Technology
Cybersecurity

Assume breach: identity-first security that survives a bad day

The controls that stop most real incidents — strong identity, fast patching, tested backups, and a plan for the day something gets through.

7 min read

Identity is the new perimeter

Most incidents that reach small organisations start with a stolen or reused credential, not a exotic exploit. Phishing-resistant multi-factor authentication on email, finance, and admin accounts removes the cheapest way in.

Give people only the access their role needs, review it on a schedule, and remove it the day someone leaves. A password manager for unique credentials is the lowest-effort, highest-return control you can roll out this week.

Close the doors attackers walk through

Keep operating systems, browsers, and business apps on automatic updates, and track the handful of internet-facing services you run. Unpatched, exposed software is how opportunistic ransomware finds a target.

Teach the team to pause on urgency: an unexpected message that asks you to log in, pay, or move data is a signal to verify through a known channel, not to click.

Practise the recovery, not just the backup

Keep at least one backup that an attacker on your network cannot reach or encrypt, and restore a file from it on a schedule so you know it works.

Write the incident plan before you need it: who is called, who can isolate a device, who talks to customers, and where the evidence goes. A rehearsed hour saves a ruined week.

The Gelllez dispatch

Useful technology, without the noise.

Clear explanations, practical tools, and smarter ways to move from curiosity to action.