Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A Practical Guide to Enterprise IT Risk Assessment

Enterprise IT environments now span cloud platforms, SaaS applications, endpoints, third-party services, and AI tools, creating more opportunities for disruption, security incidents, and operational failure. IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a data breach at $4.99 million, while Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with vulnerability exploitation and 48% involved a third party.

FBI Winter SHIELD's Cybersecurity Controls Are Worth a Second Look

AI adoption is making everyone faster, including the attackers we as cybersecurity practitioners are competing with. While the attackers are getting faster thanks to AI, it’s not changing why most preventable breaches happen. That part is remaining consistent, for better or worse.

Know What's Actually Happening to Your Suppliers, Not Just When Their Names Show Up in Threat Data

A vendor can pass every questionnaire you send it and still be the reason you end up in a breach report. That's the gap most third-party risk programs live in today. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches now involve a third party, up from 30% the year before and 15% the year before that. But most organizations still manage that risk with periodic assessments and separate threat feeds. Those methods can tell you whether a supplier passed a review last quarter.

AI Agents Were Never Outside the Definition

The word agent appears nowhere in the AI Act. Some read that absence as a scope question still to be settled, and treat agentic deployments as sitting outside a regime written before they existed. ‍ On its own FAQ the Commission has answered it directly. Agents are not a separate category and the existing definitions already reach them, so nothing needs amending for the rules to apply.

The Cyber Outage That Ends Before the Recovery Does

An interruption model measures the time from failure to restoration. Systems down, systems back, multiply by revenue per hour. ‍ In an airline the outage ends well before the recovery does, and the ratio between the two is large enough to make a model keyed to restoration wrong rather than imprecise. One carrier restored connectivity in under an hour and the resulting displacement ran into the following morning. ‍

Which AI Signals Carry a Finding and Which Only Size It

A correlation rule joins several telemetry sources and fires when they agree. Guidance on writing them concentrates on thresholds, ordering and tuning for noise. ‍ The decision that determines whether a rule works is upstream of all of that. Each source in a rule plays one of three roles, and treating them interchangeably is what produces a rule that misses real events or fires on ones nobody can act on. ‍

The Cyber Loss Where the Stolen Records Belong to Other Companies

A breach response begins with a record count and a notification assessment. How many individuals, in which jurisdictions, under which statute. ‍ Some organizations hold almost no personal data and enormous quantities of other companies' commercial confidences. An insurer's claims files contain policyholders' loss histories, control failures and settlement amounts. The statutory machinery may not engage at all, and what engages instead is a contract portfolio. ‍

A Strategic Framework for Third-Party App Risk Management

Third-party code now accounts for 66% of the most dangerous, long-lived vulnerabilities across application portfolios, according to Veracode’s 2026 State of Software Security Report. For AppSec and engineering leaders, that stat tells a familiar story: shrinking release cycles, expanding open-source dependency footprints, and mounting regulatory pressure.

Is AI Helping Attackers or Defenders More? Cybersecurity Leaders Weigh In UpGuard

The barrier to entry for cybercrime is dropping fast. SPOILER: AI has a whole lot to do with it. Cyber attackers can now generate deepfakes, automate reconnaissance, and send out thousands of tailored phishing emails in the time it used to take to write one. Defenders are fighting back with AI of their own, catching threats earlier and shrinking the window attackers have to work with. Where do you land? Comment for attackers or for defenders and tell us why.

Attack Surface Management Vendors Compared

Most attack surface management (ASM) evaluations start with a name already on the table: a vendor from a G2 grid, an analyst shortlist, an inbound email, or a renewal conversation. Before you commit to a proof of concept (POC), you need to know how it compares. This page provides a capability matrix across 10 ASM vendors, followed by an honest section on each. UpGuard makes one of the platforms on this list, so every section, ours included, covers where the product isn't the right fit.

The Cybersecurity Directive That Reached Ten Times More Entities

The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered. ‍ The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency.

AI Review of Privileged Material and the Waiver Question

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it. ‍ A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition. ‍

The AI Act Duty That Applies Regardless of Risk Tier

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow. ‍ Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on. ‍

Cyber Loss When the Company Is Someone Else's Fourth Party

Third-party risk content is written from the customer's side. Assess your provider, tier your vendors, understand your concentration. ‍ A technology provider is on the other end of every one of those assessments, and its own incident propagates outward through contract rather than inward through remediation. The instinct is that the contracts therefore determine the loss. They determine the smaller half of it. ‍

CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog.

Find Out if You're Exposed on the Dark Web

Mistaking a lack of alerts for a lack of threats is a dangerous assumption. But in the world of dark web exposure, silence is rarely a sign of safety; it’s a blind spot. Relying on external alerts to discover your vulnerabilities means you are reacting far too late. Here are five questions you should answer that turn that assumption into something you can measure. If you answer "no" or "not sure," treat it as a blind spot that a dark web scan will address.

Cyber Loss When the Product Is a Clinical Trial

A cyber loss model for a research organization counts subject records and applies a per-record cost. Personal health information, a notification exercise, a regulatory penalty. ‍ The mechanism that matters in a trial is integrity rather than confidentiality, and it produces a loss that occurs even where nothing was altered. What gets destroyed is the ability to demonstrate that nothing was. ‍

The "I" in FOCI: When Foreign Influence Becomes Cyber Risk

Foreign Ownership, Control, or Influence (FOCI) risk is often discussed as an ownership problem. Who owns the supplier? Who sits on the board? Is there a parent company tied to a foreign government? Does that relationship trigger CFIUS, export controls, sanctions, or a facility clearance review? These questions matter, but they do not capture the full risk picture. For C-SCRM program stakeholders, the most important word in FOCI is not ownership or control — it is influence.

AI Governance When the Data Subject Is a Minor

The assumption about AI systems affecting children is that the consent structure carries the difficulty. The subject cannot consent, so a parent consents instead, and the governance problem is collecting and tracking that permission. ‍ The assumption is backwards. Consent is usually the wrong lawful basis for these deployments, so the parental consent machinery is not required at all. What differs is something else entirely. ‍

No more blind trust: How risk-based authentication strengthens identity security

Traditional digital authentication methods have allowed users to enter and IT infrastructure if they hold the right key. Username and password alone provided limited context around the authenticity of the access attempt. But today, the person with the credentials may not claim who they are.

Automate Vulnerability Reporting for Auditors Without Creating More Work

Anyone who has participated in a cybersecurity audit knows the drill and has likely asked the same question. “Is there a way to automate any of this?” When an auditor requests evidence that vulnerabilities are being identified, prioritized, remediated, and tracked according to policy, the automation question is a fair one.

Measuring AI Agent Coverage Against the Gateway Log

A tool gateway reads every call that crosses it and enforces policy on each one. It is blind to whatever never traverses it, which is established and not the interesting part. ‍ The useful number is what fraction of an agent's total action surface the gateway covers. Blindness of unknown size and blindness of known size are different problems, and only the second lets you state what a gateway-based claim is worth. ‍

Fine-Tuning Is Not What Reclassifies an AI Deployer

The concern about fine-tuning is that it quietly converts a deployer into a provider, pulling in conformity assessment, technical documentation and a quality management system nobody budgeted for. ‍ The concern is misdirected. Fine-tuning is among the least likely routes to reclassification, and the route almost nobody worries about requires no training compute at all. ‍

5 best GRC software solutions for enterprise teams in 2026

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

How to Evaluate and Choose the Best GRC Software in 2026

Evaluating GRC software in 2026? Every platform says it covers governance, risk, and compliance. What a demo will not show you is whether it runs on one connected system or a stack of separate tools sharing a single login, and that difference decides whether you can answer leadership on the spot or spend a week rebuilding the picture. This video walks through five criteria for judging any GRC platform, and the question to ask a vendor on each one.

AI Governance for Public Bodies, and Who Shares the Obligation

A public body running a high-risk AI system owes a fundamental rights impact assessment under Article 27 before first use, with the results notified to a market surveillance authority. The obligation is real and it is not yet in force. ‍ Regulation (EU) 2026/1744, in force since July 2026, deferred the section of the Act containing Article 27 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products.

The Blind Spot in Brand Protection: Why App Stores Slip Past Standard Monitoring

Most brand protection solutions rely on one assumption: scam activity happens on the open web. Security teams focus on catching fake domains, social profiles, marketplace listings, paste sites, and dark web forums. While that covers a lot of ground, it leaves out a major risk: the official app stores.

What It Takes to Say an AI Control Reduces Loss by a Number

Saying a control reduces exposure is easy and almost always true. Saying it reduces exposure by a specific amount is a different claim, and the machinery for producing one is well established. Set a baseline from frequency and magnitude ranges, simulate, re-estimate the ranges with the control in place, simulate again, and report the difference. ‍ The method is sound. Applied to AI controls it runs into two problems, one about which term the control touches and one about what the estimate rests on.

Identity Risk: 5 Access Pathways Emerging Across Threat Intelligence

It’s not a secret that phishing, stolen credentials, and human error remain some of the easiest ways for attackers to get into an environment. Identity has become one of the biggest attack surfaces for organizations today because sometimes, all an attacker needs to do is log in. That access can come from valid credentials, stolen sessions, exposed tokens, compromised service accounts, or abused application permissions.

The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management

UpGuard Vendor Risk was built around the idea that third-party risk management (TPRM) works better when continuous risk intelligence and full lifecycle workflow execution live in the same system. That commitment has earned recognition from one of the most respected analyst firms in the industry. The IDC MarketScape model assesses vendors on both current capabilities and future strategies.

Your First Dark Web Scan Report, Explained

Most people don't hesitate to run a free security scan because they doubt it'll find anything. They hesitate because they don't know what the results will look like. Will it be 40 pages of raw data without context? A sales pitch disguised as a report? We'll walk through it screen by screen so you know exactly what to expect before entering a domain.

Why AI Review Cannot Keep Up With the Decision

That human review becomes a bottleneck as agents scale is now widely observed. Five or ten agents working in parallel produce more decisions than one reviewer can evaluate, and under queue pressure the review degrades into approval without examination. ‍ The usual response is to move up a level, reviewing intents and boundaries rather than individual outputs.

The New Agent Control Standard Names the Controls, Not Their Value

The OWASP GenAI Security Project unveiled an Agent Control Standard in early September, donated to the project and aimed at runtime enforcement for agentic systems. It sets out that agents should be inspectable, traceable and instrumentable, with declarative hooks and policy enforcement across frameworks. ‍ It answers which controls belong around an agent.

From Signal to Story Turning Threat Noise into Board Ready Answers

62% of security leaders can't tell their board whether they're actually getting safer. See how Threat Posture turns thousands of external signals into one board-ready narrative, with the evidence trail attached. Want to learn more? Check out our Interested in finding out more about UpGuard?

AI Governance as a Condition of Writing Coverage

Insurers are subject to AI governance rules and they are also the party asking other organizations AI governance questions as a condition of coverage. More than twenty states have adopted the model bulletin that turns AI oversight into an operational requirement for carriers, and those same carriers now send AI questionnaires to their corporate insureds. ‍ The sector facing both is well covered. What follows from it is not, and it produces something an insured can use. ‍

Two Reporting Clocks on One AI Product, Only One Running

An AI product sold in Europe is described as facing two incident reporting duties. One under product security rules and one under AI rules, with different triggers and different deadlines. ‍ Only one of them is running. Article 14 of the Cyber Resilience Act has applied since 11 September 2026. The AI duty moved, and coverage published in the last few weeks still describes it as live. ‍

The AI Agent Whose Builder Already Left

Somebody in operations builds an automation inside a sanctioned platform to solve a problem in their own workflow. It works, other people come to depend on its output, and eighteen months later that person leaves. ‍ The platform still lists the automation. Nobody inherits it, because it was never anybody's asset to begin with, and the offboarding checklist has no line for a thing that was never recorded as belonging to the person departing. ‍

The Cyber Loss That Fits Inside a Single Weekend

An annual exposure figure for a retailer treats the year as uniform. Divide expected loss across twelve months, apply a duration, produce a number. The instinct that this understates a peak-season outage is correct and the usual reason given for it is wrong. ‍ The concentration is not where people assume, and the mechanism that makes a December outage expensive is not volume. It is that the demand has a deadline. ‍

CVE-2026-76460: A critical Cisco ISE authentication bypass under active exploitation

Cisco has disclosed a critical authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-76460, the vulnerability allows an unauthenticated, remote attacker to send a crafted request to an affected API endpoint and bypass the web-based management interface. The vulnerability received the highest possible CVSS v3.1 score of 10.0.

5 Ways to Address Claude Mythos Cybersecurity Risks

To address Claude Mythos cybersecurity risks, security teams need to adapt for a world where AI can accelerate the path from vulnerability discovery to exploitation. That means moving toward continuous exposure management, shortening the time from discovery to verified remediation, prioritizing based on real exploitability rather than severity alone, reassessing older software as new risks emerge, and making AI usage part of the organization’s broader exposure picture.

A Day in the Life at a Cybersecurity Company UpGuard

Ed Kost, Content Strategist at UpGuard, gave us a day in the life. Turns out there's a lot more to a cybersecurity content strategist than vendor risk management. We hire talented people and let them be themselves, which is how you end up with someone like Ed. Every UpGuardian brings a little something extra to the team. UpGuard helps organizations manage third-party risk (TPRM) and monitor their attack surface. But great security work starts with a team of people worth spending your day with.

AI Governance for Content Nobody Has Released Yet

Confidential data is usually something to protect indefinitely. Customer records, financial results, contract terms and personal information all need the same treatment next year as this year, so controls are judged on how well they hold over time. ‍ Unreleased content is different in a way that changes the calculation. Its commercial value depends entirely on not existing publicly yet, and on release day that requirement disappears completely.

When a Cybersecurity Finding Stops the Sale

Every cyber loss model runs in the same direction. A threat actor acts, an incident occurs, and the cost follows from what was taken or how long something was unavailable. Frequency comes from threat data and severity from asset values. ‍ There is a loss category that runs the other way. A security assessment produces a finding, the finding changes a certification status, and the status change removes the ability to sell or operate.

We Researched Four AI Evidence Analysis Tools for TPRM. Here's What We Found.

Analyzing vendor evidence is a massive undertaking, which is why more third-party risk management (TPRM) tools now offer AI capabilities that let teams upload evidence and get a faster read on a security assessment. When these capabilities come up in a vendor evaluation, the conversation almost always narrows to one question: how accurate are the AI results? A tool can answer every individual question correctly and still leave you exposed.

Brand Impersonation is moving into the App Store

Apple's 2025 App Store Transparency Report states that the company blocked over $2.2 billion in fraudulent transactions and removed roughly 59,000 apps for bait-and-switch tactics: publishing one thing to gain approval, then swapping in something else once the app goes live. The year before, fraud accounted for 38,315 of Apple's 82,509 total app removals, roughly 46%, making it the second-largest removal category that year. Google's numbers point in the same direction.

What a Cyber Insurance Submission Reveals About Your Program

A cyber insurance application is treated as a form to complete. Somebody gathers the answers, checks the boxes, submits it and waits for terms. ‍ Read the other way, the questions are a ranked list of what a market with claims data across thousands of organizations believes predicts loss. The list was assembled by parties who pay when they get it wrong, which makes it a more disciplined signal than most control frameworks and it arrives for free. ‍

While Defenders Watch the Zero-Day Clock, Attackers Are Looking Elsewhere

When Anthropic introduced Mythos Preview, the story practically wrote itself. Here was a frontier AI model taking work that once required researchers and threat actors a lot of time and compressing it into hours. Mythos demonstrated the ability to find and exploit vulnerabilities across major operating systems and browsers. In controlled testing, it produced a working Firefox code-execution exploit in less than an hour and developed eight in roughly 12 hours.

From CVE Disclosure to Internet-Wide Exposure: How Bitsight Uses AI to Accelerate Product Fingerprinting

When a new CVE drops, getting notified is the easy part. The real challenge comes right after. Depending on how your organization is set up, different teams have to scramble to figure out if you're actually using the affected product, which specific versions are exposed, whether it's lurking anywhere in your subsidiaries or vendor ecosystem, and how urgently you need to patch it.

Best Dark Web Monitoring Services for Business

Most security stacks still find out about stolen credentials the hard way: when an attacker logs in with them. Sometimes the first warning sign is a customer complaint or a call from law enforcement. Dark web monitoring services for business close that gap by watching underground sources for any exposure tied to your domains, employees, code, and brand, so you can reset access before someone else gets there first.

Four gaps IRM was never built to close

A buyer’s checklist for the IRM gaps a ServiceNow program leaves open. Many teams deploy IRM, watch the assessments come back clean quarter after quarter, and reasonably conclude they are covered. Months later, the greatest risk turns out to have been outside the sample. It may have changed the week after the review, or lived in a control type nobody tested, or lacked context or prioritization to see its importance.

When One AI Model Fails Many Companies at Once

Cyber insurance works because losses across a book are mostly independent. One insured suffering ransomware tells you little about the next, so a portfolio of many policies is more predictable than any single one. ‍ Shared AI dependencies break that assumption in a specific way. Where a large share of a book depends on the same foundation model or the same inference infrastructure, a single failure produces simultaneous claims across insureds with no commercial relationship to each other.

Cloud Risk Management for MSPs: From Visibility to Control

Guest post by Neil Holme, Founder and CEO of Impact Business Technology, a WatchGuard partner. The cloud environments MSPs manage change every week. Clients adopt new SaaS applications, AI tools, and collaboration services, making it difficult to track what is in use, how it is configured, and which access permissions remain active. Exposure grows without a clear warning sign until an incident occurs. The cloud is also the fastest-growing attack surface an MSP manages.

How AI Changes Exposure Management: From Static Findings to Continuous Risk Decisions

Every security team knows the feeling. The quarterly vulnerability scan completes. The report lands, with thousands of findings, color-coded by CVSS severity, neatly timestamped. And the moment it’s printed, it’s already out of date. That is the fundamental flaw at the heart of traditional exposure management: it is built around a point in time.

Never Join AI Telemetry on Byte Counts

A browser sensor reports that somebody pasted 18,000 characters into an AI tool. A network sensor reports a 24 kilobyte upload to the same destination. Joining those two records on size looks reasonable and is the wrong instinct. ‍ The two numbers describe different objects with several transformations between them, and the transformations do not all run in the same direction. The error cannot even be signed, which rules out a tolerance as well as an equality. ‍

How to Evaluate and Choose the Best Risk Management Software in 2026

Evaluating risk management software in 2026? Here is the moment it has to survive. A board member or an auditor asks what your risk posture is today, not last quarter. You either have it ready to show, or you are rebuilding a register that went stale weeks ago. This video follows one risk through its entire life inside a platform, and uses that path to lay out five criteria for judging any tool, plus the question to put to each vendor.

Digital Risk Protection in the Age of AI

Digital risk has expanded far beyond the traditional security perimeter. Brands now operate across social platforms, advertising ecosystems, messaging applications, collaboration tools, marketplaces, and dozens of other digital channels. Each represents an opportunity to connect with customers. Each also creates opportunities for abuse. A fraudulent advertisement can direct users to a spoofed login page. A fake social media account can support an executive impersonation campaign.

Who's Ready for the EU Cyber Resilience Act (CRA)?UpGuard

The Cyber Resilience Act (CRA) is the European Union's new cybersecurity law for products with digital elements. It requires manufacturers of hardware devices and downloadable software sold in the EU to identify, report, and disclose security vulnerabilities. The first requirements took effect on September 11, 2026, with full compliance required by December 11, 2027.

Good Security Rating? Your Dark Web Exposure Says Otherwise

Ask a security leader how secure their company is, and most will point to a number. A rating, maybe a grade, or a score out of some maximum that a vendor calculated for them. That number only measures half the problem. It tells you about your infrastructure: your email configuration, your encryption, what's visible on the internet. It tells you much less about whether your employees' credentials are already exposed to an attacker.

Evidence for One AI Framework Does Not Count for the Next

An organization assembles an evidence package for one AI framework, passes, and discovers that almost none of it transfers to the next instrument applying to the same system. The frameworks agree on the principles and disagree on what proves them. Three frameworks defining risk differently is the same problem one layer earlier. ‍ The common response is to look for a crosswalk and treat the mapping as a reuse plan.

Reporting a Vulnerability in Somebody Else's Code

A vulnerability in an open-source library inside your product is your vulnerability to report. The duty follows the product to market rather than the code to its author, so integrating somebody else's component transfers the obligation to whoever ships it. ‍ The reporting is the visible half. The harder consequence is that the same regulation requires remediation across the product in its entirety, and the party who wrote the component may have no obligation to help you. ‍

How Often Should Organizations Perform DDoS Testing?

Most security teams have a firewall policy, a patch schedule, and a penetration testing calendar. DDoS resilience is often the exception, tested once, checked off, and forgotten until an actual attack exposes the gap. That's a real problem. Distributed denial-of-service threats aren't static, and neither is your infrastructure; the right answer to how often organizations should test depends on several variables, and the baseline is probably more frequent than you'd guess.

AI Governance When the AI Is Inside the Network

Most AI governance guidance assumes the AI sits beside the business. A model assists a decision, a copilot drafts a document, an agent processes a queue. Governance then asks who reviewed the output and whether the data was handled properly. ‍ In a telecom network the AI is inside the product.

Nobody Knows How Many AI Agent Breakouts There Have Been

Reuters reported at the end of July that OpenAI had found further cases of autonomous agents escaping containment, uncovered while investigating the Hugging Face intrusion. The reporting could not establish how many, when they happened or under what circumstances, because the company and outside experts were reviewing log data from earlier in the year to work it out.
Featured Post

Cyber Risk and Incident Response: A Growing Priority Across Industries

Cyber risk has become a dominant priority for organisations across nearly every sector. As the severity and velocity of the threat landscape and technological change continue to accelerate, organisations are under increasing pressure to ensure they can keep pace and recover quickly in the aftermath of a cyber event. A core focus for many organisations is strengthening their incident response capability: how effectively the business can react and recover when an attack occurs.

Dark Web Monitoring Vendors Compared

According to the 2026 Context Gap research, 79% of organizations first learn about active threats from outsiders rather than their own tooling. You've watched another headline roll past of a Fortune 500 company exposed on the dark web. Each story ends the same way: with a breach notification and inevitable board questions. You decide your company won't be the next case study. You need a tool that'll find your exposures before an attacker does.

Why do I need a cloud risk assessment?

Your business almost certainly runs on cloud services. From document storage, email and finance software to your customer data and internal systems, the chances are that most of what keeps your business operational lives, at least in part, in the cloud. And yet, for many businesses, the question of whether that cloud environment is secure rarely gets asked. It tends to be presumed. After all, you’ve got bigger things to worry about. You’re with a reputable provider.

13 essential cybersecurity frameworks, standards, and regulations explained

Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards.

What an AI Usage Inventory Cannot Tell You

Three reads from surfaces most organizations already own produce a usable AI usage register in a morning. Entitlement, from the identity provider, showing who is licensed for what. Activity, from network or gateway logs, showing who reached which destination and how much. Identity, from the directory, showing who those people are and which scopes they sit in. ‍ The register answers more questions than people expect.

Insider Risk Breaks the Frequency Side of the Model

External threat models estimate how often somebody gets in and what they reach afterward. The susceptibility term does most of the work, weighing what an attacker can do against what the controls prevent. ‍ An insider is already inside. The credentials are valid, the access is entitled and the workflow is familiar. None of that makes the model harder to run, it changes which side of it breaks, and the break is on frequency rather than on magnitude. ‍

How to Audit AI Compliance from Both Sides of the Table

The tricky thing about AI compliance is that most organizations are going to experience it from both sides. You need to be able to explain how AI is being used inside your own organization, what it can access, and how you're managing the risk. At the same time, you need to understand how your vendors are using AI and whether that introduces new risk into your environment.

The Best Vendor Performance Management Tools and Software (2026)

If you manage vendors, supplier drift looks familiar. A delivery arrives late. A vendor misses a service-level agreement (SLA) target, and nobody flags it. Tickets sit unresolved, and quality dips just enough that it never makes the weekly stand-up. The problem is timing. Most teams find out a vendor missed its uptime or response-time targets at renewal, months after anyone could’ve fixed it.

What an AI Correlation Rule Does When Sources Disagree

A correlation rule joins records from several sources to establish that one thing happened. Two of those sources return different answers about the same identity, the same session or the same action. Something has to happen next, and what most systems do is pick a winner. ‍ Picking is the wrong default. The disagreement carries information that resolving it discards, and in a few specific cases the disagreement is the most useful thing the system produced. ‍

When a Cyber Loss Becomes a Recall

Cyber loss models are built around information leaving an organization. Records exposed, notification costs, regulatory penalty, litigation from affected individuals. Every category assumes the harm is informational. ‍ A compromise affecting vehicles in the field produces something the model has no term for. The vehicle can behave differently, the manufacturer may have to recall it, and the recall cost is frequently larger than anything the cyber categories would have produced. ‍

Approved Tools, Unapproved Agents

Approval works at the tool layer and it works well. A platform is assessed, terms are reviewed, a data processing agreement is signed, the tool enters the register, and named identities are entitled to it. Everything about that maps cleanly. ‍ Then somebody uses the approved platform to assemble an agent that acts on their behalf, with its own reach and its own credentials. The approval covered the application.

Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached

Computers are not safe. Even the best hardware and software products have the potential to conceal as-yet unknown vulnerabilities. And they aren’t all made that well. Many are shuffled into the world without a plan to detect, remediate, and notify users of those vulnerabilities. The EU’s Cyber Resilience Act aims to improve that situation.

A Complete Audit Trail That Names No One

An AI assistant reads four hundred documents across a tenant. Every read is logged. The application is named, the file is named, the timestamp is exact, and the access is attributed to an account that belongs to nobody. ‍ The audit trail is complete and it cannot answer the question an auditor asks. Nobody asks whether an access was recorded. They ask who reached the data and whether that person was authorized, and a shared service account answers neither. ‍

When the Loss Is Downtime Rather Than Data

Most cyber loss models are shaped around a breach. Records exposed, notification cost per record, regulatory penalty, credit monitoring, litigation. The arithmetic is well established and the inputs are reasonably well evidenced. ‍ Apply that model to an outage where nothing left and nothing was taken and every one of those categories returns zero. The organization was down for four days and the model reports almost no loss, which is not a calibration problem but the wrong model. ‍

Evaluating Risk Remediation Software for Enterprise Scalability

Enterprise software delivery is accelerating with more applications, more teams, more pipelines, more third-party code shipping faster than ever. And you can add the compounding risks of AI onto all of that. At the same time, compliance pressure is rising across development, security, and audit teams.

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Introducing App Store Threat Detection: Visibility Where Brand Monitoring Couldn't Reach

In January 2024, Craig Raw, the developer of the real Sparrow Wallet, a Bitcoin wallet app, warned that a fake version of his app was live on the Apple App Store. He reported it repeatedly, but the listing stayed up. By August 2025, three people had lost a combined $1.8 million to it: Jalen Delgado (about $120,000 in May 2025), James Ramirez (about $875,000 in July 2025), and Christopher Ellis (about $840,000 in August 2025). All three are now suing Apple. The complaint, Ramirez, et al. v.

Best Shadow AI Governance Tools for Enterprises: Buyer's Shortlist

Security teams already know employees use generative AI. The harder problem is buying the right platform before unsanctioned apps move sensitive data outside your visibility and control. UpGuard research found 81% of employees and 88% of security leaders use unapproved AI tools, and 45% of workers find a workaround when their employer blocks an app. That last number should shape your buying criteria more than the first two. Demand doesn't disappear when you block it. It moves somewhere you can't see.

Quantifying Cyber Risk Without Revenue to Lose

A public body has no revenue to lose, no share price to move and no insurance market pricing it the way one prices a manufacturer. It faces the same regulatory pressure to quantify cyber exposure as anyone else, and the standard model's central input does not exist. ‍ Substituting the loss categories is the easy half and it is where most guidance stops. The harder question is what the resulting figure is for, because the decisions a private company makes with it are mostly unavailable. ‍

When the AI Arrives Inside Software You Already Bought

An application that was AI-free at the last audit may be processing corporate data through a language model today. Nobody procured it, nobody approved it and nobody was asked. A vendor shipped a release. ‍ Third-party AI governance is built almost entirely around procurement. Assess the vendor, negotiate terms, sign a data processing agreement, add the tool to a register. The apparatus requires a purchasing event, and an embedded feature produces none, so the apparatus never engages. ‍

Key Features of an Insider Risk Management Program

Most organizations already have an insider risk management (IRM) program in some form. They have a tool, a dashboard, and an analyst reviewing alerts. What they often lack is a program built on the specific capabilities that turn activity logs into stopped incidents and reduced insider risk.

Top 4 enterprise risk management software solutions

Good enterprise risk management software gives you one place to record and score every risk, keeps that record current by watching your controls instead of waiting for a quarterly review, maps risks to the frameworks you report against, connects to the tools your teams already use, and turns all of it into dashboards your executives and board will read. The hard part is telling which products do those things well and which just store risks in a nicer grid. Below are the features that matter, a scorecard to weigh them, and four tools worth a look.
Featured Post

Why Annual Third-Party Cyber Risk Assessments Are No Longer Enough

As regulators tighten expectations and cyber attacks increasingly exploit supply chains, organisations must shift from periodic vendor assessments to continuous third-party cyber resilience. For years, third-party cyber risk management focused primarily on vendor due diligence and annual security assessments. The objective was simple: determine whether a supplier met an acceptable level of security at a specific point in time.

The Best IT and Cyber Risk Management Software

When you search for IT risk management software, the results rarely agree on what the category is. Product pages pitch enterprise governance, risk, and compliance (GRC) suites. Tool roundups mix project trackers with cyber platforms, and review aggregators combine tools that solve different problems. If you're a security analyst or CISO trying to shortlist platforms, that ambiguity costs you weeks and often ends in a proof of concept with the wrong vendor.

One Domain, Two Tenants, Only One Governed

An organization licenses ChatGPT Enterprise. An employee opens a second browser profile, signs into the personal account already logged in there, and pastes a customer extract into it. Same laptop, same managed browser, same corporate egress, same person, same web address. ‍ Every control in the path reads that session as ordinary and correct, because by every attribute any of them can see, it is.

Quantifying Cyber Risk With No Incident History

A company too young or too small to have an incident history still has to answer the underwriter at renewal, the enterprise customer running a security review, and the board asking what the exposure is. The usual objection is that quantification needs a baseline and there is none. ‍ The objection rests on a mistaken assumption about how these models work.

Four Functions, One Obligation, No Owner

The standard answer to fragmented AI compliance is a responsibility matrix mapped across the lifecycle. Procurement accountable at intake, legal responsible for regulatory vetting, engineering accountable at implementation, security accountable for monitoring. Every stage has an owner and every function knows its part. ‍ Read that arrangement carefully and the problem is visible inside the solution.

Evidence on Demand, and Why Most Programs Cannot

A governance program looks complete until somebody asks it to prove something on a deadline it did not set. A supervisor sends an information request. An underwriter asks for control coverage before binding. A prospect's security team asks how a specific control operated last quarter, and the deal waits on the answer. ‍ Most programs can describe what they do accurately and cannot evidence it inside the window. The difference is not a documentation problem.

What a Cyber Risk Number Cannot Tell You

Arguments for quantifying cyber risk are abundant and mostly sound. What gets published far less often is a plain account of what a modeled figure does not tell you, which is unfortunate, because stating the limits is more persuasive to a skeptical audience than another argument for the method. ‍ We build these models. What follows is what they cannot do, written plainly, followed by what remains useful once those limits are accepted. ‍

From Hotspots to Lookalike Domains: 3 Phishing Tactics to Watch

In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.

Exploitability Without Exploitation: When Attention Is the Signal

Nucleus Insights flagged 14 vulnerabilities with real-world exploitation activity that looked risky before CISA added them to KEV. The key takeaway: all 14 were later listed in KEV. Acting on those signals would have been the right call every time, just earlier.

Top 7 Recommended Digital Risk Protection Platforms in 2026

The best digital risk protection platforms in 2026 are CloudSEK XVigil, ZeroFox, Recorded Future, Flashpoint, Check Point External Risk Management, Group-IB, and ReliaQuest GreyMatter DRP. They separate less on what they detect, since every vendor scrapes the same forums, than on whether they validate a finding, remove it, and connect it to an attack path. No two are strong at the same jobs.

Introducing Subprocessor listing in Trust Center profiles

At UpGuard, we believe your Trust Center should be the single place your prospects and customers go to get their trust questions answered. Today, we're excited to announce subprocessor listing in the Trust Center. This capability lets you publish your subprocessors directly where buyers already look for trust signals. You can also keep that list up to date and enable customers to subscribe to updates.

Cybersecurity Leaders React to OpenAI's Hugging Face Breach UpGuard

In July 2026, OpenAI's own AI agents escaped their sandbox and reached Hugging Face's production systems during an internal cybersecurity evaluation. In its latest report, OpenAI called the incident "a warning shot for us and for the world." We asked cybersecurity leaders for their reactions to the breach and what it signals for every team racing to deploy AI. One detail stands out. Hugging Face's own systems detected the attack and traced its full shape, but the alert never escalated high enough for a human to act on it.

Three Frameworks, Three Definitions of AI Risk

Cross-mapping tables for AI evidence in life sciences already exist and are broadly right. Data integrity practice lines up against data governance requirements, software lifecycle logs against technical documentation and logging, human review checks against human oversight duties, post-market surveillance against post-market monitoring. Build one repository, present it two ways. ‍ All of that is sound and it starts one step too late.

Single-Agent Monitoring Records Nodes, Not Edges

Monitoring an agent tells you what that agent did. Every useful question about a multi-agent deployment concerns what happened between agents, and those are properties of the connections rather than of the participants. A per-agent view records nodes and the problems live on the edges. ‍ The shortfall is not a tooling problem waiting on a product.

A Risk Number Does Not Decay on a Smooth Curve

An annual quantification gets produced in March and quoted as fact in November. Everyone involved knows the figure has aged and nobody knows by how much, so it keeps being presented with the same confidence it had on the day it was signed off. ‍ The usual framing is that a number decays gradually and needs refreshing more often. The framing is half right and it misleads on the part that matters, because most of the decay does not happen gradually at all. ‍

How to Choose Trust Center Software

Trust center software is what helps you publish a branded, access-controlled security page so buyers can self-serve certifications, policies, and answers to previously completed questionnaires. The tool helps vendors proactively share their security posture with potential customers and efficiently address common security concerns that block sales. Don't confuse this with Microsoft Office Trust Center. That's an entirely different tool that governs macros and active content in Excel and Word.

Biggest Data Breaches in Telecommunications (Updated September 2026)

Telecommunications providers sit at the center of modern life, carrying the calls, messages, locations, account credentials, and identity data that connect billions of people and businesses. Which makes them uniquely valuable targets: criminals want subscriber records they can monetize, while nation-state actors want access to the networks themselves. The biggest telecom data breaches show how quickly weak security measures can escalate from a customer privacy incident into a national security event.