Tag: Ransomware

  • How Ransomware Negotiation Actually Works in 2026

    How Ransomware Negotiation Actually Works in 2026

    Ransomware negotiation in 2026 runs as a structured process, not as the panicked back and forth the movies suggest. The negotiation has a beginning, a middle, and an end, with the professionals on both sides, with the rules the professionals follow, with the outcomes the professionals achieve. The 2026 guide to how ransomware negotiation actually…

  • Third Party Risk Management in 2026: The Honest Guide

    Third Party Risk Management in 2026: The Honest Guide

    Third party risk management in 2026 amounts to a $15B annual market, with the typical enterprise running 500-2000 third party relationships, with the third party risk program trying to assess the security of each one. The honest guide covers what works, what does not work, and what to actually do.

  • Phishing Statistics 2026: What the Numbers Actually Look Like

    Phishing Statistics 2026: What the Numbers Actually Look Like

    The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went down, the time to first report went up. The state of the phishing problem in…

  • A Field Guide to the Zero Trust Rollout

    A Field Guide to the Zero Trust Rollout

    Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…

  • The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.

  • Supply Chain Attacks: When the Software You Trust Is the Problem

    Supply Chain Attacks: When the Software You Trust Is the Problem

    Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.

  • Why the Supply Chain Attack Keeps Winning

    Why the Supply Chain Attack Keeps Winning

    The supply chain attack keeps winning because defenders optimise for the wrong layer. Here is what actually works, in 2026, against the upstream dependency, the build pipeline, and the signed vendor update.

  • Malware in the Open Source Supply Chain Is Now the Default

    Malware in the Open Source Supply Chain Is Now the Default

    The malicious npm package, the typosquatted PyPI release, the compromised Docker image. The pattern has matured. The frequency has increased. The defence has not kept up.

  • Modern Phishing as a Service Is Boring (And That Is Why It Works)

    Modern Phishing as a Service Is Boring (And That Is Why It Works)

    Phishing in 2026 is not a clever technical exploit. Phishing in 2026 is a service industry, a well oiled business, and the most reliable way into a corporate network. Here is why it works.

  • The Incident Responder’s Playbook When Malware Hits

    The Incident Responder’s Playbook When Malware Hits

    The first 60 minutes of a malware incident decide the next 60 days. Here is what the responder actually does, in order, with the tooling that holds up under pressure.