Tag: Zero Trust

  • The Windows Event Log Primer

    The Windows Event Log Primer

    The Windows event log in 2026 amounts to the single most underused source of security data in the typical enterprise. The enterprise buys the SIEM, the enterprise points the SIEM at the network, the enterprise misses the threats that the Windows event log would have caught. The primer for what the events are, what they…

  • The Secrets Rotation Playbook

    The Secrets Rotation Playbook

    A field guide to secrets rotation in 2026, with what the right cadence is, what to rotate and what to retire, and the automation that makes the rotation actually happen without breaking the production.

  • SIEM Cost Optimization: The Honest Guide

    SIEM Cost Optimization: The Honest Guide

    SIEM cost optimisation in 2026 amounts to a $5B annual problem for the enterprises running the legacy SIEMs, and a $1B annual problem for the enterprises that already moved to the cloud native SIEMs. The cost has not gone down, the data volumes have not gone down, the licensing model has gotten worse. The honest…

  • Password Reuse Is Still Winning in 2026

    Password Reuse Is Still Winning in 2026

    Password reuse is still winning in 2026. People reuse passwords. They reuse the same password across work and personal accounts. They reuse the same password across the work accounts of every job they have ever had. The advice to use unique passwords is good advice. The advice is not being followed. The attackers know.

  • Third Party Risk Management in 2026: The Honest Guide

    Third Party Risk Management in 2026: The Honest Guide

    Third party risk management in 2026 amounts to a $15B annual market, with the typical enterprise running 500-2000 third party relationships, with the third party risk program trying to assess the security of each one. The honest guide covers what works, what does not work, and what to actually do.

  • A Field Guide to the Zero Trust Rollout

    A Field Guide to the Zero Trust Rollout

    Zero trust in 2026 stands as the security framework that has been overhyped for a decade and that has finally started to deliver on the value. The 2026 zero trust rollout looks like the maturity of the tooling, the maturity of the standards, the maturity of the patterns, the maturity of the operational practice. The…

  • What osquery Tables Actually Tell You in 2026

    What osquery Tables Actually Tell You in 2026

    osquery in 2026 amounts to the most underused endpoint visibility tool in the typical enterprise. The enterprise deploys the EDR, the EDR catches the known threats, the EDR misses the unknown threats, the unknown threats sit on the endpoint unobserved. The osquery tables expose the endpoint state in a way the EDR cannot. The guide…

  • The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The Internet’s Biggest Security Problem Isn’t AI. It’s Forgotten Infrastructure

    The loudest story in security is AI. The quietest one is the same problem we have had for twenty years: someone forgot to turn off a server.

  • Supply Chain Attacks: When the Software You Trust Is the Problem

    Supply Chain Attacks: When the Software You Trust Is the Problem

    Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.

  • Why the Supply Chain Attack Keeps Winning

    Why the Supply Chain Attack Keeps Winning

    The supply chain attack keeps winning because defenders optimise for the wrong layer. Here is what actually works, in 2026, against the upstream dependency, the build pipeline, and the signed vendor update.