Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Featured Post

Organisations Don't Need a Cloud-Native Network to Adopt SASE

In a perfect world, every business would design its network from day one with the need for scalability, connectivity from anywhere and zero-trust security in mind. In the real world, of course, few organisations have this luxury. Most have entrenched technology investments in place, and overhauling them to conform with modern network access and security paradigms isn't always feasible.

Health care cybersecurity threats MSPs should watch in 2026

The threat landscape facing health care organizations and their managed service providers (MSPs) in 2026 is constantly becoming more dangerous. Businesses and service providers in the field are increasingly popular targets for attackers. The attack perimeter for health care organizations is rapidly expanding beyond internal threats to involve third parties, especially MSPs.

Protecting PHI Beyond Names and ID Numbers

A few years ago, an Australian government health agency released what it believed was a fully de-identified dataset covering 10% of the national population. Names, addresses, and other obvious identifiers had been stripped out. Researchers showed individuals could be re-identified using nothing more than rare medical procedure codes and treatment dates cross-referenced with publicly available information. No names were needed.

SCIM & REST API Provisioning for Jira and Confluence

Wouldn't it be great if managing user accounts didn't take hours of manual effort? For many IT teams, unfortunately, that's exactly the reality. Every new employee needs access for all the apps they intend to use. When someone switches roles, permissions need updating. And when someone leaves, all their access needs to be revoked immediately. These tasks might sound simple, but they become exponentially more challenging as your company grows.

AI Agent Identity: Securing Desktop, SaaS, and Enterprise AI Agents

Your enterprise probably has a few thousand employees with managed identities. HR provisioned them, IT governs them, and your IAM platform watches them. Now count the AI agents running across your org. The Claude Code and codex instance that sit inside every dev's IDE. The Salesforce Einstein bot with access to every open deal. The Zapier AI that reads your CRM, writes to your Slack, and forwards summaries to email. You can't count, secure, or govern them with traditional IAM, can you?

CMMC for MSPs and ESPs: Who Needs Certification?

The Cybersecurity Maturity Model Certification, CMMC, is currently the most important information security framework for thousands of businesses across the country. Businesses that wish to work with the Department of Defense, or a DoD subcontractor, are quite likely to need to earn their CMMC certification in order to win those contracts. For those businesses that haven't been paying attention, this can come as a significant surprise.

How Data Security Fits Into a Data Management Framework

Most data management frameworks list security as one component among several, including governance, quality, integration, retention, architecture, and analytics. Security is often treated as an equally weighted checkbox on the same list as the others. That framing is where data security programs start to break down.

The Agentic Attack Surface Is Growing Faster Than Your API Inventory

Ask any security leader how many APIs their organization runs, and you’ll usually get a confident number. Ask them how many AI agents are operating in their environment right now, what those agents are deciding to do, and which APIs they’re calling to do it, and the confidence tends to disappear.

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers.

5 reasons why spreadsheets for risk management don't work (and what you can do instead)

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.