Does the recommendation to use password managers also apply to corporate environments?

In $SomeCorpo there is a policy that passwords must never be stored anywhere else except employees’ heads. Paper notes, password managers, storing passwords in browsers, etc, are all forbidden. To facilitate this they are even willing to r… Continue reading Does the recommendation to use password managers also apply to corporate environments?

Which security measures are reasonable for senior management in a Fortune 500 company if nation state threat actors like APT28 become a concern?

Current Threat Intelligence leads me to believe, that Senior Management of my company could be targeted by Threat Actors like APT28.
Threats I am concerned about are – listed by priority:

Information gathering
Corporate Espionage
Disrupti… Continue reading Which security measures are reasonable for senior management in a Fortune 500 company if nation state threat actors like APT28 become a concern?

Difference between the telegram (win1) desktop app and web interface when it is "managed by your organization"?

Sometime ago I was told by our cyber department that Telegram desktop app is not "safe" as it allows silent installation of programs (first I heard about it, and they could not back it by anything). Which makes me think they are … Continue reading Difference between the telegram (win1) desktop app and web interface when it is "managed by your organization"?

Cyber Essentials at a small business (20 employees) that keeps all business data within SaaS

Background
I’ve recently joined a rapidly growing small business (from 4 to 20 people in last 12 months) with a very DIY IT setup. It’s fallen to me (I’m a developer so I just happen to be sitting nearest IT world…) to improve their secu… Continue reading Cyber Essentials at a small business (20 employees) that keeps all business data within SaaS