Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Conditional Access Protects Microsoft 365 Apps From Unmanaged Devices

Your sales representative logged into Outlook from a coffee shop laptop that isn't enrolled, isn't encrypted, and hasn't seen a security patch in eight months. Should Microsoft 365 let that sign-in through just because the password was correct? That single question is why conditional access exists. Passwords tell you who someone claims to be. They say nothing about whether the device behind that login is safe to trust with your company's email, SharePoint files, or Teams chats.

5 Tips for Scaling Cloud Security Without Adding Complexity

For years, managed service providers (MSPs) have secured customer cloud environments through periodic reviews of each tenant. That approach worked when a customer ran two or three cloud applications. As organizations adopt more SaaS applications, the number of environments, identities, and configurations to monitor also increases. The challenge is already visible.

Quantifying Cyber Risk With No Incident History

A company too young or too small to have an incident history still has to answer the underwriter at renewal, the enterprise customer running a security review, and the board asking what the exposure is. The usual objection is that quantification needs a baseline and there is none. ‍ The objection rests on a mistaken assumption about how these models work.

One Domain, Two Tenants, Only One Governed

An organization licenses ChatGPT Enterprise. An employee opens a second browser profile, signs into the personal account already logged in there, and pastes a customer extract into it. Same laptop, same managed browser, same corporate egress, same person, same web address. ‍ Every control in the path reads that session as ordinary and correct, because by every attribute any of them can see, it is.

SACR's New ECP Framework: What It Means for AI and Data Security

A new report from Software Analyst Cyber Research (SACR), The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security, outlines a new era of endpoint security shaped by AI agents, copilots, SaaS applications, browser-based workflows, and increasingly autonomous activity. The report introduces Endpoint Control and Prevention (ECP) as a framework for understanding this shift and the new security capabilities it requires.

The Best IT and Cyber Risk Management Software

When you search for IT risk management software, the results rarely agree on what the category is. Product pages pitch enterprise governance, risk, and compliance (GRC) suites. Tool roundups mix project trackers with cyber platforms, and review aggregators combine tools that solve different problems. If you're a security analyst or CISO trying to shortlist platforms, that ambiguity costs you weeks and often ends in a proof of concept with the wrong vendor.

Mend Renovate Enterprise: managing dependencies at agentic scale

Automated dependency updates are not new. For years, Mend Renovate has scanned repositories, flagged outdated or vulnerable packages, and opened pull requests. What has changed is the sheer velocity of the pipeline. AI coding agents now write a significant share of production code, introducing open source packages continuously across thousands of repositories.

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense. Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases.

Certificate monitoring for your intranet hosts

Certificate monitoring from the cloud only sees what the internet sees, like your public websites. But the vCenter console, the internal API, the switch management page, or that thing on db01.corp.internal are invisible to it. Those certificates expire just like public ones. They just don’t warn anybody first. This gap became very clear when we shipped Private PKI. Now CertKit can issue certificates for internal names and IP addresses, deploy them, and install the root into your trust stores.

What is a cyber maturity assessment, and why do I need one?

Your business is growing. Your IT team is doing a solid job. And your cybersecurity feels like it’s broadly in order. You’ve got firewalls in place, antivirus software running, and backups happening somewhere. But there’s a nagging question that won’t quite go away; Do you actually know where you stand from a cybersecurity perspective? For many organisations, the honest answer is no. Not really.