Research, engineering and threat intelligence from GNSAC.
Technical articles, threat analyses and field notes from the teams that develop and operate GNSAC security products.
Building an Enterprise Cyber Threat Intelligence Programme from Scratch
A practical guide for CISOs and security leaders establishing a structured threat-intelligence capability with defined requirements, workflows and measures.
The True Cost of Data Breaches in 2026: Beyond the Headlines
A structured view of the direct, operational and long-term impacts that organisations should consider when assessing cyber risk.
Digital Risk Protection for Global Enterprises: A CISO's Guide
How multinational organisations can structure digital-risk monitoring across regions, brands and business units.
Phishing Simulation Metrics That Actually Matter
A practical guide to phishing-simulation metrics that help security teams assess behaviour, reporting and improvement over time.
Engineering notes from the product team.
Long-form articles on product architecture, data engineering and applied cybersecurity, published under the @gnsac byline.
What I Learned Scaling a Credential Exposure Engine to 3.8 Billion Records
Storage layout, indexing and query design behind Vigil’s credential intelligence — and the mistakes made on the way to billions of rows.
Read on HackerNoonBuilding a Multi-Channel Phishing Simulation Platform in Go for Regulated Industries
Deployment architecture, multi-channel concurrency and per-recipient analytics of GNSAC Phishing — written for teams that must run it on-prem.
Read on HackerNoonAI in Cybersecurity Is Not What Vendors Are Selling You
Where machine learning genuinely helps in security (scale problems) and where it fails (judgement problems) — a practitioner’s view.
Read on HackerNoonexposure-check Earns a 70 Proof of Usefulness Score by Building an Open-Source Exposure Scanner
The story behind exposure-check: an open-source scanner that shows what attackers can see about your GitHub orgs, repos and domains.
Read on HackerNoonOpen-source tools for independent evaluation.
Review and run selected tools published by the GNSAC team, subject to their documented scope and licences.
All repositoriesFind what attackers can see before they do — open-source exposure scanner for GitHub orgs, repos and domains. The same idea Vigil’s CTI Scan runs at platform scale.
Discuss your external-risk assessment requirements.
Review Vigil’s methodology, representative outputs and authorised evaluation process with a GNSAC security specialist.
