Financial services
Three recent financial-sector breaches, the exact privileged-access gap behind each, and a 60-second self-check. Finance brief
Most breaches do not start with a clever zero-day. They start with privileged access left broader, longer-lived, or less watched than anyone realized. One brief per industry: three recent breaches, the exact gap behind each, and a 60-second self-check for your own environment. The summary is open on every page; the full two-page brief is a form away.
Three recent financial-sector breaches, the exact privileged-access gap behind each, and a 60-second self-check. Finance brief
The campaign that moved straight through the US insurance sector, the access gaps it exploited, and how to check your exposure. Insurance brief
The largest healthcare breach ever recorded began with stolen credentials and a missing MFA prompt. Healthcare brief
One unretired VPN account shut down the largest fuel pipeline in the US. The pattern has not changed. Energy brief
The largest breach of student data in US history took one stolen password and a support portal with no MFA. Education brief
The retailers breached recently have something in common with Target a decade earlier: the attackers did not break in, they logged in. Retail brief
A ten-minute phone call to a help desk took a casino operator offline for ten days. Hospitality brief
Every brief opens with incidents from public reporting, the access gap behind each, and five questions you can answer in a minute. If any answer is "I would have to ask", that is the gap. The sector pages carry the fuller picture — start at the industries we work in.
A free audit is 30 minutes with a certified engineer, findings in writing. No cost, no obligation.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.