Security writing that is useful
Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
ITSIGN Administrator · October 29, 2025
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
ITSIGN Administrator · October 22, 2025
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
ITSIGN Administrator · October 15, 2025
External email banners that help instead of training people to ignore them
If every newsletter is tagged EXTERNAL, staff will stop reading the tag. Tune it.
ITSIGN Administrator · October 8, 2025
Shared mailboxes are not a reason to skip MFA
info@ and ar@ without MFA are a BEC starter kit. Convert, licence, or stop using them for money.
ITSIGN Administrator · October 1, 2025
A Microsoft 365 email security baseline that fits a 40-person firm
You do not need every blade in the portal. You need a short list that stays on.
ITSIGN Administrator · September 24, 2025
SPF, DKIM and DMARC without the mystique
Three records. One policy you tighten over time. The cheapest email-forgery control you are not done with.
ITSIGN Administrator · September 17, 2025
QR-code phishing is email with extra steps
A poster in the lobby or a PDF in the inbox. The destination is still a credential farm.
ITSIGN Administrator · June 4, 2025
Lookalike domains and your legal name
Register the obvious typos. Monitor the rest. Tell finance what your real sending domain is.
ITSIGN Administrator · May 28, 2025
Spear phishing executives is a process problem
Assistants, travel, and public speaking calendars are OSINT. Treat VIP mailboxes like privileged accounts.
ITSIGN Administrator · May 14, 2025
Invoice fraud and the callback rule
The cheapest control in the building: call the number you already have, not the one on the invoice.
ITSIGN Administrator · May 7, 2025
The first hour after someone clicks
Reset, revoke, hunt the rule, tell the right people. Do not start with a lecture.
ITSIGN Administrator · April 30, 2025
Business email compromise is still the expensive one
In Canada this is still the claim that hurts: a changed bank detail, a rushed payment, a quiet mailbox rule.
ITSIGN Administrator · April 23, 2025
What phishing emails actually look like in 2026
Fewer princes. More Microsoft 365 notices, freight invoices, and threads that were already in the mailbox.
ITSIGN Administrator · April 16, 2025
