Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Building Customer Trust Through Strong Security and Compliance Practices

A software company had everything going for it. Its product solved a real problem, customer reviews were positive, and new demos were converting into paying clients. Then, during the procurement process with a large enterprise customer, the conversation changed. Instead of discussing features or pricing, the prospect sent a security questionnaire that stretched over dozens of pages. They wanted documentation, evidence of internal controls, and proof that customer data was being handled responsibly.

The Role of Mechanical Insulation in Sustainable Building Design

Sustainable building design has become more than just a trend. Across commercial, industrial, and institutional projects, owners are looking for practical ways to reduce energy use, lower operating costs, and create healthier environments for occupants. While technologies like solar panels, smart lighting, and automated HVAC controls often receive the most attention, one of the most effective solutions is also one of the least visible: mechanical insulation.

Episode 19 - The Cap on Inference: Proving How Network Data Quality Drives AI Security ROI

In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight.

The New CISO Ep. 148 - Lou Rabon | How Many Tokens to Breach Your Network?

What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.

TeamPCP Profile: Why Developer Tools Are Becoming the Attack Path

TeamPCP is a financially motivated ransomware group tied to software supply chain compromise, credential theft, extortion, and abuse of developer infrastructure. The group is also tracked through aliases including ShellForce, PCPcat, TeamPCP, DeadCatx3, Altered Spider, and PersyPCP. The group has also claimed ownership of CipherForce, which it describes as its private locker.

Trust, Verify, Protect: Modernizing Email Security for the Cloud

Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email. In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?

Access Governance vs. Access Management: What's the Difference?

Most organizations deploy access management tools and believe they have identity security covered. They do not. What they have is a way to let users in, but no systematic way to ask whether those users should still have that access at all. Access governance and access management are related but distinct disciplines.