Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

150 hours saved in one month: Inside Jamf's IT Ops automation strategy

What would your IT team do with 150 extra hours in just one month? That’s exactly what Jamf achieved - the equivalent of nearly one additional full-time employee - while dramatically accelerating workflow delivery and reducing manual operational overhead. In this session, hear directly from the Jamf team on how they replaced manual, ticket-based IT work with intelligent workflows - from responsive phishing reporting and employee alert notifications to on-demand FileVault key recovery.

Self-hosted password vault: why security teams are taking the keys back

A self-hosted password vault runs on infrastructure you control instead of a vendor's cloud, giving you direct custody of encryption keys, backups, and access logs. It trades vendor convenience for operational responsibility: you patch it, you back it up, and you decide who reaches it. For teams with data residency requirements, air-gapped environments, or a board that keeps asking where the credentials live, that trade is usually worth making.

Cautiously Optimistic: NOAA Predicts "Below-Normal" 2026 Hurricane Season

With forecasters expecting yet another eventful Atlantic hurricane season, how can you ensure your business and its data are protected? Get (and stay) prepared with disaster recovery. Does your business have a hurricane preparedness plan? For businesses operating along the Southern and Eastern Atlantic coast, each hurricane season ushers in a storm front of anxiety and trepidation — in addition to all that wind and rain. And for good reason.

TITAN AI Demo Series: How AI Pre-fills Vendor Assessments from Security Policies

TITAN Assess reads vendor security policies and pre-fills assessment responses automatically so your team reviews findings instead of copying answers from PDFs. In this installment of SecurityScorecard's TITAN AI demo series, see AI pre-fill from vendor policies in action and find out how much faster your team moves through assessments when the manual work disappears.

Cloud Transition Challenges: From On-Prem to Multi-Cloud Security #shorts

Organizations are fully onboarded in multi-cloud environments (AWS, Azure, GCP), but transitioning from traditional on-prem security to the cloud poses a significant challenge. Cloud security teams now need to collaborate with traditional network engineering teams, each with different objectives, to bridge the gap.

Microsoft Purview DLP Limitations and How to Close Them

Security teams that roll out Microsoft Purview DLP inside their Microsoft ecosystem often assume coverage extends further than it does. Policies apply cleanly to Word, Excel, and Outlook. Then a sensitive.dwg is inspected only by extension because Purview doesn't scan CAD content, a developer on a Linux workstation falls outside endpoint coverage entirely, or raw source code moves to a USB drive without matching the source-code classifier, which runs on the endpoint only for Office and PDF files.

Best Tools for Securing MCP and LLM Integrations

Shadow IT used to mean employees spinning up unsanctioned software-as-a-service (SaaS) apps that stored company data without approval. Today, shadow MCP and unsanctioned LLM integrations represent the next evolution, and they're more dangerous. Model context protocol (MCP) servers don't merely store data; they act on it, executing code, calling APIs, and accessing internal tools on behalf of AI agents that developers connect with a config file.

Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs

An initial access broker associated with the Payouts King ransomware group is using Microsoft Teams phishing to deploy a malicious Microsoft Edge web browser extension, according to researchers at Zscaler. Once the hackers have a foothold within an organization, they sell the access to the ransomware gang to conduct follow-on attacks.

From Awareness to Digital Workforce Security

Security must evolve from a static training program into dynamic, AI-powered human and AI risk orchestration embedded across the organization. The traditional model of security awareness aimed to get a message into people’s heads and hope it stayed there long enough to stop insecure actions. Organizations trained, tested, reported a completion rate to the auditor, and moved on.