Blog

From Compliance to Combat: Why Financial Services Still Bleed

From Compliance to Combat: Why Financial Services Still Bleed 1200 630 Andrew Heller
Audit-ready is not attack-ready. Lares shows financial institutions how adversaries bypass compliance to target payments, PII, and mainframes. read more

AI Didn't Breach You. Your Configuration Did.

AI Didn't Breach You. Your Configuration Did. 1200 630 Andrew Heller
Despite headlines about autonomous LLM-driven cyberattacks, recent incidents like the ServiceNow Count(er) Strike vulnerability and so-called “LLM hijacking” campaigns all came down to old techniques: enumeration, poor ACLs, and exposed credentials. read more

The MFA That Wasn’t (Part 2)

The MFA That Wasn’t (Part 2) 1200 630 Andrew Heller
We didn’t escalate privileges. We didn’t break anything. We authenticated, then watched the CRM leak full names, departments, employee IDs, and account IDs into the browser. Everything trusted the login. And that trust is what got them compromised. read more

What Your Pentest Isn't Telling You

What Your Pentest Isn't Telling You 1200 630 Andrew Heller
Passing a penetration test doesn’t mean you’re secure. Most pentests follow strict rules and timelines that attackers ignore. Red Teaming simulates real-world adversaries to reveal how threats move, persist, and evade detection. Purple Teaming turns these insights into immediate defensive improvements. Shift from compliance to true readiness with realistic attack simulation, live defender collaboration, and measurable results. read more

HIPAA's Physical Security Wake-Up Call: What the 2025 Rule Gets Right and Still Misses

HIPAA's Physical Security Wake-Up Call: What the 2025 Rule Gets Right and Still Misses 1200 630 Andrew Heller
The 2025 HIPAA update introduces mandatory physical security requirements for healthcare organizations, including annual assessments and access control planning. This blog explores what the new rule changes, where it falls short, and how real-world attackers continue to exploit common physical security gaps inside hospitals and clinics. read more

Employee Behavior Is the Breach (Part 1)

Employee Behavior Is the Breach (Part 1) 1200 630 Andrew Heller
In this first installment of a real-world Lares engagement, we show how weak passwords, reused credentials, and login portal behavior enabled valid access to QA, sales, finance, and even the company’s founder—without phishing or exploiting a single vulnerability. Using only public data and internal credential leaks, we chained small wins into full authentication. This blog reveals how predictable employee behavior can bypass security controls long before an exploit is ever needed. read more

Your AI CCTV System is a Near-Sighted Toddler

Your AI CCTV System is a Near-Sighted Toddler 1200 630 Andrew Heller
Discover how Lares engineers bypass AI-enabled CCTV systems using real-world tactics. Learn why modern surveillance fails under pressure, how to test and tune detection models through purple teaming, and what steps your organization can take to improve physical security before a breach occurs. read more

Stop Over-Scoping. Start Pressure Testing.

Stop Over-Scoping. Start Pressure Testing. 1200 630 Andrew Heller
Most pen tests are scoped too tightly to provide real value. Learn why Lares advocates for pressure-based testing, open scope, and the PTES framework to uncover real risk and build stronger security programs. read more

Vulnerability Scanning Isn't Security Testing

Vulnerability Scanning Isn't Security Testing 1200 630 Andrew Heller
Solely on vulnerability scanning creates a false sense of security. Learn the limits of automated tools versus comprehensive, adversary-focused security testing for true cyber resilience. read more

Think Your Group Chat is Safe?

Think Your Group Chat is Safe? 1280 720 Andrew Heller

Why business chat platforms are an excellent vector for social engineering.Author: Andrew Heller – Lares Marketing ManagerMy Slack channels at work feel safe.They’re internal.They’re informal.They are where I get 90%…

read more

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.