Cybersecurity notes · United Kingdom
Netivaleo
A small cybersecurity practice, writing about what actually reduces risk for the organisations that run essential services: knowing what you expose, keeping the network segmented, and doing the basics well. No hype, no scare stories.
Recent notes
- AI changes the tempo, not the fundamentals
AI rarely opens new doors into a network. It just gets through the old ones faster. What that means for defenders, and what to actually do.
- No one is too small to be scanned
"Who would bother with us?" is one of the most common — and most dangerous — assumptions in smaller organisations. Here's why size is no protection.
- A firewall won't protect your OT
A firewall at the internet edge is necessary, but it's rarely what protects your control systems. Segmentation on the inside is. The difference matters.
Reference
- The UK rules, in brief
A short, plain orientation to the UK cyber rules for essential services: the NIS Regulations, the Cyber Security and Resilience Bill, and the NCSC frameworks. Not legal advice.
- What “attack surface” actually means
A plain explanation of attack surface: what it includes, why a list of your known domains misses half of it, and why it changes every week.
Netivaleo also takes on a small number of attack-surface reviews for organisations that ask. It's not our main business, and there's no sales pitch — just the work, done carefully.