Resources

Downloadable PDFs

Lares Continuous Defensive Improvement Through Adversarial Simulation and Collaboration corporate profile (image)

News & Events

Blog

HIPAA's Physical Security Wake-Up Call: What the 2025 Rule Gets Right and Still Misses 1200 630 Andrew Heller

HIPAA's Physical Security Wake-Up Call: What the 2025 Rule Gets Right and Still Misses

The 2025 HIPAA update introduces mandatory physical security requirements for healthcare organizations, including annual assessments and access control planning. This blog explores what the new rule changes, where it falls short, and how real-world attackers continue to exploit common physical security gaps inside hospitals and clinics.

read more
Employee Behavior Is the Breach (Part 1) 1200 630 Andrew Heller

Employee Behavior Is the Breach (Part 1)

In this first installment of a real-world Lares engagement, we show how weak passwords, reused credentials, and login portal behavior enabled valid access to QA, sales, finance, and even the company’s founder—without phishing or exploiting a single vulnerability. Using only public data and internal credential leaks, we chained small wins into full authentication. This blog reveals how predictable employee behavior can bypass security controls long before an exploit is ever needed.

read more
Your AI CCTV System is a Near-Sighted Toddler 1200 630 Andrew Heller

Your AI CCTV System is a Near-Sighted Toddler

Discover how Lares engineers bypass AI-enabled CCTV systems using real-world tactics. Learn why modern surveillance fails under pressure, how to test and tune detection models through purple teaming, and what steps your organization can take to improve physical security before a breach occurs.

read more
Stop Over-Scoping. Start Pressure Testing. 1200 630 Andrew Heller

Stop Over-Scoping. Start Pressure Testing.

Most pen tests are scoped too tightly to provide real value. Learn why Lares advocates for pressure-based testing, open scope, and the PTES framework to uncover real risk and build stronger security programs.

read more
Red, Blue, and Purple Teams – What They Actually Mean, and How Lares Helped Build the Model Everyone Uses Today 1200 630 Andrew Heller

Red, Blue, and Purple Teams – What They Actually Mean, and How Lares Helped Build the Model Everyone Uses Today

Everyone uses the Red/Blue/Purple model—but most organizations only apply part of it. This post breaks down the real roles behind each function, how Lares helped build the model into what it is today, and how to apply it even if you don’t have formal teams. Whether you’re running full adversarial simulations or just starting structured testing, this is what effective security collaboration actually looks like.

read more
Vulnerability Scanning Isn't Security Testing 1200 630 Andrew Heller

Vulnerability Scanning Isn't Security Testing

Solely on vulnerability scanning creates a false sense of security. Learn the limits of automated tools versus comprehensive, adversary-focused security testing for true cyber resilience.

read more
Think Your Group Chat is Safe? 1280 720 Andrew Heller

Think Your Group Chat is Safe?

Why business chat platforms are an excellent vector for social engineering. Author: Andrew Heller – Lares Marketing Manager My Slack channels at work feel safe. They’re internal. They’re informal. They are where I get 90% of my collaboration done…way faster than anything I could do over email/outlook. And attackers know it. From Backchannel to Breach…

read more
Protecting Your Business – Ransomware Prevention and Recovery Best Practices 2000 1379 Andrew Heller

Protecting Your Business – Ransomware Prevention and Recovery Best Practices

Ransomware attacks have emerged as one of the most significant cybersecurity threats to organisations worldwide, creating substantial challenges for data security and business continuity. Ransomware attacks have emerged as one of the most significant cybersecurity threats to organisations worldwide, particularly financial institutions, creating substantial challenges for data security and business continuity. These attacks have become…

read more
Adapt or Get Compromised: What a Real Vishing Engagement Revealed 1600 1067 Andrew Heller

Adapt or Get Compromised: What a Real Vishing Engagement Revealed

Vishing isn’t theoretical. It’s happening every day, and most companies don’t even know they’ve been compromised. This post breaks down one of our real-world voice phishing simulations and what it revealed about an otherwise mature security program. The Objective: Breach by Phone A global retailer hired us to test their frontline defenses, specifically their customer…

read more
Weaponizing the Human Element: Inside a Vishing Operator’s Playbook 1600 1067 Andrew Heller

Weaponizing the Human Element: Inside a Vishing Operator’s Playbook

This blog focuses on how vishing works and how we weaponize human behavior to get in. The Psychology Behind Vishing Effective vishing exploits emotion and urgency. Every call is calibrated to: Create pressure (“We need this now.”) Leverage authority (“Your manager asked us to do this.”) Instill doubt (“We’re seeing some odd behavior on your…

read more

Webcasts

Videos

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.