Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached

Computers are not safe. Even the best hardware and software products have the potential to conceal as-yet unknown vulnerabilities. And they aren’t all made that well. Many are shuffled into the world without a plan to detect, remediate, and notify users of those vulnerabilities. The EU’s Cyber Resilience Act aims to improve that situation.

A Complete Audit Trail That Names No One

An AI assistant reads four hundred documents across a tenant. Every read is logged. The application is named, the file is named, the timestamp is exact, and the access is attributed to an account that belongs to nobody. ‍ The audit trail is complete and it cannot answer the question an auditor asks. Nobody asks whether an access was recorded. They ask who reached the data and whether that person was authorized, and a shared service account answers neither. ‍

When the Loss Is Downtime Rather Than Data

Most cyber loss models are shaped around a breach. Records exposed, notification cost per record, regulatory penalty, credit monitoring, litigation. The arithmetic is well established and the inputs are reasonably well evidenced. ‍ Apply that model to an outage where nothing left and nothing was taken and every one of those categories returns zero. The organization was down for four days and the model reports almost no loss, which is not a calibration problem but the wrong model. ‍

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Introducing App Store Threat Detection: Visibility Where Brand Monitoring Couldn't Reach

In January 2024, Craig Raw, the developer of the real Sparrow Wallet, a Bitcoin wallet app, warned that a fake version of his app was live on the Apple App Store. He reported it repeatedly, but the listing stayed up. By August 2025, three people had lost a combined $1.8 million to it: Jalen Delgado (about $120,000 in May 2025), James Ramirez (about $875,000 in July 2025), and Christopher Ellis (about $840,000 in August 2025). All three are now suing Apple. The complaint, Ramirez, et al. v.

Best Shadow AI Governance Tools for Enterprises: Buyer's Shortlist

Security teams already know employees use generative AI. The harder problem is buying the right platform before unsanctioned apps move sensitive data outside your visibility and control. UpGuard research found 81% of employees and 88% of security leaders use unapproved AI tools, and 45% of workers find a workaround when their employer blocks an app. That last number should shape your buying criteria more than the first two. Demand doesn't disappear when you block it. It moves somewhere you can't see.

Quantifying Cyber Risk Without Revenue to Lose

A public body has no revenue to lose, no share price to move and no insurance market pricing it the way one prices a manufacturer. It faces the same regulatory pressure to quantify cyber exposure as anyone else, and the standard model's central input does not exist. ‍ Substituting the loss categories is the easy half and it is where most guidance stops. The harder question is what the resulting figure is for, because the decisions a private company makes with it are mostly unavailable. ‍

When the AI Arrives Inside Software You Already Bought

An application that was AI-free at the last audit may be processing corporate data through a language model today. Nobody procured it, nobody approved it and nobody was asked. A vendor shipped a release. ‍ Third-party AI governance is built almost entirely around procurement. Assess the vendor, negotiate terms, sign a data processing agreement, add the tool to a register. The apparatus requires a purchasing event, and an embedded feature produces none, so the apparatus never engages. ‍

Top 4 enterprise risk management software solutions

Good enterprise risk management software gives you one place to record and score every risk, keeps that record current by watching your controls instead of waiting for a quarterly review, maps risks to the frameworks you report against, connects to the tools your teams already use, and turns all of it into dashboards your executives and board will read. The hard part is telling which products do those things well and which just store risks in a nicer grid. Below are the features that matter, a scorecard to weigh them, and four tools worth a look.
Featured Post

Why Annual Third-Party Cyber Risk Assessments Are No Longer Enough

As regulators tighten expectations and cyber attacks increasingly exploit supply chains, organisations must shift from periodic vendor assessments to continuous third-party cyber resilience. For years, third-party cyber risk management focused primarily on vendor due diligence and annual security assessments. The objective was simple: determine whether a supplier met an acceptable level of security at a specific point in time.

The Best IT and Cyber Risk Management Software

When you search for IT risk management software, the results rarely agree on what the category is. Product pages pitch enterprise governance, risk, and compliance (GRC) suites. Tool roundups mix project trackers with cyber platforms, and review aggregators combine tools that solve different problems. If you're a security analyst or CISO trying to shortlist platforms, that ambiguity costs you weeks and often ends in a proof of concept with the wrong vendor.

One Domain, Two Tenants, Only One Governed

An organization licenses ChatGPT Enterprise. An employee opens a second browser profile, signs into the personal account already logged in there, and pastes a customer extract into it. Same laptop, same managed browser, same corporate egress, same person, same web address. ‍ Every control in the path reads that session as ordinary and correct, because by every attribute any of them can see, it is.

Quantifying Cyber Risk With No Incident History

A company too young or too small to have an incident history still has to answer the underwriter at renewal, the enterprise customer running a security review, and the board asking what the exposure is. The usual objection is that quantification needs a baseline and there is none. ‍ The objection rests on a mistaken assumption about how these models work.

Four Functions, One Obligation, No Owner

The standard answer to fragmented AI compliance is a responsibility matrix mapped across the lifecycle. Procurement accountable at intake, legal responsible for regulatory vetting, engineering accountable at implementation, security accountable for monitoring. Every stage has an owner and every function knows its part. ‍ Read that arrangement carefully and the problem is visible inside the solution.

Evidence on Demand, and Why Most Programs Cannot

A governance program looks complete until somebody asks it to prove something on a deadline it did not set. A supervisor sends an information request. An underwriter asks for control coverage before binding. A prospect's security team asks how a specific control operated last quarter, and the deal waits on the answer. ‍ Most programs can describe what they do accurately and cannot evidence it inside the window. The difference is not a documentation problem.

What a Cyber Risk Number Cannot Tell You

Arguments for quantifying cyber risk are abundant and mostly sound. What gets published far less often is a plain account of what a modeled figure does not tell you, which is unfortunate, because stating the limits is more persuasive to a skeptical audience than another argument for the method. ‍ We build these models. What follows is what they cannot do, written plainly, followed by what remains useful once those limits are accepted. ‍

From Hotspots to Lookalike Domains: 3 Phishing Tactics to Watch

In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.

Exploitability Without Exploitation: When Attention Is the Signal

Nucleus Insights flagged 14 vulnerabilities with real-world exploitation activity that looked risky before CISA added them to KEV. The key takeaway: all 14 were later listed in KEV. Acting on those signals would have been the right call every time, just earlier.

Top 7 Recommended Digital Risk Protection Platforms in 2026

The best digital risk protection platforms in 2026 are CloudSEK XVigil, ZeroFox, Recorded Future, Flashpoint, Check Point External Risk Management, Group-IB, and ReliaQuest GreyMatter DRP. They separate less on what they detect, since every vendor scrapes the same forums, than on whether they validate a finding, remove it, and connect it to an attack path. No two are strong at the same jobs.

Introducing Subprocessor listing in Trust Center profiles

At UpGuard, we believe your Trust Center should be the single place your prospects and customers go to get their trust questions answered. Today, we're excited to announce subprocessor listing in the Trust Center. This capability lets you publish your subprocessors directly where buyers already look for trust signals. You can also keep that list up to date and enable customers to subscribe to updates.

Cybersecurity Leaders React to OpenAI's Hugging Face Breach UpGuard

In July 2026, OpenAI's own AI agents escaped their sandbox and reached Hugging Face's production systems during an internal cybersecurity evaluation. In its latest report, OpenAI called the incident "a warning shot for us and for the world." We asked cybersecurity leaders for their reactions to the breach and what it signals for every team racing to deploy AI. One detail stands out. Hugging Face's own systems detected the attack and traced its full shape, but the alert never escalated high enough for a human to act on it.

Three Frameworks, Three Definitions of AI Risk

Cross-mapping tables for AI evidence in life sciences already exist and are broadly right. Data integrity practice lines up against data governance requirements, software lifecycle logs against technical documentation and logging, human review checks against human oversight duties, post-market surveillance against post-market monitoring. Build one repository, present it two ways. ‍ All of that is sound and it starts one step too late.

Single-Agent Monitoring Records Nodes, Not Edges

Monitoring an agent tells you what that agent did. Every useful question about a multi-agent deployment concerns what happened between agents, and those are properties of the connections rather than of the participants. A per-agent view records nodes and the problems live on the edges. ‍ The shortfall is not a tooling problem waiting on a product.

A Risk Number Does Not Decay on a Smooth Curve

An annual quantification gets produced in March and quoted as fact in November. Everyone involved knows the figure has aged and nobody knows by how much, so it keeps being presented with the same confidence it had on the day it was signed off. ‍ The usual framing is that a number decays gradually and needs refreshing more often. The framing is half right and it misleads on the part that matters, because most of the decay does not happen gradually at all. ‍

How to Choose Trust Center Software

Trust center software is what helps you publish a branded, access-controlled security page so buyers can self-serve certifications, policies, and answers to previously completed questionnaires. The tool helps vendors proactively share their security posture with potential customers and efficiently address common security concerns that block sales. Don't confuse this with Microsoft Office Trust Center. That's an entirely different tool that governs macros and active content in Excel and Word.

Biggest Data Breaches in Telecommunications (Updated September 2026)

Telecommunications providers sit at the center of modern life, carrying the calls, messages, locations, account credentials, and identity data that connect billions of people and businesses. Which makes them uniquely valuable targets: criminals want subscriber records they can monetize, while nation-state actors want access to the networks themselves. The biggest telecom data breaches show how quickly weak security measures can escalate from a customer privacy incident into a national security event.