Tag: Tools
-

Cloud Detection and Response: The Buyers Guide
The cloud detection and response buyers guide has become the guide the procurement team has been quietly trying to write, the guide the security team has been quietly trying to follow, the guide the vendor demo has been quietly trying to confuse.
-

AI Coding Tools: What Worked and What Did Not, Six Months In
Six months into the AI coding tool rollout, the picture has clarified enough to say what worked, what did not, and what the next six months should look like. The tool the developer has been using, the tool the developer has been abandoning, the tool the executive team has been paying for.
-

The Honest State of Open Source Security in 2026
Open source security in 2026 has matured, with the SCA tools, the SBOM standards, the SLSA framework, the supply chain attestation, the package signing, the major platform support. The state of the open source security in 2026 amounts to the state of a market that has the tooling, the standards, the platform support, the adoption…
-

The Developer Security Tax
The developer security tax in 2026 amounts to the hidden cost the developer pays for the security tools the security team mandates. The cost shows up in the slower PRs, the failed CI runs, the rejected deploys, the manual approvals, the context switches, the frustrated developers. The tax amounts to a real cost, the tax…
-

Network Segmentation: A Field Guide for 2026
A field guide to the network segmentation in 2026, with what the segmentation actually does, the three layers that matter, what to segment first, and what the operations team needs to keep the segmentation working.
-

Lateral Movement Without Exploits in 2026
Lateral movement without exploits in 2026 amounts to the dominant attack pattern in the typical enterprise breach. The attacker compromises one endpoint with a phishing email, the attacker uses the legitimate credentials the phishing email captured, the attacker moves to the next endpoint with the legitimate credentials, the attacker does not need a single exploit…
-

The Tools We Actually Use to Read a Site’s Security Posture
An afternoon and five free open source tools is enough to read the public security posture of almost any website. Here is the kit we use, in the order we use it, and what it does and does not show.
-

The State of the Browser in Q3 2026
The browser serves as the most attacked surface in the enterprise. It has been the most attacked surface for two years, and the margin keeps growing. The risk has migrated from phishing links to extensions, to session tokens, to data residency in the cloud profiles the browser keeps for the user.
-

AI-Generated Code Is Now in Your Production Stack. Here’s How to Review It.
The useful question is no longer whether developers should use AI-generated code. They already do. The question is whether teams review it with the same discipline they would apply to code written by an unfamiliar contractor.
-

EDR vs XDR in 2026
EDR vs XDR runs as the question that is no longer the right question. The vendors have converged. The market has converged. The distinction is now a marketing slide. The buyer who still asks the question ends up buying the wrong product for the wrong reason.