# rollcagedefence.com > Cyber Security Simplified ## Posts - [DMARC - One protocol to bind them all](https://rollcagedefence.com/dmarc-one-protocol-to-bind-them-all/): DMARC tells the receiving email server what do when SPF and DKIM policy checks fail. However DMARC performs another vital step. DMARC checks that that the domain of the author, as seen by the end-user fully the domain validated by SPF and DKIM. This is known as ‘alignment’. ✉️ From: “The domain of the email author.’📋 SPF “Is the connecting allowed to send mail for its domain?”🔑 DKIM “Was the email changed along the way?”🚨 DMARC “Align the checks with Authors domain, then enforce policy.” We’re going to review three critical elements in a received email, then show you how DMARC uses policy […] - [DKIM - Why you need it](https://rollcagedefence.com/why-you-need-dkim/): DKIM (DomainKeys Identified Mail) is an email authentication mechanism that lets a sending domain sign an email. Think of DKIM as a tamper-evident seal on an email envelope. If someone opens it and messes with the contents, the seal is broken, and the fraud is detected. The receiving mail server can then verify that: A Primer on e-Signatures DKIM relies upon public key cryptography, which uses a pair of matching cryptographic keys. This pair comprises a public key which is available to all, and a private key which is completely confidential. Anything which is locked with a private key can only be unlocked with […] - [Redirect domains explained](https://rollcagedefence.com/redirect-domains-explained/): Redirected domains are web domains that don’t directly host services. Instead they act as aliases, and redirect users to your authoritative (a.k.a. canonical) site. Redirected domains have some security weaknesses, but we’ll get to that later. First we’ll examine the top-four use-cases and how they can help your business. Campaign domains Campaign domains generally catchy, focussed domains that provide a targeted way to market products. Sometimes we call these ‘vanity’ domains. They’re generally short and look clean in your advertising copy. Rollcage Defence uses the campaign domain ‘getcyberessentials.ie’ to advertise the Cyber Essentials Certification to Irish businesses. getcyberessentials.ie is redirected […] - [Protect your reputation with SPF](https://rollcagedefence.com/protect-your-reputation-with-spf/): You’ve just receive an email from a client saying: “Thanks — we’ve paid the invoice to the new bank account as instructed.” Super. No. Wait. What? You never sent them an email. Fuck! What happened? This type of attack is known as ‘invoice fraud’ and the mechanism is called ‘spoofing’. Someone ‘borrowed’ your @company.com domain name, and sent an email to a customer from their own server, pretending to be you[1]. The recipient saw an email with your exact email address, so they had very little reason to be suspicious. There is a simple and powerful way to stop attacks like […] - [The dirty secret of OTP recovery codes](https://rollcagedefence.com/otp-backup-codes/): Have you ever wondered how those OTP recovery, or backup, codes work? I know we are told to ‘keep them safe’ but what happens if we don’t. What’s the worst that could happen? How TOTP Works Here’s a quick recap on the three main security factors [1] for authentication: TOTP is a second factor [2] which can be used in addition your password – a ‘something you know’ credentials. We previously explored how TOTP works in depth, but for now recall that TOTP is: When TOTP stores this shared secret in an Authenticator App, then TOTP becomes a second authentication […] - [How TOTP (time-based OTP) works](https://rollcagedefence.com/how-totp-works/): Two factor authentication is meant to add a second method, or factor, of authentication beyond the traditional username and password combo. In this article, we’ll explore one specific type of 2FA known as Time-based One-Time Password – TOTP. In this article, we look at how TOTP works and how much you should trust it. TOTP is one of many different types of 2FA, so we’ll refer to it as TOTP. In this article the term service provider refers to the application or service you’re trying to authenticate to. The journey begins Seen recently on a website…. “That QR code is […] - [What is ARP?](https://rollcagedefence.com/whats-arp/): ARP is a technology that underpins most networking and network security operations. There are so many primer and explanations out there already. So rather than pursue the traditional route, I wanted to explore an alternative method and explain it by analogy. I wanted to experiment with an analogy to What App messaging – and called the analogy WhatsARP? ARP is a fundamental networking protocol, and stands for Address Resolution Protocol. It is used when a message is received by a computer with a destination IP address. In our analogy the computer (blue) knows that a computer with that IP Address […] - [Positive Paths To Safety](https://rollcagedefence.com/positive-paths-to-safety/): Balancing threats with solutions It’s really important to discuss cybersecurity risks and threats, but we must also accompany that discussion with a clear and positive path to resolution. If we only present the negative side, the problem can seem too complex, too expensive, and too difficult to resolve. It can feel overwhelming for the business involved so the threat and the resolution often get pushed down the line and never addressed. As and industry we often forget just how many hats business owners wear, and that cybersecurity is just one of ninety-nine problems. Similar dangerous pursuits We can learn a […] - [Zero Trust - Hard on the outside](https://rollcagedefence.com/zero-trust-lion-bars-and-lans/): I’d be lying if I said, “they don’t make networks like they used to”. Sadly, we’re still making networks exactly like we used to, and that has to change. Crunchy on the outside, chewy on the inside Traditional networks are built with a hardened internet-facing exterior firewall, and a trusted LAN interior for your users and systems. Crunchy on the outside, and chewy in the center, just like Lion bars [1]. The ‘moat-and-castle’ design was a solid design, but was based on assumptions that haven’t aged well: Well, times change. Remote access is now commonplace. Users are generally well intended […] - [Do you carry cash?](https://rollcagedefence.com/do-you-carry-cash/): Don’t worry, I’m not looking for a loan. I just want to know if you, right now, have any cash on your person. Or perhaps you’re just winging it, flying solo, tapping to pay, all the way. Let’s take a minute to think through our dependency upon complex systems. Tap to pay is magical “Any sufficiently advance technology is indistinguishable from magic” – Arthur C. Clarke I love the magic of contactless payment. I’ve spent decades in high-tech industries and yet still marvel at the ability to wave my mobile supercomputer to pay for goods and services. From facial recognition, […] - [Insecure Things - The coming shakeup in IoT security](https://rollcagedefence.com/insecure-things-the-coming-shakeup-in-iot-security/): Internet of things (IoT) devices have a terrible reputation for security, but is that fair? Yes. Yes they do, IoT devices do deserve the bad rep and then some. They are highly insecure, and the IoT market isn’t incentivised to change. Just make them secure already “Why can’t ‘they’ just make it secure!?!” – My Dad The answer is ‘market forces’. Market forces dictate that a winning consumer IoT solution must be: Cheap Working quickly Easy to operate Easy to upgrade Monitored As you can see, vendors have no financial incentive to prioritise security. Industrial IoT (IIoT) is also known […] - [Why your Sec and Dev teams are butting heads](https://rollcagedefence.com/why-your-sec-and-dev-teams-are-butting-heads/): Why won’t Dev and Ops teams engage with your security program? Perhaps they’re sticking their heads in the sand, wilfully creating security holes. Uncaring. Perhaps they don’t understand the threat landscape, or they’d be taking this a lot more seriously! Perhaps. Or. Maybe the security team needs to take more responsibility. Perhaps it’s a much bigger issue than technologies or threat landscapes, or wilful ignorance. There are a number of process pitfalls that can befall a security program. The list below may seem harsh, but these are real perspectives based on real experience. No Buy in Delivery teams can see […] ## Pages - [Cyber Essentials for Irish SMEs](https://rollcagedefence.com/get-cyber-essentials/): Certification and Solid Protection Cyber Essentials delivers meaningful security improvements, and the certification to prove it. At Rollcage Defence we put the right protections in place, without guesswork, box-ticking, or last-minute panic. Our Cyber Essentials Assured service delivers: ✅ A clear assessment of your current security posture ✅ A practical plan to close gaps and reduce real risk ✅ Resources and consultancy to help you prepare efficiently ✅ Predictable outcomes on assessment day Why Cyber Essentials? Cyber Essentials is a UK government-backed certification which verifies your business has a baseline set of protections against common cyberattacks. In practice, it is […] - [Smart Phishing Simulation](https://rollcagedefence.com/smart-phishing-simulation/): Smart Phishing Simulation Phishing and email attacks form the majority of attacks on small and medium businesses, and most businesses are exposed to these attacks. Because phishing is the dominant threat, it makes sense to strengthen our phishing defences as a priority. This is the definition of risk-led response to threats. Having a policy and using PowerPoint to train your users are good starting points, but hackers won’t read your documents. You need email security skills, and an active training system. Rollcage Defence has partnered with SoSafe to offer industry-leading phishing simulation and training solutions. SoSafe phishing simulations are flexible, […] - [EI Cyber Review](https://rollcagedefence.com/eicyberreview/): Strengthen your cyber security with an EI Cyber Review Enterprise Ireland offer their clients an 80% funded Cyber Security Review performed by independent cybersecurity providers such as Rollcage Defence. The EI Cyber review is fast, yet thorough. It provides the insights your business requires to prioritise and plan your cyber security investments. With EI grant support this review is outstanding value. It’s a full review of your cyber security for €800 ex-VAT, with a detailed report containing a prioritised and costed improvement plan. This is a smart investment in your business – even if you’re not yet an EI client. […] - [Resources](https://rollcagedefence.com/resources/) - [Home](https://rollcagedefence.com/): Cyber Security for SMEs Defend Recover Endure Rollcage Defence helps SMEs reduce risk, recover quickly, and move forward with confidence. We design cyber security in practical layers. Each layer adds protection, limits disruption, and supports recovery: Understand What Matters We start by understanding the assets and systems your business needs to survive — your Crown Jewels — through a focused cyber review. This helps us understand how your business operates, your risk appetite, and where disruption would hurt most. From there, we build a risk-based action plan that fits your organisation, focusing effort where it reduces real impact. Most improvements can be delivered […] - [Contact](https://rollcagedefence.com/contact/): Send us an email: info@rollcagedefence.com - [Articles](https://rollcagedefence.com/blog/) [comment]: # (Generated by Hostinger Tools Plugin)