Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Soteria scaled its MDR practice on LimaCharlie

Soteria started as a consulting and advisory firm focused on penetration testing and incident response. Co-founder and managing principal Paul Ihme describes the company's growth from there as organic, expanding into virtual CISO work, offensive security, managed detection and response, and Microsoft 365 security products.

Investigate your network in plain English: introducing Natural Language Query

Every SOC analyst has been there. An alert fires. You know what you need to find. Maybe it's all outbound connections from a specific host that spiked overnight. Maybe it's every DNS query over 100 characters from a subnet you're watching. You know the question. What you don't know is the exact query syntax you need to ask it. So you open the documentation. You search for field names. You try a query, get it wrong, adjust, and try again. Minutes pass.

Canada Raises the Bar for Critical Infrastructure Cybersecurity. Is Your Network Ready?

Canada has taken a significant step toward strengthening national cyber resilience. With Royal Assent now granted to Bill C-8, the Government of Canada is establishing a new framework for protecting critical cyber systems and securing the country's most essential services.

How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important question is what happens to human expertise when machines take on more of the investigative workload. Across the industry, there is growing concern that AI will narrow the path into technical careers.

The "I" in FOCI: When Foreign Influence Becomes Cyber Risk

Foreign Ownership, Control, or Influence (FOCI) risk is often discussed as an ownership problem. Who owns the supplier? Who sits on the board? Is there a parent company tied to a foreign government? Does that relationship trigger CFIUS, export controls, sanctions, or a facility clearance review? These questions matter, but they do not capture the full risk picture. For C-SCRM program stakeholders, the most important word in FOCI is not ownership or control — it is influence.

Building an AI-Ready Engineering Team in 2026

Two engineering teams can have access to the same AI tools and get very different results. The difference is rarely the technology. It's engineering practices, technical leadership, and a shared understanding of where AI actually helps versus where it produces fast-looking work that creates problems later. Building an AI-ready team isn't about replacing developers with automation or hiring a separate group of AI specialists. It's about preparing existing teams to use AI without giving up the software quality, security, and accountability the work requires.

DDI Central 6500: Modern DHCP, unified visibility, and layered access control

DDI Central's release 6300 focused on authentication and identity: GSS-TSIG for secure DNS updates, LDAP/LDAPS-based user provisioning, and native Windows scavenging. Each aimed at cutting down the manual work behind keeping DNS and user access clean. DDI Central 6500 shifts focus elsewhere.

No more blind trust: How risk-based authentication strengthens identity security

Traditional digital authentication methods have allowed users to enter and IT infrastructure if they hold the right key. Username and password alone provided limited context around the authenticity of the access attempt. But today, the person with the credentials may not claim who they are.
Featured Post

One View, More Control: The Strategic Value of an Integrated IT Operating Model

Businesses are managing increasingly complex technology environments. Infrastructure, cloud, data protection, cybersecurity and continuity services all play a critical role in keeping organisations productive, resilient and ready to grow. At the same time, technology leaders are under pressure to improve efficiency, control costs and demonstrate clear value from every investment. In this environment, the challenge is not just choosing the right technology, but creating an operating model that gives the business control without adding unnecessary complexity.

5 best GRC software solutions for enterprise teams in 2026

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.