Preparing for a penetration test: a 10-point checklist for SMEs
What to do before your first pentest. From defining scope to managing access, a practical guide to solidify your preparation.
read more →blog & insights
Expert guides and current analysis on software development, product, integration and cyber security.
01 — featured
June 12, 2026 · 7 min read · cyber security
What to do before your first pentest. From defining scope to managing access, a practical guide to solidify your preparation.
read more →02 — blog
May 28, 2026 · 5 min read · infrastructure
Real protection against data loss requires more than a regular backup. An untested backup is no backup.
May 20, 2026 · 8 min read · software
There is no single answer for every business. The criteria to weigh when deciding.
May 14, 2026 · 6 min read · cyber security
The “trust everyone inside” era is over. Why does modern security verify every access?
May 7, 2026 · 5 min read · marketing
To be visible you must first be findable. How do search engines understand your site?
May 1, 2026 · 7 min read · erp / crm
Disconnected systems create data silos. How should modern integration be designed?
July 9, 2026 · 7 min read · software
APIs are the backbone of modern software, and also its most attacked layer. In 2024, 37% of organizations suffered an API breach. Inside OWASP API Security Top 10.
July 29, 2026 · 7 min read · cyber security
Personal phones touching company data is not the problem; unmanaged access is. What separates MDM from MAM, the limits of remote wipe, and off-boarding.
July 8, 2026 · 7 min read · infrastructure
Moving to the cloud does not transfer security responsibility to your provider. Where the shared responsibility model ends, your job begins. Here is the line.
July 22, 2026 · 7 min read · cyber security
A DDoS attack floods your site with fake traffic until real users can't reach it. Records hit 31.4 Tbps in 2025. Here's how they work and how to defend.
July 20, 2026 · 7 min read · cyber security
Antivirus catches known malware by matching signatures, but 79% of 2024 attacks used no malware file at all. Here is what EDR does differently and why you need it.
July 8, 2026 · 7 min read · cyber security
Anyone can send email that shows your domain in the From line. Here is how SPF, DKIM and DMARC stop domain spoofing, and the safe order to set the three records up.
August 1, 2026 · 8 min read · cyber security
Vulnerabilities keep appearing in end-of-life software, but patches stop. Windows 10, Exchange and SQL Server 2016: inventory, ESU cost and a migration plan.
July 8, 2026 · 7 min read · software
Writing an API key, password or token into your source code makes a leak inevitable. In 2025, 29 million secrets were exposed on public GitHub. Here is the fix.
July 23, 2026 · 7 min read · cyber security
HTTPS encrypts your traffic and proves your server's identity. Certificate lifetimes drop to 47 days by 2029, ending manual renewal. Here is what to know.
July 27, 2026 · 7 min read · cyber security
The first day after you spot an attack decides how bad it gets. How to contain it without destroying evidence, who to call, and when the legal clock starts.
July 28, 2026 · 7 min read · cyber security
An ISO 27001 certificate proves you run an information security management system in a declared scope, not that you are secure. What the 93 controls and audits show.
July 31, 2026 · 8 min read · cyber security
Collecting logs is not detection. Which logs actually matter, why 90 days of retention is not enough, and whether you should run monitoring in-house or buy MDR.
July 19, 2026 · 7 min read · cyber security
MFA blocks more than 99% of automated account attacks, but not all MFA is equal. Here is why SMS codes are the weakest link and which second factor resists phishing.
July 18, 2026 · 8 min read · cyber security
OWASP has updated its Top 10 after four years. What is the number one web risk in 2025, what changed, and how should your company actually use the list?
July 8, 2026 · 7 min read · cyber security
A passkey swaps your password for a cryptographic key on your device. Here is how it works, why it resists phishing, and where your business should start.
July 21, 2026 · 7 min read · cyber security
Exploiting unpatched flaws is now attackers' top way in, past stolen passwords. WannaCry's fix had shipped two months before the attack. Which do you patch first?
July 11, 2026 · 7 min read · cyber security
Why phishing hits small and mid-sized businesses so often, and the low-cost steps you can take today to protect your company and its accounts.
July 17, 2026 · 7 min read · cyber security
Ransomware no longer just encrypts your files, it steals them first. Here is how the attack works, how your company can defend against it, and whether paying helps.
July 8, 2026 · 7 min read · cyber security
Your team is pasting company data into tools like ChatGPT. Why the Shadow AI risk is so widespread, and how to build a safe, compliant usage policy today.
July 8, 2026 · 7 min read · cyber security
Every open source library you install is a door into your systems. Here is how software supply chain attacks really work and how to defend your company.
August 2, 2026 · 8 min read · software
Whoever writes the code owns it by default. Turkish law requires a written, itemised transfer of rights. What your contract, handover list and escrow must cover.
July 30, 2026 · 8 min read · cyber security
A scanner lists known vulnerabilities. A pentest proves how far someone can get with them. Why PCI DSS and Turkish banking rules require both, separately.
03 — subscribe
Once a month, only value-adding content. No spam, unsubscribe anytime.