<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Protoxol Blog</title>
  <link href="https://protoxol.com/blog.html"/>
  <link rel="self" href="https://protoxol.com/atom.xml"/>
  <id>https://protoxol.com/blog.html</id>
  <updated>2026-06-11T11:20:56.427Z</updated>
  <author><name>Protoxol</name><email>contact@protoxol.com</email></author>
  
  <entry>
    <title>Hardening macOS fleets for enterprise</title>
    <link href="https://protoxol.com/blog/hardening-macos-fleets-for-enterprise.html"/>
    <id>https://protoxol.com/blog/hardening-macos-fleets-for-enterprise.html</id>
    <updated>2026-02-09T00:00:00.000Z</updated>
    <published>2026-02-09T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on hardening macos fleets for enterprise. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Phishing-resistant authentication: passkeys, FIDO2, and reality</title>
    <link href="https://protoxol.com/blog/phishing-resistant-authentication-passkeys-fido2-and-reality.html"/>
    <id>https://protoxol.com/blog/phishing-resistant-authentication-passkeys-fido2-and-reality.html</id>
    <updated>2026-02-09T00:00:00.000Z</updated>
    <published>2026-02-09T00:00:00.000Z</published>
    <category term="Concepts Base"/>
    <summary>Practical guidance on phishing-resistant authentication: passkeys, fido2, and reality. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>AWS security quick wins: 15 controls to implement first</title>
    <link href="https://protoxol.com/blog/aws-security-quick-wins-15-controls-to-implement-first.html"/>
    <id>https://protoxol.com/blog/aws-security-quick-wins-15-controls-to-implement-first.html</id>
    <updated>2026-02-08T00:00:00.000Z</updated>
    <published>2026-02-08T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on aws security quick wins: 15 controls to implement first. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Email gateway tuning: reducing false positives without risk</title>
    <link href="https://protoxol.com/blog/email-gateway-tuning-reducing-false-positives-without-risk.html"/>
    <id>https://protoxol.com/blog/email-gateway-tuning-reducing-false-positives-without-risk.html</id>
    <updated>2026-02-08T00:00:00.000Z</updated>
    <published>2026-02-08T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on email gateway tuning: reducing false positives without risk. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>How attackers bypass MFA (and how to stop them)</title>
    <link href="https://protoxol.com/blog/how-attackers-bypass-mfa-and-how-to-stop-them.html"/>
    <id>https://protoxol.com/blog/how-attackers-bypass-mfa-and-how-to-stop-them.html</id>
    <updated>2026-02-08T00:00:00.000Z</updated>
    <published>2026-02-08T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on how attackers bypass mfa (and how to stop them). What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Security review of third parties: vendor risk in practice</title>
    <link href="https://protoxol.com/blog/security-review-of-third-parties-vendor-risk-in-practice.html"/>
    <id>https://protoxol.com/blog/security-review-of-third-parties-vendor-risk-in-practice.html</id>
    <updated>2026-02-06T00:00:00.000Z</updated>
    <published>2026-02-06T00:00:00.000Z</published>
    <category term="Compliance"/>
    <summary>Practical guidance on security review of third parties: vendor risk in practice. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>OAuth and OIDC pitfalls in SaaS integrations</title>
    <link href="https://protoxol.com/blog/oauth-and-oidc-pitfalls-in-saas-integrations.html"/>
    <id>https://protoxol.com/blog/oauth-and-oidc-pitfalls-in-saas-integrations.html</id>
    <updated>2026-02-05T00:00:00.000Z</updated>
    <published>2026-02-05T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on oauth and oidc pitfalls in saas integrations. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Azure security quick wins: identity, logging, and segmentation</title>
    <link href="https://protoxol.com/blog/azure-security-quick-wins-identity-logging-and-segmentation.html"/>
    <id>https://protoxol.com/blog/azure-security-quick-wins-identity-logging-and-segmentation.html</id>
    <updated>2026-02-05T00:00:00.000Z</updated>
    <published>2026-02-05T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on azure security quick wins: identity, logging, and segmentation. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Cyber insurance readiness: controls that affect underwriting</title>
    <link href="https://protoxol.com/blog/cyber-insurance-readiness-controls-that-affect-underwriting.html"/>
    <id>https://protoxol.com/blog/cyber-insurance-readiness-controls-that-affect-underwriting.html</id>
    <updated>2026-02-04T00:00:00.000Z</updated>
    <published>2026-02-04T00:00:00.000Z</published>
    <category term="Compliance"/>
    <summary>Practical guidance on cyber insurance readiness: controls that affect underwriting. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Threat hunting 101: hypotheses, data, and success metrics</title>
    <link href="https://protoxol.com/blog/threat-hunting-101-hypotheses-data-and-success-metrics.html"/>
    <id>https://protoxol.com/blog/threat-hunting-101-hypotheses-data-and-success-metrics.html</id>
    <updated>2026-02-04T00:00:00.000Z</updated>
    <published>2026-02-04T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on threat hunting 101: hypotheses, data, and success metrics. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>IoT security for SMBs: what matters and what doesn’t</title>
    <link href="https://protoxol.com/blog/iot-security-for-smbs-what-matters-and-what-doesn-t.html"/>
    <id>https://protoxol.com/blog/iot-security-for-smbs-what-matters-and-what-doesn-t.html</id>
    <updated>2026-02-03T00:00:00.000Z</updated>
    <published>2026-02-03T00:00:00.000Z</published>
    <category term="Devices"/>
    <summary>Practical guidance on iot security for smbs: what matters and what doesn’t. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>OSCP study plan for busy professionals</title>
    <link href="https://protoxol.com/blog/oscp-study-plan-for-busy-professionals.html"/>
    <id>https://protoxol.com/blog/oscp-study-plan-for-busy-professionals.html</id>
    <updated>2026-02-02T00:00:00.000Z</updated>
    <published>2026-02-02T00:00:00.000Z</published>
    <category term="Certifications"/>
    <summary>Practical guidance on oscp study plan for busy professionals. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Attack surface management: external exposure in reality</title>
    <link href="https://protoxol.com/blog/attack-surface-management-external-exposure-in-reality.html"/>
    <id>https://protoxol.com/blog/attack-surface-management-external-exposure-in-reality.html</id>
    <updated>2026-02-01T00:00:00.000Z</updated>
    <published>2026-02-01T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on attack surface management: external exposure in reality. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>HSMs explained: when you need them</title>
    <link href="https://protoxol.com/blog/hsms-explained-when-you-need-them.html"/>
    <id>https://protoxol.com/blog/hsms-explained-when-you-need-them.html</id>
    <updated>2026-01-31T00:00:00.000Z</updated>
    <published>2026-01-31T00:00:00.000Z</published>
    <category term="Devices"/>
    <summary>Practical guidance on hsms explained: when you need them. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>How to choose a SIEM in 2026: cost, data, and outcomes</title>
    <link href="https://protoxol.com/blog/how-to-choose-a-siem-in-2026-cost-data-and-outcomes.html"/>
    <id>https://protoxol.com/blog/how-to-choose-a-siem-in-2026-cost-data-and-outcomes.html</id>
    <updated>2026-01-31T00:00:00.000Z</updated>
    <published>2026-01-31T00:00:00.000Z</published>
    <category term="Recovery"/>
    <summary>Practical guidance on how to choose a siem in 2026: cost, data, and outcomes. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Red teaming vs purple teaming: choosing the right exercise</title>
    <link href="https://protoxol.com/blog/red-teaming-vs-purple-teaming-choosing-the-right-exercise.html"/>
    <id>https://protoxol.com/blog/red-teaming-vs-purple-teaming-choosing-the-right-exercise.html</id>
    <updated>2026-01-31T00:00:00.000Z</updated>
    <published>2026-01-31T00:00:00.000Z</published>
    <category term="Ethical Hacking"/>
    <summary>Practical guidance on red teaming vs purple teaming: choosing the right exercise. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Ransomware readiness: a short plan that works</title>
    <link href="https://protoxol.com/blog/ransomware-readiness-a-short-plan-that-works.html"/>
    <id>https://protoxol.com/blog/ransomware-readiness-a-short-plan-that-works.html</id>
    <updated>2026-01-27T00:00:00.000Z</updated>
    <published>2026-01-27T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on ransomware readiness: a short plan that works. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Microsoft 365 security baseline for SMBs</title>
    <link href="https://protoxol.com/blog/microsoft-365-security-baseline-for-smbs.html"/>
    <id>https://protoxol.com/blog/microsoft-365-security-baseline-for-smbs.html</id>
    <updated>2026-01-22T00:00:00.000Z</updated>
    <published>2026-01-22T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on microsoft 365 security baseline for smbs. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>ISO 27001 implementation roadmap for fast-moving teams</title>
    <link href="https://protoxol.com/blog/iso-27001-implementation-roadmap-for-fast-moving-teams.html"/>
    <id>https://protoxol.com/blog/iso-27001-implementation-roadmap-for-fast-moving-teams.html</id>
    <updated>2026-01-19T00:00:00.000Z</updated>
    <published>2026-01-19T00:00:00.000Z</published>
    <category term="Compliance"/>
    <summary>Practical guidance on iso 27001 implementation roadmap for fast-moving teams. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>MITRE ATT&amp;CK mapping without the theater</title>
    <link href="https://protoxol.com/blog/mitre-att-ck-mapping-without-the-theater.html"/>
    <id>https://protoxol.com/blog/mitre-att-ck-mapping-without-the-theater.html</id>
    <updated>2026-01-19T00:00:00.000Z</updated>
    <published>2026-01-19T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on mitre att&amp;ck mapping without the theater. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>NIST CSF: a practical implementation guide</title>
    <link href="https://protoxol.com/blog/nist-csf-a-practical-implementation-guide.html"/>
    <id>https://protoxol.com/blog/nist-csf-a-practical-implementation-guide.html</id>
    <updated>2026-01-14T00:00:00.000Z</updated>
    <published>2026-01-14T00:00:00.000Z</published>
    <category term="Compliance"/>
    <summary>Practical guidance on nist csf: a practical implementation guide. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Secure remote work: beyond VPN</title>
    <link href="https://protoxol.com/blog/secure-remote-work-beyond-vpn.html"/>
    <id>https://protoxol.com/blog/secure-remote-work-beyond-vpn.html</id>
    <updated>2026-01-10T00:00:00.000Z</updated>
    <published>2026-01-10T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on secure remote work: beyond vpn. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Credential stuffing: detection signals and mitigation steps</title>
    <link href="https://protoxol.com/blog/credential-stuffing-detection-signals-and-mitigation-steps.html"/>
    <id>https://protoxol.com/blog/credential-stuffing-detection-signals-and-mitigation-steps.html</id>
    <updated>2026-01-10T00:00:00.000Z</updated>
    <published>2026-01-10T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on credential stuffing: detection signals and mitigation steps. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Threat modeling for product teams: fast and effective</title>
    <link href="https://protoxol.com/blog/threat-modeling-for-product-teams-fast-and-effective.html"/>
    <id>https://protoxol.com/blog/threat-modeling-for-product-teams-fast-and-effective.html</id>
    <updated>2026-01-09T00:00:00.000Z</updated>
    <published>2026-01-09T00:00:00.000Z</published>
    <category term="Education"/>
    <summary>Practical guidance on threat modeling for product teams: fast and effective. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Threat intel to detection: turning reports into rules</title>
    <link href="https://protoxol.com/blog/threat-intel-to-detection-turning-reports-into-rules.html"/>
    <id>https://protoxol.com/blog/threat-intel-to-detection-turning-reports-into-rules.html</id>
    <updated>2026-01-07T00:00:00.000Z</updated>
    <published>2026-01-07T00:00:00.000Z</published>
    <category term="Recovery"/>
    <summary>Practical guidance on threat intel to detection: turning reports into rules. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Backup strategy that survives ransomware</title>
    <link href="https://protoxol.com/blog/backup-strategy-that-survives-ransomware.html"/>
    <id>https://protoxol.com/blog/backup-strategy-that-survives-ransomware.html</id>
    <updated>2026-01-07T00:00:00.000Z</updated>
    <published>2026-01-07T00:00:00.000Z</published>
    <category term="Recovery"/>
    <summary>Practical guidance on backup strategy that survives ransomware. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>SBOMs that help: operationalizing component risk</title>
    <link href="https://protoxol.com/blog/sboms-that-help-operationalizing-component-risk.html"/>
    <id>https://protoxol.com/blog/sboms-that-help-operationalizing-component-risk.html</id>
    <updated>2026-01-05T00:00:00.000Z</updated>
    <published>2026-01-05T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on sboms that help: operationalizing component risk. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>How to run a post-incident review that improves security</title>
    <link href="https://protoxol.com/blog/how-to-run-a-post-incident-review-that-improves-security.html"/>
    <id>https://protoxol.com/blog/how-to-run-a-post-incident-review-that-improves-security.html</id>
    <updated>2026-01-04T00:00:00.000Z</updated>
    <published>2026-01-04T00:00:00.000Z</published>
    <category term="Recovery"/>
    <summary>Practical guidance on how to run a post-incident review that improves security. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>API security checklist for SaaS teams</title>
    <link href="https://protoxol.com/blog/api-security-checklist-for-saas-teams.html"/>
    <id>https://protoxol.com/blog/api-security-checklist-for-saas-teams.html</id>
    <updated>2026-01-02T00:00:00.000Z</updated>
    <published>2026-01-02T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on api security checklist for saas teams. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Key management: KMS basics and common failures</title>
    <link href="https://protoxol.com/blog/key-management-kms-basics-and-common-failures.html"/>
    <id>https://protoxol.com/blog/key-management-kms-basics-and-common-failures.html</id>
    <updated>2025-12-27T00:00:00.000Z</updated>
    <published>2025-12-27T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on key management: kms basics and common failures. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>DNS as a control plane: detecting exfiltration patterns</title>
    <link href="https://protoxol.com/blog/dns-as-a-control-plane-detecting-exfiltration-patterns.html"/>
    <id>https://protoxol.com/blog/dns-as-a-control-plane-detecting-exfiltration-patterns.html</id>
    <updated>2025-12-27T00:00:00.000Z</updated>
    <published>2025-12-27T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on dns as a control plane: detecting exfiltration patterns. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Okta / IdP incidents: hardening identity providers</title>
    <link href="https://protoxol.com/blog/okta-idp-incidents-hardening-identity-providers.html"/>
    <id>https://protoxol.com/blog/okta-idp-incidents-hardening-identity-providers.html</id>
    <updated>2025-12-25T00:00:00.000Z</updated>
    <published>2025-12-25T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on okta / idp incidents: hardening identity providers. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>SOC staffing models: 24/7 coverage without burnout</title>
    <link href="https://protoxol.com/blog/soc-staffing-models-24-7-coverage-without-burnout.html"/>
    <id>https://protoxol.com/blog/soc-staffing-models-24-7-coverage-without-burnout.html</id>
    <updated>2025-12-23T00:00:00.000Z</updated>
    <published>2025-12-23T00:00:00.000Z</published>
    <category term="Education"/>
    <summary>Practical guidance on soc staffing models: 24/7 coverage without burnout. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Password managers for enterprises: rollout plan and pitfalls</title>
    <link href="https://protoxol.com/blog/password-managers-for-enterprises-rollout-plan-and-pitfalls.html"/>
    <id>https://protoxol.com/blog/password-managers-for-enterprises-rollout-plan-and-pitfalls.html</id>
    <updated>2025-12-23T00:00:00.000Z</updated>
    <published>2025-12-23T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on password managers for enterprises: rollout plan and pitfalls. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Data loss prevention for modern SaaS: a pragmatic approach</title>
    <link href="https://protoxol.com/blog/data-loss-prevention-for-modern-saas-a-pragmatic-approach.html"/>
    <id>https://protoxol.com/blog/data-loss-prevention-for-modern-saas-a-pragmatic-approach.html</id>
    <updated>2025-12-22T00:00:00.000Z</updated>
    <published>2025-12-22T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on data loss prevention for modern saas: a pragmatic approach. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Data sovereignty: what changes with regions and cloud</title>
    <link href="https://protoxol.com/blog/data-sovereignty-what-changes-with-regions-and-cloud.html"/>
    <id>https://protoxol.com/blog/data-sovereignty-what-changes-with-regions-and-cloud.html</id>
    <updated>2025-12-18T00:00:00.000Z</updated>
    <published>2025-12-18T00:00:00.000Z</published>
    <category term="Compliance"/>
    <summary>Practical guidance on data sovereignty: what changes with regions and cloud. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Detection engineering: writing detections that survive production</title>
    <link href="https://protoxol.com/blog/detection-engineering-writing-detections-that-survive-production.html"/>
    <id>https://protoxol.com/blog/detection-engineering-writing-detections-that-survive-production.html</id>
    <updated>2025-12-18T00:00:00.000Z</updated>
    <published>2025-12-18T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on detection engineering: writing detections that survive production. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>How to build an incident response retainer that actually helps</title>
    <link href="https://protoxol.com/blog/how-to-build-an-incident-response-retainer-that-actually-helps.html"/>
    <id>https://protoxol.com/blog/how-to-build-an-incident-response-retainer-that-actually-helps.html</id>
    <updated>2025-12-18T00:00:00.000Z</updated>
    <published>2025-12-18T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on how to build an incident response retainer that actually helps. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Browser-based attacks: modern exploit chains to watch</title>
    <link href="https://protoxol.com/blog/browser-based-attacks-modern-exploit-chains-to-watch.html"/>
    <id>https://protoxol.com/blog/browser-based-attacks-modern-exploit-chains-to-watch.html</id>
    <updated>2025-12-17T00:00:00.000Z</updated>
    <published>2025-12-17T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on browser-based attacks: modern exploit chains to watch. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Incident response playbook: roles, timelines, and comms</title>
    <link href="https://protoxol.com/blog/incident-response-playbook-roles-timelines-and-comms.html"/>
    <id>https://protoxol.com/blog/incident-response-playbook-roles-timelines-and-comms.html</id>
    <updated>2025-12-17T00:00:00.000Z</updated>
    <published>2025-12-17T00:00:00.000Z</published>
    <category term="Practical Guides"/>
    <summary>Practical guidance on incident response playbook: roles, timelines, and comms. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>SOC as a Service: what you get and what to ask before buying</title>
    <link href="https://protoxol.com/blog/soc-as-a-service-what-you-get-and-what-to-ask-before-buying.html"/>
    <id>https://protoxol.com/blog/soc-as-a-service-what-you-get-and-what-to-ask-before-buying.html</id>
    <updated>2025-12-16T00:00:00.000Z</updated>
    <published>2025-12-16T00:00:00.000Z</published>
    <category term="Concepts Base"/>
    <summary>Practical guidance on soc as a service: what you get and what to ask before buying. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Mobile device security for leadership (BYOD without regret)</title>
    <link href="https://protoxol.com/blog/mobile-device-security-for-leadership-byod-without-regret.html"/>
    <id>https://protoxol.com/blog/mobile-device-security-for-leadership-byod-without-regret.html</id>
    <updated>2025-12-13T00:00:00.000Z</updated>
    <published>2025-12-13T00:00:00.000Z</published>
    <category term="Devices"/>
    <summary>Practical guidance on mobile device security for leadership (byod without regret). What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Secure coding: top 10 patterns that prevent incidents</title>
    <link href="https://protoxol.com/blog/secure-coding-top-10-patterns-that-prevent-incidents.html"/>
    <id>https://protoxol.com/blog/secure-coding-top-10-patterns-that-prevent-incidents.html</id>
    <updated>2025-12-08T00:00:00.000Z</updated>
    <published>2025-12-08T00:00:00.000Z</published>
    <category term="Education"/>
    <summary>Practical guidance on secure coding: top 10 patterns that prevent incidents. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Tabletop exercises: running a cyber crisis simulation</title>
    <link href="https://protoxol.com/blog/tabletop-exercises-running-a-cyber-crisis-simulation.html"/>
    <id>https://protoxol.com/blog/tabletop-exercises-running-a-cyber-crisis-simulation.html</id>
    <updated>2025-12-08T00:00:00.000Z</updated>
    <published>2025-12-08T00:00:00.000Z</published>
    <category term="Education"/>
    <summary>Practical guidance on tabletop exercises: running a cyber crisis simulation. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>GIAC certifications: picking the right track for your domain</title>
    <link href="https://protoxol.com/blog/giac-certifications-picking-the-right-track-for-your-domain.html"/>
    <id>https://protoxol.com/blog/giac-certifications-picking-the-right-track-for-your-domain.html</id>
    <updated>2025-12-07T00:00:00.000Z</updated>
    <published>2025-12-07T00:00:00.000Z</published>
    <category term="Certifications"/>
    <summary>Practical guidance on giac certifications: picking the right track for your domain. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Threat intelligence program: what to collect and how to use it</title>
    <link href="https://protoxol.com/blog/threat-intelligence-program-what-to-collect-and-how-to-use-it.html"/>
    <id>https://protoxol.com/blog/threat-intelligence-program-what-to-collect-and-how-to-use-it.html</id>
    <updated>2025-12-02T00:00:00.000Z</updated>
    <published>2025-12-02T00:00:00.000Z</published>
    <category term="Recovery"/>
    <summary>Practical guidance on threat intelligence program: what to collect and how to use it. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Secure browser isolation: when it makes sense</title>
    <link href="https://protoxol.com/blog/secure-browser-isolation-when-it-makes-sense.html"/>
    <id>https://protoxol.com/blog/secure-browser-isolation-when-it-makes-sense.html</id>
    <updated>2025-11-30T00:00:00.000Z</updated>
    <published>2025-11-30T00:00:00.000Z</published>
    <category term="Cloud &amp; Infra"/>
    <summary>Practical guidance on secure browser isolation: when it makes sense. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Shadow IT: discovery and governance without blocking teams</title>
    <link href="https://protoxol.com/blog/shadow-it-discovery-and-governance-without-blocking-teams.html"/>
    <id>https://protoxol.com/blog/shadow-it-discovery-and-governance-without-blocking-teams.html</id>
    <updated>2025-11-30T00:00:00.000Z</updated>
    <published>2025-11-30T00:00:00.000Z</published>
    <category term="Education"/>
    <summary>Practical guidance on shadow it: discovery and governance without blocking teams. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>XSS: modern exploitation paths and defenses</title>
    <link href="https://protoxol.com/blog/xss-modern-exploitation-paths-and-defenses.html"/>
    <id>https://protoxol.com/blog/xss-modern-exploitation-paths-and-defenses.html</id>
    <updated>2025-11-25T00:00:00.000Z</updated>
    <published>2025-11-25T00:00:00.000Z</published>
    <category term="Ethical Hacking"/>
    <summary>Practical guidance on xss: modern exploitation paths and defenses. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
  <entry>
    <title>Insider threat: detection signals and fair policy design</title>
    <link href="https://protoxol.com/blog/insider-threat-detection-signals-and-fair-policy-design.html"/>
    <id>https://protoxol.com/blog/insider-threat-detection-signals-and-fair-policy-design.html</id>
    <updated>2025-11-24T00:00:00.000Z</updated>
    <published>2025-11-24T00:00:00.000Z</published>
    <category term="Threat Trends"/>
    <summary>Practical guidance on insider threat: detection signals and fair policy design. What matters, how to implement it, and what to prioritize first.</summary>
  </entry>
</feed>