top of page
SecuSolutions Blog


Why Your Cybersecurity Program Needs an Outside Perspective
Did you know that you can hire the best information technology team, equip them with all the resources they need to keep your business operation and your systems running, provide them with healthy budgets and empower them to make great technology decisions, and you could still have a serious cybersecurity problem? Organizations invest significant time and money into firewalls, endpoint protection, multi-factor authentication (MFA), vulnerability management, security awareness
Paulita Laing
2 min read


From Compliance to Culture
Gone are the years where cybersecurity is seen as a responsibility isolated to the IT team, or a boring but necessary box to check for compliance. Cyber threats (and their perpetrators are growing in sophistication every day, so organizations need to move quickly and transform their approach beyond the bare minimum (cybersecurity policy sign offs and annual training) towards a culture where security is part of how people work every day. Let’s rewind. Old-school compliance-dri
Paulita Laing
2 min read


The economics of offence have changed faster than the economics of defence
Attack resources, once limited to skilled researchers, organized crime, and nation states are now widely accessible, while building and maintaining secure systems remains difficult and expensive. Security is no longer free. For years, security was something many teams postponed until after shipping. Many systems survived not because they were secure, but because no one was actively looking for weaknesses. Hidden endpoints, obscure workflows, and edge-case bugs often went undi
Andrey Tcherepanov
2 min read


Trust After You Verify: Why AI Output Needs Human Quality Assurance and Manual Review
There's a pattern we keep running into on engagements, and it's worth naming directly: employees increasingly trust AI output over professional expertise sitting right next to them. This expertise may be internal resources or colleagues, or external subject matter experts. Increasingly, oversight occur not because the AI is right more often, but because it comes across as so confident (often incorrectly), fast, and frictionless. This is a combination that is dangerous - in wa
Daniel Tcherepanov
3 min read


Phishing: how an individual's emotions can lead to an entire company's compromise
An exhausted HR manager at 4:45 PM receives an "urgent" email from his CEO. He demands the entire staff user list, listed in plain csv: first name, last name, and email address, for an upcoming audit. Without hesitation, eager to put an end to an already grueling day, he complies, exporting and delivering the user list, without confirming the sender or verifying the request through other forms of communication. Just like that, the hacker now has a list of targets, knowing tha
Chad Broadhurst
2 min read


The human firewall: How employee training stops cyber attacks
People are the weakest link in your cybersecurity armour. A company can stack firewalls, scanners, and encryption high, yet a single employee and a fake invoice can knock every layer flat. When someone holds the door open for a stranger, the strength of the locks no longer matter. The same applies in security. If an employee hands an attacker the password, even the best security products can’t protect your organization. Phishing, ransomware, and malicious downloads pose serio
Frances Kootnekoff
2 min read


Don’t Develop Tunnel Vision
Talking to companies about security is what we do, and we’ve been doing it for nearly 25 years. Over the years we have had some interesting engagements with some very prominent companies. Many of the companies we have serviced have had very comprehensive security programs in place and have utilized the latest in security technologies. Some follow security standards like NIST, ISO and SOC. These companies, by security standards, are doing the right thing. So why are so many st
jimkootnekoff
2 min read
bottom of page

