Tag: Ransomware

  • Why Your Incident Response Runbook Is Wrong

    Why Your Incident Response Runbook Is Wrong

    The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.

  • Security Tooling in 2026 Is Bigger Than Ever, and About the Same

    Security Tooling in 2026 Is Bigger Than Ever, and About the Same

    A field guide to the security tooling market in 2026, with the consolidation, the categories that are over funded, the categories that are under funded, and the part about the dashboard that is going to get ignored.

  • What an Honest Security Audit Looks Like

    What an Honest Security Audit Looks Like

    An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.

  • The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)

    The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)

    Phishing has not improved because filters got worse. It has improved because attackers can produce clean, context-aware messages, imitate legitimate login flows, proxy sessions, and exploit normal human urgency.

  • Hiring a Security Expert Is Not Going to Save You

    Hiring a Security Expert Is Not Going to Save You

    The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program is the organisation whose security posture is the same. Here is why the single hire does not work, and what does.

  • Why Your MFA Push Notifications Are a Security Hole

    Why Your MFA Push Notifications Are a Security Hole

    The MFA push notification in 2026 sits as the security control the typical enterprise has deployed to replace the password, with the push notification promising the security the password cannot provide. The 2026 reality amounts to the reality where the push notification has become the attack vector the attacker uses, with the MFA fatigue attack,…

  • What Cybersecurity Insurance Actually Buys You

    What Cybersecurity Insurance Actually Buys You

    Cybersecurity insurance in 2026 amounts to a $20B annual market, with the typical enterprise paying $50K-$500K per year for the coverage, with the coverage paying out roughly 40% of the time the enterprise has a claim, with the payout typically running at 30-50% of the claim. The insurance buys the enterprise some financial protection, the…

  • Your CI/CD Pipeline Is Your Weakest Link

    Your CI/CD Pipeline Is Your Weakest Link

    The CI/CD pipeline is the place where the code, the credentials, the secrets, the production access, and the third party integrations all meet, and the place where the security is the thinnest. The CI/CD pipeline is the supply chain, and the supply chain is the attack surface.

  • What Happens When Your Vendor Gets Breached

    What Happens When Your Vendor Gets Breached

    What happens when your vendor gets breached, in 2026, is that you find out about it from the press, your CISO gets paged at 2 AM, the incident response plan turns out to not match the actual scenario, and the next 72 hours are spent trying to figure out what data the vendor had on…

  • The People Who Run Your Systems Don’t Trust Your Vendors

    The People Who Run Your Systems Don’t Trust Your Vendors

    The people who actually run production systems, the ones who carry a pager and answer the 2 AM page, do not trust the vendors they buy software from. The trust gap is not new, but it has gotten wider in the last three years.