Resources

Insights, guides, and field notes from the trenches.

Practical content from the engineers and advisors running real environments. No fluff, no gated white papers for basics.

Featured

Start here.

Guide

The pragmatic SOC 2 timeline

An honest breakdown of what each phase actually costs in calendar time and internal effort — for orgs 25-200 people.

Read the guide
Checklist

Ransomware readiness — 24 point check

If you can't check at least 20 of these, you're betting your business. Covers backup, identity, network, and response.

Get the checklist
Comparison

CrowdStrike vs. SentinelOne vs. Defender for Business

When each one wins — by size, stack, and budget. Field observations, not vendor talking points.

Read the comparison
Framework

vCIO KPIs that matter to the board

The 12 metrics we report quarterly that actually shift decisions — and the vanity metrics we stopped showing.

Read the framework
Playbook

M365 tenant hardening in 30 checkpoints

Our baseline hardening script for new M365 tenants, explained one setting at a time.

Open the playbook
Guide

CMMC Level 2 without re-architecting everything

How we use CUI enclaves to reduce scope by 80%+ for small/mid-size DoD suppliers.

Read the guide
Primer

ZTNA: what it replaces, what it doesn't

Zero trust network access is a better VPN — but it's not a firewall replacement. Here's the clean mental model.

Read the primer
Template

Information security policy — starter pack

A pragmatic policy suite you can adapt in a week, not a quarter.

Download
Article

Why we stopped doing unlimited "project hours"

On the economics of MSP pricing and what actually aligns incentives between client and provider.

Read the article
Subscribe

Occasional. Useful. No sales pitch.

Monthly-ish digest of new guides, security advisories worth acting on, and the occasional opinion. Unsubscribe anytime.