START HERE · SERIESThe Kerberos Attack ChainKerberos for the CISSP exam, in order: how the protocol works, then the attacks built on it (golden tickets, silver tickets, and Kerberoasting).
Software Development Security LONG-GUIDE · 30 SEPT 2026

Buffer Overflow and the Stack Canary Explained for CISSP

How a buffer overflow overwrites the return address, how a stack canary detects it before the return, and why the fix belongs in the code, not the platform.

Security Architecture INSIGHT · 11 SEPT 2026

Dual Control vs Separation of Duties: What Is the Difference?

Separation of duties splits a workflow across people and stages. Dual control makes two people act together on one action. The difference is when they act.

Security Operations LONG-GUIDE · 09 SEPT 2026

End of Life vs End of Support: The Two Dates CISSP Candidates Confuse

What End of Life and End of Support mean, why only the second date is a security cliff, and how CISSP scenarios may test the difference between them.

Risk Management & Governance LONG-GUIDE · 08 SEPT 2026

STRIDE Threat Model Explained: The Six Categories and What They Break for CISSP

STRIDE sorts threats into six categories, each the mirror of a security property it breaks. It finds threats thoroughly but does not rank them.

Security Architecture INSIGHT · 05 SEPT 2026

Need to Know vs Least Privilege: What Is the Difference?

Need to know asks whether you require this specific information. Least privilege asks what the minimum authority for the task is. Clearance settles neither.

Security Architecture LONG-GUIDE · 02 SEPT 2026

Trusted Computing Base Explained: Reference Monitor, Rings and Security Kernel for CISSP

What the trusted computing base includes, where its security perimeter sits, and how the reference monitor, security kernel and protection rings enforce it.

Security Operations INSIGHT · 31 AUG 2026

Security Assessment vs Security Audit: What Is the Difference?

An assessment advises the organisation and can be self-performed. An audit gives an outsider a formal opinion, so independence is mandatory.

Business Continuity LONG-GUIDE · 26 AUG 2026

Business Impact Analysis Explained: The BIA Process and Outputs for CISSP

How a business impact analysis finds critical functions, measures impact over time, maps dependencies, and produces the recovery priorities strategy must meet.

Business Continuity LONG-GUIDE · 26 AUG 2026

Business Continuity Planning Explained: The BCP Lifecycle and Testing for CISSP

The five phases of the BCP lifecycle, how BCP differs from DRP, who is accountable for the programme, and the six testing methods in order of disruption.

Risk Management & Governance LONG-GUIDE · 23 AUG 2026

Quantitative Risk Formulas: SLE, ARO and ALE

The five quantitative risk formulas in the order they run, worked end to end from asset value to a funded decision, plus where the method breaks down.

Network Security LONG-GUIDE · 20 AUG 2026

SPF, DKIM and DMARC: Complete Guide for CISSP

Email authentication for the CISSP: what SPF, DKIM and DMARC each check, why forwarding breaks SPF, and how alignment ties a pass to the visible From.

Software Development Security LONG-GUIDE · 17 AUG 2026

TOCTOU Explained: Time of Check Time of Use Race Conditions for CISSP

How a TOCTOU race condition turns a passed security check into an exploit, why symbolic links make it dangerous, and how to close the window.

Risk Management & Governance LONG-GUIDE · 14 AUG 2026

Data Security Roles: Owner, Custodian, Controller and Processor for CISSP

What each data security role does, how owner differs from custodian and controller from processor, and why accountability never transfers with the work.

Security Operations LONG-GUIDE · 14 AUG 2026

SOC Reports Explained: SOC 1, SOC 2 and SOC 3 for CISSP

What SOC 1, SOC 2 and SOC 3 cover, how Type 1 differs from Type 2, and what a CISSP candidate needs to know about third party assurance.

Business Continuity INSIGHT · 05 AUG 2026

Disaster Recovery Sites: Hot, Warm, Cold and Cloud

Hot, warm, cold and cloud recovery sites compared. The BIA sets the RTO, and the RTO picks the site. A CISSP insight with a manager mindset.

Exam Strategy INSIGHT · 05 AUG 2026

Due Diligence vs Due Care: What Is the Difference?

Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both.

Security Architecture INSIGHT · 05 AUG 2026

Fail Safe vs Fail Secure: What Is the Difference?

Fail safe defaults to open and protects people. Fail secure defaults to locked and protects assets. A CISSP insight on matching the default to the risk.

Network Security INSIGHT · 05 AUG 2026

IPsec AH vs ESP: What Is the Difference?

AH authenticates but never encrypts and breaks through NAT. ESP encrypts, authenticates and traverses NAT. A CISSP insight on the IPsec protocol choice.

Software Development Security INSIGHT · 05 AUG 2026

What Is SAST? Static Application Security Testing

SAST reads source code without running it, catching flaws at the cheapest point in the SDLC. A CISSP insight on its strengths, blind spots and CI/CD role.

Identity & Access Management LONG-GUIDE · 29 JAN 2026

Silver Ticket Attack: Forging Tickets Past the KDC

How a stolen service account hash forges a service ticket that never reaches the KDC, why that keeps it out of domain logs, and how to catch it.

Security Architecture LONG-GUIDE · 07 JAN 2026

Bell-LaPadula: No Read Up, No Write Down (CISSP)

The Bell-LaPadula rules in plain terms: no read up, no write down, and why a subject may write above its clearance but never read there.

Security Architecture LONG-GUIDE · 07 JAN 2026

Biba Model: No Read Down, No Write Up (CISSP)

The Biba rules in plain terms: no read down, no write up, and why integrity inverts the Bell-LaPadula directions it is confused with.

Security Architecture LONG-GUIDE · 07 JAN 2026

Chinese Wall Model (Brewer-Nash) Explained

How the Chinese Wall model stops consultant conflicts of interest: conflict classes, access that narrows as you read, and dynamic separation of duties.

Security Architecture LONG-GUIDE · 07 JAN 2026

Clark-Wilson Model: The Access Triple Explained

How Clark-Wilson protects commercial integrity: the access triple, well-formed transactions, separation of duties, and how it differs from Biba.

Security Architecture LONG-GUIDE · 07 JAN 2026

Graham-Denning: The Eight Protection Rules

The eight Graham-Denning operations for creating and deleting subjects and objects and transferring access rights, and where Harrison-Ruzzo-Ullman extends them.

Exam Strategy INSIGHT · 03 JAN 2026

Certificate Pinning: What Should You Pin First?

The foundational certificate pinning decision: choosing between certificate fingerprints, public key hashes and chain elements. A CISSP exam insight.

Exam Strategy INSIGHT · 03 JAN 2026

What Is the Difference Between Scoping and Tailoring?

Scoping makes binary yes or no calls on whether a control applies. Tailoring customises how it is implemented. A CISSP insight with a manager mindset.

Business Continuity LONG-GUIDE · 09 DEC 2025

RPO, RTO, WRT and MTD on One Recovery Timeline

How RPO, RTO, WRT and MTD sit on a single outage timeline, and why MTD is the ceiling the other three have to fit inside.

Identity & Access Management LONG-GUIDE · 07 DEC 2025

Kerberoasting: Cracking Service Passwords Offline

How any domain user can request a service ticket for an SPN and crack the service account password offline, and why long managed passwords stop it.

Identity & Access Management LONG-GUIDE · 07 DEC 2025

Golden Ticket Attack: Forging a TGT from krbtgt

How a stolen krbtgt hash lets an attacker forge any Kerberos TGT, why no domain controller checks it, and why krbtgt must be reset twice.

Identity & Access Management LONG-GUIDE · 07 DEC 2025

Kerberos: The Six-Step Ticket Flow Explained

How Kerberos issues a TGT and then service tickets across six messages, what the AS, TGS and KDC each do, and why clock drift breaks logon.