Endpoint detection, cloud security posture management, email security, identity and access management, network segmentation. Security teams invest heavily in all these active risk vectors, but one category is growing faster than the rest: human risk, which considers what employees do… Read More "How to Mitigate Human Risk in Cybersecurity: A Practical Framework"
Is a SOC 2 Report Enough to Assess a Cloud Vendor?
A vendor sends over a SOC 2 report. It lands in the queue, someone reads the cover page, sees the auditor’s name and a clean-looking opinion letter, and marks the assessment complete. The reviewer moves on to the next vendor.… Read More "Is a SOC 2 Report Enough to Assess a Cloud Vendor?"
The Vendor Assurance Confidence Gap: Why It’s Widest With Your Most Critical Vendors
Vendor assurance efforts are increasing, but risk leaders don’t trust the results of that effort. In KPMG’s Global Third-Party Risk Management (TPRM) Survey, only 15% of risk leaders said they have high confidence in the data that underpins their TPRM… Read More "The Vendor Assurance Confidence Gap: Why It’s Widest With Your Most Critical Vendors"
Best TPRM Software for Higher Education: What to Look For
Higher education institutions don’t run on a single vendor ecosystem. They run on dozens of overlapping ones. Teaching, research, identity, payments, student services, cloud infrastructure, alumni engagement, and campus operations all rely on different third-party vendors. These often enter the… Read More "Best TPRM Software for Higher Education: What to Look For"
Solving Human Risk: Close the Visibility Gap
The human element is redefining cybersecurity. With every individual user accessing your network, tools, and sensitive data, managing your human attack surface is increasingly critical. Yet, as user autonomy increases and AI erupts, this task has become increasingly difficult, if… Read More "Solving Human Risk: Close the Visibility Gap"
Solving Human Risk: Automate Governance and Prioritize Action
In our previous blog post, “Closing the Visibility Gap,” we established that visibility is the first step in managing the modern human attack surface; however, prioritizing that data is the next major concern for any CISO. Prioritization of human risk… Read More "Solving Human Risk: Automate Governance and Prioritize Action"
Cisco Vulnerability Exploited Months Before Disclosure, Google Warns
A threat actor started exploiting a severe vulnerability in Cisco products at least two months before the flaw was disclosed, a new Google report warned. Tracked as CVE-2026-20245, this high-severity (CVSS 7.8) privilege escalation vulnerability stems from insufficient validation of… Read More "Cisco Vulnerability Exploited Months Before Disclosure, Google Warns"
CMC Releases Analysis and Guidance for Education Sector After Canvas D
The UK’s Cyber Monitoring Centre (CMC) has shared its analysis of the Canvas cyber incident affecting Instructure’s Learning Management System as the education technology firm prepares to share its own findings next week. The CMC said that approximately 160 UK… Read More "CMC Releases Analysis and Guidance for Education Sector After Canvas D"
China-Linked Hackers Strike Asian CNI with New Backdoor
A sustained campaign by a China-linked threat actor targeting government entities and critical infrastructure in Southeast Asia has been uncovered by researchers at Palo Alto Networks’ Unit 42. The group, tracked as CL-STA-1062 by Unit 42 researchers, has been active… Read More "China-Linked Hackers Strike Asian CNI with New Backdoor"
NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The UK’s leading cybersecurity agency has introduced plans to build an ambitious new national cyber-defense capability powered by agentic AI. The National Cyber Security Centre (NCSC) said that the Cyber Shield project is necessary to counter the offensive threat to… Read More "NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense"