Tag: Vulnerability
-

Why Your Security Questionnaire Is a Waste of Time
The security questionnaire has become the procurement ritual the security team has been asked to fill out for every vendor, the questionnaire that takes six hours per vendor, the questionnaire that asks the same fifty questions the questionnaire has been asking for ten years.
-

What an Honest Vendor Demo Looks Like
The vendor demo has become the polished thirty minutes the vendor uses to sell the procurement team on the tool the vendor has spent six months building. The demo that shows the tool working in the conditions the demo was designed to handle, the conditions the enterprise environment does not match.
-

Hardware Hacking in 2026 Is Having a Moment
Hardware hacking has gone from the conference talk that draws the small audience to the front page story that draws the regulator. The firmware vulnerability the researcher found in the conference demo, the vulnerability that sits in the device the enterprise has deployed across the fleet, the vulnerability that the vendor has been quietly patching…
-

Why Your Incident Response Runbook Is Wrong
The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.
-

How to Read a CVE
The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.
-

What an Honest Security Audit Looks Like
An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.
-

The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)
Phishing has not improved because filters got worse. It has improved because attackers can produce clean, context-aware messages, imitate legitimate login flows, proxy sessions, and exploit normal human urgency.
-

Hiring a Security Expert Is Not Going to Save You
The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program is the organisation whose security posture is the same. Here is why the single hire does not work, and what does.
-

How to Read a Vulnerability Disclosure
Every CVE announcement looks the same. The implications are not the same. Here is how to read a vulnerability disclosure like a defender, not like a marketer, in 2026.
-

The Three Lines of Defense That Actually Work
The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.