Tag: Zero Trust
-

Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong
We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.
-

Why Compliance Frameworks Don’t Catch the Breaches
The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.
-

How to Spot a Vendor That Is About to Get Acquired
The vendor the enterprise relies on just got acquired. The product roadmap is now the acquirer’s product roadmap, the support contract is now the acquirer’s support contract, the data the enterprise shared with the vendor is now the acquirer’s data. The acquisition has happened before the enterprise knew it was happening.
-

The Postman Problem and Why Your API Will Get Breached
Every API gets breached the same way. The attacker does not break the API. The API breaks itself, and the developer who built it learns about it from the breach disclosure.
-

Your Attack Surface Is Bigger Than You Think
The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that the attacker does not even bother with because the attacker has found something the security…
-

Why Your Security Questionnaire Is a Waste of Time
The security questionnaire has become the procurement ritual the security team has been asked to fill out for every vendor, the questionnaire that takes six hours per vendor, the questionnaire that asks the same fifty questions the questionnaire has been asking for ten years.
-

What an Honest Vendor Demo Looks Like
The vendor demo has become the polished thirty minutes the vendor uses to sell the procurement team on the tool the vendor has spent six months building. The demo that shows the tool working in the conditions the demo was designed to handle, the conditions the enterprise environment does not match.
-

Why Your Incident Response Runbook Is Wrong
The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.
-

How to Read a CVE
The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.
-

Security Tooling in 2026 Is Bigger Than Ever, and About the Same
A field guide to the security tooling market in 2026, with the consolidation, the categories that are over funded, the categories that are under funded, and the part about the dashboard that is going to get ignored.