01 — Blog
Notes from the field.
Practical thinking on cybersecurity, regulation, and building security that actually works.
HardeningJULY 2026 · 4 min read
How to enable MFA in Microsoft 365 — a step-by-step guide
Multi-factor authentication stops most account attacks. A concrete guide for Microsoft 365: what to enable, in what order, and how to verify it actually works.
Read the article →
HardeningJul 10, 2026 · 4 min read
Asset and data inventory: build it in a day, keep it alive
You can't protect what you don't know you have. How to build your company's inventory of devices, applications and data in one day, with a simple spreadsheet — and keep it current.
HardeningJul 10, 2026 · 4 min read
Backups with the 3-2-1 rule — the plan that survives ransomware
3 copies, on 2 kinds of storage, with 1 off-site. How to build a backup ransomware can't reach, and how to test it so it's a plan, not a hope.
HardeningJul 10, 2026 · 4 min read
BitLocker and automatic updates: secure your Windows machines in an hour
A lost laptop without encryption is a data breach. How to turn on BitLocker, where to store the recovery key, and how to make sure Windows updates itself.
HardeningJul 10, 2026 · 4 min read
A one-page incident response plan — write it today
In a crisis there's no time to invent the procedure. One page with the first 5 actions, who decides and who you call — plus the DNSC reporting deadlines if NIS2 applies to you.
HardeningJul 10, 2026 · 4 min read
Router, Wi-Fi and remote access: the essential settings, step by step
The out-of-the-box router is a front door left unlocked. Admin password, firmware updates, a separate guest Wi-Fi, and remote access through VPN — not open ports.
HardeningJul 10, 2026 · 5 min read
SPF, DKIM and DMARC: stop fake emails sent in your company's name
Three DNS records stop fake invoices and phishing sent "from" your domain. A step-by-step guide for Microsoft 365 and Google Workspace, with verification at the end.
HardeningJul 10, 2026 · 4 min read
Who owns security? The governance minimum for a small company
Without a "who", every measure belongs to nobody. How to name an owner, what leadership discusses once a quarter, and the three written rules to start with.
TrainingJul 6, 2026 · 6 min read
How to spot a phishing attack before it's too late
Three signals that give away a phishing email — artificial urgency, look-alike domains, unusual requests — and what to do about them with your team.
RiskJul 6, 2026 · 6 min read
What a security incident really costs your business
No global-report averages: the real cost structure of a security incident for a 30-person company — and the 10-minute calculation you can do yourself.
RegulationJun 18, 2026 · 5 min read
CyberFundamentals 2025 (CyFun): the framework behind NIS2 self-assessment
Romania's official NIS2 self-assessment is built on the CyberFundamentals framework. What the 6 functions and assurance levels are, and how they map to NIS2 obligations.
Security cultureJun 8, 2026 · 6 min read
Why security culture matters more than your tooling
Organizations invest heavily in security tools but remain breached through human vectors. The gap between investment and outcomes is a culture problem, not a product problem.
RegulationJun 8, 2026 · 6 min read
NIS2 in Romania: what organizations actually owe DNSC in 2026
OUG 155/2024 and Legea 124/2025 set concrete deadlines for incident reporting, registration changes, and audit obligations. Here is what in-scope organizations need to know.
No articles match the current filter.
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.