Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Same Numbers, Two Audiences: Insurer and Board

The same quantification run supports two conversations that happen weeks apart. One with a board asking whether the organization is managing cyber risk sensibly. One with an underwriter deciding what to charge for it. ‍ Most guidance treats these as a formatting problem, where the board version gets charts and the submission gets detail.

State AI Laws Change Faster Than Compliance Programs

Colorado passed the first comprehensive state AI law in May 2024, and organizations spent the following year building impact assessment processes against it. Those obligations never took effect. The statute was delayed twice, blocked by a federal court, then repealed and replaced by a narrower framework before its own effective date arrived. ‍ Anyone who built a compliance program to that specific statute prepared for a regime that never existed.

Ask Why Before You Walk Away from a VMware Deal

Here is a deal that almost died for the wrong reason. The customer said, “We need Hyper-V.” The partner logged it as a technical requirement, qualified the opportunity out of any VMware conversation, and moved on. Reasonable enough. That is what a stated requirement is supposed to mean. Except it was not technical. When someone finally asked why Hyper-V, the answer had nothing to do with the hypervisor.

Get Your CTEM Initiative Moving with Seemplicity

CTEM scoping isn’t about putting everything you can scan into scope. It’s about defining what matters most to the business and keeping that definition current as your environment changes. Get scoping right, and every stage that follows—from discovery to prioritization and mobilization—becomes more focused, relevant, and effective. Continuous Threat Exposure Management breaks down into five stages: scoping, discovery, prioritization, validation, and mobilization.

Code is the easy part with Rohan Varma from OpenAI | Zero-Shot Learning

As a product leader who went from working on Cursor to OpenAI’s Codex, Rohan Varma got a personal preview of a shift most developers are just beginning to catch up to. His conversation with 1Password CTO Nancy Wang upends the idea that AI helps developers write code faster, reimagines code reviews, and explores how developer skills expand once agents take over implementation. In this episode: Zero-Shot Learning is a builder-to-builder podcast about how AI systems are designed, deployed, and secured. Subscribe for more.

Google Authenticator vs YubiKey: Which Authentication Method Is More Secure?

Compare Google Authenticator and YubiKey to understand how each authentication method works, their security strengths, phishing resistance, deployment considerations, and which option is best for your organization. Passwords alone are no longer enough. Multi-factor authentication (MFA) is now the baseline but not all MFA methods are equally secure. Two of the most commonly compared options are Google Authenticator, a free smartphone app, and YubiKey, a physical hardware security key.

Continuous Compliance Monitoring: A Practical Guide

83% of organizations reported moderate or major delays from manual compliance work in 2026, while 53% said one full-time employee's worth of effort is spent on evidence collection, according to the 2026 State of Continuous Compliance Monitoring report. Those figures describe the operational problem more accurately than another promise of an audit-ready dashboard.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

In July 2026, researchers at Noma Labs coaxed GitHub's new Agentic Workflows into leaking data from a private repository. It wasn’t from malware. They created a plausible-looking issue in a public repository containing instructions for the agent to retrieve information from other repositories in the organization. After testing variations of the prompt, they found that adding one word, "Additionally," was enough to get past GitHub's guardrails.

How Do You Operationalize CTEM and Prove It's Working?

Having the right security platform is only part of the equation. Two organizations can have similar security stacks and still achieve very different outcomes depending on how they operationalize their Continuous Threat Exposure Management (CTEM) program. In this video, learn what separates reactive, ad hoc security validation from a mature CTEM program—including: See how a structured CTEM program can turn continuous security validation into measurable progress across your organization.