Tag: Phishing

  • Building a Virtual CISO Program in 2026

    Building a Virtual CISO Program in 2026

    The virtual CISO program in 2026 sits as the program the small enterprise has been quietly turning to, the program the consultant has been quietly building, the program the auditor has been quietly accepting.

  • Why Your VPN Is About to Get Weird

    Why Your VPN Is About to Get Weird

    The corporate VPN is the longest-running piece of security theater in tech. It is being replaced, slowly, by a stack of small ideas that happen to work better now than they did five years ago.

  • Hardware Tokens: The Quiet Comeback

    Hardware Tokens: The Quiet Comeback

    The hardware token in 2026 has made a quiet comeback, with the YubiKey, the Titan, the Feitian all seeing the adoption that the push notification lost, with the hardware token sitting as the authentication that cannot be phished, that cannot be bypassed, that cannot be social engineered. The 2026 guide covers why the hardware token…

  • A Weekend Migration: Replacing One Cloud Service With a Self Hosted Alternative

    A Weekend Migration: Replacing One Cloud Service With a Self Hosted Alternative

    We migrated a paid analytics service to a self hosted alternative and wrote down the actual time it took, the actual failures, and the actual cost. The Saturday afternoon is real. The Tuesday evening for DNS cutover is also real.

  • The CISO Handbook: The Second Edition

    The CISO Handbook: The Second Edition

    The first edition sold the idea that the CISO could be a peer to the CIO. The second edition quietly walks that back. The role has shifted, the board has shifted, the threat has shifted, and the playbook that worked in 2020 does not work in 2026.

  • Lateral Movement Without Exploits in 2026

    Lateral Movement Without Exploits in 2026

    Lateral movement without exploits in 2026 amounts to the dominant attack pattern in the typical enterprise breach. The attacker compromises one endpoint with a phishing email, the attacker uses the legitimate credentials the phishing email captured, the attacker moves to the next endpoint with the legitimate credentials, the attacker does not need a single exploit…

  • Inside a Modern Ransomware Attack

    Inside a Modern Ransomware Attack

    Modern ransomware is not a virus. It is a business process. The attackers run it like a company, with departments, SLAs, and customer support for the victims.

  • The State of the Browser in Q3 2026

    The State of the Browser in Q3 2026

    The browser serves as the most attacked surface in the enterprise. It has been the most attacked surface for two years, and the margin keeps growing. The risk has migrated from phishing links to extensions, to session tokens, to data residency in the cloud profiles the browser keeps for the user.

  • Phishing Resistant MFA Deep Dive

    Phishing Resistant MFA Deep Dive

    Passwords died somewhere around 2022. The funeral for SMS codes happened in 2024. The survivors in 2026 sit at three: hardware keys, passkeys, certificate based auth. The choice between them runs as the choice the enterprise has been postponing for three years, and the postponement has cost enough breaches to retire the debate.

  • DDoS Mitigation on a Budget

    DDoS Mitigation on a Budget

    The DDoS attack in 2026 amounts to the attack the typical enterprise faces 5-20 times per year, with the attack peaking at 1-10 Tbps, with the attack lasting 1-24 hours, with the attack costing the enterprise $20K-$200K per hour in lost revenue. The mitigation in 2026 amounts to the work the typical enterprise does on…