Research and guidance

Security insights

Vulnerability research and practical observations from the work of testing, protecting, and improving real environments.

An MSSP Should Deliver Decisions, Not Just Dashboards

Evaluate MSSP delivery through customer boundaries, useful evidence, accountable decisions, and a review cadence leaders can use.

Read the article

Form 8-K Starts With a Defensible Reporting Record

Organize evidence, ownership, timelines, and review for Form 8-K reporting, including the distinct cybersecurity-incident deadline.

Read the article

Third-Party Risk Is a Business Dependency Map, Not a Questionnaire

Manage third-party risk by mapping business dependencies, accountable owners, access, evidence, resilience limits, and follow-through.

Read the article

Customer Data Isolation Is a Business Requirement, Not a Database Setting

Treat customer data isolation as a business requirement with owner-approved boundaries, repeatable evidence, and meaningful SaaS assurance.

Read the article

From Cyber Findings to Board-Ready Risk Decisions

Turn technical observations into accountable, board-ready risk decisions supported by business context, evidence, and recurring review.

Read the article

Access Ownership Is the Missing Layer in Identity Programs

Make consequential access decisions reviewable by connecting business purpose, system and data context, evidence, accountable owners, and follow-through.

Read the article

From Agentic Code Findings to Governed Remediation: A Practical Look at VulnHunter

Use customer-authorized VulnHunter output as third-party evidence linked to application owners, business context, remediation, and verification.

Read the article

BIA and Recovery Limits: Make RTO and RPO Business Decisions

Turn maximum tolerable downtime, recovery time, and data-loss limits into owner-approved business decisions that teams can exercise and improve.

Read the article

Least Privilege Begins With Business Functions, Not Groups

Directory membership shows assigned access. It does not prove that the access is required for a person's position and allocated functions.

Read the article

From Point-in-Time Assessment to Continuous Assurance

Map the business, establish the observed baseline, define the target, verify remediation, and monitor for unauthorized drift.

Read the article

Why a Technical Baseline Cannot Prove Your Environment Is Secure

An audit records what exists. A defensible security conclusion requires approved business functions, ownership, access, data flow, and recovery context.

Read the article

Caremark, Cyber Risk, and a Defensible Oversight System

Build the business-linked reporting, material-risk register, escalation, remediation, acceptance, and recurring review evidence that supports executive due care.

Read the article

i-GEN opLYNX Central Authentication Bypass

CVE-2012-4688. Client-side authentication logic allowed access when JavaScript was disabled.

Read the disclosure

AxxonSoft Axxon Next Directory Traversal

CVE-2018-7467. A directory traversal issue in the AxxonSoft client web interface.

Read the disclosure

Managed Vulnerability Scanning as a Service

Why recurring authenticated discovery, reporting, remediation, and validation are foundational to a durable security program.

Read the article