Aller au contenu principal
Blog

Blog & Cybersecurity Insights

Articles, best practices and news to protect your business against cyber threats.

Best Practices 4 min18 June 2026

The CISO's biggest challenge isn't technical: convincing the board

Security teams speak CVE and CVSS; executives think revenue, continuity and customer trust. Two conversations that never meet. Here is how to translate cyber risk into business language and finally be heard in the boardroom.

CISO GRC Risk Management Governance ISO 27001
Read article
DevSecOps 5 min17 June 2026

47 seconds: why manual secret scanning will never keep up

A founder pushes an AWS key to GitHub. 47 seconds later, a bot had found it — not us. The real problem with manual secret scanning: you're asking humans to watch something faster than they can react. Here's the setup I put in place, without slowing devs down.

DevSecOps Secret Scanning Gitleaks Vault Cloud Security
Read article
News 5 min17 June 2026

Cyber Weekly Recap #25 — Supply chain, offensive AI and cloud under pressure

Week 25 confirms a deep trend: attackers are moving away from complex vulnerabilities towards software supply chains, identities and cloud environments. PyPI/NPM typosquatting, AI speeding up exploitation, critical infrastructure under pressure — and the actions to take.

Supply Chain Threat Intel DevSecOps Cloud AI
Read article
Best Practices 5 min17 June 2026

Out of firefighting mode: how a security team shifts from reactive to proactive

Why do so many cybersecurity teams spend their days putting out fires? Often it's not a lack of resources, but a lack of proactive time. Here are three concrete levers to break the vicious cycle.

SOC Governance Maturity Automation Risk Management
Read article
Awareness 4 min17 June 2026

OSINT: what a stranger can find out about you (and how to reduce your exposure)

A few open searches, a few cross-references, sometimes just an email address: that's how OSINT works. It's also an excellent way to assess your own digital exposure. Here's how to run your OSINT self-audit and shrink your footprint.

OSINT Digital footprint Privacy Phishing Awareness
Read article
Best Practices 4 min17 June 2026

5 tools I actually use every day (out of 30+ tested)

I've tested over 30 tools in the past two years. Today, I actually use 5. Because productivity isn't about stacking tools — it's about removing friction. Here is my stack, and why.

Productivity Tools GRC DevOps Knowledge Management
Read article
Technical 4 min17 June 2026

Cisco SD-WAN: handling an actively exploited flaw with no patch (CVE-2026-20245)

What do you do when a vulnerability is actively exploited but no patch is available yet? That's the situation with CVE-2026-20245 on Cisco Catalyst SD-WAN Manager. When the patch doesn't exist yet, compensating controls become your first line of defence.

Cisco SD-WAN CVE Vulnerability Incident
Read article
Compliance 4 min8 June 2026

€5M CNIL Fine: The IQVIA Lesson on Health Data

€5 million fine imposed by the CNIL on IQVIA for failures in handling health data. Behind that number lies a lesson every organisation should remember: with sensitive data, there is no room for approximation.

GDPR CNIL Health data Privacy DPIA
Read article
Compliance 4 min30 March 2026

Weekly Regulatory Recap #13 — NIS2, GDPR, CRA: The 5 Key Regulatory Updates

NIS2 ANSSI guides, EDPB coordinated action on GDPR transparency, cyber threat landscape +35%, Cyber Resilience Act and ENISA CVE Root Authority. Your weekly regulatory roundup.

NIS2 GDPR ANSSI ENISA Cyber Resilience Act
Read article
Awareness 2 min27 April 2026

Security Tip: 3 Simple Reflexes to Stop Falling for Phishing

Phishing does not target your systems. It targets your employees. And 91% of breaches start there. Here are the 3 reflexes to adopt immediately.

Phishing Awareness Human Factor MFA Reporting
Read article
News 5 min27 April 2026

Cyber Weekly Recap — Trivy, Cisco RCE, European Commission, LiteLLM, Hasbro

5 major incidents this week: Trivy compromised in CI/CD, actively exploited Cisco RCE, European institution hit, LiteLLM in the AI supply chain, and Hasbro offline.

Weekly Supply Chain CVE Ransomware ThreatIntel
Read article
Best Practices 4 min27 April 2026

I Almost Got Compromised Because of My Passwords. Here's What I Changed.

Artificial complexity, forced rotation, security questions… A large part of what we've been taught is outdated. What NIST actually recommends today.

Passwords MFA NIST Awareness Bitwarden
Read article
Technical 4 min27 April 2026

I Secured My SSH in Less Than 10 Minutes. Here's Exactly What I Did.

Root login enabled, port 22 exposed, password auth without fail2ban… The most common SSH mistakes and the 7-step checklist to fix them permanently.

SSH Linux Hardening SysAdmin DevOps
Read article
News 4 min13 April 2026

Threat Intel Weekly #15 — 3 Threats to Watch (April 10–13, 2026)

Critical RCE on Marimo already exploited, 4,000 industrial devices exposed on the internet, 20,000 crypto fraud victims. The threat recap for the week.

Threat Intel RCE IoT/OT Crypto Weekly
Read article
Compliance 3 min27 April 2026

GRC Cybersecurity in 60 Seconds: Your Strategic Shield

Governance, Risk, Compliance — three letters many equate to paperwork. In reality, GRC is the lever that lets you make better decisions, anticipate risks and structure your security.

GRC ISO 27001 GDPR NIS2 Governance
Read article
Best Practices 3 min27 April 2026

He Lost 3 Years of Photos in an Instant. The 3-2-1 Rule Would Have Saved Everything.

A hard drive clicking, then nothing. 3 years of memories gone. A simple rule, taking 15 seconds to understand, would have prevented it all.

Backup Data SME Freelance Continuity
Read article
News 4 min27 April 2026

Data Breach at ANTS: A Basic Flaw, Millions of Citizens Exposed

Up to 19 million French citizens potentially exposed following an IDOR vulnerability on the National Secure Documents Agency platform. A closer look at a simple flaw with major consequences.

Data Breach IDOR AppSec GDPR France
Read article
DevSecOps 4 min27 April 2026

I Accidentally Committed a Secret. So I Secured Everything in 45 Minutes.

Over 50% of code files contain sensitive data. Here's how to set up detection, prevention and monitoring so it never happens again.

DevSecOps Git Secrets DLP ShiftLeft
Read article
Best Practices 5 min26 April 2026

SME Cybersecurity: The Essential Checklist (Implement Today)

Running an SME without cybersecurity is like leaving the front door open. Discover the 10 priority measures to drastically reduce your risks — without being an expert.

SME Cybersecurity GDPR Best Practices
Read article
Technical 4 min29 April 2026

I Set Up a PAM Foundation in 45 Minutes. Here's How — and Why.

A large share of breaches involve privileged accounts. When an attacker gains admin access, they stop hacking… they simply operate legitimately. Here's how to build a minimal PAM in 45 minutes.

PAM IAM ZeroTrust AccessManagement KeePassXC
Read article
Awareness 3 min29 April 2026

5 Tell-Tale Signs: Spot a Phishing Email in 30 Seconds

Phishing remains the #1 attack vector. The good news: in most cases it can be detected in seconds. Here are the 5 warning signals you need to know.

Phishing Email Awareness SecurityAwareness InfoSec
Read article
Best Practices 3 min29 April 2026

Best Practice — Secure Your Passwords in 1 Hour

81% of breaches involve weak or reused credentials. The good news: you can dramatically reduce this risk in under an hour.

PasswordManager MFA Bitwarden SecurityBestPractices InfoSec
Read article
Technical 4 min29 April 2026

Blue Team Use Case — Detecting Mimikatz

Mimikatz remains the reference tool for credential theft. 80% of breaches involve credential dumping. Here is how to detect it before exfiltration.

BlueTeam SOC Mimikatz Sigma ThreatDetection
Read article
DevSecOps 4 min29 April 2026

Best Practice — Preventing SQL Injection (SQLi)

Despite 20 years of awareness, SQL Injection remains a major vulnerability: 18% of web breaches still exploit it. Yet 94% are preventable with simple best practices.

SQLInjection AppSec OWASP SecureCoding DevSecOps
Read article
Technical 4 min29 April 2026

Red Team — Testing WAF Resilience Against XSS

Modern WAFs effectively filter classic payloads. But they are not infallible. Here are the essential test axes for evaluating their robustness during an audit.

RedTeam XSS WAF Pentest BugBounty
Read article
Technical 4 min31 May 2026

The Invisible That Saves Everything — Shadow Work, May 2026

A whole month polishing the invisible. Shadow Audit, GRC automation, robustness by design. What nobody sees… until the day it saves everything.

BuildInPublic ShadowAudit GRC SaaSFactory Resilience
Read article
DevSecOps 5 min31 May 2026

Secure Cloud by Default? No. Here's How to Go from Hope Mode to Proof Mode.

The best firewalls protect nothing if an S3 bucket accidentally goes public. For 2 years I lived with that tension. Here are the 3 pillars that changed everything.

CloudSecurity AWS Azure DevSecOps Monitoring MultiCloud
Read article
Technical 4 min31 May 2026

Red Team Reality Check — Understanding the Radar Rather Than Evading It

Modern EDRs see almost everything. Good SOCs no longer rely on signatures. Modern Red Teaming is no longer just about staying under the radar — it's about understanding how it works.

RedTeam BlueTeam SOC ThreatHunting EDR InfoSec
Read article
Technical 5 min31 May 2026

Blue Team Use Case — Incident Detection & Response: The First 15 Minutes

Your SOC detects suspicious activity at 3am. What happens in the first 15 minutes can make all the difference. A real Finance case study + the 5 practices that change everything.

BlueTeam SOC IncidentResponse DFIR ThreatDetection InfoSec
Read article
Compliance 4 min3 June 2026

PolicyForge: Compliance Documentation Finally Accessible to SMBs

ISO 27001, SOC 2 or NIS2 compliance always starts with documentation. PolicyForge generates professional, customised policies to address this challenge without spending weeks on it.

ISO 27001 Compliance GRC SMB PolicyForge GDPR NIS2
Read article

Get our next articles

Best practices, threat alerts and real-world cases straight to your inbox.