Tag: Breach
-

The Most Important Cybersecurity Story of 2025
Picking one story is unfair. Picking one story is also the only way to focus the lesson. Here is the 2025 story that mattered most, and the three it would have been if you asked me tomorrow.
-

How to Read a Vulnerability Disclosure
Every CVE announcement looks the same. The implications are not the same. Here is how to read a vulnerability disclosure like a defender, not like a marketer, in 2026.
-

What Cybersecurity Insurance Actually Buys You
Cybersecurity insurance in 2026 amounts to a $20B annual market, with the typical enterprise paying $50K-$500K per year for the coverage, with the coverage paying out roughly 40% of the time the enterprise has a claim, with the payout typically running at 30-50% of the claim. The insurance buys the enterprise some financial protection, the…
-

Your CI/CD Pipeline Is Your Weakest Link
The CI/CD pipeline is the place where the code, the credentials, the secrets, the production access, and the third party integrations all meet, and the place where the security is the thinnest. The CI/CD pipeline is the supply chain, and the supply chain is the attack surface.
-

What Happens When Your Vendor Gets Breached
What happens when your vendor gets breached, in 2026, is that you find out about it from the press, your CISO gets paged at 2 AM, the incident response plan turns out to not match the actual scenario, and the next 72 hours are spent trying to figure out what data the vendor had on…