Sign in

Steelwise.uk

@steelwise.bsky.social
35 followers 26 following 278 posts

Steelwise is a technology advisory practice based in Sheffield. We help businesses make smart decisions about security, infrastructure, and AI, backed by over two decades of doing the work, not just advising on it.

PostsRepliesMedia
Steelwise.uk @steelwise.bsky.social · 14h
A policy that treats generative AI as one thing over-restricts the safe uses and under-restricts the risky ones. The categories that matter: what data goes in, what action comes out, and who is accountable for the answer. Read the filing #AI #infosec #cybersecurity
steelwise.uk
Your AI policy should say something | Steelwise
Most AI policies are vendor templates that ban the obvious and permit the vague. A coherent policy is a short one that takes a position.
000
Steelwise.uk @steelwise.bsky.social · 18h
When you stop using something, switch it off. Not parked, not next quarter: account closed, key revoked. It is the cheapest security control there is, and nobody markets it because nobody can sell it. That is why it gets skipped. Read the filing #infosec #cybersecurity #devops #sysadmin
steelwise.uk
The stuff you stopped using is still attacking you | Steelwise
NCSC guidance on decommissioning assets. Things you no longer use stop being assets and start being liabilities. The boring job most businesses skip.
000
Steelwise.uk @steelwise.bsky.social · 20h
September's Microsoft updates stopped File History backups, hung Always On VPN, left Office 2016 and 2019 unlicensed, and sent PDFs saved to SharePoint into a hidden folder. The fix or workaround for each one. Read the filing #windows11 #microsoft365 #patchtuesday #devops
steelwise.uk
What September
September 2026 Microsoft updates broke File History, Always On VPN, Office 2016/2019 licences, and Word PDF saving. The fix or workaround for each.
010
Steelwise.uk @steelwise.bsky.social · 06/10/2026
A question worth putting to any supplier who monitors things for you: when your alarms fire, what happens next, and how quickly? AWS detected its own billing fault in eight minutes and nobody acted for four and a half hours. Read the filing #aws #cloudreliability #devops #sysadmin
steelwise.uk
AWS
AWS
000
Steelwise.uk @steelwise.bsky.social · 06/10/2026
A macOS flaw lets a script with no admin rights silently swap the insides of a trusted app, then ask for your Keychain wearing that app's name and icon. Apple decided it does not warrant a fix. A familiar icon proves nothing. Read the filing #notepad #macos #malware #infosec
steelwise.uk
The app you trust is now the thing carrying the malware | Steelwise
Attackers are hiding malware inside apps staff already trust: a clean Notepad++ carrying a bad plugin, and a macOS app-swap flaw Apple won
000
Steelwise.uk @steelwise.bsky.social · 06/10/2026
Citrix NetScaler, FortiMail, Check Point, and MikroTik were all found under attack in one fortnight, mostly before a fix existed. Patching closes the door. It does not tell you who came through it first. Read the filing #citrix #fortinet #patching #infosec
steelwise.uk
Four ways in through the front door, in one fortnight | Steelwise
Citrix NetScaler, FortiMail, Check Point, and MikroTik flaws were all exploited in one fortnight. What to check, and what to ask your IT provider.
000
Steelwise.uk @steelwise.bsky.social · 05/10/2026
The supplier that stopped existing, and the script that did not. Your website's page source still names companies that no longer exist. The script tag keeps working, or keeps failing quietly, and nobody notices either way. Then somebody buys… Read the filing #thirdpartyscripts #csp #sri #infosec
steelwise.uk
The supplier that stopped existing, and the script that did not | Steelwise
Dead suppliers leave live script tags on your site. Why nothing breaks, why scanners miss it, and how to inventory what your pages load.
000
Steelwise.uk @steelwise.bsky.social · 05/10/2026
Only 22% of UK leaders think their insurance would cover an attack. One in five have never worked out what one would cost. Same fact: you cannot size a policy against a number you never calculated. Read the filing #insurance #resilience #businesscontinuity #infosec
steelwise.uk
Work out the number before your insurer does | Steelwise
Most UK leaders doubt their cover and have never modelled an attack
000
Steelwise.uk @steelwise.bsky.social · 05/10/2026
Every account recovery method you add is another door into the same room. Google's selfie sign-in is a case in point: before letting staff enrol a face video, ask what your recovery story is when someone loses their phone. Read the filing #google #authentication #deepfakes #infosec
steelwise.uk
Is a selfie a safe key to your business Google account? | Steelwise
Google
020
Steelwise.uk @steelwise.bsky.social · 04/10/2026
The NCSC waited years to recommend passkeys, until syncing worked and roughly half of Google's UK users had one registered. The advice is now official: passkeys first, password plus two-step verification as the fallback. Read the filing #infosec #cybersecurity
steelwise.uk
NCSC says passkeys first, passwords second | Steelwise
NCSC now recommends passkeys as the default and password plus two-step verification as the fallback. Traditional codes are still phishable.
111
Steelwise.uk @steelwise.bsky.social · 04/10/2026
One crew, five names in a year: BlackFile, Redact, Pink, Helix, Falcon. Same templates, same victims, shared infrastructure, wallets holding roughly 10.7 million dollars. The pitch never changes: IT calling, urgent upgrade. Read the filing #vishing #phishing #passkeys #infosec
steelwise.uk
The call that comes from your own IT desk | Steelwise
Attackers ring staff on personal mobiles posing as IT support and capture logins on fake portals. The callback rule that stops it.
000
Steelwise.uk @steelwise.bsky.social · 04/10/2026
In a small firm, one finance manager often holds the keys to the bank, payroll, and expenses at once. Cifas found fraud tolerance at every level of seniority. Segregating those duties is the cheapest control there is. Read the filing #infosec #cybersecurity
steelwise.uk
Insider fraud is mostly the people you already hired | Steelwise
Cifas surveyed 2,000 UK employees. 24% know someone who fiddled expenses, 13% know someone who sold a login. Insider risk is a culture problem first.
000
Steelwise.uk @steelwise.bsky.social · 03/10/2026
Researchers turned a Google Calendar invite title into a covert livestream of the victim. An email AI worm copied itself across inboxes while stealing data. Prompt injection is a seven-stage kill chain, and the demos are real. Read the filing #AI #infosec #cybersecurity
steelwise.uk
Prompt injection is not the new SQL injection | Steelwise
Schneier et al have reframed prompt injection as
100
Steelwise.uk @steelwise.bsky.social · 03/10/2026
Nothing looks wrong when a portal leaks to anonymous visitors. No failed logins, no alerts, because nobody logs in. The data just flows out looking like the site working as designed. Worth asking what yours shows a stranger with no account. Read the filing #salesforce #servicenow #saas #infosec
steelwise.uk
Your customer portal may be readable by strangers | Steelwise
An attacker spent 17 months reading data from misconfigured Salesforce and ServiceNow portals. Why guest access leaks, and what to check today.
010
Steelwise.uk @steelwise.bsky.social · 03/10/2026
HR thought IT would revoke the leaver's access. IT was waiting on HR. The ex-employee logged back in and corrupted a database. Offboarding rarely fails on tooling. It fails because nobody owned it. Read the filing #offboarding #accesscontrol #insiderrisk #infosec
steelwise.uk
Nobody was told to switch the account off | Steelwise
A leaver kept working credentials for days and cost a company six figures. How to build an offboarding checklist that names an owner and a deadline.
000
Steelwise.uk @steelwise.bsky.social · 02/10/2026
If your staff record client calls with an AI notetaker, in law you are the controller and it is your processor. When it leaks, the phone calls are yours. The cheapest fix: decide what never gets recorded, and write the rule down. Read the filing #notetakers #gdpr #suppliers #infosec
steelwise.uk
Who is recording your meetings, and who else can read them | Steelwise
An AI notetaker let any user list every meeting on it, including live calls. Reported in January, still open in July. What to ask before you use one.
000
Steelwise.uk @steelwise.bsky.social · 02/10/2026
Security insurance mostly pays: UK insurers paid out £197m in claims in 2024. The refusals trace back to proposal forms that said things that were not true. Treat the renewal questionnaire as a statement of fact, because in law it is one. Read the filing #insurance #mfa #backups #infosec
steelwise.uk
Your insurance questionnaire is the policy | Steelwise
UK insurers paid £197m in claims in 2024, and refusals mostly trace to the proposal form. What security insurance covers, excludes, and demands.
010
Steelwise.uk @steelwise.bsky.social · 02/10/2026
Get Cyber Essentials before someone makes you. Cyber Essentials is still voluntary for most UK businesses. Supply chain pressure and new legislation are both closing that window, and certifying on your own timetable is cheaper and… Read the filing #cyberessentials #supplychain #compliance #infosec
steelwise.uk
Get Cyber Essentials before someone makes you | Steelwise
Cyber Essentials is still voluntary for most UK firms. Why certifying on your own timetable beats doing it when a customer or a law requires it.
001
Steelwise.uk @steelwise.bsky.social · 01/10/2026
What makes a backup a backup. A mirrored disk is not a backup. A sync folder is not a backup. Four properties separate a copy of your data from something that will still be there after a bad week, and most inherited setups are missing at… Read the filing #backups #ransomware #immutability #infosec
steelwise.uk
What makes a backup a backup | Steelwise
RAID is not a backup and nor is Dropbox. The four properties a copy of your data needs before it counts as a backup, and how to check yours.
120
Steelwise.uk @steelwise.bsky.social · 01/10/2026
When something breaks, the instinct is to act. The better first moves protect your options: capture logs before they rotate, snapshot before you change state, and say early that you are aware and investigating. Read the filing #infosec #cybersecurity
steelwise.uk
The first five minutes of incident response | Steelwise
Containment over correctness. Reversibility over impact. Protecting state before touching services. What your first five minutes should actually look like.
410
Steelwise.uk @steelwise.bsky.social · 01/10/2026
Attackers only scan for what they still find. Decades after plaintext logins should have vanished, Telnet scanning was still heavy enough that its sudden stop was measurable worldwide. Forgotten services outlive every assumption. Read the filing #infosec #cybersecurity
steelwise.uk
Insecure defaults have a long half-life | Steelwise
Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass dropped. The lesson is current.
020
Steelwise.uk @steelwise.bsky.social · 30/09/2026
The patching habit that saved us more hours than anything else: every CVE carries a visible state, seen, evaluated, or closed, with who and why. One assessment, recorded once, visible to everyone. Read the filing #patching #vulnmanagement #infosec #cybersecurity
steelwise.uk
What
AI is pushing patch volume and speed up at once. Here is what we do about it, and a genuine question back to you: what works for your team?
000
Steelwise.uk @steelwise.bsky.social · 30/09/2026
Four in 800 recovered on time. An incident response firm's data from over 500 ransomware recoveries found almost nobody hits their own recovery target. The reasons are checkable: recovery plans depend on Active Directory, the same… Read the filing #ransomware #backups #activedirectory #infosec
steelwise.uk
Four in 800 recovered on time | Steelwise
Fenix24
100
Steelwise.uk @steelwise.bsky.social · 30/09/2026
Remote management platforms hold the largest set of keys there is: administrative control of every machine they manage, for hundreds of businesses at once. That concentration is exactly what makes them worth attacking. Read the filing #msp #rmm #supplychain #infosec
steelwise.uk
Your IT provider
Attackers abused an MSP remote-control platform to reach customer machines, and the access outlived the fix. What to ask your IT provider now.
000
Steelwise.uk @steelwise.bsky.social · 29/09/2026
Cyber Essentials now fails you automatically for two things: a cloud login without multi-factor authentication, and a high-risk update older than 14 days. Neither requirement is new. The scheme just stopped treating them as negotiable. Read the filing #cyberessentials #mfa #compliance #infosec
steelwise.uk
Two answers now fail Cyber Essentials outright | Steelwise
Cyber Essentials
000
Steelwise.uk @steelwise.bsky.social · 29/09/2026
The Cyber Essentials control that trips up most small businesses is user access control. Giving everyone admin is convenient right up until it is not. The other four: firewalls, secure configuration, malware protection, patching. Read the filing #infosec #cybersecurity
steelwise.uk
What Cyber Essentials actually involves | Steelwise
A plain-English walk through the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn
000
Steelwise.uk @steelwise.bsky.social · 29/09/2026
Two WordPress plugins, two compromises, one week. An unauthenticated remote code execution flaw in a WooCommerce plugin, and a backdoored update to a completely unrelated admin plugin, hit WordPress sites this week for different reasons.… Read the filing #wordpress #plugins #infosec #cybersecurity
steelwise.uk
Two WordPress plugins, two compromises, one week | Steelwise
Two unrelated WordPress plugin compromises this week show why your plugin list is your real attack surface. What to check.
001
Steelwise.uk @steelwise.bsky.social · 28/09/2026
Ordinary brand domains transfer in about 88% of .uk disputes. Short low-vowel acronyms like ghd and g4s split roughly 50-50: a three-letter string is legitimately claimable by many parties, and the experts treat it that way. Read the filing #typosquatting #domains #phishing #infosec
steelwise.uk
What decides a .uk domain dispute: the story, not the paperwork | Steelwise
Typosquatters lose 98% of .uk domain disputes, dictionary words mostly survive, and short acronyms are a coin flip. How DRS cases are really decided.
110
Steelwise.uk @steelwise.bsky.social · 28/09/2026
If your main cloud provider doubled the price or went down for a week, what would you do? Most firms have never asked. And if you cannot export your data in a format you can use elsewhere, you do not really control it. Read the filing #devops #sysadmin
steelwise.uk
The sovereignty tax: why UK firms want off US cloud and cannot move | Steelwise
Two-thirds of UK firms want off US cloud, but only 15% have moved. The lock-in is the story. How SMEs keep the option to switch open.
010
Steelwise.uk @steelwise.bsky.social · 28/09/2026
Your chatbot can email people on your behalf. Who checked that?. A researcher earned over 50,000 US dollars finding ways to trick AI customer-service chatbots into emailing phishing messages from a company's own trusted address. The bug is not… Read the filing #chatbots #emailspoofing #AI #infosec
steelwise.uk
Your chatbot can email people on your behalf. Who checked that? | Steelwise
Researchers earned $50,000+ finding ways to trick AI chatbots into sending phishing emails from a company
000
Steelwise.uk @steelwise.bsky.social · 27/09/2026
Many privacy policies say: if you have a complaint, contact the ICO. Under the UK's new complaints duty that is the wrong order. People complain to you first; you acknowledge within 30 days. The fix is a paragraph, not a portal. Read the filing #infosec #cybersecurity
steelwise.uk
No, you don
Lots of guidance says you need a web form for data complaints by 19 June 2026. The statute doesn
000
Steelwise.uk @steelwise.bsky.social · 27/09/2026
Quick MFA test: when you log in, does your phone buzz and you tap approve? That is the kind an attacker can beat by sending prompts until someone gives in. Number matching, a rate cap, and passkeys for admins close the route. Read the filing #infosec #cybersecurity
steelwise.uk
MFA prompt bombing, or when the attacker just asks nicely | Steelwise
MFA prompt bombing defeats push-based authentication. How the attack works, why number matching helps, and what an SME should switch on this week.
010
Steelwise.uk @steelwise.bsky.social · 27/09/2026
The play starts on the phone, not at the door. IT will not ring you out of the blue asking you to install AnyDesk or TeamViewer. Hang up, ring your provider on a known number, and check. The office visit is only the fallback. Read the filing #infosec #cybersecurity
steelwise.uk
When the IT guy turns up, and isn
FBI warns Silent Ransom Group is sending people into law firms posing as IT. What to tell reception, partners, and staff at UK professional services firms.
000
Steelwise.uk @steelwise.bsky.social · 26/09/2026
Half of subscription-bombing floods land on a Friday, and 80% start between 8am and 10am, when inboxes get cleared fastest. Targets are directors and above. One victim found an iPhone bought on their card buried in the flood. Read the filing #infosec #cybersecurity
steelwise.uk
Subscription bombing: the distraction is the attack | Steelwise
Inbox flooded with newsletter confirmations? It
000
Steelwise.uk @steelwise.bsky.social · 26/09/2026
Most incident checklists predate passkeys. After a compromise, review every registered sign-in method and remove what you cannot account for: passkeys, authenticator apps, recovery numbers. A password reset is no longer enough. Read the filing #passkeys #phishing #incidentresponse #infosec
steelwise.uk
The passkey the attacker added to your account | Steelwise
A phishing kit registers the attacker
020
Steelwise.uk @steelwise.bsky.social · 26/09/2026
"Do you have MFA?" is the wrong question. The right one is whether it covers every route in. Check for policies scoped to some apps or some groups, rules that trust a location, and anything still sitting in report-only mode. Read the filing #microsoft365 #mfa #entra #infosec
steelwise.uk
Your MFA is on, and it did not apply | Steelwise
78 Microsoft accounts fell to old passwords replayed through a legacy sign-in route. Most victims had MFA on. Why it did not apply, and what to check.
000
Steelwise.uk @steelwise.bsky.social · 25/09/2026
A vendor safety score answers a narrow question: did these written-down attacks work? Not whether someone who read the defences can build a chain afterwards. Treat the number as a floor, and judge the tool by what it can reach. Read the filing #promptinjection #aiagents #claudecode #AI
steelwise.uk
The safety number that was zero until someone tried | Steelwise
A commissioned test scored an AI agent 0.00% vulnerable. A researcher then broke it 60-80% of the time. Why vendor safety numbers mislead.
010
Steelwise.uk @steelwise.bsky.social · 25/09/2026
"AI Act compliant" is going to appear on a lot of vendor websites. For a UK small business the Act itself lands almost nowhere. The useful part is the duty on model providers to document what they built and pass it downstream, to you. Read the filing #aiact #aigovernance #compliance #AI
steelwise.uk
The AI Act questions you can now ask your supplier | Steelwise
The EU AI Act is now being enforced. It puts almost nothing on a UK SME directly, but it does change what you can ask your AI suppliers to prove.
000
Steelwise.uk @steelwise.bsky.social · 25/09/2026
What GDPR still requires when AI does the processing. Staff are already pasting customer details into ChatGPT, Copilot, and Claude to draft emails and summarise documents. UK GDPR still applies to every bit of that personal data, and the law… Read the filing #gdpr #dataprotection #aicompliance #AI
steelwise.uk
What GDPR still requires when AI does the processing | Steelwise
Staff already paste customer data into AI tools at work. UK GDPR still applies. What a director is on the hook for, and what to ask suppliers.
000
Steelwise.uk @steelwise.bsky.social · 24/09/2026
Documents left on printers, unlocked screens, tailgating, loose talk in corridors. The unfashionable risks still catch people out, and the NPSA gives away a campaign kit on exactly these, tested across national infrastructure. Read the filing #infosec #cybersecurity
steelwise.uk
The free security awareness campaign you didn
The NPSA gives away a full, professionally designed security awareness campaign kit: posters, booklets, checklists, starter guide. Most firms don
001
Steelwise.uk @steelwise.bsky.social · 24/09/2026
Nine in 10 organisations are confident they could recover from an attack. Fewer than one in three ransomware victims got all their data back. The gap is testing, and a monthly ten-minute restore test closes most of it. Read the filing #backups #ransomware #recovery #infosec
steelwise.uk
Test your backups before an attacker does | Steelwise
90% of firms are confident in recovery; under a third of ransomware victims fully recovered. How to run a restore test, and what to check.
000
Steelwise.uk @steelwise.bsky.social · 24/09/2026
The verification prompt that tells you to open Run. A fake CAPTCHA or error message asks the visitor to copy a short command and paste it somewhere to prove they are human or fix a problem. It works on Windows and on Mac, and it does not… Read the filing #clickfix #phishing #infosec #cybersecurity
steelwise.uk
The verification prompt that tells you to open Run | Steelwise
ClickFix tricks staff into pasting malware into Run or Terminal via a fake CAPTCHA. What to tell staff and what IT should check this week.
000
Steelwise.uk @steelwise.bsky.social · 23/09/2026
Parliament says UK AI rules are not fit for purpose. A parliamentary committee has told the government that the UK has no AI law worth the name, just a patchwork of existing rules and voluntary promises from AI companies. For any business already using AI… Read the filing #airegulation #jchr #AI
steelwise.uk
Parliament says UK AI rules are not fit for purpose | Steelwise
A parliamentary committee says the UK has no proper AI law, just existing rules and voluntary promises. Formal regulation is coming.
000
Steelwise.uk @steelwise.bsky.social · 23/09/2026
An AWS access key never expires. So the one a contractor pasted into a repo in 2019 probably still controls your account today. Researchers found 88% of leaked keys still work. Delete root keys, disable old ones, set a billing alarm. Read the filing #aws #credentials #cloud #infosec
steelwise.uk
The AWS key you leaked years ago probably still works | Steelwise
88% of leaked AWS keys still authenticate, some five years on, researchers found. Why nobody rotates them, and the credential habits that fix it.
000
Steelwise.uk @steelwise.bsky.social · 23/09/2026
Think about what people type into your website: card details, logins, enquiry forms. Every third-party script on the page can read it, and a supplier can change them tonight without telling you. Most sites load five to 20. Read the filing #supplychain #javascript #csp #infosec
steelwise.uk
The code on your website you did not write | Steelwise
An advertising script was altered to rewrite payment details in visitors
000
Steelwise.uk @steelwise.bsky.social · 22/09/2026
Not giving your AI write access stops it changing the outside world. It does nothing to stop it telling the outside world what it just read. Searching is outbound, and the confidential thing is often the question, not the answer. Read the filing #ai #dataprotection #privacy #infosec
steelwise.uk
We only use AI to answer questions | Steelwise
000
Steelwise.uk @steelwise.bsky.social · 22/09/2026
AI agents attacked RubyGems, and nobody noticed for months. In May 2026, autonomous OpenAI agents flooded RubyGems.org with malicious packages and gained code execution on RubyDoc.info's servers. Nobody worked out who was behind it until… Read the filing #rubygems #supplychain #openai #AI
steelwise.uk
AI agents attacked RubyGems, and nobody noticed for months | Steelwise
Autonomous OpenAI agents attacked RubyGems.org in May 2026, gaining remote code execution on RubyDoc.info. Disclosed four months later.
000
Steelwise.uk @steelwise.bsky.social · 22/09/2026
The worst patching rule we tested is the one most firms fall back on: just do the criticals. 20,491 items to catch under a third of the flaws that get exploited. A 9.8 with a near-zero chance of attack is not tomorrow's emergency. Read the filing #vulnerabilitymanagement #patching #cve #infosec
steelwise.uk
The patching rule that beats "just do the criticals" | Steelwise
Patching by CVSS 7+ means 89,697 items, 98% never exploited. A different rule gives 3,513 items and catches 72% of exploited flaws. The numbers.
000
Steelwise.uk @steelwise.bsky.social · 21/09/2026
Attack complexity carries real weight in the severity formula. Across 248,176 records it did not predict exploitation at all. What did: no privileges needed, and no user interaction. Read the vector, not the number. Read the filing #cvss #vulnerabilitymanagement #riskmanagement #infosec
steelwise.uk
97% of critical vulnerabilities are never exploited by anyone | Steelwise
Only 2.8% of vulnerabilities scored 9.0+ show any exploitation evidence, while 12% of confirmed-exploited flaws scored under 7. What severity misses.
000
Steelwise.uk @steelwise.bsky.social · 21/09/2026
Your AI vendor wrote its contract so accuracy is your responsibility, not theirs. They sell the capability and push liability for the output down to you. Know which gap you are standing in before the model faces a customer. Read the filing #AI #infosec #cybersecurity
steelwise.uk
You can
If your business publishes anything an AI wrote, you own what it says.
000