Category: Field Guides
-

A Field Guide to the Endpoint Detection and Response in 2026
The EDR the enterprise has been deploying has finally matured into the tool the security team has been waiting for, the tool that catches the breach the SIEM missed, the tool that the postmortem will describe as the detection that saved the response.
-

A Field Guide to the Runtime Application Self Protection in 2026
The RASP the security team has been postponing has finally become the layer the breach disclosure will name as the layer the enterprise should have had, the layer that the modern web application framework already supports.
-

A Field Guide to the Managed Detection and Response in 2026
The managed detection and response the enterprise has been quietly buying has finally become the service the small security team can actually use, the service the alert fatigue has been quietly demanding, the service the postmortem will name as the difference.
-

A Field Guide to the Public Key Infrastructure
The public key infrastructure the enterprise has been quietly depending on sits as the infrastructure the audit will quietly test, the infrastructure the post quantum deadline is quietly trying to replace, and the infrastructure the security team has been quietly assuming works.
-

A Field Guide to the Network Tap in 2026
The network tap the security team has been deploying has finally become the tool the modern network detection has been depending on, the tool the cloud native alternative has been trying to replace, the tool the postmortem will describe as the visibility that saved the response.
-

How to Actually Do a SOC 2 Without the Pain in 2026
The SOC 2 the enterprise has been quietly trying to ship has become the certification the auditor has been quietly trying to make easier, the certification the automation has been quietly trying to flatten, the certification the customer has been quietly demanding.
-

The post-quantum migration: who has actually moved in 2026, and what broke
Two years after NIST finalised the first post-quantum standards, the migration that everyone agreed was urgent has, in most places, not happened. Here is what shipped, what is stuck, and what a defensible end of year position looks like.
-

A Field Guide to the Cloud Native Application Protection Platform in 2026
CNAPP was supposed to be the answer to multi-cloud security sprawl. The pitch from 2021 was one platform, one agent, one data lake, one console. Five years later the category has split into four overlapping sub-markets, the platforms are stitching them back together, and the buyers are asking why they are paying for a single…
-

A Field Guide to the Supply Chain Incident Response
The supply chain incident response has become the response the security team has been quietly dreading, the response the IR plan does not actually cover, the response the next breach will demand.
-

The Vendor Incident Playbook
The vendor incident playbook has become the playbook the security team has been quietly trying to write, the playbook the breach response the vendor will produce has been quietly mocking, the playbook the next third party breach will demand.