Network and Firewalls2 min read

Guest Wi-Fi that can see finance is not guest Wi-Fi

Cameras, visitors and the shop floor do not belong on the same VLAN as the accounting share.

ITSIGN Administrator · March 19, 2025

Network and Firewalls2 min read

Next-gen firewalls vs the one you already paid for

Buying a new logo does not enable the features sitting unused on the current box.

ITSIGN Administrator · March 12, 2025

Network and Firewalls2 min read

Firewall rules that look secure and are not

Any-any leftovers, shadowed rules, and objects named after people who left in 2019. A walk-through.

ITSIGN Administrator · March 5, 2025

Penetration Testing2 min read

When a pentest is really for the insurance form

Be honest about the audience. Then still do the work so the form is not the only thing you get.

ITSIGN Administrator · February 26, 2025

Penetration Testing2 min read

Why the retest is the part you should not skip

A finding list without a retest is homework you never marked. Insurers and customers notice.

ITSIGN Administrator · February 19, 2025

Penetration Testing2 min read

Scoping a pentest without wasting money

Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.

ITSIGN Administrator · February 12, 2025

Penetration Testing2 min read

Pentest vs vulnerability scan: stop mixing them up

Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.

ITSIGN Administrator · February 5, 2025

Penetration Testing2 min read

How to read a pentest report without getting lost

Skip the CVSS column. Start with the path that reaches a business system, then the owner and the due date.

ITSIGN Administrator · January 29, 2025

Penetration Testing2 min read

Web application pentesting for Canadian SMBs

Customer portals and admin consoles are where the money sits. Testing them is not the same as scanning the office firewall.

ITSIGN Administrator · January 22, 2025

Penetration Testing2 min read

Internal vs external penetration testing

External tests the internet edge. Internal assumes someone is already inside. You usually need both, in that order.

ITSIGN Administrator · January 15, 2025

Penetration Testing2 min read

What a penetration test actually buys you

A scan lists software versions. A pentest tells you whether someone can reach payroll. Here is how to buy the second one.

ITSIGN Administrator · January 8, 2025