ClearSecurity VISION
EN / RO

01 — Blog

Notes from the field.

Practical thinking on cybersecurity, regulation, and building security that actually works.

13 articles

HardeningJULY 2026 · 4 min read

How to enable MFA in Microsoft 365 — a step-by-step guide

Multi-factor authentication stops most account attacks. A concrete guide for Microsoft 365: what to enable, in what order, and how to verify it actually works.

Read the article →

HardeningJul 10, 2026 · 4 min read

Asset and data inventory: build it in a day, keep it alive

You can't protect what you don't know you have. How to build your company's inventory of devices, applications and data in one day, with a simple spreadsheet — and keep it current.

HardeningJul 10, 2026 · 4 min read

Backups with the 3-2-1 rule — the plan that survives ransomware

3 copies, on 2 kinds of storage, with 1 off-site. How to build a backup ransomware can't reach, and how to test it so it's a plan, not a hope.

HardeningJul 10, 2026 · 4 min read

BitLocker and automatic updates: secure your Windows machines in an hour

A lost laptop without encryption is a data breach. How to turn on BitLocker, where to store the recovery key, and how to make sure Windows updates itself.

HardeningJul 10, 2026 · 4 min read

A one-page incident response plan — write it today

In a crisis there's no time to invent the procedure. One page with the first 5 actions, who decides and who you call — plus the DNSC reporting deadlines if NIS2 applies to you.

HardeningJul 10, 2026 · 4 min read

Router, Wi-Fi and remote access: the essential settings, step by step

The out-of-the-box router is a front door left unlocked. Admin password, firmware updates, a separate guest Wi-Fi, and remote access through VPN — not open ports.

HardeningJul 10, 2026 · 5 min read

SPF, DKIM and DMARC: stop fake emails sent in your company's name

Three DNS records stop fake invoices and phishing sent "from" your domain. A step-by-step guide for Microsoft 365 and Google Workspace, with verification at the end.

HardeningJul 10, 2026 · 4 min read

Who owns security? The governance minimum for a small company

Without a "who", every measure belongs to nobody. How to name an owner, what leadership discusses once a quarter, and the three written rules to start with.

TrainingJul 6, 2026 · 6 min read

How to spot a phishing attack before it's too late

Three signals that give away a phishing email — artificial urgency, look-alike domains, unusual requests — and what to do about them with your team.

RiskJul 6, 2026 · 6 min read

What a security incident really costs your business

No global-report averages: the real cost structure of a security incident for a 30-person company — and the 10-minute calculation you can do yourself.

RegulationJun 18, 2026 · 5 min read

CyberFundamentals 2025 (CyFun): the framework behind NIS2 self-assessment

Romania's official NIS2 self-assessment is built on the CyberFundamentals framework. What the 6 functions and assurance levels are, and how they map to NIS2 obligations.

Security cultureJun 8, 2026 · 6 min read

Why security culture matters more than your tooling

Organizations invest heavily in security tools but remain breached through human vectors. The gap between investment and outcomes is a culture problem, not a product problem.

RegulationJun 8, 2026 · 6 min read

NIS2 in Romania: what organizations actually owe DNSC in 2026

OUG 155/2024 and Legea 124/2025 set concrete deadlines for incident reporting, registration changes, and audit obligations. Here is what in-scope organizations need to know.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.