Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Often Should Organizations Perform DDoS Testing?

Most security teams have a firewall policy, a patch schedule, and a penetration testing calendar. DDoS resilience is often the exception, tested once, checked off, and forgotten until an actual attack exposes the gap. That's a real problem. Distributed denial-of-service threats aren't static, and neither is your infrastructure; the right answer to how often organizations should test depends on several variables, and the baseline is probably more frequent than you'd guess.

AI Governance When the AI Is Inside the Network

Most AI governance guidance assumes the AI sits beside the business. A model assists a decision, a copilot drafts a document, an agent processes a queue. Governance then asks who reviewed the output and whether the data was handled properly. ‍ In a telecom network the AI is inside the product.

Nobody Knows How Many AI Agent Breakouts There Have Been

Reuters reported at the end of July that OpenAI had found further cases of autonomous agents escaping containment, uncovered while investigating the Hugging Face intrusion. The reporting could not establish how many, when they happened or under what circumstances, because the company and outside experts were reviewing log data from earlier in the year to work it out.
Featured Post

Cyber Risk and Incident Response: A Growing Priority Across Industries

Cyber risk has become a dominant priority for organisations across nearly every sector. As the severity and velocity of the threat landscape and technological change continue to accelerate, organisations are under increasing pressure to ensure they can keep pace and recover quickly in the aftermath of a cyber event. A core focus for many organisations is strengthening their incident response capability: how effectively the business can react and recover when an attack occurs.

Dark Web Monitoring Vendors Compared

According to the 2026 Context Gap research, 79% of organizations first learn about active threats from outsiders rather than their own tooling. You've watched another headline roll past of a Fortune 500 company exposed on the dark web. Each story ends the same way: with a breach notification and inevitable board questions. You decide your company won't be the next case study. You need a tool that'll find your exposures before an attacker does.

Why do I need a cloud risk assessment?

Your business almost certainly runs on cloud services. From document storage, email and finance software to your customer data and internal systems, the chances are that most of what keeps your business operational lives, at least in part, in the cloud. And yet, for many businesses, the question of whether that cloud environment is secure rarely gets asked. It tends to be presumed. After all, you’ve got bigger things to worry about. You’re with a reputable provider.

13 essential cybersecurity frameworks, standards, and regulations explained

Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards.

When a Cyber Loss Becomes a Recall

Cyber loss models are built around information leaving an organization. Records exposed, notification costs, regulatory penalty, litigation from affected individuals. Every category assumes the harm is informational. ‍ A compromise affecting vehicles in the field produces something the model has no term for. The vehicle can behave differently, the manufacturer may have to recall it, and the recall cost is frequently larger than anything the cyber categories would have produced. ‍

Approved Tools, Unapproved Agents

Approval works at the tool layer and it works well. A platform is assessed, terms are reviewed, a data processing agreement is signed, the tool enters the register, and named identities are entitled to it. Everything about that maps cleanly. ‍ Then somebody uses the approved platform to assemble an agent that acts on their behalf, with its own reach and its own credentials. The approval covered the application.

What an AI Usage Inventory Cannot Tell You

Three reads from surfaces most organizations already own produce a usable AI usage register in a morning. Entitlement, from the identity provider, showing who is licensed for what. Activity, from network or gateway logs, showing who reached which destination and how much. Identity, from the directory, showing who those people are and which scopes they sit in. ‍ The register answers more questions than people expect.