Field Notes
The blog.
Long-form posts from the ThinSky security team — open-source stack economics, incident response patterns, and the practical realities of running it in production.
-
Your SMB Cyber Quote Is Probably 3× Too Big
Most SMB cybersecurity proposals recommend eight or nine products. A right-sized open-source stack needs four — sometimes three. Here is which ones, and why.
-
CAIQ vs SIG: Which Questionnaire Should You Maintain?
What the CAIQ is, how it overlaps with the SIG and SIG Lite, when buyers send each one, and whether you need to maintain both.
-
SIG Lite vs SIG Core: Which One Did the Buyer Actually Send?
What's different between SIG Lite and SIG Core, how to tell which one you've received, and how long each takes to answer honestly.
-
What Is a SIG Questionnaire? A Plain-English Guide for Vendors
What the SIG questionnaire actually is, who publishes it, what's inside it, and the realistic options when a buyer sends you one before they'll sign.
-
Security Questionnaires Are a Sales Problem, Not Compliance
Why vendor security questionnaires stall deals, why aspirational answers backfire at audit time, and how an answer library turns panic into routine.
-
Okta Pricing in 2026: Real Costs and a Flat-Rate Way Out
Okta's per-user pricing climbs past $100K/yr at 500 users. How managed Keycloak gives you SSO, MFA, and lifecycle at a flat rate. 2026 cost comparison.
-
Keycloak vs Okta: Identity Management Without Per-User Fees
Keycloak vs Okta: how open-source IAM ends per-user pricing. Honest feature comparison, cost math, and what a managed Keycloak migration involves.
-
OpenVAS vs Qualys: What Vulnerability Scanning Should Cost
An honest cost comparison of OpenVAS, Qualys and Tenable for small Canadian businesses — what managed OpenVAS covers, what it costs, and where it doesn't fit.
-
Velociraptor vs CrowdStrike Falcon: Incident Response Cost
Velociraptor vs CrowdStrike Falcon: an honest feature and cost comparison, plus when managed Velociraptor handles incident response for less.
-
2024 Cybersecurity Budget: Where SMB Money Goes
Where does your 2024 cybersecurity budget actually go? See the leaks — shelfware, overlap, vendor-driven buys — and how SMBs cover a full stack for less.
-
Velociraptor Digital Forensics: DFIR for Small Business
What DFIR actually is, how the open-source Velociraptor platform works, and what a managed deployment looks like for a Canadian small business.
-
The Canadian Cybersecurity Advantage
Why working with a Canadian security provider matters: PIPEDA, Quebec Law 25, the US CLOUD Act, and what data sovereignty means for your security stack.
-
Teleport vs CyberArk (2026): An Honest Comparison
Teleport vs CyberArk in 2026 — where each wins, renewal-cost framing and a 60-day CyberArk migration roadmap. Honest comparison from ThinSky.
-
Zero Trust vs VPN: What Zero Trust Actually Requires
What zero trust architecture actually means, why VPN-based castle-and-moat security fails, and how Teleport implements real zero trust access.
-
Open Source Security for Enterprises: Costs & Stack
Open source security for enterprises in 2026: tool-by-tool stack (Wazuh, Keycloak, OpenVAS), honest cost ranges vs commercial SIEM/EDR/IAM, and how to migrate.
-
SonarQube vs Veracode: DevSecOps at a Fraction of the Cost
Veracode's true multi-year cost vs managed SonarQube. What SonarQube covers (SAST), what it doesn't (DAST/SCA), and when the savings make sense.
-
Automated Penetration Testing: The Smart Way to Test
How automated penetration testing works, what it costs, how it complements an annual manual pentest, and how authorised testing stays safe and legal.
-
Hardcoded Secrets in Code: How to Find Them First
How API keys and credentials end up in git repositories, the real public incidents they caused, and how automated secrets scanning catches them pre-commit.
-
Paying 5x Too Much for SIEM? Cut the Bill
Paying 5x too much for SIEM? See why Splunk runs six figures while managed Wazuh delivers core SIEM for a fraction — and how to switch. Get the breakdown.
-
Phishing Training for Employees: Cost, ROI, What Works
Why annual security-awareness slideshows fail, how phishing simulations change behaviour, and what per-user training really buys. No hype.