Tag: Phishing

  • The Windows Event Log Primer

    The Windows Event Log Primer

    The Windows event log in 2026 amounts to the single most underused source of security data in the typical enterprise. The enterprise buys the SIEM, the enterprise points the SIEM at the network, the enterprise misses the threats that the Windows event log would have caught. The primer for what the events are, what they…

  • SIEM Cost Optimization: The Honest Guide

    SIEM Cost Optimization: The Honest Guide

    SIEM cost optimisation in 2026 amounts to a $5B annual problem for the enterprises running the legacy SIEMs, and a $1B annual problem for the enterprises that already moved to the cloud native SIEMs. The cost has not gone down, the data volumes have not gone down, the licensing model has gotten worse. The honest…

  • Critical Infrastructure Attacks in 2026: The Patterns

    Critical Infrastructure Attacks in 2026: The Patterns

    The critical infrastructure attack has stopped being the hypothetical scenario the national security advisor uses to justify the budget. It has become the operational reality the utility operator, the water utility, the hospital network has started to live with.

  • Third Party Risk Management in 2026: The Honest Guide

    Third Party Risk Management in 2026: The Honest Guide

    Third party risk management in 2026 amounts to a $15B annual market, with the typical enterprise running 500-2000 third party relationships, with the third party risk program trying to assess the security of each one. The honest guide covers what works, what does not work, and what to actually do.

  • Phishing Statistics 2026: What the Numbers Actually Look Like

    Phishing Statistics 2026: What the Numbers Actually Look Like

    The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went down, the time to first report went up. The state of the phishing problem in…

  • A Field Guide to the Zero Trust Rollout

    A Field Guide to the Zero Trust Rollout

    Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…

  • The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.

  • Supply Chain Attacks: When the Software You Trust Is the Problem

    Supply Chain Attacks: When the Software You Trust Is the Problem

    Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.

  • The Cloud Misconfiguration Tax You Are Paying

    The Cloud Misconfiguration Tax You Are Paying

    The cloud misconfiguration tax shows up in three places. Most organisations do not see all three. Here is what you are actually paying, and what the fix costs.

  • Why the Supply Chain Attack Keeps Winning

    Why the Supply Chain Attack Keeps Winning

    The supply chain attack keeps winning because defenders optimise for the wrong layer. Here is what actually works, in 2026, against the upstream dependency, the build pipeline, and the signed vendor update.