Latest posts
-
AI in Forensics… Hype vs. Reality
Artificial Intelligence is everywhere in cybersecurity marketing right now, from “AI-driven EDR” to “autonomous SOC.” But when it comes to digital forensics and incident response (DFIR), the conversation often swings between over-hyped promises and under-appreciated realities. So where does AI actually fit today, and what’s still just buzz? Where AI Shows Real Promise… Triage &…
-
When an Empire Falls… The Cost of One Weak Password.
History teaches us that empires rarely collapse from a single battle. The Roman Empire did not fall overnight, it crumbled under years of pressure, compounded by one weakness after another, until the final blow came. In cybersecurity, many companies are facing their own version of that story. Last week, a headline stopped me cold: “How…
-
You Want to Be in Cybersecurity? Better Learn to Read nMaps and Swim with the Wiresharks…
Every week, I get a few messages from people eager to break into cybersecurity. The question is usually the same… “Where do I start?” They expect me to say certifications, or expensive courses, or maybe the name of the latest buzzword tool. But my answer is always simpler… and far less glamorous. Learn networking fundamentals.…
-
The Salesforce / Salesloft-Drift Breach. How Far the Blast Radius Really Goes…
Beyond the Firewall… How Lateral Movement Now Lives in Your Integrations When news breaks of yet another big breach, the headlines usually stop at “what was stolen” and “who was hit.” But the Salesforce / Salesloft-Drift breach is different. This isn’t just about a single vendor compromise, it’s about how interconnected SaaS ecosystems turn one…
-
Navigating the New Cybersecurity Regulatory Landscape. What Leaders Need to Know.
While on a recent advisory board Zoom call, one of the topics we tackled was the rapidly changing regulatory and policy landscape in cybersecurity. What stood out to me is how quickly the ground is shifting beneath us, and how many organizations are still underestimating the speed and scope of these changes. This isn’t just…
-
Microsoft’s “=COPILOT” in Excel–> Innovation or Risk?
For decades, Excel has been the gold standard for precision. Whether crunching financial reports, managing budgets, or building data models, users expect formulas to behave deterministically, 2 + 2 always equals 4. Microsoft’s latest move challenges that assumption by embedding its AI assistant directly into the spreadsheet itself. The new =COPILOT() function allows users to…
-
Network Fingerprinting… What It Is and How Security Teams Can Detect and Respond
Every device connected to a network leaves behind subtle digital traces. Just as detectives use fingerprints to identify suspects, attackers use network fingerprinting to identify operating systems, services, and vulnerabilities on their targets. Understanding what fingerprinting is, and how to defend against it, is essential for cybersecurity teams working to protect modern IT environments. What…
-
Booming Litigation… The Next Wave of Cyber Risk
While reading through the latest developments at the intersection of law and cybersecurity, I found myself drawn to one theme that seems to be accelerating faster than most–> the courtroom fallout from data breaches. It’s not just regulators and compliance officers weighing in anymore, there’s a growing wave of lawsuits that can change the trajectory…
-
Autonomous AI Cyberattacks… When Machines Learn to Hack Back
Artificial Intelligence has become a cornerstone of modern business, from copilots that write code to predictive engines that optimize supply chains. But as defenders race to integrate AI into their security stacks, attackers are preparing to do the same, with devastating consequences. This week, industry leaders raised the alarm on a new frontier… autonomous AI-powered…
-
SSL Certificates Are About to Change Forever (Starting 2026)
Most people don’t get excited about SSL/TLS certificates. They’re the quiet little digital passports that let your browser trust a website, light up that comforting padlock, and keep data flowing securely. But in 2026, two huge changes are coming that will impact every IT team, security pro, and organization that manages certificates. Think of it…