Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Posture Management: A Modern Approach to Building Security That Holds

Security posture is one of the most used yet misunderstood concepts in cybersecurity. For some, it means being audit-ready. For others, it’s shorthand for how many tools are deployed across endpoints, identities, and cloud environments. But in practice, posture is something deeper. It’s the ability of your environment to withstand real-world threats, not just meet compliance requirements. Strong posture doesn’t just reflect what’s present.

How CISOs Should Brief the Board on AI in the SOC

John White is the Field CISO for EMEA at Torq. A respected security executive with more than 20 years of leadership experience, John previously served as CISO at Virgin Atlantic, where he led a multi-year transformation deploying the Torq AI SOC Platform to modernize cyber operations. Prior to that, he built and transformed security functions for global organizations, including ASOS, Liberty Global, AEG Europe, and KPMG.

9,000+ Incident Response Investigations Later: The 11 Essential Cybersecurity Controls

Organizations with mature security programs still get breached. Teams that pass audits still find themselves responding to ransomware, Business Email Compromise (BEC), and credential theft. The controls that satisfy an audit requirement and the controls that significantly reduce the likelihood, impact, and cost of an intrusion are often not the same.

CISO Risk Intel Brief: Exploited Control Planes, Not Patch Volume, Define Residual Risk

This executive intelligence briefing covers from the past week (2–9 September 2026) and the past month (approximately 10 August – 9 September 2026). CISOs, start here: do not open a 974-row spreadsheet. That queue is the failure mode. This week’s material risk sits in four places you can name before noon.

FIPS 140-2 vs FIPS 140-3, Explained

FIPS 140-3 is the current standard for validating cryptographic modules, which are the specific hardware or software components that implement encryption and manage keys inside a defined boundary. FIPS 140-3 was approved on March 22, 2019, became effective on September 22, 2019, and supersedes FIPS 140-2, which dates back to 2001. Most FIPS 140-3 security requirements come from ISO/IEC 19790:2012, with test requirements drawn from ISO/IEC 24759:2025.

Ransomware in OT environments: why it's different and how to recover

OT ransomware is not IT ransomware with an industrial label. An encrypted HMI, engineering workstation, SCADA server or virtualization host can remove operator visibility and force a controlled shutdown even when PLCs continue running. Recovery ends only when operations, engineering, safety and security agree that restored systems and the physical process are trustworthy.

MFA for Telecommunications: Securing Networks, Admins, and Customer Accounts

A single telecom login is one of the most dangerous keys in existence. Behind it sit subscriber identities, billing systems, and the network backbone every other industry depends on. In April 2025, SK Telecom admitted attackers had stolen authentication records tied to its USIM cards, affecting 27 million subscribers, with malware present for years before discovery. Weeks earlier, the FBI warned of a campaign using AI-generated voice and text to trick targets into handing over account access.