Security writing that is useful
Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.
A board briefing that fits in ten minutes
Residual risk, open highs, last restore test, last simulation. Then stop talking.
ITSIGN Administrator · December 10, 2025
Vendor questionnaires that waste a week
Keep a living packet: MFA, backup, pentest date, policies. Answer from the packet, not from memory.
ITSIGN Administrator · December 3, 2025
SOC 2 readiness for a 40-person firm
You do not need a 20-person GRC team. You need owners, evidence locations, and a scope that matches the customer who asked.
ITSIGN Administrator · November 26, 2025
Cyber insurance questions you will fail on a Thursday
MFA everywhere? Offline backups? EDR? Privileged access? If you cannot evidence it, the answer is no.
ITSIGN Administrator · November 19, 2025
PIPEDA and a mailbox breach
If personal information left the building, you have a clock. Know who calls whom before it starts.
ITSIGN Administrator · November 12, 2025
Multi-factor authentication is no longer optional
Most Canadian cyber-insurance policies now treat MFA as a precondition. Here is how to roll it out without a revolt.
ITSIGN Administrator · November 5, 2025
