Resources
Technical articles.No fluff.
Lessons from real projects, practical compliance guides (NIS2, ISO 27001, GDPR), new technology analyses. We publish only when we have something useful to say.
AI voice agent on your phone line: what it can and cannot do
The company phone rings while you are with a customer, and the call is lost without even leaving a number behind. An AI voice agent picks it up — but since 2 August 2026 it has to say, in the first seconds, that it is an AI system. That changes the question you need to ask completely.
What an unpatched vulnerability on a server costs
In 2025, Romania's national cyber security authority notified 2,020 institutions and operators about more than 43,000 exploitable vulnerabilities on publicly exposed infrastructure. At the food group hit by ransomware that same year, the way in was a CVE from 2020.
Fixed asset inventory: the asset number D406 requires
The XML file fails validation again. The most common cause is not a broken accounting formula but a fixed asset line with an empty inventory number — an identifier many companies still treat as a sticker glued to a cabinet.
Phishing simulation: click rate is not the real metric
At Tohan SA, attackers compromised two email accounts, set up message forwarding and edited documents inside conversations that were already running. The result, from the 2025 annual report of Romania’s DNSC: fraudulent transfers of more than EUR 20,000.
Security alert triage: who reads it at 3 a.m.?
Sophos analysed 661 incident response cases: 88% of ransomware payloads are deployed outside business hours. Attackers do not wait for the night out of superstition — they wait until nobody is watching any more.
Internet-exposed servers: not if, but when they get hit
Open your firewall's rejected-connection log for the past 24 hours. If it is empty, or nobody knows where to find it, you already have the first answer: somebody is already trying to get in, non-stop, automatically.
ISO 27001 nonconformities: why firms fail Stage 2
The auditor opens your Statement of Applicability, picks a control marked "fully implemented" and asks for the evidence. That is where most ISO 27001 certifications are decided — not in the months of preparation before.
The 3-2-1-0 backup rule: why "having backups" is not protection
Your backup is the attacker's first target, not your last safety net: in most ransomware attacks the backups are hit directly — and usually compromised. "Having backups" and "being able to recover" are two completely different things. Here is what separates them.
IT infrastructure cost optimisation in 2026
IT costs are rising from every direction in 2026 — licences, cloud, hardware. But cutting blindly breaks things that were working. Here is how to reduce costs based on a TCO audit, not intuition.
NIS2 in 2026: are you ready for a DNSC audit?
The DNSC registration deadline expired in September 2025 — but the obligation, and the real work, are only starting now. The 2026 question is no longer "am I in scope?" but "can I prove compliance?". Here is what DNSC checks and how to prepare.
Cybersecurity audit: why your client is asking for one
More and more SMBs get the same surprise: a large client sends a security questionnaire or demands an audit to keep the contract. It is not bureaucracy — it is the NIS2 effect cascading down the supplier chain. Here is what it means and how to prepare.
Backup audit: why a "green job" doesn't mean recoverable
A "green" backup in the dashboard and a backup you can actually recover from are two different things. 2025-2026 data shows only a fraction of restores succeed when it truly matters. Here is what a backup audit checks — and why a successful job is no guarantee.
AI for SMBs in 2026: why 95% fail and how to succeed
AI has become a marketing word. Studies from 2025-2026 show the vast majority of company AI projects never produce real value. Here is why they fail, where the concrete ROI is and how to build a project that actually works.
Why IT projects fail (and how to save them)
The data is brutal: only a fraction of IT projects hit scope, time and budget at once. And the cause is almost never the technology. Here is what really kills projects — and how to bring them home in 2026.
GDPR data retention: how long are you allowed to keep data?
Many business owners keep "everything, just in case". In 2026 that is no longer prudence but risk. Here is how long you are allowed (and required) to keep data and how to delete it correctly.
Disaster recovery: why an untested backup won't save you
"We have backups" is the most dangerous false calm in IT. An untested backup is not a safety net — it is a hope. Here is the difference between backup and disaster recovery, and what 2025-2026 data shows about the companies that actually recover their data.
NIS2 in Romania: a compliance guide for SMBs
The NIS2 Directive has been transposed in Romania and brings concrete cybersecurity obligations — including for mid-sized companies that were previously unregulated. Here is who is in scope and what you need to do.
Backup 3-2-1: how to protect your business from ransomware
Most companies discover their backup does not work on the exact day they need it most. The 3-2-1 rule is the simplest defence against ransomware — if you apply it correctly.
ISO 27001 for small businesses: where to start and what it costs
ISO 27001 is not just for corporations. More and more small businesses need certification to win contracts. Here is what it involves, what it costs and how to approach it without drowning in bureaucracy.
Cloud migration for SMBs: how to avoid runaway costs
The cloud promises flexibility and lower costs — yet many companies end up paying more than on-premises. The difference is the migration strategy, not the provider. Here is how to get it right.
Cyber threats 2026: why SMBs are the #1 target
In 2026, attackers no longer hunt only corporations — SMBs have become the preferred target precisely because they are less well defended. AI phishing and ransomware have changed the rules. Here is what changed and how to protect yourself.