Why Foundry Cyber has a blog
· 1 min read
Most security writing is either fear or filler. Ten tips you’ve read ten times. A breach story with a quote from someone selling the cure. A vendor pitch dressed up as advice. We think UK businesses deserve better, so this blog is us writing the thing we kept wishing we could send to customers.
What we’ll write about
Three things, mostly.
How the standards actually work. Cyber Essentials, NIST CSF, NCSC guidance. What the wording means for a normal business, what changed between versions, and what to do about it. First up: what actually changed in Cyber Essentials v3.3.
What we see in real cloud environments. We run continuous assessments across Microsoft 365, Google Workspace, AWS and GCP. The patterns are instructive: the same handful of gaps come up again and again, and they’re rarely the ones the headlines worry about. Anything we share is anonymised and aggregated. Always.
Opinions we’re prepared to defend. How security is sold, priced and reported, and where the industry serves itself before its customers. We’ve already started: security isn’t a pricing tier.
The rules we write by
- Plain English. If a sentence needs a glossary, it gets rewritten.
- Primary sources. NCSC, NIST, ENISA and the cloud vendors’ own documentation. Not somebody’s summary of somebody’s summary.
- No scare tactics. Fear sells, but it doesn’t secure anything.
- Specific beats general. One setting that matters beats ten tips that don’t.
- Corrections in public. When we get something wrong, we’ll fix it on the post and say so.
How often
When we have something worth saying. We’d rather skip a week than pad one out, and you can hold us to that.
There’s an Atom feed if you’d like posts as they land. If you’d rather have all of this applied to your own environment instead of reading about it, that’s the day job. Say hello.