Tag: Zero Trust

  • What an Honest Security Audit Looks Like

    What an Honest Security Audit Looks Like

    An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.

  • The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)

    The Phishing Email That Works in 2026 (And Why Your Filters Won’t Save You)

    Phishing has not improved because filters got worse. It has improved because attackers can produce clean, context-aware messages, imitate legitimate login flows, proxy sessions, and exploit normal human urgency.

  • Hiring a Security Expert Is Not Going to Save You

    Hiring a Security Expert Is Not Going to Save You

    The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program is the organisation whose security posture is the same. Here is why the single hire does not work, and what does.

  • How to Read a Vulnerability Disclosure

    How to Read a Vulnerability Disclosure

    Every CVE announcement looks the same. The implications are not the same. Here is how to read a vulnerability disclosure like a defender, not like a marketer, in 2026.

  • Why Your MFA Push Notifications Are a Security Hole

    Why Your MFA Push Notifications Are a Security Hole

    The MFA push notification in 2026 sits as the security control the typical enterprise has deployed to replace the password, with the push notification promising the security the password cannot provide. The 2026 reality amounts to the reality where the push notification has become the attack vector the attacker uses, with the MFA fatigue attack,…

  • The Three Lines of Defense That Actually Work

    The Three Lines of Defense That Actually Work

    The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.

  • What Cybersecurity Insurance Actually Buys You

    What Cybersecurity Insurance Actually Buys You

    Cybersecurity insurance in 2026 amounts to a $20B annual market, with the typical enterprise paying $50K-$500K per year for the coverage, with the coverage paying out roughly 40% of the time the enterprise has a claim, with the payout typically running at 30-50% of the claim. The insurance buys the enterprise some financial protection, the…

  • The Phishing Test Everyone Failed

    The Phishing Test Everyone Failed

    A simulated phishing email sent to every employee at a mid sized company, the email was a fake package delivery notification, the link went to a fake login page. The click rate was 17 percent. The interesting part is who clicked.

  • What Happens When Your Vendor Gets Breached

    What Happens When Your Vendor Gets Breached

    What happens when your vendor gets breached, in 2026, is that you find out about it from the press, your CISO gets paged at 2 AM, the incident response plan turns out to not match the actual scenario, and the next 72 hours are spent trying to figure out what data the vendor had on…

  • Most Security Advice Is Written for Someone Who Is Not You

    Most Security Advice Is Written for Someone Who Is Not You

    Most security advice is written for the median enterprise, the median small business, the median home user, the median developer, and the median is nobody. The advice that is right for the median is wrong for the outliers, which is most of the people actually reading the advice.