<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Steelwise Filings</title>
        <link>https://steelwise.uk/filings/</link>
        <description>Practical thinking on security, infrastructure, and AI from Steelwise.</description>
        <language>en-gb</language>
        <lastBuildDate>Sat, 28 Feb 2026 15:09:45 GMT</lastBuildDate>
        <atom:link href="https://steelwise.uk/feed.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title>The ICO is becoming the Information Commission</title>
            <link>https://steelwise.uk/filings/the-ico-is-becoming-the-information-commission.html</link>
            <guid>https://steelwise.uk/filings/the-ico-is-becoming-the-information-commission.html</guid>
            <pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate>
            <description>The UK's data protection regulator is being restructured under the Data (Use and Access) Act 2025. New board, new CEO, new statutory objectives. The name is the least interesting part.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>What the Cyber Security and Resilience Bill actually means</title>
            <link>https://steelwise.uk/filings/what-the-cyber-security-and-resilience-bill-actually-means.html</link>
            <guid>https://steelwise.uk/filings/what-the-cyber-security-and-resilience-bill-actually-means.html</guid>
            <pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate>
            <description>The biggest overhaul of UK security regulation since 2018 is in committee. MSPs are in scope, incident reporting gets a 24-hour clock, and fines go up to £17 million. Here's what it means in practice.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>The free security awareness campaign you didn't know existed</title>
            <link>https://steelwise.uk/filings/free-security-awareness-campaign-you-didnt-know-existed.html</link>
            <guid>https://steelwise.uk/filings/free-security-awareness-campaign-you-didnt-know-existed.html</guid>
            <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
            <description>The NPSA gives away a complete, professionally designed security awareness campaign kit. Posters, booklets, checklists, and a full starter guide. Most organisations don't know it exists.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>Chrome's first zero-day of 2026: update now, don't wait</title>
            <link>https://steelwise.uk/filings/chrome-zero-day-cve-2026-2441-update-now.html</link>
            <guid>https://steelwise.uk/filings/chrome-zero-day-cve-2026-2441-update-now.html</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description>CVE-2026-2441 is actively being exploited in the wild. A use-after-free bug in CSS handling means a crafted webpage is all it takes. Push the update now.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>AI just claimed your spinning disks too</title>
            <link>https://steelwise.uk/filings/ai-just-claimed-your-spinning-disks-too.html</link>
            <guid>https://steelwise.uk/filings/ai-just-claimed-your-spinning-disks-too.html</guid>
            <pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate>
            <description>Western Digital's entire HDD capacity for 2026 is sold out. Cloud is 89% of their revenue. HDD prices are up 46% since September. The window for sensible storage pricing is closing.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>Prompt injection is not the new SQL injection</title>
            <link>https://steelwise.uk/filings/prompt-injection-is-not-the-new-sql-injection.html</link>
            <guid>https://steelwise.uk/filings/prompt-injection-is-not-the-new-sql-injection.html</guid>
            <pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate>
            <description>Schneier and co have reframed prompt injection as 'promptware' — a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>The first five minutes of incident response</title>
            <link>https://steelwise.uk/filings/the-first-five-minutes-of-incident-response.html</link>
            <guid>https://steelwise.uk/filings/the-first-five-minutes-of-incident-response.html</guid>
            <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
            <description>Containment over correctness, reversibility over impact, protecting state before touching services. What your first five minutes should actually look like.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>When your payment processor can't send a valid email</title>
            <link>https://steelwise.uk/filings/when-your-payment-processor-cant-send-email.html</link>
            <guid>https://steelwise.uk/filings/when-your-payment-processor-cant-send-email.html</guid>
            <pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate>
            <description>Viva.com sends verification emails missing the Message-ID header. Google Workspace and Zoho reject them. The fix is one line of code.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>Microsoft is a cloud company that also makes Windows</title>
            <link>https://steelwise.uk/filings/microsoft-is-a-cloud-company-that-also-makes-windows.html</link>
            <guid>https://steelwise.uk/filings/microsoft-is-a-cloud-company-that-also-makes-windows.html</guid>
            <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
            <description>Microsoft's FY2025 numbers tell a clear story. Azure and M365 are two-thirds of revenue. Windows is about 6%. This is a cloud and productivity company.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>Patch your text editors</title>
            <link>https://steelwise.uk/filings/patch-your-text-editors.html</link>
            <guid>https://steelwise.uk/filings/patch-your-text-editors.html</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description>Notepad++ had its update service hijacked by state-sponsored attackers. Windows Notepad got a CVSS 8.8 command injection. Two editors, two attack vectors, same lesson.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>Insecure defaults have a long half-life</title>
            <link>https://steelwise.uk/filings/insecure-defaults-have-a-long-half-life.html</link>
            <guid>https://steelwise.uk/filings/insecure-defaults-have-a-long-half-life.html</guid>
            <pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate>
            <description>Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass was disclosed. The protocol is old. The lesson is current.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
        <item>
            <title>What Cyber Essentials actually involves</title>
            <link>https://steelwise.uk/filings/what-cyber-essentials-actually-involves.html</link>
            <guid>https://steelwise.uk/filings/what-cyber-essentials-actually-involves.html</guid>
            <pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate>
            <description>A plain-English walkthrough of the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn't prove about your security.</description>
            <author>contact@steelwise.uk (Carl Heaton)</author>
        </item>
    </channel>
</rss>
