Category: Cloud Security

  • Your SaaS Sprawl Is Your Biggest Breach Surface

    Your SaaS Sprawl Is Your Biggest Breach Surface

    The average enterprise in 2026 uses somewhere between 100 and 300 SaaS applications. The enterprise has direct visibility into maybe 20% of them. The other 80% is shadow SaaS, signed up by individual employees or teams, integrated into the workflow, holding company data, often with admin access to the company’s primary systems.

  • The Platform Team and the Incident Response in 2026

    The Platform Team and the Incident Response in 2026

    The platform team has become the team the incident response depends on, the team the CISO has been quietly relying on, the team the breach response will land on before the security team has even opened the runbook.

  • The Platform Team as a Product in 2026

    The Platform Team as a Product in 2026

    The platform team that the enterprise has been building has been quietly developing into a product, the product the developer consumes, the product the developer has been treating as the internal vendor.

  • The SEC Cyber Rules Are Forcing Boards to Finally Read the Risk Page

    The SEC Cyber Rules Are Forcing Boards to Finally Read the Risk Page

    Two years in, the most important cybersecurity regulation of the decade is not from the cybersecurity agencies. It is from the Securities and Exchange Commission.

  • A Field Guide to the Cloud Detection Rule in 2026

    A Field Guide to the Cloud Detection Rule in 2026

    The cloud detection rule has become the rule the SOC analyst has been writing, the rule the cloud architect has been reviewing, the rule the breach disclosure will reference when the rule fired but the SOC missed the alert.

  • The Cloud Security Shared Responsibility Model Is a Lie

    The Cloud Security Shared Responsibility Model Is a Lie

    Every cloud provider has a shared responsibility model diagram. The diagrams are clear. The diagrams are also misleading. In practice, the boundary between provider responsibility and customer responsibility is full of grey areas, and the grey areas are where the breaches live.

  • The Real Cost of a Cloud Misconfiguration in 2026

    The Real Cost of a Cloud Misconfiguration in 2026

    The cloud misconfiguration has become the breach cause the cloud architect has been ignoring, the cause the attacker has been scanning for, the cause the postmortem will describe after the fact.

  • A Field Guide to the Cloud Native Application Protection Platform in 2026

    A Field Guide to the Cloud Native Application Protection Platform in 2026

    CNAPP was supposed to be the answer to multi-cloud security sprawl. The pitch from 2021 was one platform, one agent, one data lake, one console. Five years later the category has split into four overlapping sub-markets, the platforms are stitching them back together, and the buyers are asking why they are paying for a single…

  • You Downloaded the Model. That Does Not Mean Your AI Is Private.

    You Downloaded the Model. That Does Not Mean Your AI Is Private.

    Running an open source model does not automatically create a private system. Data can still leave through analytics, model routers, remote embeddings, browser tools, third party MCP servers, cloud databases, crash reports and application logs.

  • Cloud Detection and Response: The Buyers Guide

    Cloud Detection and Response: The Buyers Guide

    The cloud detection and response buyers guide has become the guide the procurement team has been quietly trying to write, the guide the security team has been quietly trying to follow, the guide the vendor demo has been quietly trying to confuse.