Plain Security

Security, explained for the board.

Plain-language briefings on the risks that matter and the single control that stops each one. Every topic ends with what it means for your risk register and for NIS2, DORA, SOC 2 and ISAE 3402. English and Dutch.

Email securityInterception, tampering, spoofing and man-in-the-middle. What each costs, what stops it. RansomwareOne stolen login, four steps to a standstill. What happens at each step, what breaks the chain. PhishingFake login pages, MFA fatigue, CEO fraud and every other channel. What one click can and cannot do. Passwords & identityReused passwords, phone-read codes, leavers and standing admins. Who can get in, who can do anything. Entra ID: the keys to Microsoft 365Global Admins, an open Conditional Access gate, guests who never left, and the hybrid sync back door. IAM: who may do whatOrphaned service accounts, wildcard roles, one person with both signatures, shared admin logins. With examples. Supply chain attacksBreached through someone we trust: vendor updates, supplier logins, open-source code and SaaS leaks. Cloud misconfigurationThe cloud is secure, our settings are not. Four mistakes behind most cloud breaches, and what prevents each. Insider threatFour people who already have the keys: leaver, careless colleague, unwatched admin, pressured employee. DDoS & availabilityOffline without a break-in. Floods, fake shoppers, one DNS provider, extortion, what keeps us up. The unpatched serverKnown hole, published fix, still open. Four ways patching fails, and the one control that closes each. Shadow IT & SaaS sprawlCompany data in tools nobody approved, accounts nobody manages, apps nobody revoked. How to see it again. AI at workPublic chatbots, hijacked assistants, cloned voices and confident nonsense. What each costs, what contains it. Your website is a front doorInjection, forgotten plugins, account takeover and skimmed checkouts. Four ways in, one control each. Laptops, phones and the kitchen tableLost laptops, unmanaged phones, admin for everyone, an outdated browser. Where the data really lives. Knowing what to protectCrown jewels nobody can name, forty copies, links for anyone, data kept fifteen years. How to see it again. Would we even notice?Logs nobody kept, alerts nobody read, half the estate unwatched, tickets read Monday. Would we notice? The factory, the building and the camerasProduction lines, building systems and cameras that cannot be patched. Four ways they stop, one fix each. Building software that holdsSecrets in code, a hijacked build server, testing after launch, apps nobody owns. What closes each gap. The first 72 hoursWho decides, what gets wiped, who says what, who to call. How the first three days derail. Cyber insurance: what it pays, what it won'tThe policy is a control with small print. Questionnaire, exclusions, sub-limits, notification: what each costs. NIS2 & DORA: what the board must ownThe law now names the board. Four things that changed, and what has to be in place before the audit.

Missing a topic your board keeps asking about? Request it and it goes on the list.

Request a topic