David Kowalski

Articles by David Kowalski

German office building representing NIS2-regulated entities facing the BSI enforcement phase
Compliance & RegulationsFor MSPs & Partners

Germany NIS2: Grace Deadline Expired, Enforcement Begins

The BSI's final grace deadline for NIS2 registration expired on 31 July 2026 with thousands of in-scope German entities still unregistered. Germany's NIS2 regime now enters its enforcement phase, and registration failures alone can draw fines of up to EUR 500,000.

David Kowalski·8/16/2026·5 min read
A manager configuring access permissions for team members on a laptop
Compliance & RegulationsProduct Updates

Custom Roles and Granular Permissions in empowsec Explained

empowsec lets company admins build custom roles with granular permissions, renders a dashboard with only the tabs each user may see, and gives reseller teams an equivalent permission system - so nobody needs full admin access just to do one job.

David Kowalski·8/15/2026·7 min read
Close-up of a browser address bar on a laptop screen in an office
Phishing & Social EngineeringThreat Intelligence

Menlo Report: 1 in 5 Phishing Links Evade URL Filters

Menlo Security's 2026 Browser Threat Report finds one in five clicked phishing links goes completely undetected by URL filtering, and a third of evasive threats come from 'trusted' domains. The data-driven case for trained humans as the last line of defense.

David Kowalski·8/7/2026·5 min read
Setting up two-factor authentication
Security Awareness TipsProduct Updates

Stronger Logins with TOTP Two-Factor Authentication

empowsec supports time-based one-time password (TOTP) two-factor authentication so that even a stolen password cannot open an account. Here is how it works and why it matters for every security-conscious organization.

David Kowalski·7/17/2026·6 min read
Configuring single sign-on for empowsec
Compliance & RegulationsProduct Updates

Single Sign-On for empowsec: SAML, OIDC, and OAuth Explained

empowsec supports single sign-on via SAML 2.0, OIDC, and OAuth, with per-domain configuration, attribute mapping, auto-provisioning on first login, and cross-domain authentication for white-label deployments - centralizing access and reducing password risk.

David Kowalski·7/15/2026·9 min read
Importing employees from a CSV file
Security Awareness TipsProduct Updates

User Management, CSV Import, and Employee Onboarding

empowsec makes it easy to add employees one at a time or in bulk via CSV, organize them into departments and groups, assign granular roles, and ensure every new user receives a smooth onboarding experience with welcome emails and registration reminders.

David Kowalski·7/9/2026·8 min read
Security awareness reporting dashboards
Compliance & RegulationsProduct Updates

empowsec Reporting Dashboards: Metrics That Drive Action

empowsec reporting dashboards consolidate training completion, phishing simulation results, and risk scores into a single view - filterable by user, department, or company - with the same data available via API for your existing BI tools.

David Kowalski·7/1/2026·7 min read
Employee searching for a software download on a laptop in an office
Phishing & Social EngineeringThreat Intelligence

Malvertising & SEO Poisoning: The Fake Download Trap

Attackers are buying ads and gaming search results so the top hit for popular software is a trojanized download. Here's how malvertising and SEO poisoning infect employees - and how to train against it.

David Kowalski·6/28/2026·7 min read
Close inspection of a web address on a laptop screen with a magnifying glass
Phishing & Social EngineeringThreat Intelligence

Lookalike Domains & Typosquatting: A Defense Guide

An 'rn' that reads as an 'm', an extra word, a wrong TLD — lookalike domains impersonate trusted brands in phishing and brand abuse. Here is how to spot them and the controls that blunt them.

David Kowalski·6/22/2026·7 min read
« Previous12Next »