mksim.pro
Blog

Notes on data, AI, IT and security

No marketing fog. The way I think about real problems with founders and managers.

Security

Legacy on the factory floor: securing Windows XP and 7 systems you cannot patch

Industrial equipment lives 15 to 30 years, and the control PCs under it run on Windows XP and 7 that lost support long ago. A routine patch can void the vendor warranty or crash the process. What to do when you cannot update: move the defense from the host to isolation and compensating controls.

Read
Security

AI on the factory floor and a new class of attack: how to protect an industrial model

Factories put neural nets on predictive maintenance and process optimization. A new class of attack - poisoning the training data and quietly spoofing telemetry - pushes the AI into decisions that wreck equipment. Where the real line of defense actually runs.

Read
Security

When AI exposes the debt sitting in your codebase

The first numbers from Anthropic's Glasswing project are not a story about a smart model. They are a story about how much old vulnerability lives in code we use every day.

Read
Security

Shadow AI: how the new shadow IT is becoming a security problem

Employees are using AI tools without IT department oversight. The pattern is familiar - but the risks are different from classic shadow IT.

Read
Security

Data, IT, and security cannot be separated

Why splitting these three areas across different teams turns any technology project into a quiet source of hidden risk.

Read
Security

NIS2 simplification package: where compliance becomes less paperwork

What the EU regulatory simplification package around NIS2 means for companies working with European partners or clients.

Read
Security

AI shifts the phishing baseline: what companies need to rethink

Generative models have reduced the cost of producing convincing phishing emails to zero. I break down how this changes the threat model and what needs to change in defence.

Read
Security

The CrowdStrike outage lesson: when protection becomes a single point of failure

The CrowdStrike update incident in July 2024 halted operations at thousands of companies worldwide. What it reveals about resilience architecture.

Read
Security

Zero trust: what it means in practice for a mid-size company

Zero trust has become a buzzword. Behind it is a genuinely useful access model - but getting there requires specific decisions, not just a policy statement.

Read
Security

AI assistants and identity: the new attack surface

When corporate AI assistants gain access to email, documents, and systems, a new class of threats emerges that managers need to understand.

Read
Security

SaaS supply chain attacks: lessons for managers

Incidents from early 2025 show that a company's security perimeter now runs through its SaaS providers. What this means in practice.

Read
Security

2024 in security: what changed and what stayed the same

A brief look at what 2024 added to the information security landscape - for those who make decisions, not just execute them.

Read