Category Archives: General

Why Security Documentation Is an Editorial Problem, Not Just a Technical One

In March 2024, CISA published an advisory about an actively exploited vulnerability in a widely used VPN appliance. The advisory had what security teams needed on paper—CVE number, affected versions, CVSS score, proof-of-concept references. But the remediation guidance? Buried on … Continue reading

Posted in General | Comments Off on Why Security Documentation Is an Editorial Problem, Not Just a Technical One

The Password Is Not the Problem: Why Non-Technical Users Are Being Left Behind in Security

Kira Mikkonen has spent fifteen years watching people click on things they shouldn’t. She’s seen a finance director forward a phishing email to the entire company with a cheerful note asking, “Is this real?” She’s watched a senior surgeon plug … Continue reading

Posted in General | Comments Off on The Password Is Not the Problem: Why Non-Technical Users Are Being Left Behind in Security

The Human Firewall: Why Your Instincts Matter More Than Your Antivirus

Every morning, billions of us reach for a phone or open a laptop and step, often without a second thought, into a world that is quietly, relentlessly under siege. We check bank balances, share photos of our kids, and run … Continue reading

Posted in General | Comments Off on The Human Firewall: Why Your Instincts Matter More Than Your Antivirus

The Human Firewall: Why Everyday Users Are the First and Last Line of Defense

We built a world that runs on trust. We trust the email from the bank, the link from a coworker, the software update that pops up at the worst possible moment. Attackers know this. They don’t waste time chipping away … Continue reading

Posted in General | Comments Off on The Human Firewall: Why Everyday Users Are the First and Last Line of Defense

Why We Keep Failing Non-Technical People on Security—and How to Finally Fix It

Kira Mikkonen here. I’ve spent over a decade watching the same sad story play out: a well-meaning person clicks a link, opens an attachment, or reuses a password, and their digital life implodes. The security community’s response? Usually a sigh, … Continue reading

Posted in General | Comments Off on Why We Keep Failing Non-Technical People on Security—and How to Finally Fix It

The Documentation Gap: Why Security Write-Ups Fail the Public They Claim to Protect

Late March 2024, a Microsoft engineer chasing down sluggish SSH logins tripped over one of the most elaborate supply chain attacks ever attempted. The xz Utils backdoor, planted over years by a patient adversary who earned trust inside an open … Continue reading

Posted in General | Comments Off on The Documentation Gap: Why Security Write-Ups Fail the Public They Claim to Protect