Zero Assumptions · Week 9 of 25 · Pillar 2: Software stack & contextual risk Your SIEM fired an alert at 09:14.Your EDR caught the same attack at 09:24. Two tools. Same attacker. Ten minutes apart. Neither told the other. Your analyst saw two separate alerts in two separate consoles and triaged them as two separate incidents. The attacker had already moved. In weeks 6, 7, and 8 we covered the operational gaps between assessment cycles, session windows, and board oversight. This week we move...
2 days ago • 7 min read
Zero Assumptions · Week 7 of 25 · Pillar 2: Software stack & contextual risk Your morning login was legitimate.So the session running at 17:00 must be too. Session tokens are hijacked, not phished. Once an attacker has your token, they don't need your password, your MFA, or your hardware key. They already passed authentication. The question is whether your SOC finds them before they find what they came for. Last week we covered identity drift — the entitlement state that diverges from policy...
16 days ago • 6 min read
Zero Assumptions · Week 6 of 25 · Pillar 2: Software stack & contextual risk Your annual pen test showed no critical findings.So your identity posture is under control. A penetration test is a point-in-time snapshot. Your identity risk changes daily — new users, new devices, drifting permissions, unchecked access accumulation. The gap between the snapshot and today is where most incidents begin. Welcome to Pillar 2 — Software stack & contextual risk Pillar 1 covered the adversary tactics...
30 days ago • 5 min read
Zero Assumptions · Week 5 of 25 Your cloud SSO is hardened.So your identity perimeter is secure. 92% of enterprise employees still authenticate via username and password — mostly against on-premises systems outside your cloud MFA scope. Attackers target the seam between the two environments, and it is almost never monitored. Cloud-first security programmes have driven significant investment into securing Microsoft 365, Okta, Azure AD, and the SaaS applications behind them. Conditional access...
about 1 month ago • 3 min read
Zero Assumptions · Week 4 of 25 Your FIDO2 token passed the certification test.That means it's secure. FIDO2 certification validates protocol compliance. It does not validate firmware integrity, chip supply chain, or where your authentication data goes after it leaves the device. The decision to deploy hardware security keys is the right one. Where most organisations go wrong is treating that decision as finished once they have a FIDO2-certified product in hand. FIDO2 certification tells you...
about 1 month ago • 3 min read
Zero Assumptions · Week 3 of 25 Your helpdesk just verified the attacker.Then reset their password. KBA and a Zoom check are the most reliably social-engineered controls in your environment. Deepfake audio and video are now commodity tools — purpose-built to defeat them. In weeks 1 and 2 we covered what happens when an attacker blinds your EDR from inside the endpoint, and how AiTM toolkits intercept your OTP codes in real time. This week we step back further — to the moment before any of...
about 2 months ago • 3 min read
Zero Assumptions · Week 2 of 25 Your SMS code just left the building.And your MFA is fine. A 76% surge in AI-powered phishing bypass kits — and the structural reason why hardware-bound authentication is the only fix. Last week we looked at what happens inside your endpoint when a skilled attacker blinds your EDR before pulling credentials. This week, we step back to the moment before that — the authentication event itself. The assumption most organisations are still making: SMS OTP or push...
about 2 months ago • 2 min read
Emma Zaman Strategic Advisor: Sovereign Identity & Compliance Your EDR will catch lateral movement The assumption your SOC makes every morning — and the 2–4 day window sophisticated attackers rely on. Zero Assumptions Edition Volume 1 Most security teams have significant confidence in their EDR stack. The dashboards show green. The last pen test came back clean. The SOC has playbooks. The assumption — rarely tested, almost never spoken aloud — is that when a sophisticated attacker moves...
2 months ago • 1 min read
Emma Zaman Strategic Advisor: Sovereign Identity & Compliance The attackers who hit your peers last quarter didn't break in. They logged in using valid, phished, or socially engineered credentials. Legacy MFA didn't stop them, and yours won't either. CISO Edition | June 2026 84% of organizations got hit by an identity breach in 2025. In 1 in 3, the attacker just logged in. Phishing surged 76% because the toolkit does the work now—your attacker needs zero skill. If your authentication relies...
3 months ago • 1 min read