Category: Blog


  • What is a Strong Password?

    Using information such as birthdays, your company’s name, sports teams etc. should be avoided as this information can usually be gathered from social media profiles, making life easier for a cyber criminal. A password should also never be reused on another account. For example, using the same password for your email and Spotify means someone…

  • In today’s digital landscape, the reliance on external third-party suppliers, freelancers and partnerships has become universal. This dependency, however, comes with significant cyber security risks, as evidenced by the sharp rise in third-party and supply chain breaches. An extreme example was seen in the July 2024 CrowdStrike-Microsoft incident, where an issue in one entity led…

  • I (Farzan speaking here) remember when I was first looking to break into cyber security just over two years ago.  Reading 100s of job descriptions trying to work out what was needed to enter the industry. I came across “ISO 27001” listed within job duties and required experience. My immediate thoughts were what is this…

  • During late 2023, Practical Infosec were fortunate enough to have the opportunity to conduct an engagement with UK-based charity: Parathyroid UK. This project was a personal highlight, delivering the entire end-to-end process to increase their security resilience.  Who is Parathyroid UK?  Parathyroid UK is a small charity based in the UK & Ireland, providing practical…

  • During 2023, we worked on one of our favourite projects to date! We helped Africa’s Climate Venture Builder, Persistent, develop a cybersecurity toolkit for its portfolio companies under the Energy Entrepreneurs Growth Fund (EEGF).  We helped Persistent understand some of the security risks faced by small and medium-sized enterprises (SMEs) in Africa. We then designed…

  • October 17th, 2024 marks the day that the EU’s cyber security legislation: NIS2 becomes effective. EU member states will have to publish and adopt the measures to comply with this directive. With the 1 year countdown beginning (October 17th, 2023), what is this updated legislation? What do organisations have to consider? Well let’s have a…

  • In the world of cyber security, budgeting is far from a one-size-fits-all formula. Various factors will come into play when determining the right investment for your organisation’s security needs. Let’s delve into some key considerations that can guide the decision making process. Understanding the landscape A report by Deloitte highlighted that, as of 2020, around…

  • 1 year ago, a hipster cafe serving specialty coffee opened in my small, quiet neighbourhood of Barcelona. Given that the majority of establishments and people in my neighbourhood are at least 60 years old, I was overwhelmed with excitement when I saw the “opening soon” sign of the new cafe, whilst walking the streets one…

  • The other day I was vacuuming the flat. Naturally, as one does, my mind was wandering various places to keep myself entertained whilst doing an otherwise autopilot task – one can only be present for so long whilst cleaning the house. Suddenly, my thoughts were rudely interrupted when the vacuum cleaner failed to pick up…

  • With more businesses taking initiative to be more environmentally sustainable, carbon footprint calculators and sustainability consulting firms are becoming a popular way to measure impact. We believe these platforms have a lot of value to offer, however, we are also curious to examine these platforms through a security lens. The value these calculators offer is…