Moving a domain controller from Hyper-V to Proxmox can look like a simple virtual machine migration. In practice, Active Directory carries identity, DNS, time, trust and recovery assumptions.
Read article →AI transparency will not be solved by a small icon under an image. Organisations will need provenance metadata, signatures, watermarking, verification tools, human review and audit evidence.
Read article →AI can generate working applications quickly, but functionality is not the same as security. The next challenge is proving that AI-generated systems are hardened, compliant and trustworthy enough for production.
Read article →The future of AI will not be decided only by larger models or longer context windows. It will be decided by the engineering process around them: workflow, memory, rules, verification, review and evidence.
Read article →Every piece of software contains weaknesses. The real question is not whether a bug exists, but whether we find it first or an attacker does.
Read article →Vibe coding is fast, but without durable memory, reusable skills, deterministic verification and independent review, AI-assisted development can quickly become chaos.
Read article →AI makes it easier than ever to build and deploy software. That also means basic web security, AppSec and DevSecOps checks must happen before publishing, not after deployment.
Read article →Autonomous AI agents change enterprise security assumptions. The next generation of cybersecurity will be about continuously proving that infrastructure is still trustworthy.
Read article →NIS2, AI and modern infrastructure change risk management from a static register into a continuous evidence problem. Existing open-source tools solve parts of it, but the missing layer is proof of trust.
Read article →A practical explanation of how FILIP:OS creates an integrity baseline, detects filesystem drift, classifies changes and preserves evidence without treating every difference as an attack.
Read article →Real compliance is not about collecting policies and audit screenshots. It is about proving that important controls work when the business actually needs them.
Read article →The future of AI will not be defined only by what systems can do, but by who can govern their risks, security, accountability and auditability.
Read article →When HR uses AI to screen, score or evaluate people, the question is not only whether it is useful, but whether it is legal, safe, fair and governed.
Read article →A server outage at 3:00 AM reveals whether cybersecurity exists as a real operating capability, not only as documentation.
Read article →Many companies spend thousands on cybersecurity tools, audits and certificates, but still lack ownership, decision-making and a managed security system.
Read article →FILIP:OS started from a simple frustration: Linux is powerful, but real operations too often become scattered scripts, manual fixes and unsafe commands.
Read article →In 1994, the problem was a polymorphic virus. Today, the problem is polymorphic attacks. The technology changed, but the principle stayed familiar.
Read article →A firewall, antivirus, backups and logs are not enough. The real question is whether information security is owned, controlled, evidenced and repeatable.
Read article →Before investing in firewalls, monitoring, backups or audits, companies should understand the real business cost of one hour of downtime.
Read article →Modern IT is no longer a printer-support function. It connects legal, operational, manufacturing and cybersecurity responsibility into one risk space.
Read article →In 1994, dealing with the OneHalf polymorphic virus was not about frameworks or best practices. It was about understanding the mechanism and keeping systems working.
Read article →If a company believes compliance, tools and a passed audit mean cybersecurity is under control, it may only have an illusion of security.
Read article →If I came into a company with no real cybersecurity, I would not start by buying tools or running an audit. I would start with ownership, decisions and control.
Read article →The worst failure I have seen during a security incident was not technology. It was hesitation, unclear authority and loss of control.
Read article →The fastest way to test whether a company has real cybersecurity is not to ask about tools. It is to ask who decides, who communicates and who owns the impact.
Read article →Regular cybersecurity training may create certificates, but real security depends on whether people know how to react when something actually happens.
Read article →Monitoring tells you that something is wrong. Preparedness decides what happens next.
Read article →Companies are adopting AI quickly, but the hard question is who can prove what tools are used, what data enters them, what decisions they influence and who is responsible.
Read article →Cybersecurity is not only a technical problem. It becomes real when IT and leadership are connected through decisions, risk ownership and business context.
Read article →A short note on using advanced WiFi Sensing and CSI to detect unknown people in critical infrastructure spaces without cameras.
Read article →