<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>Gociux Insights</title>
  <link>https://gociux.com/insights/</link>
  <description>Practical security engineering — vulnerability management, compliance, incident response, automation.</description>
  <language>en</language>
  <item>
    <title>Which CVEs actually matter? KEV and EPSS, explained for busy teams</title>
    <link>https://gociux.com/insights/kev-epss-vulnerability-prioritization.html</link>
    <guid>https://gociux.com/insights/kev-epss-vulnerability-prioritization.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>Around 3,000 CVEs are published every month and only a small fraction are ever exploited. How CISA KEV and EPSS turn an impossible patching backlog into a short, defensible priority list.</description>
  </item>
  <item>
    <title>NIS2 just made you a regulated company. Now what?</title>
    <link>https://gociux.com/insights/nis2-requirements-explained.html</link>
    <guid>https://gociux.com/insights/nis2-requirements-explained.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>A practical guide to the EU NIS2 directive: who is in scope, the 24-hour and 72-hour incident reporting cascade, the ten baseline security measures, management liability, and where to start.</description>
  </item>
  <item>
    <title>Hardening Entra ID: the ten controls that stop real tenant compromises</title>
    <link>https://gociux.com/insights/entra-id-tenant-hardening.html</link>
    <guid>https://gociux.com/insights/entra-id-tenant-hardening.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>A field-tested Microsoft Entra ID hardening checklist: killing legacy authentication, Conditional Access done right, phishing-resistant MFA for admins, break-glass accounts, app consent, and privileged role hygiene.</description>
  </item>
  <item>
    <title>PCI DSS logging requirements without the panic: what Requirement 10 actually asks</title>
    <link>https://gociux.com/insights/pci-dss-logging-requirements.html</link>
    <guid>https://gociux.com/insights/pci-dss-logging-requirements.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>A practical engineering view of PCI DSS Requirement 10 — what to log, how long to keep it, daily review, time sync, and log integrity — and how to generate the evidence continuously instead of before the audit.</description>
  </item>
  <item>
    <title>SIEM for a mid-sized regulated company: build, buy, or managed?</title>
    <link>https://gociux.com/insights/siem-build-buy-managed.html</link>
    <guid>https://gociux.com/insights/siem-build-buy-managed.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>The honest economics of SIEM: why licensing is the smaller cost, where in-house deployments stall, what managed offerings trade away, and the questions that cut through vendor noise.</description>
  </item>
  <item>
    <title>A phishing campaign just hit your Microsoft 365 tenant. The first hour.</title>
    <link>https://gociux.com/insights/phishing-response-microsoft-365.html</link>
    <guid>https://gociux.com/insights/phishing-response-microsoft-365.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>A practical first-hour runbook for phishing response in Microsoft 365: scoping with message trace, purging delivered mail, blocking the wave, finding who clicked, and containing compromised accounts.</description>
  </item>
  <item>
    <title>Secrets in your repos: how credentials leak through CI/CD and how to stop it</title>
    <link>https://gociux.com/insights/secrets-in-cicd-pipelines.html</link>
    <guid>https://gociux.com/insights/secrets-in-cicd-pipelines.html</guid>
    <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
    <description>Why API keys end up in git history, the three layers of secrets scanning that actually work, what to do in the first hour after a leak, and how short-lived credentials make the whole problem smaller.</description>
  </item>
</channel></rss>