Service Offerings
- Cyber security training
- Product reviews
- Blog or article writing
- SME & UHNWI cyber security
Chapter Author
Contact Graeme
Journalists, students or potential clients:
graeme@datasecurityexpert.co.uk
Something private to say?
PGP public key
graeme@datasecurityexpert.co.uk
Something private to say?
PGP public key
No AI Used Here

There’s Two-Factor Authentication... and Then There’s Two-Factor Authentication
- Details
- Category: Cyber Security (Personal)
RSA introduced its well-known SecurID token in 1987, although these devices were rarely seen outside specialist environments until the early 2000s. At the time, they were used primarily to secure corporate VPN connections. The idea was simple but highly effective: a dedicated hardware device generated a code that was completely separate from the computer being used. Unless the token was physically stolen, it offered a very strong layer of security. Unlike today's authentication methods, these early devices typically lacked PIN or biometric protection.
Fast forward to 2026, and organisations have a wide range of authentication options available. These include physical devices, SMS and email-based codes, authenticator apps, push notifications, security keys, and passkeys. As adoption has increased, costs have generally fallen, making stronger authentication available to organisations of all sizes.
However, increased usage does not automatically mean better security. To understand why, it helps to consider a security triangle based on three competing factors: cost, usability, and security.
A low-cost authentication solution is often easier for employees to use and can significantly improve security compared to passwords alone. However, lower-cost options are not necessarily the most resilient against modern attacks. Conversely, the most secure solutions can be more expensive and less convenient to deploy and manage.
Let's examine the most commonly used authentication methods in 2026.
Other countries have overt corruption (yes, we have corruption, albeit more polite) and what the United Kingdom has is extreme greed
- Details
- Category: Private Thoughts
Twenty years ago, my mother said to me that travel broadens the mind and 69 countries later I firmly believe this. Think for a second; has the UK government or media ever said anything positive about China, Belarus, China or Iran? I cannot think of anything, and I have spent time in Belarus so can tell you there are many positive points to the negatively viewed country. China, I have only transited through twice, so it is hard to judge the country however one thing I noticed is the pricing of food & drinks in the airport. Socialist pricing is what comes to mind and well the country is run by the CCP! 60p for a bottle of water in vending machines whereas in Western airports you could be looking at 6x the price.
In May, I spent two weeks in Republic of China (better known as Taiwan) and R.O.C is an advanced country by Asian standards. When I travel, I like to explore properly by car and speak to locals, as I did, to see the pros and cons of a sovereign state. Taiwan is not left leaning and is Western unlike People’s Republic of China (better known as China).
Let’s look at the prices and issues of the United Kingdom before looking at two other countries I have spent time in – Belarus and Taiwan:
Diving inside a semi or targeted email phishing campaign
- Details
- Category: Blog
Why is it different? Normally the email says your password is expiring or that there has been suspicious activity on your account and asks you to click a link. These two emails are talking about something I may actually be interested in offering. Mass-market messages address you as “Dear Sir/Madam.”
Let’s look at the differences and red flags:
- Inquiry in the subject line – In British English, "inquiry" refers to a legal investigation. However, in American English, it is the correct word. This can or cannot be deemed as a mistake in the English language depending on the location received.
- Hi Graeme in the subject line – This is not the appropriate place to greet me.
- I tried calling in the email body – I did not receive a call or voicemail, and my website does not list a phone number.
- Your teams in the email body – If they had read my website correctly, they would have seen that it is just me.
- Elizabeth Lee – This name does not appear in search engines or on LinkedIn as an employee.
- Kelsostrategy.us – This domain is different from kelso.com.
- Kelsostrategy.us – was registered on 21st March and used to re-direct to kelso.com.
- Kelso – is a bona fide business and is a private equity firm based in Mid-Manhattan and may not be the correct organization to approach me for training.
- 1000 Main Street – 1000 Main Street is the listed whois address, but there is no apartment block at the address listed on Google Maps.
- Teams/Calendar/Kelso/Elizabeth – This is not a URL and the actual URL is a Microsoft Azure Blob
- Michael - is mentioned in the body but is not cc’ed on the email.
Page 1 of 62
