Hacker Summer Camp wrapped up last week. Black Hat USA 2026 ran August 1-6 at Mandalay Bay, DEF CON 34 followed August 6-9 at the Las Vegas Convention Center, and somewhere north of 50,000 security professionals spent the better part of two weeks in 105-degree heat talking about the things that are going to show…
August 2 came and went. If you spent the last several months building toward that deadline, here’s the update you may have missed: the EU AI Act’s high-risk AI system requirements are no longer due August 2, 2026. On May 7, 2026, EU lawmakers reached political agreement on revisions to the AI Act, pushing the…
The 4th of July just wrapped up. Somewhere between the cookout and the fireworks show, your organization ran on skeleton crew coverage, half your security team was on PTO, and a meaningful chunk of your workforce was connecting from personal devices on home networks, hotel Wi-Fi, or wherever the holiday took them. That’s not a…
August 2 is five days from when this publishes. That’s the date the EU AI Act’s major provisions — including the full requirements for high-risk AI systems — become applicable. If you’ve been tracking it as an upcoming deadline, it’s no longer upcoming. We covered the strategic overview in April. This post is for the…
Six months in. It’s a reasonable moment to step back from the tactical and look at the rest of the year as a whole — what’s coming, what’s already behind schedule, and where security and GRC programs need to be positioned heading into Q3 and Q4. This isn’t a predictions post. It’s a planning post.…
July 1 brought another wave of state privacy law changes into effect. If your compliance calendar had these flagged, this is the time to confirm your program is actually operational — not just documented. If you didn’t have them flagged, here’s what you need to know. We covered the broader state privacy landscape in the…
Zero Trust is one of the most marketed concepts in cybersecurity. It’s also one of the most misunderstood. If you’ve sat through enough vendor presentations, you’ve heard it positioned as a product — something you buy, deploy, and check off the maturity model. The reality is different, and the gap between the marketing narrative and…
Third-party risk has been a fixture of security program conversations for years. Most organizations with a mature GRC function have a vendor risk management process — tiering, assessments, questionnaires, contractual requirements. The process exists. The problem is that the scale and nature of supply chain attacks have outpaced what those processes were built to handle.…
Summer is operationally the most complicated season for security teams, and it’s rarely discussed that way. The conversation tends to focus on threat actors and external risks. The more immediate problem is internal: interns onboarding with broader access than they need, senior staff on extended PTO, temporary employees hired for seasonal peaks, and an organizational…
If your organization has been tracking state privacy legislation as a “watch and monitor” item, that posture is overdue for a change. Twenty states now have comprehensive consumer privacy laws in effect. Three more — Connecticut, Arkansas, and Utah — have significant updates or new provisions taking effect July 1, 2026. That’s thirty days from…