Category: Cybersecurity
-

The OWASP Top 10 Hasn’t Kept Up
The OWASP Top 10, the canonical list of web application security risks, has been a foundational reference for 20 years. The 2021 edition added four new categories. The 2025 edition is overdue. The categories do not adequately cover the threats that have emerged in the last 5 years: prompt injection, agent autonomy, training data poisoning,…
-

The ‘AI in Security’ Vendor Pitch Is Not the Same as AI in Security
Every security vendor now says they use AI. The phrase, in the security context, is even more inflated than the broader ‘we use AI’ problem. The products that actually use AI in security, in ways that materially change detection, response, or prevention, are a small subset.
-

Your Threat Intelligence Feed Is Mostly Noise
Every enterprise in 2026 subscribes to one or more commercial threat intelligence feeds. The feeds promise context about who is attacking, what they want, and how they operate. The feeds deliver, in most cases, a firehose of indicators that nobody has time to action.
-

The Cyber Insurance Market Is Breaking
Cyber insurance used to be a hedge. Premiums are up 200 to 400% over the last 4 years. Coverage is down. Exclusions are everywhere. The insurers are pulling out of the market. The market is breaking, and the breaking is going to reshape how companies think about cyber risk.
-

The Password Is Dying. The Passkey Is Not Winning.
Every year for the last 10 years has been the year the password was going to die. The year has not arrived. The password is still the dominant authentication mechanism. The passkey, the technology that was supposed to replace it, is technically a complete success and is still stuck in adoption.
-

Your SaaS Sprawl Is Your Biggest Breach Surface
The average enterprise in 2026 uses somewhere between 100 and 300 SaaS applications. The enterprise has direct visibility into maybe 20% of them. The other 80% is shadow SaaS, signed up by individual employees or teams, integrated into the workflow, holding company data, often with admin access to the company’s primary systems.
-

The Zero Trust Marketing Has Eaten Zero Trust
Zero trust was a security architecture model. Zero trust is now a marketing term. The original model, articulated by John Kindervag at Forrester in 2010, was a specific approach to security. The marketing co-opted the model. The term now appears on products that have nothing to do with the model.
-

The CISO and the Acquisition Due Diligence in 2026
The acquisition due diligence the CISO has been involved in has become the diligence the CISO has been quietly dreading, the diligence that decides whether the enterprise buys the company the CISO is about to inherit the security debt of.
-

Why Your Vulnerability Scanner Is Missing the Vulnerabilities That Matter
The vulnerability scanner is good at finding known CVEs. It is not good at finding the vulnerabilities that lead to breaches, which are misconfigurations, exposed credentials, over privileged identities, exposed secrets, and custom code. The scanner is a compliance tool that produces a 200 page report nobody reads. The actual security work is somewhere else.
-

How to Actually Do Zero Trust Without the Cost in 2026
The Zero Trust the enterprise has been told to adopt has been sold as the platform the enterprise has to buy, the platform that costs more than the security budget can afford, the platform the CISO has been quietly writing off as the unreachable goal.