Know what attackers know, before they use it on you.
Cyber Short is a free weekly roundup of the 3–4 best security articles I come across while staying current as a working penetration tester — no fluff, just what's actually worth reading.
✓ You're on the list — first issue lands next Tuesday.
Every Tuesday. Read by security and IT folks who'd rather not miss the important stuff. Unsubscribe anytime.
The signal, not the noise.
No aggregated feeds, no vendor rewrites. Every issue is the 3–4 articles I actually stopped and read this week while staying current as a working penetration tester — picked, not scraped.
Picked by someone in the field
Every link is something I read myself this week while doing the job — not pulled from an RSS dump.
Respect for your inbox
Just the 3–4 articles worth your time. No 4,000-word roundups between you and the links.
Why it matters, not just what it is
Each link comes with a line on why it's worth reading and what to actually do with it — not just a headline dump.
Recent dispatches
Need more than a newsletter?
HutchSec also runs hands-on offensive security engagements — from a single web app to a full red team objective.
Every issue of Cyber Short.
47 issues and counting, filed by topic. Pick a thread and start reading — or subscribe to get the next one in your inbox.
Don't wait for the archive to catch up
New issue every Tuesday morning.
✓ Subscribed — welcome aboard.
Hi, I'm Nick.
I'm a penetration tester and the founder of HutchSec. I spend most weeks breaking into networks, web apps, and cloud environments on purpose — with permission — so the people who own them can fix what I find before someone without permission does.
I started Cyber Short because most security news is either recycled vendor marketing or written for people who already have a SOC on retainer. This is the newsletter I wanted when I was the only IT person at a 40-person company trying to figure out what actually mattered.
A rough timeline
Started in sysadmin & network engineering
Ran infrastructure for a regional MSP — the fastest way to learn what breaks in production.
Moved into offensive security
Junior pentester, then lead, at a boutique consultancy focused on mid-market clients.
Started leading red team engagements
Objective-based assessments spanning phishing, AD, and cloud attack paths.
Founded HutchSec
Independent pentest practice — and started writing Cyber Short as a weekly habit.
180+ engagements, 6,200+ subscribers
Still doing the work myself — no bait-and-switch to a junior team after the sales call.
Offensive security engagements.
Scoped, hands-on testing — delivered by the same person who tests it, writes it up, and walks your team through the findings.
Let's scope the work.
Tell me a bit about what you need tested and I'll reply with next steps — usually within one business day.
Read the newsletter first
to get a feel for how I write engagements up.
Typical response time
Within 1 business day, Mon–Fri.
NDA-first
Happy to sign your NDA before any scoping details are shared.