Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Top tips: How to tell when an app has too much access to your data

Top tips is a weekly column where we highlight what's happening in the tech world and list practical ways to navigate these developments. This week, we're looking at an everyday cybersecurity concern that often goes unnoticed: the amount of access apps have to our data and devices. We install apps to make life easier. A navigation app needs our location, a messaging app needs access to contacts, and a video-conferencing app may need the microphone and camera.

A Practical Guide to Enterprise IT Risk Assessment

Enterprise IT environments now span cloud platforms, SaaS applications, endpoints, third-party services, and AI tools, creating more opportunities for disruption, security incidents, and operational failure. IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a data breach at $4.99 million, while Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with vulnerability exploitation and 48% involved a third party.

Keep your Qualys vulnerability scanner: Fix what it finds with Patch Manager Plus

Most organizations that run a vulnerability scanner have already made a significant investment. They chose Qualys, Tenable, Rapid7, or CrowdStrike based on their detection needs, their compliance requirements, and the way their security team works. That scanner is embedded in their workflows, audit processes, and reporting chain. Then they look at their vulnerability remediation times and realize the problem is not on the scanning side.

[Webinar] Beyond security logs: Why operational context matters in security investigations

A security event tells you what happened. But understanding why —and what was happening across the environment at the same time—can make all the difference. Modern security teams have access to vast amounts of security data through SIEM platforms. Logs, events, user activity, threat indicators, and alerts provide critical evidence for detecting and investigating potential incidents.

No more blind trust: How risk-based authentication strengthens identity security

Traditional digital authentication methods have allowed users to enter and IT infrastructure if they hold the right key. Username and password alone provided limited context around the authenticity of the access attempt. But today, the person with the credentials may not claim who they are.

DDI Central 6500: Modern DHCP, unified visibility, and layered access control

DDI Central's release 6300 focused on authentication and identity: GSS-TSIG for secure DNS updates, LDAP/LDAPS-based user provisioning, and native Windows scavenging. Each aimed at cutting down the manual work behind keeping DNS and user access clean. DDI Central 6500 shifts focus elsewhere.

Lessons from Microsoft's September 2026 Patch Tuesday

This month's Patch Tuesday just became the largest security release in Microsoft's history (so far), and it's tempting to let that record stand as the headline. However, the volume isn't the highlight. What a cycle this size exposes is how most patching processes are built, and exactly where they buckle. Here's what this month actually taught us, and what we need to change before the next record-breaking cycle arrives.

How to secure Exchange Server beyond the CVE-2026-62911 fix

Remote access has always been a core part of how on-premises Exchange works. Users need OWA to read their email from outside the office. Their devices need Autodiscover to set themselves up automatically. Keeping both reachable means keeping Exchange accessible from the Internet, and that opens up more of the server than most organisations realise. CVE-2026-62911 is the latest example. Microsoft released the fix on August 11, 2026.

Agentic AI for ITOps: Is your organization ready for the security challenges?

AI is set to provide increasing value in IT by enabling more ways to simplify complex IT operations, offering actionable insights, automating routine tasks with context-aware automation, and detecting abnormal events with advanced machine learning algorithms. With agentic AI, systems can understand what is happening in an IT environment, reason about the most probable root causes, determine the right course of action, and implement these changes without requiring additional human intervention.

ManageEngine Listed on the UK Government's G-Cloud 15 Framework

For public sector organisations, digital change is rarely just a question of new tech. It is also about finding solutions that are secure, effective, sustainable, and just as importantly, straightforward to procure. That is why we are delighted to announce that ManageEngine has been awarded a place on the UK Government’s G-Cloud 15 framework, with our cloud applications listed under Lot 2b: Software as a Service (SaaS).