Security writing that is useful
Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.
Why on-site still matters in Toronto and Vancouver
Remote fixes the tenant. Hands fix the switch, the backup appliance, and the room nobody labelled.
ITSIGN Administrator · December 24, 2025
Your first IT hire vs an MSP
A generalist drowns in tickets and never does the project. An MSP without a named person feels like a queue. You can have both.
ITSIGN Administrator · December 17, 2025
A board briefing that fits in ten minutes
Residual risk, open highs, last restore test, last simulation. Then stop talking.
ITSIGN Administrator · December 10, 2025
Vendor questionnaires that waste a week
Keep a living packet: MFA, backup, pentest date, policies. Answer from the packet, not from memory.
ITSIGN Administrator · December 3, 2025
SOC 2 readiness for a 40-person firm
You do not need a 20-person GRC team. You need owners, evidence locations, and a scope that matches the customer who asked.
ITSIGN Administrator · November 26, 2025
Cyber insurance questions you will fail on a Thursday
MFA everywhere? Offline backups? EDR? Privileged access? If you cannot evidence it, the answer is no.
ITSIGN Administrator · November 19, 2025
PIPEDA and a mailbox breach
If personal information left the building, you have a clock. Know who calls whom before it starts.
ITSIGN Administrator · November 12, 2025
Multi-factor authentication is no longer optional
Most Canadian cyber-insurance policies now treat MFA as a precondition. Here is how to roll it out without a revolt.
ITSIGN Administrator · November 5, 2025
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
ITSIGN Administrator · October 29, 2025
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
ITSIGN Administrator · October 22, 2025
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
ITSIGN Administrator · October 15, 2025
External email banners that help instead of training people to ignore them
If every newsletter is tagged EXTERNAL, staff will stop reading the tag. Tune it.
ITSIGN Administrator · October 8, 2025
Shared mailboxes are not a reason to skip MFA
info@ and ar@ without MFA are a BEC starter kit. Convert, licence, or stop using them for money.
ITSIGN Administrator · October 1, 2025
A Microsoft 365 email security baseline that fits a 40-person firm
You do not need every blade in the portal. You need a short list that stays on.
ITSIGN Administrator · September 24, 2025
SPF, DKIM and DMARC without the mystique
Three records. One policy you tighten over time. The cheapest email-forgery control you are not done with.
ITSIGN Administrator · September 17, 2025
Capacity before the busy season, not after the outage
Retail in November. Accounting in April. Manufacturing when the line is booked. Size for that.
ITSIGN Administrator · September 10, 2025
Privileged access on the LAN is still a gift
Local admin everywhere, shared jump boxes, and service accounts that never expire.
ITSIGN Administrator · September 3, 2025
Ransomware and the copy they cannot reach
Immutable or offline. Tested. The rest is optimism.
ITSIGN Administrator · August 27, 2025
Network documentation you can use at 2 a.m.
A diagram, a password path, and who to call. Not a 90-page binder from 2018.
ITSIGN Administrator · August 20, 2025
End-of-life servers are a management decision
IT can flag them. Someone has to fund the move. Write the residual risk in business language.
ITSIGN Administrator · August 13, 2025
Active Directory hygiene for firms that still have one
Stale admins, nested groups nobody can explain, and a domain that trusts too much.
ITSIGN Administrator · August 6, 2025
Backups that restore, not backups that exist
A green job is not a company that can open on Monday. Test the restore. Time it.
ITSIGN Administrator · July 30, 2025
Patching that actually happens
A window, an owner, an exception list. Without those you have a wish and a scanner.
ITSIGN Administrator · July 23, 2025
Awareness training for hybrid and remote teams
Home routers, family PCs, and coffee-shop Wi-Fi are part of your estate whether you like it or not.
ITSIGN Administrator · July 16, 2025
Building a report-it culture
The best control you do not have to licence: staff who forward the weird mail in under two minutes.
ITSIGN Administrator · July 9, 2025
Why the annual security video fails
People click complete. Attackers do not wait for your LMS calendar.
ITSIGN Administrator · July 2, 2025
Training finance is not training the shop floor
One module for everyone is how you waste the hour and miss the risk.
ITSIGN Administrator · June 25, 2025
Measuring phishing click-through without lying to yourself
A 2% click rate on a cartoonish lure is not the same as 2% on a real invoice.
ITSIGN Administrator · June 18, 2025
Security awareness that changes behaviour
Short, role-specific, measured. Annual videos are a compliance artefact, not a control.
ITSIGN Administrator · June 11, 2025
QR-code phishing is email with extra steps
A poster in the lobby or a PDF in the inbox. The destination is still a credential farm.
ITSIGN Administrator · June 4, 2025
Lookalike domains and your legal name
Register the obvious typos. Monitor the rest. Tell finance what your real sending domain is.
ITSIGN Administrator · May 28, 2025
Reporting phishing without humiliating staff
Named-and-shamed click lists kill the programme. Report trends. Thank the people who forward mail.
ITSIGN Administrator · May 21, 2025
Spear phishing executives is a process problem
Assistants, travel, and public speaking calendars are OSINT. Treat VIP mailboxes like privileged accounts.
ITSIGN Administrator · May 14, 2025
Invoice fraud and the callback rule
The cheapest control in the building: call the number you already have, not the one on the invoice.
ITSIGN Administrator · May 7, 2025
The first hour after someone clicks
Reset, revoke, hunt the rule, tell the right people. Do not start with a lecture.
ITSIGN Administrator · April 30, 2025
Business email compromise is still the expensive one
In Canada this is still the claim that hurts: a changed bank detail, a rushed payment, a quiet mailbox rule.
ITSIGN Administrator · April 23, 2025
What phishing emails actually look like in 2026
Fewer princes. More Microsoft 365 notices, freight invoices, and threads that were already in the mailbox.
ITSIGN Administrator · April 16, 2025
Do you still need a perimeter firewall?
Yes, if you have an office. No, it is not your only control. Identity is the new edge, and both still matter.
ITSIGN Administrator · April 9, 2025
Site-to-site VPN mistakes we still walk into
Overlapping subnets, stale tunnels, and a second office that was never documented.
ITSIGN Administrator · April 2, 2025
Firewall change control that people will actually follow
If the process takes a week, someone will bypass it on a Friday. Make it short and recorded.
ITSIGN Administrator · March 26, 2025
Guest Wi-Fi that can see finance is not guest Wi-Fi
Cameras, visitors and the shop floor do not belong on the same VLAN as the accounting share.
ITSIGN Administrator · March 19, 2025
Next-gen firewalls vs the one you already paid for
Buying a new logo does not enable the features sitting unused on the current box.
ITSIGN Administrator · March 12, 2025
Firewall rules that look secure and are not
Any-any leftovers, shadowed rules, and objects named after people who left in 2019. A walk-through.
ITSIGN Administrator · March 5, 2025
When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
ITSIGN Administrator · February 26, 2025
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
ITSIGN Administrator · February 19, 2025
Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
ITSIGN Administrator · February 12, 2025
Pentest vs vulnerability scan: stop mixing them up
Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.
ITSIGN Administrator · February 5, 2025
How to read a pentest report without getting lost
Skip the CVSS column. Start with the path that reaches a business system, then the owner and the due date.
ITSIGN Administrator · January 29, 2025
Web application pentesting for Canadian SMBs
Customer portals and admin consoles are where the money sits. Testing them is not the same as scanning the office firewall.
ITSIGN Administrator · January 22, 2025
Internal vs external penetration testing
External tests the internet edge. Internal assumes someone is already inside. You usually need both, in that order.
ITSIGN Administrator · January 15, 2025
What a penetration test actually buys you
A scan lists software versions. A pentest tells you whether someone can reach payroll. Here is how to buy the second one.
ITSIGN Administrator · January 8, 2025
