Synced 17 Jun 2026 22:27 UTC Account
← Home

Security guides & playbooks

Practical, vendor-neutral how-tos for practitioners — each one ends in a free tool you can use right away · browse the glossary → · updated June 2026

Where the glossary answers "what is X?", these guides answer "how do I actually do X?" — frameworks, checklists and step-by-step playbooks, grounded in well-established standards (OWASP, NIST, CISA). No fluff, no sign-up to read.

AI security

Vulnerability management

Compliance

Procurement

SOC 2 vs ISO 27001: which to ask a vendor for

Both signal a mature security program, but they are not the same thing. The practical differences, and which one to request when assessing a vendor.

6-min read · Read the guide →
What an SBOM tells you that a security questionnaire can’t

A questionnaire is what the vendor says; an SBOM and vulnerability data are independently verifiable. Why you need both to assess a product.

6-min read · Read the guide →
Third-party risk management (TPRM): a practical starter guide

A lightweight TPRM program you can actually run: inventory vendors, tier by risk, assess, and monitor — without drowning in spreadsheets.

8-min read · Read the guide →
Vendor risk assessment: a step-by-step process

How to run a vendor security assessment end to end — scope, questionnaire, independent verification, scoring and sign-off — before you buy.

7-min read · Read the guide →
How to read a SOC 2 report

A SOC 2 report is dense. What to actually check: the type, period, scope, the auditor’s opinion, and — most importantly — the exceptions.

7-min read · Read the guide →
SaaS security checklist for buyers

Before you sign: the access, data, compliance and operational controls to confirm — plus the software-vulnerability check most checklists miss.

6-min read · Read the guide →
Shadow IT: how to find and assess unsanctioned software

Teams adopt tools faster than security can review them. How to surface shadow IT, triage it by risk, and bring it under assessment.

6-min read · Read the guide →

Incident response

Product patching guides

Need to patch a specific product? See the step-by-step how-to-patch guides for Windows Server, Exchange, VMware ESXi, FortiGate, Cisco IOS, WordPress, PHP, Ubuntu, Red Hat and SQL Server — each with the latest safe version and live exploitation exposure.

Use the tools the guides point to

Start with the agentic AI tools →