Category: Tools & Reviews

  • The Honest State of the VPN in 2026

    The Honest State of the VPN in 2026

    The VPN in 2026 has become the security control the enterprise has been questioning, the control the Zero Trust pitch has been promising to replace, the control the recent breach has been quietly exposing as the control that the breach came through.

  • The Tools We Actually Use to Read a Site’s Security Posture

    The Tools We Actually Use to Read a Site’s Security Posture

    An afternoon and five free open source tools is enough to read the public security posture of almost any website. Here is the kit we use, in the order we use it, and what it does and does not show.

  • The State of the Browser in Q3 2026

    The State of the Browser in Q3 2026

    The browser serves as the most attacked surface in the enterprise. It has been the most attacked surface for two years, and the margin keeps growing. The risk has migrated from phishing links to extensions, to session tokens, to data residency in the cloud profiles the browser keeps for the user.

  • EDR vs XDR in 2026

    EDR vs XDR in 2026

    EDR vs XDR runs as the question that is no longer the right question. The vendors have converged. The market has converged. The distinction is now a marketing slide. The buyer who still asks the question ends up buying the wrong product for the wrong reason.

  • When to Self Host: The Honest Guide

    When to Self Host: The Honest Guide

    The self host vs cloud decision in 2026 amounts to the decision the typical enterprise makes 5-10 times per year, with the decision affecting the cost, the control, the compliance, the reliability. The honest guide covers when the self host wins, when the cloud wins, and what the decision framework looks like for the typical…

  • What Replaces the VPN in 2026

    What Replaces the VPN in 2026

    A field guide to what replaces the VPN in 2026, with the four approaches the enterprise is taking, the tradeoffs the enterprise is making, and the part about the right answer for the specific workload.

  • The Burp Suite Replacement Question

    The Burp Suite Replacement Question

    The Burp Suite replacement question in 2026 amounts to the question the typical application security team asks every 2-3 years, with the question prompted by the Burp Suite licence renewal, the new tool on the market, the security team turnover. The honest answer covers what the Burp Suite does, what the replacements do, and what…

  • Tools the Engineering Team Should Pay For

    Tools the Engineering Team Should Pay For

    The engineering team has a budget. The free tools cover most of the work. A handful of paid tools are worth the spend. Here is what is worth it in 2026.

  • The Tools Worth Paying For in 2026

    The Tools Worth Paying For in 2026

    The free and the cheap tools are fine for most teams. But there are a handful of products in 2026 that genuinely earn their price tag. Here is what is worth the spend, and what is not.

  • The Quiet Return of the Local Database

    The Quiet Return of the Local Database

    There is a quiet return of the local database, and the people who are running it are not the people the cloud native crowd would expect. The local database is not a return to 2005, the local database is a return to common sense.