MiliSec
  • Home
  • Services
  • About
  • Trust
  • Blog
  • FAQ
  • Contact
Free Audit
  • Home
  • Services
  • About
  • Trust
  • Blog
  • FAQ
  • Contact
Awareness

Business threat awareness: the latest risks explained

Threats move fast. Your decision makers must understand risk without becoming engineers.

2026-08-033 min readMiliSec
Awareness

Employee awareness: your first security control

The human factor stays the number one entry point. An informed team catches phishing before it spreads.

2026-08-033 min readMiliSec
Cryptography

AES-256 encryption: protecting data at rest and in transit

AES-256 remains a reference for encryption. But a poorly managed key cancels the encryption.

2026-08-033 min readMiliSec
Detection

SIEM: turning logs into security signal

A SIEM centralises and correlates events. Without correlation, logs only help after the incident.

2026-08-033 min readMiliSec
Network

IDS/IPS: detect and block on the network

An IDS alerts on suspicious activity, an IPS blocks it. Together they shrink time to detect.

2026-08-033 min readMiliSec
Network

WAF and NGFW: filter at the right layer

A WAF protects web apps; an NGFW filters the network with inspection. They are complementary, not interchangeable.

2026-08-033 min readMiliSec
Asset Management

Discovery: you only protect what you can see

Attack surface explodes with cloud, SaaS and remote work. Without a living inventory, assets stay unprotected.

2026-08-033 min readMiliSec
Public Sector

Government cyber security: sovereignty and resilience

Public entities are priority targets. The response combines sovereign cloud, hardening and continuity.

2026-08-033 min readMiliSec
AI

AI security: the risks the headlines miss

AI agents and LLMs add new surfaces: data leakage, prompt injection, unaudited decisions.

2026-08-033 min readMiliSec
IAM

IAM: manage identities as the new perimeter

In cloud and hybrid, identity is the new frontier. One over-privileged account equals one compromised server.

2026-08-033 min readMiliSec
IAM

MFA and 2FA: the control that blocks 99% of account takeovers

Multi-factor authentication is the best security ROI. Without MFA, a stolen password is enough.

2026-08-033 min readMiliSec
Zero Trust

ZTNA: why the perimeter VPN is no longer enough

Zero Trust starts from a simple rule: never trust by default, verify every access, all the time.

2026-08-033 min readMiliSec
Threat Intel

Hacking and attacks: decoding motive behind technique

Understanding why an attack happens changes your control priorities. Financial, espionage, destruction: each needs a different response.

2026-08-033 min readMiliSec
Threat

Cyber threat 2026: the vectors that actually matter

Attackers no longer hunt rare bugs. They hunt default configs, forgotten accounts and compromised suppliers.

2026-08-033 min readMiliSec
Pentest

Penetration testing: what the attacker sees before you do

A pentest is not a vulnerability scan. It simulates an attack to reveal your real exploitable surface.

2026-08-033 min readMiliSec
GDPR

UK GDPR 2026: records, DPIA and evidence for ICO scrutiny

The ICO tightens lawful-basis and tracking-pixel enforcement; evidence must be ready.

2026-07-123 min readMiliSec
CISO

Virtual CISO vs consultancy: why an outsourced function decides better

A vCISO brings senior security leadership without a full-time hire, and stays editorially independent.

2026-07-153 min readMiliSec
GRC

NIST CSF 2.0: Govern before you Protect

CSF 2.0 adds the Govern function as the bedrock of the six functions.

2026-07-183 min readMiliSec
Supply chain

Supply-chain cyber risk: mapping Critical Third Parties

ENISA names supply chain among the dominant 2026 threats, with Critical Third Parties carrying high impact.

2026-07-203 min readMiliSec
Ransomware

Ransomware resilience programme: the 4 pillars (NCSC)

The NCSC stresses no sector is immune; resilience beats hoping not to be hit.

2026-07-223 min readMiliSec
ISO 27001

ISO 27001: from certification to a living ISMS (2022 Annex A)

The 2022 Annex A moves from 114 to 93 controls, themed as organisational, people, technological and physical.

2026-07-253 min readMiliSec
SOC 2

SOC 2: what an auditor actually examines (Trust Services Criteria)

SOC 2 assesses controls against the TSC: Security, Availability, Processing Integrity, Confidentiality, Privacy.

2026-07-283 min readMiliSec
CISO

The CISO and the board: 5 dashboards that actually decide

The board does not read a vulnerability scan. It wants risk exposure, investment and decisions.

2026-07-303 min readMiliSec
GRC

Building an operational GRC model (Governance, Risk, Compliance)

GRC is the enterprise's risk-decision engine - not a compliance silo. COSO and ISO 37301 frame it.

2026-08-023 min readMiliSec
APT

APT tradecraft: how state-grade intrusions actually unfold

The NCSC and CISA describe APT campaigns as staged intrusions, not single exploits - with living-off-the-land techniques.

2026-08-013 min readMiliSec
NIS2

NIS2 and SMEs: when a contract pulls you into scope

Being a supplier to an essential entity can bring NIS2 obligations by extension.

2026-07-263 min readMiliSec
NCSC

NCSC: end of passwords alone for privileged access

The NCSC reiterates phishing-resistant MFA for all administrative access.

2026-07-273 min readMiliSec
Government

UK cyber sovereignty: securing public-sector cloud

The UK accelerates secure public-cloud and sovereign data handling.

2026-07-283 min readMiliSec
Incident

Healthcare ransomware: 72 hours to regain control

A hospital ransomware case: segmentation and tested backups limited downtime.

2026-07-293 min readMiliSec
ENISA

ENISA 2026 Threat Landscape: AI and supply chain dominate

ENISA's 2026 report flags AI-enabled attacks and supply-chain compromise as top risks.

2026-07-303 min readMiliSec
NIS2

UK alignment: NIS2-style duties and board accountability

UK operators with EU footprints inherit NIS2 duties; board accountability is now explicit.

2026-07-313 min readMiliSec
DORA

DORA: UK financial entities must map ICT third-party risk

Under DORA, UK banks and fintechs must map ICT third-party risk and run resilience testing.

2026-08-013 min readMiliSec
ICO

ICO: lawful basis and stricter tracking-pixel enforcement

The ICO clarifies lawful basis expectations for ad/measurement pixels under UK GDPR.

2026-08-023 min readMiliSec
CERT-UK

CERT-UK alert: SaaS account takeover via MFA fatigue

CERT-UK warns of account takeover campaigns targeting SaaS critical to operational resilience.

2026-08-033 min readMiliSec
NCSC

NCSC: 2026 supply-chain guidance for critical suppliers

The UK NCSC updates supply-chain security guidance, stressing assured SaaS and third-party risk for NIS-style regimes.

2026-08-043 min readMiliSec
MiliSec
  • Home
  • Services
  • Blog
  • Blog FR
  • Blog UK
  • Privacy
  • Cookies
  • Legal
  • Contact
Request a Virtual CISO assessment

© 2026 MiliSec. All rights reserved.