Articles tagged: Security
19 articles on Security from the Top Floor insights library.
2026-08-25
Incident Response for Small Businesses: What You Can Actually Get
A company with no security team can get real incident response, and most of it is already paid for or free: the panel inside its cyber policy, a retainer with no annual fee, the FBI and CISA reporting channels, and counsel who hires the investigator. What each one gives you, and the order to use them in.
2026-08-25
Do You Need a Notified Body Under the CRA?
Only if your product's core functionality is an important or critical category and, for class I, no harmonised standard covers the risks of that core functionality. The Commission's guidance turns both of those into tests you can run.
2026-08-25
How Long Does EU CRA Conformity Take?
About fifteen months to the main obligations, weeks to the reporting duties, and a conformity route whose duration nobody can quote yet, because the product-specific standards are still in approval and the notified body listing is still marked once available. What you control, what you do not, and the sequence that survives both.
2026-08-23
Should You Pay the Ransom? The Legal and Practical Answer
Paying is not generally illegal, but OFAC penalties are strict liability, so not knowing who received the money is not a defense. What payment actually buys, the four facts that decide it, and why reporting early is the single cheapest thing you can do.
2026-08-23
Best Penetration Testing Firms for Startups: How to Compare
Startups are choosing among five kinds of provider, not five brands. What each archetype is good at, the four terms that decide whether the report survives enterprise review, and who should not hire us.
2026-08-23
How Long Does a Penetration Test Take?
The testing is days. The engagement is weeks. NIST's own methodology puts a whole phase before testing in which no testing happens, and that phase, plus the retest at the other end, is where your date actually goes.
2026-08-23
What Audit Logging Does HIPAA Actually Require?
The audit controls standard is one sentence long and names no log type, no retention period, and no review cadence. The six years everyone quotes is a documentation rule, not a log rule, and the requirement people miss is the one about reading the logs.
2026-08-22
How Long Does Ransomware Recovery Actually Take?
Survey data puts most organizations back within a week and the average at about three weeks, but the distribution is wide and more than one factor widens it. What 'fully recovered' leaves out, and the clocks that keep running after systems come back.
2026-08-21
Red Team vs Penetration Test: Which Does Your Company Need?
A penetration test finds as many vulnerabilities as possible in a defined scope. A red team tests whether anyone notices an attack in progress. CISA's own red team went undetected for an entire assessment at a mature organization, which is the argument for building detection before you buy the exercise that measures it.
2026-08-21
How to Answer a Cyber Insurance Questionnaire Honestly
Carriers treat application answers as warranties. Travelers went to federal court in 2022 to rescind a ransomware policy over an overstated MFA answer, and the policyholder agreed to the rescission. Here is how to answer without voiding your own cover.
2026-08-20
Cloud Penetration Testing: What AWS, Azure, and GCP Allow
None of the three major providers require pre-approval to test your own resources, and all three prohibit denial-of-service testing. The harder question is scope: a network test pointed at cloud IP addresses misses the risks that are actually cloud risks.
2026-08-19
Internal vs External Penetration Testing: Do You Need Both?
PCI DSS answers the question for anyone handling card data: both, every 12 months. For everyone else the honest answer is conditional, and a cloud-only company often gets more from a cloud assessment than from a classic internal test.
2026-08-18
What Type of Penetration Test Do You Need?
Match the test to your attack surface, not to a vendor's menu of nine test types. Most first-time buyers need one or two, and the scoping call should tell you which before anyone quotes a number.
2026-08-16
Does the EU Cyber Resilience Act Apply to Your Product?
If you place hardware or software on the EU market and it connects to anything, assume yes and work backwards. The scoping traps are remote data processing, the Annex III important classes, and products already on the market.
2026-08-16
What the EU Cyber Resilience Act Requires in an SBOM
Annex I Part II makes a machine-readable software bill of materials a legal requirement, with top-level dependencies as the floor. It is documentation you hold and produce on request, not a file you publish.
2026-08-16
Is Your Product Important Under the CRA? Annex III and the Conformity Routes
Most products self-assess. Annex III class I products self-assess only if they apply harmonized standards in full, class II and critical products cannot. Which list you land on decides your budget and your timeline.
2026-08-16
7 Red Flags When Hiring a Security Consulting Firm
Seven warning signs that reliably predict a bad engagement, and the mechanism behind each one. Any one of them is a reason to slow down. Two or more is a reason to walk.
2026-08-16
How to Choose a Penetration Testing Company
Four evidence points, in order: named testers' credentials, the manual-to-automated balance, a sanitized sample report, and whether the SOW names the people. Price is the fifth criterion, not the first.
2026-03-07
Building a Vendor Risk Management Program from Scratch
A step-by-step guide to inventorying vendors, classifying risk tiers, running assessments, and meeting SOC 2, ISO 27001, and NIST CSF supply chain requirements.