Support & Education Free. Ungated. No email wall. Written for the people we build for

Everything we know,
written down
and handed over.

We kept answering the same questions in the same meetings: about breaches, about what a client owes their users, about what to do when someone asks you to unlock your phone. So we started writing the answers down properly, with sources, and giving them away.

This is the shelf. Free. Ungated. No email wall. Nothing here requires an account or an email address: every page, every tool and the whole workbook open on the spot. Bookmark this page; it is the current index to the library.

See the shelf ↓
Take what is useful.
Copy it, print it, put your own logo on the workbook if it helps your team. That is what it is for.

The shelf.

↳ thirteen on the shelf
Guideabout 24 min

Security is how you build.

How organizations actually get compromised: the eight boring ways, what happened here in Puerto Rico, a breach check for your own address, and two self-assessments you can run with your team today.

You leave withA breach check for your own address, a hygiene self-assessment, an infrastructure posture summary, and a prioritized list of things to fix.
Read it →
Settings guideabout 26 min, one platform

The settings that matter.

Microsoft 365 versus Google Workspace, for whoever owns the admin console. The ten highest-value settings ranked by risk removed per minute, with exact console paths, and the tier walls that decide what you can even turn on.

You leave withA filterable ten-item checklist for your platform, three defaults nobody knows are off, a tier table to take into the renewal, and the deletion clocks that decide what is still recoverable.
Read it →
Dated briefabout 7 min

The AI threat record.

What actually happened once attackers got agents: vibe hacking, PROMPTFLUX and PROMPTSTEAL, the GTG-1002 espionage campaign, and the evaluation that got out onto Hugging Face production infrastructure. Revised as the record grows.

You leave withFour sourced incidents you can cite in a board paper, three numbers with their denominators attached, and a clear line between the record and our opinion about it.
Read it →
For parentsabout 18 min

The kids are already in the dataset.

What happened to family photographs when machine learning arrived, what teenagers are facing on their phones this year, and why a trained model has no delete key. Every figure carries its caveat, including the famous ones we think are overstated.

You leave withA breach check for every address in your house, six things worth doing on a Saturday, the sextortion conversation to have before it is needed, and the numbers to call if it already happened.
Read it →
Know your rightsabout 24 min

Protect your privacy.

What you can decline when someone asks you to unlock a device (at a traffic stop, at an airport, in Puerto Rico), with the settled law and the genuinely open questions marked separately.

You leave withThree sentences worth memorizing, and a clear sense of which confident advice circulating online is wrong.
Read it →
Protocolabout 11 min

Deepfake-proof your organization.

Convincing synthetic voice and video are increasingly accessible and inexpensive, which weakens the oldest verification method there is: recognizing someone. This is the protocol that supplements it.

You leave withA callback rule, a family code word, and a one-screen verification protocol you can send to your finance team this afternoon.
Read it →
Drilldesigned for 45 min

The first hour.

A tabletop drill you can run with your team over lunch. Four scenarios, one guided flow, and the decision points where most teams quietly go wrong.

You leave withA rehearsed run-through, a filled-in roles sheet, and the specific knowledge of who calls whom before it matters.
Read it →
Self-checkabout 10 min

Which PR website rules apply?

A starting checklist for several Puerto Rico statutes that may apply to a business website, and for the coverage questions that decide whether they reach you at all.

You leave withApparent gaps, open questions and possible triggers, each naming the statute behind it, in a form you can hand to a lawyer.
Read it →
Workbook · 14 pagesPrintable

Own your stack.

The whole practice on paper: infrastructure inventory, vendor and access audits, a password migration checklist, a patch calendar, a Microsoft and Google settings worksheet, an incident one-pager, a family exposure audit, a Puerto Rico compliance check, and a rights carry-card.

You leave withFourteen Letter-size pages your team can fill in with a pen, no login and no download form.
Open the workbook →
Guideabout 27 min

AI at work.

What your staff are already pasting in, what each tool does with it, what has gone wrong in court, and the short list of what Puerto Rico law actually requires.

You leave withA nine-element policy starter mapped to NIST anchors, a consumer-versus-commercial table for the major tools, and three statistics you should stop repeating.
Read it →
Guideabout 23 min

Who’s watching.

An honest tour of everyday surveillance: data brokers, the location trail, cameras, and whether your phone is really listening. The debunkings are the useful part.

You leave withA breach check that annotates each result with what a broker can join using it, four changes with measured evidence behind them, and a clear sense of which famous surveillance stories are folklore.
Read it →
Field notesabout 20 min

The next CMS is a conversation.

Why the admin panel on your own website was always a trade, what a governed conversation replaces it with, and the four rails that decide whether any of it is safe to hand a marketing team. With a sandbox you can try to break.

You leave withA plain-language account of MCP, four rails you can ask any vendor about, the line items that stop existing when the editing machinery leaves production, and a working demo of a refusal.
Read it →
Field guide · en español20 min · español

Estafas en Puerto Rico.

Written in Spanish, for you and for your parents. The schemes running on this island right now, documented by the banks themselves, and what to do in the hour after the money leaves.

You leave withA breach check for your own correo, a five-line list of things that will never happen, a WhatsApp setting worth two minutes, a family code word, and every number worth calling from Puerto Rico.
Léelo →

One email,
four times a year.

↳ the only mailing on the whole shelf

Everything here is free to read without giving us anything. The one exception you can opt into: when the AI threat record is re-cut, we will tell you. That is the entire list.

Quarterly brief

The next revision, by email.

We send the quarterly brief update and nothing else. Unsubscribe any time.

↳ you are on the list

That is the whole subscription: one email when the brief is re-cut, and nothing in between. The next revision goes out when the record changes shape rather than on a schedule we invented.

Wrong address, or changed your mind? Reply to any of it, or write to info@mutiny-labs.com.

How to use this.

↳ it is not a reading list

If you have ten minutesRun the self-check

Start with the Puerto Rico website check, or the breach lookup on the security page. Both produce a list of findings or questions to investigate about your own organization. Neither determines compliance or overall security, which is rather the point: they tell you where to look.

If you have an hour with your teamRun the drill

The first-hour tabletop is designed for exactly that: a room, a screen, and the people who would actually be called. It surfaces disagreements that are much cheaper to have on a Tuesday than during an incident.

If you own the riskPrint the workbook

Fourteen pages, one pen, no software. Work through it with whoever runs operations and you will leave with a structured inventory and a list of questions for your technical and legal advisers.

↳ why we give this away:

We are a small studio and we would rather work with organizations that already understand this material. Everything on this shelf is the conversation we would have with you anyway. Writing it down once means we spend the meeting on your actual problem instead.

If something here is wrong, out of date, or unclear, tell us. Several corrections on these pages came from readers.

↳ when reading stops being enough

Bring us the hard part.

If you worked through any of this and did not like what you found, that is a good reason to talk. A senior partner reads every message.