Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached

Computers are not safe. Even the best hardware and software products have the potential to conceal as-yet unknown vulnerabilities. And they aren’t all made that well. Many are shuffled into the world without a plan to detect, remediate, and notify users of those vulnerabilities. The EU’s Cyber Resilience Act aims to improve that situation.

A Complete Audit Trail That Names No One

An AI assistant reads four hundred documents across a tenant. Every read is logged. The application is named, the file is named, the timestamp is exact, and the access is attributed to an account that belongs to nobody. ‍ The audit trail is complete and it cannot answer the question an auditor asks. Nobody asks whether an access was recorded. They ask who reached the data and whether that person was authorized, and a shared service account answers neither. ‍

When the Loss Is Downtime Rather Than Data

Most cyber loss models are shaped around a breach. Records exposed, notification cost per record, regulatory penalty, credit monitoring, litigation. The arithmetic is well established and the inputs are reasonably well evidenced. ‍ Apply that model to an outage where nothing left and nothing was taken and every one of those categories returns zero. The organization was down for four days and the model reports almost no loss, which is not a calibration problem but the wrong model. ‍

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Introducing App Store Threat Detection: Visibility Where Brand Monitoring Couldn't Reach

In January 2024, Craig Raw, the developer of the real Sparrow Wallet, a Bitcoin wallet app, warned that a fake version of his app was live on the Apple App Store. He reported it repeatedly, but the listing stayed up. By August 2025, three people had lost a combined $1.8 million to it: Jalen Delgado (about $120,000 in May 2025), James Ramirez (about $875,000 in July 2025), and Christopher Ellis (about $840,000 in August 2025). All three are now suing Apple. The complaint, Ramirez, et al. v.

Best Shadow AI Governance Tools for Enterprises: Buyer's Shortlist

Security teams already know employees use generative AI. The harder problem is buying the right platform before unsanctioned apps move sensitive data outside your visibility and control. UpGuard research found 81% of employees and 88% of security leaders use unapproved AI tools, and 45% of workers find a workaround when their employer blocks an app. That last number should shape your buying criteria more than the first two. Demand doesn't disappear when you block it. It moves somewhere you can't see.

Quantifying Cyber Risk Without Revenue to Lose

A public body has no revenue to lose, no share price to move and no insurance market pricing it the way one prices a manufacturer. It faces the same regulatory pressure to quantify cyber exposure as anyone else, and the standard model's central input does not exist. ‍ Substituting the loss categories is the easy half and it is where most guidance stops. The harder question is what the resulting figure is for, because the decisions a private company makes with it are mostly unavailable. ‍

When the AI Arrives Inside Software You Already Bought

An application that was AI-free at the last audit may be processing corporate data through a language model today. Nobody procured it, nobody approved it and nobody was asked. A vendor shipped a release. ‍ Third-party AI governance is built almost entirely around procurement. Assess the vendor, negotiate terms, sign a data processing agreement, add the tool to a register. The apparatus requires a purchasing event, and an embedded feature produces none, so the apparatus never engages. ‍

Top 4 enterprise risk management software solutions

Good enterprise risk management software gives you one place to record and score every risk, keeps that record current by watching your controls instead of waiting for a quarterly review, maps risks to the frameworks you report against, connects to the tools your teams already use, and turns all of it into dashboards your executives and board will read. The hard part is telling which products do those things well and which just store risks in a nicer grid. Below are the features that matter, a scorecard to weigh them, and four tools worth a look.
Featured Post

Why Annual Third-Party Cyber Risk Assessments Are No Longer Enough

As regulators tighten expectations and cyber attacks increasingly exploit supply chains, organisations must shift from periodic vendor assessments to continuous third-party cyber resilience. For years, third-party cyber risk management focused primarily on vendor due diligence and annual security assessments. The objective was simple: determine whether a supplier met an acceptable level of security at a specific point in time.