Tag: Compliance

  • The Kubernetes Security Checklist

    The Kubernetes Security Checklist

    A field guide to Kubernetes security in 2026, with the checklist that actually matters, the order to apply the items, and the items that are pure theatre.

  • A Field Guide to the SOC 2 Audit

    A Field Guide to the SOC 2 Audit

    A field guide to the SOC 2 audit in 2026, with what the audit is actually for, why most implementations fail, and the right way to make the model work in a modern security organisation.

  • Critical Infrastructure Attacks in 2026: The Patterns

    Critical Infrastructure Attacks in 2026: The Patterns

    The critical infrastructure attack has stopped being the hypothetical scenario the national security advisor uses to justify the budget. It has become the operational reality the utility operator, the water utility, the hospital network has started to live with.

  • Developer Experience Versus Security: The Tension Is Real

    Developer Experience Versus Security: The Tension Is Real

    Developer experience and security live in tension in 2026. The developers want the tools that work, the tools that are fast, the tools that do not get in the way. The security team wants the tools that are safe, the tools that are auditable, the tools that enforce the policy. The two sets of requirements…

  • An AI Policy Framework That Actually Holds Up

    An AI Policy Framework That Actually Holds Up

    The AI policy framework in 2026 sits as the document the typical enterprise has been wanting to write, with the policy covering the acceptable use, the data handling, the model selection, the compliance. The 2026 guide covers what the framework should include, what the framework should not include, and what the enterprise can do to…

  • GDPR Enforcement 2026: The Fines, the Decisions, the Patterns

    GDPR Enforcement 2026: The Fines, the Decisions, the Patterns

    GDPR enforcement in 2026 is no longer the warning shot phase. The fines are landing, the precedent is being set, and the gap between the regulator’s interpretation of the regulation and the typical enterprise’s implementation of it is being measured in millions of euros per incident.

  • What osquery Tables Actually Tell You in 2026

    What osquery Tables Actually Tell You in 2026

    osquery in 2026 amounts to the most underused endpoint visibility tool in the typical enterprise. The enterprise deploys the EDR, the EDR catches the known threats, the EDR misses the unknown threats, the unknown threats sit on the endpoint unobserved. The osquery tables expose the endpoint state in a way the EDR cannot. The guide…

  • A Field Guide to the IAM Policy

    A Field Guide to the IAM Policy

    Most IAM policies in 2026 are written the way the IAM team learned to write them, which is to say they are written to satisfy the auditor and not the attacker. The result is a sprawl of over privileged roles, a stack of unused permissions, and a service account inventory that has not been touched…

  • Regulatory Enforcement: Q1 2026 in Numbers

    Regulatory Enforcement: Q1 2026 in Numbers

    The regulators moved from guidance to enforcement in 2025. Q1 2026 was the first full quarter of the new normal. Here is what the numbers actually look like, and what they tell you about what is coming.

  • The Cloud Misconfiguration Tax You Are Paying

    The Cloud Misconfiguration Tax You Are Paying

    The cloud misconfiguration tax shows up in three places. Most organisations do not see all three. Here is what you are actually paying, and what the fix costs.