Nimrics · Blog · InfoSec
Notes & essays.

Data Privacy for Startups in Qatar: What the PDPPL Actually Requires
Qatar's Personal Data Privacy Protection Law applies to almost every company that holds a customer's name and phone number. A founder's plain-language guide to the obligations, the rights you must honour, and the six things to do first.
Read
You Have Been Breached. The First 24 Hours.
The first day of an incident decides whether it is a bad week or a bad year. An hour-by-hour plan for a small company with no security team — what to contain, what to preserve, who to tell, and what not to do.
Read
Securing a Remote Team: Laptops, Wi-Fi, Accounts and the Boring Stuff That Works
A distributed team has no office firewall to hide behind — every laptop is the perimeter. The short list of controls that protect a remote company without turning it into a fortress nobody wants to work in.
Read
Your Vendors Are Your Attack Surface: Third-Party Risk for Small Teams
A small company runs on other people's software — thirty SaaS tools, a payroll provider, an agency with admin access. Each one is a door. A lightweight way to know which doors matter and how to keep them shut.
Read
Securing a Mobile App's API: Keys, Tokens, Rate Limits and the OWASP API Top 10
Your mobile app is a public client — every secret inside it is already in the attacker's hands. How to design the API behind an app so that nothing important depends on the app keeping a secret.
Read
Cloud Security for Startups: IAM, Buckets and the Mistakes Everyone Makes First
The cloud is not less secure than a server in a cupboard — but it fails in different ways, and the first five mistakes are the same at almost every startup. Here they are, with the fix for each.
Read
The 12-Point Website Security Checklist for Founders
You do not need to be an engineer to know whether your website is reasonably safe. Twelve checks — most take five minutes — that cover the ways small-business sites actually get broken into.
Read
Backups That Survive Ransomware: The 3-2-1-1-0 Rule, Explained
Most companies that pay a ransom had backups. They just had the wrong kind. What 3-2-1-1-0 means in practice, why the extra "1" and "0" matter, and a weekend plan for a small business.
Read
You Clicked a Phishing Link. Here Is What to Do in the First Ten Minutes
Clicking is not the disaster; what happens in the next ten minutes decides whether it becomes one. A calm, step-by-step response for the moment you realise a message was not what it claimed to be.
Read