Resources

Blogs
Whitepapers & Reports
Podcast
Security Tools
Events & Webinars
Search tags
Type 3+ chars to filter. Click a tag to show related posts.
Filter by tag
Clear filters
Endpoint Protection

How Endpoint Detection & Response Is Evolving in 2025

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Cloud Security

Securing Multi-Cloud Environments: Common Mistakes and How to Fix Them

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Threat Intelligence

How Threat Intelligence Helps Organizations Stay Ahead of Cyberattacks

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Compliance & Risk

Building a Compliance-First Security Program: A Practical Guide

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Compliance & Risk

Zero Trust Architecture: Why Perimeter Security Is No Longer Enough

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Network Security

7 Questions Security Leaders Should Ask After a Penetration Test

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

This is some text inside of a div block.
This is some text inside of a div block.
Compliance & Risk

Zero Trust Architecture: Why Perimeter Security Is No Longer Enough

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Compliance & Risk

Building a Compliance-First Security Program: A Practical Guide

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Threat Intelligence

How Threat Intelligence Helps Organizations Stay Ahead of Cyberattacks

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Cloud Security

Securing Multi-Cloud Environments: Common Mistakes and How to Fix Them

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Endpoint Protection

How Endpoint Detection & Response Is Evolving in 2025

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

Network Security

7 Questions Security Leaders Should Ask After a Penetration Test

A penetration testing engagement shouldn’t end with a report. Here’s how security leaders can use penetration testing results to strengthen defenses and reduce real-world attack risk.For many organizations, a penetration test feels like a finish line.

OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding | Episode 189

In this episode, the conversation focuses on software supply chain failures, now a top concern in the OWASP Top 10. Real-world examples and practical strategies are discussed to help organizations manage the risks of using third-party components and vendors.

Episode 188: Guaranteed Way to Catch Threat Actors

In this episode, we break down how deploying cyber deception and honeypots can give defenders the upper hand against threat actors. Learn actionable strategies from active internal pen testers on guaranteeing early detection and improving your blue team’s effectiveness.

Episode 187: Avoid This Cyber Leadership Trap

Avoid one of the biggest mistakes in cybersecurity leadership: buying tools before having a strategy. This episode breaks down a smarter approach that ensures security investments actually solve the right problems.

Episode 186: Real-Life Active Directory Attack Paths

Join us as we break down real-life Active Directory attack paths uncovered during internal penetration tests. Learn how attackers exploit common misconfigurations and what you can do to defend your environment.

Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

AI agents have moved far beyond chatbots and are now deeply woven into business operations, bringing new levels of risk and complexity. In this episode, we cut through the hype and break down what IT and security teams actually need to worry about.

Episode 184: Active Directory Isn’t Dead. It’s Just Undefended

Active Directory isn’t dead—it’s still powering the majority of organizations, and security risks are as critical as ever. In this episode, we dig into the real facts, common attack paths, and actionable defense strategies.

Episode 183: OWASP Top 10 Part 2 – Security Misconfigurations That Get You Hacked

In this episode of The Cyber Threat Perspective, we continue our breakdown of the OWASP Top 10 by focusing on security misconfigurations. Learn why these vulnerabilities are common, how they happen, and what you can do to avoid them in your own web applications.

Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

The 2026 Verizon Data Breach Investigations Report is out, and it’s time to break down what really matters for IT security teams. In this episode, we cut through the noise to highlight the new trends, major shifts, and actionable insights you need to know right now.

Episode 181: AI Zero-Days (Google Threat Intelligence Report)

Google’s Threat Intelligence Group just dropped a game-changing report on the role of AI in modern cyber attacks. In this episode, we break down what’s new and what it means for defenders and organizations.

Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

In this episode, we break down the dangers of echo chambers in cybersecurity and the importance of critical thinking in a hype-driven industry. Learn practical strategies to avoid falling into groupthink and make smarter decisions for your organization.

10 Things You Should Be Doing in AI Security

A practical checklist of ten steps law firms should take to secure AI use, from governance and tool inventory to access controls, testing, and monitoring.

Professional Services: 2026 Cyber-Threat Landscape

Professional services was the second-most-breached industry in 2026 — and the only major target left unprofiled in the year's most-cited breach research. Our executive summary fills that gap, translating the data into what it means for legal, accounting, consulting, and engineering firms.

AI Security Isn't New. Your Gaps Are.

Most law firms don't have an AI security program. They have an AI security document. Learn why governance, testing, and monitoring must work together to protect privileged data and reduce AI risk.