top of page
All Posts


Ransomware Negotiation Is Now a Staffed Business Process
Ransomware crews research your revenue and insurance before naming a price. What Intel 471's findings mean for mid-market incident response readiness.
3 days ago


AI Readiness Assessment: How Consultants Evaluate Businesses
How consultants run an AI readiness assessment: the four domains they score, the 2026 rules that changed, and the two gaps most assessments miss.
7 days ago


Shadow AI Discovery: How to Find Every AI Tool Your Employees Are Already Using
Shadow AI discovery starts with four data sources you already own. Here is a practical method to inventory unapproved AI tools before an auditor asks.
Sep 3


When KEV, EPSS, and CVSS Disagree on What to Patch
KEV, EPSS, and CVSS often rank the same vulnerability differently. Here is the tiebreaker rule, a realistic patch window, and who owns the final call.
Sep 2


Most vCISO Services Are Sold by Your Tool Vendor
MSP adoption of vCISO services tripled in a year. What goes wrong when one firm sells your tools, runs your program, and grades your own risk assessment.
Aug 26


Ransomware Now Targets the Mid-Market: 73% of Attacks
Mid-sized companies absorbed 73% of publicly disclosed ransomware and extortion incidents in North America and Europe between January 2023 and June 2026, according to Black Kite. More than half of those victims earned between $10 million and $50 million a year.
Aug 25


Third-Party Risk Lessons From CareCloud and CEVA
CareCloud's healthcare breach grew from roughly 350,000 to 3,756,469 people, and a cyberattack on logistics provider CEVA exposed customer data for six unrelated brands. In both cases the notification obligation landed on the customer-facing company, not the vendor that was compromised.
Aug 19


AI Security Services: What They Are and Who Needs Them
AI security services protect the AI a company builds, the AI it buys, and the AI attackers point at it. What the work includes, who needs it, and how to choose a provider.
Aug 18


Azure Directory Leak: Why Your Org Chart Is a Target
A threat actor is selling 3.64M employee records from Azure tenants. What stolen directory data really costs, and the cloud security checks to run now.
Aug 18


Cybersecurity Risk Assessment: A Buyer's Guide
Cybersecurity risk assessment explained: which ones are legally required, which are voluntary, what each type delivers, and how to choose an independent assessor.
Aug 18


AI Security Assessment: Threats Every Business Faces
AI security threats now cost more than ordinary breaches. What the data shows, what an AI security assessment covers, and where to start first.
Aug 13


Cloud Security Assessment: What It Is and Who Needs One
A cloud security assessment reviews how your cloud is configured, who has access, and what one stolen credential reaches. What it covers across AWS and Microsoft 365, who needs one, what it costs, and how to choose an independent cloud security consultant.
Aug 11


How to Choose a Healthcare Cybersecurity Provider
Start with a security risk analysis, not a product purchase. The best cybersecurity for healthcare is led by someone with no financial stake in what you buy, because that person can tell you to spend less.
Aug 11


The CISO's Guide to AI Security for Business Leaders
A CISO's guide to AI security for business leaders: how to tier your AI exposure, what insurers now require, and who owns the risk without a CISO.
Aug 10


Cybersecurity for Law Firms: Where to Start
Cybersecurity for law firms in 2026: what the ethics rules actually require, what corporate clients audit, and the first 90 days that reduce real risk.
Aug 10


Fractional CISO: Where to Start (2026 Buyer Guide)
Need a fractional CISO but not sure where to begin? A CISO walks through triggers, scoping, 2026 pricing, vetting questions, and day-90 deliverables.
Aug 10


OWASP LLM Top 10 2026: What It Means for AI Security
OWASP's 2026 LLM Top 10 is out, ranked partly on 6,639 real incidents. What changed, what it misses, and what your AI security services plan needs now.
Aug 7


How to Choose a vCISO for Long-Term Strategic Alignment
How to choose a vCISO for long-term strategic alignment: the review cadence, the business events that force a re-baseline, and the drift signals.
Aug 5


How to Select a vCISO for a Startup: A Practical Guide
How to select a vCISO for a startup in 2026: the four triggers behind the hire, real cost ranges, the questions to ask, and when to end the engagement.
Aug 5


Claude Breached 3 Companies. Detection Never Fired.
Anthropic disclosed that Claude models breached three organizations during cyber testing. The overlooked story is that nobody's detection ever fired.
Aug 4
bottom of page
