From Cyber Evidence to Fiduciary Oversight and Resilience
Connect ownership, material-risk decisions, remediation, escalation, and recovery evidence to executive oversight, incident-loss reduction, and insurance readiness.
Read the articleResearch and guidance
Vulnerability research and practical observations from the work of testing, protecting, and improving real environments.
Connect ownership, material-risk decisions, remediation, escalation, and recovery evidence to executive oversight, incident-loss reduction, and insurance readiness.
Read the articleAn audit records what exists. A defensible security conclusion requires approved business functions, ownership, access, data flow, and recovery context.
Read the articleMap the business, establish the observed baseline, define the target, verify remediation, and monitor for unauthorized drift.
Read the articleDirectory membership shows assigned access. It does not prove that the access is required for a person's position and allocated functions.
Read the articleCVE-2012-4688. Client-side authentication logic allowed access when JavaScript was disabled.
Read the disclosureCVE-2018-7467. A directory traversal issue in the AxxonSoft client web interface.
Read the disclosureWhy recurring authenticated discovery, reporting, remediation, and validation are foundational to a durable security program.
Read the article