Notes from the attack team.
Field notes on red teaming, pentesting, TIBER/DORA and offensive security training.

DORA in Iceland: what should your next resilience test prove?
Your next resilience test should establish whether a credible attacker can cross the dependencies of a critical business function - and whether your team can detect, contain and recover from that path. Iceland’s frontier-AI warning makes that question more…

UAE crypto security: scope the attack paths beyond smart contracts
A smart-contract review cannot establish whether your exchange or custody operation can withstand an attack on identities, approvals and signing workflows. For a VARA-regulated virtual-asset service provider, the regulator's testing rule explicitly extends…

🇦🇪 Your most dangerous AI agent may not be in the inventory
An AI agent reads mail, updates records, calls tools, alters data. The dangerous one is the agent nobody registered. It inherited permissions from a prototype, kept them in production, and no one reviewed what it could actually reach.