Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Hot Take: Over-permissioned agents will be the next big breach.

The next big breach won't be a hacker. It'll be an over-permissioned agent. Someone approved an agent action at some point, for a reason that made sense at the time. But access persisted long after a task was performed. Stale permissions without human intervention could turn into exposure. Listen to perspectives from people who see this problem from different roles.

DORA Compliance: Inside a Fireblocks Pooled Audit

An internal auditor from Boerse Stuttgart Digital explains how a Fireblocks-hosted pooled audit helped meet DORA's third-party ICT requirements. Instead of every customer auditing Fireblocks one by one, the pooled audit community joined forces on a single common audit: shared scope, shared evidence, shared result. In this conversation, the pooled audit coordinator walks through how the community set the scope, why a pooled audit covers customer-specific requirements that a standard SOC 2 might miss, and how Fireblocks supported the process with subject matter experts, documentation, and on-site coordination.

The Difference Between Hype and Documented Risk

How do security leaders separate legitimate AI security concerns from fear, uncertainty, and doubt? In this clip, Rik Ferguson explains why today's warnings about autonomous threats are different from past predictions. The evidence is already being documented, tested, and observed across the cybersecurity industry, making this a present challenge rather than a future possibility.

Respond to security threats faster with Tines and Observability Pipelines

Security teams face a flood of noisy logs that arrive in many formats, and often without the context teams need to detect and prioritize threats. But even normalized and contextually enriched log data is only as useful as the speed at which teams can act on it. Any step that requires manual effort can become a bottleneck that makes it difficult to keep pace with the volume.

To self-host or not to self-host your password manager

For an individual, self-hosting a password manager is rarely realistic. Most people don't run servers, handle patching, or manage uptime, so a cloud vault ends up being the only practical choice. For an organization, self-hosting becomes a real decision, one your security and IT teams can make deliberately. And once you can choose, you also take on the risks and the responsibility that come with that choice.

Introducing Adaptive Intelligence: Undermining the economics of every bot attack

Modern bot threats are increasingly driven by determined, sophisticated attackers. Often it is not even one person, but a group trading techniques with each other or a commercial service sold to anyone willing to pay. For many of them, getting past bot detection is a full-time job they genuinely enjoy. Block them and they get to work, finding a workaround. AI has simplified this further, making it even easier to set up complex configurations for attackers, lowering the overhead of an attack.

What Can Nico Hülkenberg Teach Cybersecurity Pros?

InfoSec conference speakers should give cybersecurity professionals a clear reason to invest their time in attending. The decision to book Formula 1 driver Nico Hülkenberg for InfoSec Europe raises an interesting question about whether celebrity keynote speakers deliver more value than experienced industry practitioners.

Unlock MSP Growth: How AI Drives Operational Efficiency and New Revenue

Artificial intelligence is no longer a future consideration for MSPs because it is already reshaping how leading providers run their businesses, protect their clients, and create new revenue streams. Separating real business value from hype requires a clear-eyed, practitioner-driven perspective. Join Marc Laliberte and a panel of MSP and security operations leaders for a candid discussion on how AI is being deployed today.