Tag: SaaS
-

The Vendor Incident Playbook
The vendor incident playbook has become the playbook the security team has been quietly trying to write, the playbook the breach response the vendor will produce has been quietly mocking, the playbook the next third party breach will demand.
-

Cloud Detection and Response: The Buyers Guide
The cloud detection and response buyers guide has become the guide the procurement team has been quietly trying to write, the guide the security team has been quietly trying to follow, the guide the vendor demo has been quietly trying to confuse.
-

Small Business Actually Secure in 2026
Small business security in 2026 amounts to the security work the typical 10-50 person company has to do without the budget of the Fortune 500. The work is not impossible, the work runs as the work the security vendors do not sell to the small business, the work amounts to the work the small business…
-

A Field Guide to the Supply Chain Attack
The supply chain attack in 2026 sits as the dominant attack pattern in the typical enterprise breach, with the attacker compromising the vendor, the vendor distributing the malicious update, the enterprise installing the update, the enterprise getting breached. The SolarWinds, the 3CX, the xz utils near miss, the 2024 Snowflake credential theft, all the same…
-

AI Music and the Publishing Deals
The AI music publishing deals in 2026 sit as the deals the major labels and publishers have made with the AI music vendors, with the deals reshaping the music licensing market, with the deals setting the precedent for the next wave of AI generated content. The deals cover the training rights, the output rights, the…
-

The Tools We Actually Use to Read a Site’s Security Posture
An afternoon and five free open source tools is enough to read the public security posture of almost any website. Here is the kit we use, in the order we use it, and what it does and does not show.
-

A Field Guide to the Vendor Questionnaire
The vendor security questionnaire in 2026 amounts to the 500 question form the enterprise sends to every vendor, with the vendor filling out the form, with the enterprise reviewing the answers, with the enterprise approving the vendor. The form has not changed in 10 years. The vendors have. The threats have. The field guide covers…
-

EDR vs XDR in 2026
EDR vs XDR runs as the question that is no longer the right question. The vendors have converged. The market has converged. The distinction is now a marketing slide. The buyer who still asks the question ends up buying the wrong product for the wrong reason.
-

Attack Path Mapping: The Honest Guide
Attack path mapping runs as the discipline of drawing the route an attacker would actually take through the environment, then fixing the parts of the route that are stupid. The discipline has been overcomplicated by the vendors and underused by the practitioners. The honest version is the one that produces the fixes.
-

The AI Coding Tools Rankings for Q2 2026
A field guide to the AI coding tools rankings for Q2 2026, with the methodology behind the scores, the places where the public leaderboards are lying to you, and the criteria that actually matter for production work.