Blog
Written for the people who decide, not the ones who configure.
We write about what a buyer asks before signing, and about what stays open with nobody looking. No figures we can't stand behind.
- Vendor riskSeptember 1, 2026
How to prove you vetted your vendors
The question lands in the last meeting before signing, and almost nobody can answer it with evidence. What counts as proof, and how to have it in a week.
Read → - Leadership and governanceJanuary 27, 2026
Security is not an IT problem
Three decisions no technical team can make on leadership's behalf, and why company size was never a defense.
Read → - Exposure and threatsJanuary 29, 2025
Exposure doesn't start when it goes public
In January 2025 the configurations of some 15,000 firewalls were published for free. They had been taken in 2022. What that says about the clock almost nobody measures.
Read →
Eight modules, one subscription
Vendor Risk, Attack Surface, Breach Exposure and five more modules under a single contract. Nothing to install.
Start a 30-day trial, no card