Category: Cybersecurity
-

How to Spot a Vendor That Is About to Get Acquired
The vendor the enterprise relies on just got acquired. The product roadmap is now the acquirer’s product roadmap, the support contract is now the acquirer’s support contract, the data the enterprise shared with the vendor is now the acquirer’s data. The acquisition has happened before the enterprise knew it was happening.
-

The Postman Problem and Why Your API Will Get Breached
Every API gets breached the same way. The attacker does not break the API. The API breaks itself, and the developer who built it learns about it from the breach disclosure.
-

Your Attack Surface Is Bigger Than You Think
The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that the attacker does not even bother with because the attacker has found something the security…
-

What an Honest Vendor Demo Looks Like
The vendor demo has become the polished thirty minutes the vendor uses to sell the procurement team on the tool the vendor has spent six months building. The demo that shows the tool working in the conditions the demo was designed to handle, the conditions the enterprise environment does not match.
-

Why Your Incident Response Runbook Is Wrong
The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.
-

Security Tooling in 2026 Is Bigger Than Ever, and About the Same
A field guide to the security tooling market in 2026, with the consolidation, the categories that are over funded, the categories that are under funded, and the part about the dashboard that is going to get ignored.
-

What an Honest Security Audit Looks Like
An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.
-

The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)
Phishing has not improved because filters got worse. It has improved because attackers can produce clean, context-aware messages, imitate legitimate login flows, proxy sessions, and exploit normal human urgency.
-

Hiring a Security Expert Is Not Going to Save You
The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program is the organisation whose security posture is the same. Here is why the single hire does not work, and what does.
-

Why Your MFA Push Notifications Are a Security Hole
The MFA push notification in 2026 sits as the security control the typical enterprise has deployed to replace the password, with the push notification promising the security the password cannot provide. The 2026 reality amounts to the reality where the push notification has become the attack vector the attacker uses, with the MFA fatigue attack,…