Tag: Breach

  • Ransomware Double Extortion Has Stopped Working

    Ransomware Double Extortion Has Stopped Working

    Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. By 2026 the pattern has stopped working, for three reasons that have less to do with the attacker and more…

  • A Field Guide to Patching at Scale

    A Field Guide to Patching at Scale

    Patching at scale is the unglamorous work of security. The defender who has the patching process right has solved 80 percent of the vulnerability problem. The defender who has it wrong has not. Here is what the process looks like in 2026.

  • A Field Guide to Securing the IT Help Desk

    A Field Guide to Securing the IT Help Desk

    The IT help desk has become the primary attack surface for the social engineering threat. The attacker calls, pretends to be an employee, and walks the operator through a password reset. Here is how to stop it.

  • A Field Guide to Secure Defaults in 2026

    A Field Guide to Secure Defaults in 2026

    Most breaches in 2026 exploit a default that was wrong at install. The defender who fixes the defaults fixes the breach. Here is the field guide.

  • Looking Back at February in Tech

    Looking Back at February in Tech

    A look back at February 2026 in tech, with the seven stories that actually mattered, the ones that looked like they mattered but did not, and the throughline that connects them.

  • Why Compliance Frameworks Don’t Catch the Breaches

    Why Compliance Frameworks Don’t Catch the Breaches

    The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.

  • The Postman Problem and Why Your API Will Get Breached

    The Postman Problem and Why Your API Will Get Breached

    Every API gets breached the same way. The attacker does not break the API. The API breaks itself, and the developer who built it learns about it from the breach disclosure.

  • Your Attack Surface Is Bigger Than You Think

    Your Attack Surface Is Bigger Than You Think

    The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that the attacker does not even bother with because the attacker has found something the security…

  • Why Your Security Questionnaire Is a Waste of Time

    Why Your Security Questionnaire Is a Waste of Time

    The security questionnaire has become the procurement ritual the security team has been asked to fill out for every vendor, the questionnaire that takes six hours per vendor, the questionnaire that asks the same fifty questions the questionnaire has been asking for ten years.

  • The Worst Breaches of January 2026

    The Worst Breaches of January 2026

    A look at the worst data breaches of January 2026, with the patterns the incidents share, the lessons the post mortems share, and the part that the marketing has been quietly ignoring.