DarkCode

作者: Gary Yip

Where Vulnerability Scanners Fail in Real Enterprise Practice

TL;DR: Key Takeaways Vulnerability scanners are essential for baseline hygiene, but structurally limited in depth, scope, and context. In large enterprises, especially in regulated Hong Kong sectors, organizational realities amplify these blind spots. “Clean” scan reports often mask real, exploitable attack paths inside segmented and credential-restricted environments. Use scanners for coverage and compliance — but

了解更多

IA GL20 Compliance Guide: Navigating Cybersecurity for Hong Kong Insurers

TL;DR: What Boards and Senior Executives Need to Know IA GL20 requires insurers to demonstrate cyber resilience, not just technical controls. Compliance is assessed through the Cyber Resilience Assessment Framework (CRAF): IRA, MA, and TIBAS. Most regulatory issues arise from governance gaps, weak risk articulation, and fragmented execution. With clear ownership and leadership oversight, GL20

了解更多