Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Are Auditors Looking for During a DORA Assessment

Are you prepared for a DORA assessment — and can you actually prove your organization is operationally resilient? Under the Digital Operational Resilience Act (DORA), having cybersecurity policies on paper isn't enough. Financial entities need to demonstrate how ICT risks are governed, monitored, tested, and managed in practice. In this video, we cover the key areas that assessors and regulators may review.

What Evidence Will Regulators Expect Under NIS2?

Being NIS2-ready is not just about implementing cybersecurity controls—you should also be prepared to demonstrate that appropriate cybersecurity risk-management measures are actually in place. In this video, we cover some of the key documentation and evidence organizations may need to maintain, including: Security policies and cybersecurity governance documentation Cybersecurity risk assessments and risk-management processes Incident response procedures Business continuity and crisis management plans Supply chain security practices Employee cybersecurity awareness and training activities.

Does NIS2 Apply to Your Organization Ask These 5 Questions

Many organizations assume the NIS2 Directive only applies to large enterprises based in Europe. In reality, organizations with operations, customers, suppliers, or digital services connected to the EU may also have cybersecurity compliance obligations. In this short video, we cover five practical questions that can help determine whether your organization may fall within the scope of NIS2. You'll learn.

ISO 27001 vs ISO 42001 Do You Need Both

Already certified to ISO 27001 but wondering if your organization also needs ISO 42001? In this video, we explain the difference between ISO 27001 (Information Security Management) and ISO 42001 (AI Management Systems). If your organization uses AI tools like ChatGPT, Microsoft Copilot, Gemini, or develops AI-powered products, understanding AI governance is becoming increasingly important. Learn when ISO 42001 complements ISO 27001 and how both standards help organizations strengthen security, governance, and compliance.

FreeType Vulnerability Exposed: How Hackers Exploit Outdated Libraries (And How to Fix It)

Most developers have never heard of FreeType — but attackers are actively exploiting it right now. If your system is running an outdated version of this widely used font rendering library, you could be sitting on a critical vulnerability without even knowing it. In this video, we break it all down: What you'll learn.

Server Side XSS Explained Simply with Examples

Did you know that over 30% of all web application vulnerabilities reported each year involve Cross Site Scripting (XSS)? And among them, Stored or Server Side XSS is consistently ranked as one of the most dangerous forms, because a single injected payload can silently impact hundreds or even thousands of users without any interaction.