Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Featured Post

Four Excuses That Are Leaving Your Data Exposed to AI Risk

The generative AI revolution isn't on the horizon. It's already reshaping the way your employees work. Across every industry, workers are adopting AI-powered productivity tools at a pace that far outstrips most organisations' security and governance programmes. The question is no longer whether your organisation will use AI, but whether you're prepared to use it securely. The challenge is real, but so are the misconceptions that keep organisations from acting. Let's break down the four most common excuses and explore what it takes to build a data security foundation ready for the AI era.

Your Vendors Are Rushing Into AI. Their Attack Surface Is Coming With Them

Every company you depend on is standing up AI right now. Chatbots, copilots, RAG pipelines, agent frameworks, model gateways. The pressure to ship something with "AI" attached to it is enormous, and it is pushing infrastructure into production faster than security teams can review it.

When the Breach Isn't Yours, But the Risk Still Might Be

Every time a cyber breach breaks headlines, leadership teams pose the same urgent question: Does this affect us? But a third-party risk team is likely already asking: Was one of our vendors, suppliers, partners, or other third parties involved? And increasingly: What if it was not our direct vendor, but one of theirs?

From E-Sign to RMM: DocuSign Kit Targets Windows and macOS

BlueVoyant SOC (Security Operations Center) and Threat Fusion Cell (TFC) teams are tracking a long-running phishing and remote access campaign that uses DocuSign/e-sign themed lures and a reusable web kit to drive victims into installing legitimate remote access tooling.

Your Vendor's Score Just Dropped. Now What?

Most TPRM alerts tell you the same thing: a vendor's score changed. A number moved. Something is different. What they don't tell you is which specific vulnerability caused it, whether it's real, or whether it's already inside your network. That last part is the question that keeps security leaders up at night, and most TPRM programs were never designed to answer it.

Canada's Bill C-8 Raises the Stakes for Critical Infrastructure Cybersecurity

Canada’s critical infrastructure cybersecurity rules are becoming more explicit — and more enforceable. Historically, these organizations have navigated a patchwork of sector-specific requirements, privacy breach reporting rules, regulator guidance, and voluntary frameworks. Bill C-8 raises the stakes by creating statutory cybersecurity obligations for designated operators of critical cyber systems.