top of page


An Access Review Isn't Complete Until Remediation Is Verified
Your quarterly access review can be 100% complete while leaving the underlying access risk unchanged. Here's why — and what to check instead. The gap between "completed" and "effective" NIS2 has pushed a lot of organizations across the EU to ask a simple question: are our access controls compliant? It's the wrong first question. The question that actually matters is: do they work? I encounter the gap between those two questions as one of the most common patterns when assessin
Kostas Tsiolas
5 days ago5 min read


The SSPR blind spot Microsoft's SMS retirement is about to expose
User SSPR mobile phone Two dates. One dependency map most Entra tenants have never drawn. Here's how to find it before February 2027 finds it for you. In every Entra tenant we've reviewed this quarter, one pattern keeps repeating. A meaningful share of users still have SMS or Voice registered as one of their authentication methods. Some as their only method. Many as one of two methods on an SSPR policy that requires two. And in almost every case, the identity team can't tell
Kostas Tsiolas
Sep 76 min read


Stop Blaming the User: Design Security for Human Failure
Security Awareness Training can reduce the likelihood of a successful attack. Security Architecture determines whether that attack becomes a minor incident or a business-impacting breach. The wrong question after a phishing incident is: "Why did the employee click?" The better question is: "Why was a single click enough?" For years, incident reviews have stopped at a familiar conclusion: The user clicked the link. Technically, that may be accurate. Architecturally, it explain
Kostas Tsiolas
Aug 315 min read


Passkeys by Default: Is Your Account Recovery Phishing-Resistant Too?
Microsoft is changing authentication in Entra ID. But the real Identity risk may sit in the process you use when a legitimate user loses access. From 1 September 2026, Microsoft is making a significant change to the authentication experience in Microsoft Entra ID. Users who are still enabled for SMS or voice authentication will be automatically enabled for passkeys and enrolled into a Registration Campaign prompting them to register a passkey. From 1 February 2027, Microsoft-
Kostas Tsiolas
Aug 287 min read


Passkeys by default: Είναι όμως και το account recovery σας phishing-resistant;
Η Microsoft αλλάζει το authentication στο Entra ID. Το πραγματικό Identity risk όμως μπορεί να βρίσκεται στη διαδικασία που χρησιμοποιείτε όταν ένας χρήστης χάσει την πρόσβασή του. Από την 1η Σεπτεμβρίου 2026, η Microsoft αλλάζει σημαντικά την authentication experience στο Microsoft Entra ID. Οι χρήστες που παραμένουν enabled για SMS ή voice authentication θα γίνουν automatically enabled για passkeys και θα ενταχθούν σε Registration Campaign που θα τους προτρέπει να εγγραφούν
Kostas Tsiolas
Aug 276 min read


SMS and Voice MFA Are Being Retired — And It's the Right Call
Microsoft is making passkeys the default in Entra ID and phasing out phishable SMS and voice authentication. Here's why that decision is overdue, what the risks really were, and how to migrate without locking your users out. Microsoft has set a hard deadline for a method most security teams already distrusted but few had the mandate to remove. Starting 1 September 2026, passkeys become the default authentication experience in Microsoft Entra ID. On 1 February 2027, Microsoft
Kostas Tsiolas
Jul 166 min read


Today’s Security Is Not About Stopping Breaches. It Is About Containing Them.
The dangerous lie in many security programs is not prevention itself. It is the belief that prevention is enough. Firewalls, Web Application Firewalls (WAFs), endpoint controls, phishing protection, and detection platforms all matter. They reduce risk. They stop known attacks. They make exploitation harder. But they do not eliminate compromise. One stolen credential. One leaked access key. One over-permissive service account. One poisoned pipeline. One misconfigured storage
Kostas Tsiolas
Apr 272 min read


You Cannot Secure What You Build After the Fact. Here Is Why Proactive Security Architecture Changes Everything.
Most organisations call a security advisor after something breaks. By that point the remediation cost — in time, money, architectural rework and reputational damage — is an order of magnitude higher than building it correctly from the start. I have worked on both sides of this equation across 25 years in enterprise security. The organisations that engage us before a project launches spend a fraction of what their peers spend on incident response. This post makes the case for
Kostas Tsiolas
Apr 272 min read


NIS2 Compliance Will Not Save You. NIS2 Architecture Will.
There is a dangerous gap between organisations that are NIS2 compliant and organisations that are NIS2 resilient. The compliant ones have documentation, policies and audit trails that satisfy a regulator on a good day. The resilient ones have security architectures that actually work when an attacker arrives — which is a different thing entirely. After working with organisations across financial services, industrial, government and maritime sectors on NIS2 readiness, I have s
Kostas Tsiolas
Apr 174 min read


Identity Governance Is Not an IT Project. It Is a Business Risk Decision Your Board Is Already Accountable For.
In an era where data breaches and cyber threats are rampant, businesses must prioritize identity security to safeguard their assets and maintain customer trust. The stakes are high; a single breach can lead to significant financial losses and irreparable damage to a company's reputation. This blog post explores how transforming identity security can lead to business success, offering practical strategies and real-world examples to illustrate the importance of robust identity
Kostas Tsiolas
Apr 174 min read


Zero Trust for Executives: Why Your Security Team Is Probably Starting in the Wrong Place
In today's digital landscape, the traditional security perimeter is no longer sufficient. With increasing cyber threats and the rise of remote work, organizations must rethink their security strategies. Enter Zero Trust Architecture (ZTA), a security model that operates on the principle of "never trust, always verify." This guide aims to provide executives with a comprehensive understanding of Zero Trust Architecture, its importance, and how to implement it effectively. High
Kostas Tsiolas
Apr 174 min read
bottom of page