Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Soteria scaled its MDR practice on LimaCharlie

Soteria started as a consulting and advisory firm focused on penetration testing and incident response. Co-founder and managing principal Paul Ihme describes the company's growth from there as organic, expanding into virtual CISO work, offensive security, managed detection and response, and Microsoft 365 security products.

Investigate your network in plain English: introducing Natural Language Query

Every SOC analyst has been there. An alert fires. You know what you need to find. Maybe it's all outbound connections from a specific host that spiked overnight. Maybe it's every DNS query over 100 characters from a subnet you're watching. You know the question. What you don't know is the exact query syntax you need to ask it. So you open the documentation. You search for field names. You try a query, get it wrong, adjust, and try again. Minutes pass.

Canada Raises the Bar for Critical Infrastructure Cybersecurity. Is Your Network Ready?

Canada has taken a significant step toward strengthening national cyber resilience. With Royal Assent now granted to Bill C-8, the Government of Canada is establishing a new framework for protecting critical cyber systems and securing the country's most essential services.

What We Learned Testing Jev on Security Alert Triage

Yaniv Zimmer is an AI researcher at Torq, focusing on cybersecurity research at the crossroads of artificial intelligence, deep learning, and defensive operations. Drawing on extensive experience within Unit 8200 alongside industry and academic AI research roles, his work centers on advancing SOC AI architectures and threat detection capabilities Like a lot of people, we were excited when Jev launched. The premise is genuinely useful in production: an intelligent language model built for classification.

Rubrik MSP Unscripted Episode 7 - Featuring Rajat Shah

In this episode of MSP Unscripted, Nawaz Ali sits down with Rajat Shah, Product Manager at Rubrik, to talk about the launch of multi-tenancy and what it means for managed service providers. Nawaz and Rajat discuss how shared infrastructure can help MSPs improve service economics while maintaining strong tenant isolation, expand opportunities across SMB and mid-market customers, and make services such as Backup as a Service, Disaster Recovery as a Service, isolated recovery environments, and advanced cyber recovery capabilities more scalable.

How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important question is what happens to human expertise when machines take on more of the investigative workload. Across the industry, there is growing concern that AI will narrow the path into technical careers.

The "I" in FOCI: When Foreign Influence Becomes Cyber Risk

Foreign Ownership, Control, or Influence (FOCI) risk is often discussed as an ownership problem. Who owns the supplier? Who sits on the board? Is there a parent company tied to a foreign government? Does that relationship trigger CFIUS, export controls, sanctions, or a facility clearance review? These questions matter, but they do not capture the full risk picture. For C-SCRM program stakeholders, the most important word in FOCI is not ownership or control — it is influence.

Building an AI-Ready Engineering Team in 2026

Two engineering teams can have access to the same AI tools and get very different results. The difference is rarely the technology. It's engineering practices, technical leadership, and a shared understanding of where AI actually helps versus where it produces fast-looking work that creates problems later. Building an AI-ready team isn't about replacing developers with automation or hiring a separate group of AI specialists. It's about preparing existing teams to use AI without giving up the software quality, security, and accountability the work requires.

DDI Central 6500: Modern DHCP, unified visibility, and layered access control

DDI Central's release 6300 focused on authentication and identity: GSS-TSIG for secure DNS updates, LDAP/LDAPS-based user provisioning, and native Windows scavenging. Each aimed at cutting down the manual work behind keeping DNS and user access clean. DDI Central 6500 shifts focus elsewhere.

No more blind trust: How risk-based authentication strengthens identity security

Traditional digital authentication methods have allowed users to enter and IT infrastructure if they hold the right key. Username and password alone provided limited context around the authenticity of the access attempt. But today, the person with the credentials may not claim who they are.