Category: Cybersecurity

  • Why Your VPN Is About to Get Weird

    Why Your VPN Is About to Get Weird

    The corporate VPN is the longest-running piece of security theater in tech. It is being replaced, slowly, by a stack of small ideas that happen to work better now than they did five years ago.

  • The CISO Handbook: The Second Edition

    The CISO Handbook: The Second Edition

    The first edition sold the idea that the CISO could be a peer to the CIO. The second edition quietly walks that back. The role has shifted, the board has shifted, the threat has shifted, and the playbook that worked in 2020 does not work in 2026.

  • Inside a Modern Ransomware Attack

    Inside a Modern Ransomware Attack

    Modern ransomware is not a virus. It is a business process. The attackers run it like a company, with departments, SLAs, and customer support for the victims.

  • DDoS Mitigation on a Budget

    DDoS Mitigation on a Budget

    The DDoS attack in 2026 amounts to the attack the typical enterprise faces 5-20 times per year, with the attack peaking at 1-10 Tbps, with the attack lasting 1-24 hours, with the attack costing the enterprise $20K-$200K per hour in lost revenue. The mitigation in 2026 amounts to the work the typical enterprise does on…

  • The Windows Event Log Primer

    The Windows Event Log Primer

    The Windows event log in 2026 amounts to the single most underused source of security data in the typical enterprise. The enterprise buys the SIEM, the enterprise points the SIEM at the network, the enterprise misses the threats that the Windows event log would have caught. The primer for what the events are, what they…

  • Third Party Risk Management in 2026: The Honest Guide

    Third Party Risk Management in 2026: The Honest Guide

    Third party risk management in 2026 amounts to a $15B annual market, with the typical enterprise running 500-2000 third party relationships, with the third party risk program trying to assess the security of each one. The honest guide covers what works, what does not work, and what to actually do.

  • A Field Guide to the Zero Trust Rollout

    A Field Guide to the Zero Trust Rollout

    Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…

  • The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.

  • Supply Chain Attacks: When the Software You Trust Is the Problem

    Supply Chain Attacks: When the Software You Trust Is the Problem

    Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.

  • Why the Supply Chain Attack Keeps Winning

    Why the Supply Chain Attack Keeps Winning

    The supply chain attack keeps winning because defenders optimise for the wrong layer. Here is what actually works, in 2026, against the upstream dependency, the build pipeline, and the signed vendor update.