Hacker Summer Camp wrapped up last week. Black Hat USA 2026 ran August 1-6 at Mandalay Bay, DEF CON 34 followed August 6-9 at the Las Vegas Convention Center, and somewhere north of 50,000 security professionals spent the better part of two weeks in 105-degree heat talking about the things that are going to show…
Six months in. It’s a reasonable moment to step back from the tactical and look at the rest of the year as a whole — what’s coming, what’s already behind schedule, and where security and GRC programs need to be positioned heading into Q3 and Q4. This isn’t a predictions post. It’s a planning post.…
July 1 brought another wave of state privacy law changes into effect. If your compliance calendar had these flagged, this is the time to confirm your program is actually operational — not just documented. If you didn’t have them flagged, here’s what you need to know. We covered the broader state privacy landscape in the…
For years, CISA served as a meaningful resource for organizations outside the enterprise security tier — threat intelligence sharing, incident response support, vulnerability advisories, regional coordination, and cybersecurity assessments available at no cost to critical infrastructure operators and public sector entities. That resource base has eroded significantly, and the organizations that haven’t adjusted their programs…
Most organizations have mature processes for managing human identities. Onboarding, offboarding, access reviews, least privilege — these are established practices, even if execution is inconsistent. The problem is that human identities are no longer the majority of what’s accessing your systems. Service accounts, API keys, OAuth tokens, automation scripts, and now AI agents — non-human…
Graduation season is here, and if you’re about to finish a cybersecurity degree, a bootcamp, or a certification program and step into your first job search, congratulations — and also, fair warning: the gap between what academic programs prepare you for and what the job actually looks like is real, and nobody warns you about…
Every year on March 31st, the security community celebrates World Backup Day. Vendors tweet reminders. IT teams run awareness campaigns. Someone in marketing makes a clever graphic about the 3-2-1 rule. And every year, organizations that had backups still lose everything to ransomware. That’s because we’ve been celebrating the wrong thing. We’ve been celebrating the…
February is often “Bonus Season.” If you were lucky enough to see a performance bonus hit your account this month, the temptation is immediate: a new watch, a 4K monitor, or perhaps throwing it into a volatile crypto coin. But if you treat your career like a business—let’s call it “You Inc.”—you know that the…
It is tax season, which means it is also “Tax Scam Season.” While we all know to avoid phishing emails claiming to be the IRS (pro tip: the IRS never emails you), there is a more sophisticated threat: Stolen Identity Refund Fraud. This occurs when an attacker uses your Social Security Number (SSN)—likely stolen in…
An interview is a two-way street. While the company is evaluating your technical skills to see if you can protect their network, you must evaluate their culture to see if you can protect your sanity. Security burnout is real. It is rarely caused by “too much work”; it is almost always caused by poor management,…