This is the first piece on the MALTO Cyber site. It is short on purpose.
Most cybersecurity writing on the open web fits into one of three buckets: vendor blogs that exist to harvest your email, listicles assembled by content marketers who have never been on call, or whitepapers translated into press releases. None of those help you make a decision.
What we want this space to be is the third bucket — practitioner notes. The voice we actually use when a CTO asks "do we really need to do this?" or "what does your peer in financial services do for SOC 2?" Plain-language, opinionated, willing to say "it depends" only when it actually does.
What you can expect
A typical post here will:
- Take one decision a security or compliance team is staring down — picking a framework, scoping a pen test, drafting a control narrative — and walk through the tradeoffs we'd weigh.
- Reference real engagement patterns we've seen across Canadian financial services, aviation, and growing SaaS — anonymized, but specific enough to be useful.
- Avoid the phrase "leverage synergistic capabilities" and its 47 cousins.
- Be the length the topic deserves. Sometimes 600 words. Occasionally 3,000. Never 8,000 of padding.
What we won't do
- Republish vendor news as analysis.
- Write the same SOC 2 explainer that has 12,000 nearly identical versions already.
- Pretend a piece of compliance theatre is "best practice" because everyone is doing it.
The cadence
One monthly newsletter. Field notes shipped as they're written. If a post is useful, it stays useful — we'd rather publish twelve durable pieces a year than ship a daily marketing post that decays in a week.
If that sounds like what you want in your inbox, the subscribe box is on the resources page. Otherwise, this space is here whenever you need it.
— Marcus