top of page
ESKA Security Blog
Search


What Is a Supply Chain Attack and Why Your Vendor Could Become Your Biggest Security Risk
Many companies invest heavily in protecting their own infrastructure. They deploy firewalls, endpoint protection, multi-factor authentication, backup systems, and security monitoring. Internal systems become increasingly difficult to compromise. So attackers change their strategy. Instead of attacking the organization directly, they target someone the organization already trusts. A software vendor. A cloud service provider. An IT outsourcing company. A managed service provide
ESKA ITeam
Jul 16 min read


How to Build a Cybersecurity Budget That Actually Protects Your Business
One conversation plays out in almost every company when it's time to discuss the cybersecurity budget. The CISO or IT Director walks into a meeting with a list of security initiatives, software, and services the organization needs. The CEO or CFO looks at the numbers and asks: "Why do we need all of this? Nothing has happened to us." The security team starts talking about threats, vulnerabilities, and attack vectors. Management hears technical terminology but struggles to con
ESKA ITeam
Jun 247 min read


What a Business Gets from a vCISO in the First 90 Days
When a company begins thinking seriously about cybersecurity, one question usually comes up: “Fine, we bring in a vCISO. But what exactly will change in the way the business operates?” Most descriptions of the role sound too abstract. They talk about strategy, risk management, governance, and security process development. These concepts are important, but business leaders usually want something more practical: specific actions, visible progress, and measurable outcomes. That
ESKA ITeam
Jun 1713 min read


The 5 Vulnerabilities ESKA Finds in Every Second Penetration Test
Based on penetration tests conducted by the ESKA team throughout 2024–2025, five security weaknesses appear so consistently that we actively look for them before running a single automated scanner.
ESKA ITeam
Jun 94 min read


After the Breach: How Forensic Analysis Determines What Happened, Who Did It, and What It Cost
When a security incident occurs, the first instinct in most organizations is to restore operations as quickly as possible. Rebuild the affected systems, reset credentials, patch the vulnerability, and move on. It is an understandable response, downtime is expensive and pressure from leadership is immediate. It is also one of the most damaging decisions a security team can make. Restoring systems before conducting a forensic investigation destroys evidence. Without that eviden
ESKA ITeam
Jun 36 min read


Security Questionnaires and Vendor Due Diligence: How to Respond Without Creating Liability
A few years ago, security questionnaires were something large enterprises sent to enterprise vendors. Today, they land in the inboxes of mid-sized companies, startups, and regional service providers with increasing regularity and the stakes attached to them have changed significantly.
ESKA ITeam
May 274 min read


Once a Year Is Not Enough: How Often Should You Actually Run a Penetration test?
Annual penetration testing made sense in a different era. Infrastructure changed slowly. Applications had quarterly release cycles at best. The attack surface was mostly on-premises and well-defined. Running a pentest once a year gave organizations a reasonable snapshot of their security posture because that posture did not change dramatically between tests.
ESKA ITeam
May 196 min read


What Attackers See When They Google Your Company
Before an attacker touches a single system, they search.
They search Google, LinkedIn, GitHub, breach databases, and DNS records. They look through job postings, conference talks, and developer forums. They build a detailed picture of your infrastructure, your technology stack, your employees, and your security gaps, using nothing but publicly available information and tools that anyone can access for free.
ESKA ITeam
May 117 min read


A Clean Vulnerability Scan Report Does Not Mean You Are Secure
A vulnerability scan came back with no critical findings. The team breathed a sigh of relief, marked the task complete, and moved on. Three months later, an attacker was inside the network.
ESKA ITeam
May 47 min read


Why Hackers Love Your SaaS Apps: The Security Blind Spots Most Companies Miss
Your team runs on SaaS. Sales lives in Salesforce. Finance works out of Xero. Everyone communicates through Slack or Microsoft Teams. Documents flow through Google Workspace or SharePoint. Onboarding, HR, payroll, project management: all cloud, all SaaS, all connected. Attackers know this. And they have adjusted accordingly. The assumption that SaaS is secure by default because someone else is running the infrastructure is one of the most expensive mistakes a company can make
ESKA ITeam
Apr 297 min read


ISO 27001 Passed. Now What? The 12 Months After Certification That Most Companies Get Wrong
Getting ISO 27001 certified is hard work. Months of gap analysis, risk assessments, policy writing, internal audits, and a two-stage external audit that feels like it examines everything. When it is over and the certificate arrives, the relief is real. That relief is also dangerous. The organizations that struggle most with ISO 27001 are not the ones that fail to get certified. They are the ones that treat certification as a destination rather than a starting point, and then
ESKA ITeam
Apr 226 min read


What Happens After a Penetration Test? From Report to Real Security
You passed the penetration test. The security firm sent over a 40-page PDF. Your team skimmed it, flagged a few items, and moved on. Six months later, the same vulnerabilities are still open.
ESKA ITeam
Apr 166 min read


Why Old Vulnerabilities and Third-Party Access Are as Dangerous as Phishing
Phishing still matters — and it remains one of the most common entry points for attackers. But in 2026, it is no longer the only or even always the most reliable path to compromise. Increasingly, attackers are just as likely to succeed by exploiting unpatched systems or abusing trusted third-party access as they are by sending a convincing phishing email.
ESKA ITeam
Apr 85 min read


ISO/IEC 42001 Explained: Why It Matters for Responsible AI Governance
ISO describes ISO/IEC 42001 as the first global standard for AI management systems and states that it provides requirements and guidance for organizations that develop, provide, or use AI systems.
ESKA ITeam
Mar 257 min read


What Is TLPT? Threat-Led Penetration Testing Explained
Threat-Led Penetration Testing, or TLPT, is becoming one of the most discussed cybersecurity topics in regulated industries, especially financial services. That is not because it replaces penetration testing, but because it answers a broader question: not only whether a weakness can be exploited, but whether an organization can detect, contain, and withstand a realistic attack against its critical functions.
ESKA ITeam
Mar 187 min read


What Is DORA (EU) and How Financial Companies Can Prepare for ICT Risk Management Requirements
If you operate in the financial sector in Europe or work with EU-based clients, you’ve likely heard about DORA (Digital Operational Resilience Act). The Digital Operational Resilience Act (DORA) is a regulatory framework introduced by the European Union to fundamentally strengthen how financial organizations manage technology risks and ensure business continuity in the digital era.
ESKA ITeam
Mar 1112 min read


SOC 2 Type I vs Type II: What Is the Difference and What Do You Need to Pass
The difference is simple in theory but very important in practice. SOC 2 Type I looks at whether your controls are properly designed and in place as of a specific date. SOC 2 Type II goes further and evaluates whether those controls operated effectively over a defined period of time.
ESKA ITeam
Mar 46 min read


AI Phishing vs Traditional Phishing: How the Rules Changed and How to Protect Your Business
The “classic” phishing email with broken English is no longer the baseline. Attackers now use generative AI to produce believable messages at scale, adapt in real time, and expand beyond email into voice calls, chat apps, QR codes, and OAuth consent prompts.
ESKA ITeam
Feb 266 min read


Do You Need a vCISO? What’s Included in the Service and How to Measure Results
As cyber threats grow more sophisticated and regulatory pressure increases, many companies realize they need strategic security leadership—but not necessarily a full-time, in-house CISO. This is where a vCISO (Virtual Chief Information Security Officer) becomes a practical and cost-effective solution.
ESKA ITeam
Feb 188 min read


How to Prepare an Environment for a Penetration Test (Without Derailing Release or Production)
Penetration testing should reduce risk—not introduce outages, broken releases, or noisy incidents that steal engineering time. The difference between a “smooth pentest” and a “pentest fire drill” is rarely the tester’s skill; it’s usually pre-engagement preparation: clear scope, safe test conditions, and operational guardrails.
ESKA ITeam
Feb 139 min read
bottom of page