Tag: Breach

  • Attack Path Mapping: The Honest Guide

    Attack Path Mapping: The Honest Guide

    Attack path mapping runs as the discipline of drawing the route an attacker would actually take through the environment, then fixing the parts of the route that are stupid. The discipline has been overcomplicated by the vendors and underused by the practitioners. The honest version is the one that produces the fixes.

  • The CISO Resignation Letter

    The CISO Resignation Letter

    The CISO resignation letter has become a genre. The reasons are depressingly consistent: not enough authority, not enough budget, not enough board attention, then a breach, then a quiet exit. The pattern repeats because the role has not been fixed. The resignation serves as the symptom, not the cause.

  • Third Party Risk Management in 2026: The Honest Guide

    Third Party Risk Management in 2026: The Honest Guide

    Third party risk management in 2026 amounts to a $15B annual market, with the typical enterprise running 500-2000 third party relationships, with the third party risk program trying to assess the security of each one. The honest guide covers what works, what does not work, and what to actually do.

  • Every Major Data Breach of 2026 Explained in Plain English

    Every Major Data Breach of 2026 Explained in Plain English

    A living tracker of the major 2026 data breaches. Per-incident evidence, attack types, attribution and defensive lessons. Updated as disclosures land.

  • Non-Human Identity Attestation in 2026

    Non-Human Identity Attestation in 2026

    Non-human identity attestation is the work of knowing what every service account, every API key, every bot identity, and every machine credential can do, who owns it, when it was last used, and whether it is still needed. Most enterprises in 2026 have not done this work. The attackers know. The auditors are catching up.

  • The Privacy Impact Assessment You Are Skipping

    The Privacy Impact Assessment You Are Skipping

    The privacy impact assessment sits as the document that has become the regulatory requirement the enterprise knows about and skips. The PIA the team writes for the regulator gets the PIA the regulator accepts, and the PIA the regulator accepts does not reflect the actual data flow.

  • State of the Vulnerability: Q2 2026

    State of the Vulnerability: Q2 2026

    Q2 2026 closed with 18,400 new CVEs assigned. The number is up 22 percent year over year. The number that matters is different, and the gap between the two is the story.

  • The CVE Tsunami: When the Database Becomes the Breach

    The CVE Tsunami: When the Database Becomes the Breach

    The CVE database in 2026 hit 240,000+ entries, with 28,000+ new CVEs in 2025, with the typical enterprise unable to patch the CVEs at the rate the CVEs come in. The CVE tsunami amounts to the situation where the patching program runs behind the patching demand, the database becomes the breach vector the typical enterprise…

  • The Firmware Attack Surface You Have Never Looked At

    The Firmware Attack Surface You Have Never Looked At

    Every modern endpoint runs firmware that the operating system cannot see. The OS patch cadence is monthly. The firmware patch cadence is whenever the vendor bothers. Here is what is actually in your fleet, and what to do about it.

  • Wipers, Not Ransomware, Are the New Normal

    Wipers, Not Ransomware, Are the New Normal

    Picture the standard ransomware playbook. Attacker breaches the network, encrypts the data, posts the ransom note. Victim pays, gets the decryption key, restores, files the insurance claim, moves on. That last part is the part that is breaking. A growing share of attackers are taking the ransom and refusing to hand over the key. The…