Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Data Protection Officer Under the DPDP Act: Who Needs One and What They Do

Not every organization that processes personal data has to appoint a Data Protection Officer. Under India's Digital Personal Data Protection Act, 2023, this duty applies only to Significant Data Fiduciaries (SDFs), a category the government assigns based on the scale and sensitivity of the data an entity handles. So before you assume your business needs a data protection officer, it helps to know exactly where this obligation begins and ends.

Passwordless Authentication and Passkeys: How FIDO2 Enables Secure Login

Password-based authentication is slowly disappearing from the login experience in 2026. Instead, users increasingly authenticate with a fingerprint, device PIN, or security key without typing a password. This is where passwordless authentication and passkeys come in. Built on FIDO2 and WebAuthn, passkeys use cryptographic credentials to make passwordless login simpler for users while reducing exposure to phishing and credential theft. But passkeys are only one part of the picture.

What Is a Security Token? How Does It Work?

A security token is a physical device, digital object, or software credential that helps verify a user's identity before granting access to a system, application, network, or account. Depending on the type, it can generate a one-time password (OTP), store cryptographic credentials, or work with an authentication system to prove that the person requesting access possesses the authorized token.

"Better than the tools we were quoted six figures for": How Tines' finance team built a custom billing app for <$1,000

At Tines, Salesforce and NetSuite form our core finance and billing stack. But anyone using these tools will be familiar with the issues this set-up presents — it requires manual, time-consuming work to connect data across the two platforms. Over the years, my team evaluated a bunch of solutions to this problem, including third-party tools and NetSuite’s own native offering.

RTO vs RPO: What They Mean and How to Set Them Honestly

Recovery time objective (RTO) is how long a system can be down before the impact becomes unacceptable. Recovery point objective (RPO) is how much data the business can afford to lose, measured as a window of time before the incident. RTO looks forward from the moment things break. RPO looks backward from it. That distinction takes a paragraph to explain and years to get right, because the difficult part was never the definition.

Millions of Phishing Emails Use ASCII Smuggling to Bypass Security Filters

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as “ASCII smuggling,” has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

The New Agent Control Standard Names the Controls, Not Their Value

The OWASP GenAI Security Project unveiled an Agent Control Standard in early September, donated to the project and aimed at runtime enforcement for agentic systems. It sets out that agents should be inspectable, traceable and instrumentable, with declarative hooks and policy enforcement across frameworks. ‍ It answers which controls belong around an agent.

Why AI Review Cannot Keep Up With the Decision

That human review becomes a bottleneck as agents scale is now widely observed. Five or ten agents working in parallel produce more decisions than one reviewer can evaluate, and under queue pressure the review degrades into approval without examination. ‍ The usual response is to move up a level, reviewing intents and boundaries rather than individual outputs.

Autonomous Pentesting Is About To Kill Security Abbreviations

I have watched the security industry run a very profitable game with abbreviations for the last decade. The simple way to do it is to invent a category, give it a cool catchy abbreviation, market it as the missing piece of the stack, and repeat. The greatest examples are CTEM, BAS, ASM, and EASM. Every one of them arrived promising to close the gap the last one left open, and every one of them ended up as a line item on a renewal spreadsheet that nobody at the buyer‘s side could confidently defend.

Can Autonomous Pentesting Rescue CVE Coverage From Vanity Metric Hell?

The security industry killed CVE coverage as a credible metric, and it deserved to die. Vendors inflated the numbers for years in the name of depth, and nobody in the room had an incentive to ask whether they reflected real validated risk or just a longer signature list. So “CVE coverage is a vanity metric” became earned consensus. The question I keep coming back to is whether the autonomous pentesting era makes that consensus outdated.