Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Introducing Acronis Cyber Compliance: Continuous compliance built for MSPs

There is no shortage of guidance available to MSPs on how they should secure customer environments. Security frameworks, industry standards, regulatory requirements and insurance obligations all provide recommendations on the controls organizations should have in place. Yet despite this abundance of guidance, cyber incidents remain common and continue to increase. At the same time, requirements are becoming more complex.

Securing Public Sector Software in 2026: Security Debt Demands Action

Public sector software, from defense platforms to K-12 student information systems, is accumulating a dangerous backlog of unresolved vulnerabilities. That’s the headline finding from Veracode’s 2026 State of Software Security report, and the data behind it is unambiguous: the pace of vulnerability discovery has structurally outrun the capacity to fix them.

Privileged Account and Session Management (PASM) Explained

Privileged accounts have elevated access that can be used to rewrite system configurations, alter sensitive databases, create new admin users, and exfiltrate confidential customer data. This makes them attractive targets for attackers and risky when poorly managed. Basic passwords and network firewalls aren’t enough to protect them. You need to monitor them continuously. This is where Privileged Account and Session Management (PASM) becomes essential.

How Conditional Access Protects Microsoft 365 Apps From Unmanaged Devices

Your sales representative logged into Outlook from a coffee shop laptop that isn't enrolled, isn't encrypted, and hasn't seen a security patch in eight months. Should Microsoft 365 let that sign-in through just because the password was correct? That single question is why conditional access exists. Passwords tell you who someone claims to be. They say nothing about whether the device behind that login is safe to trust with your company's email, SharePoint files, or Teams chats.

5 Tips for Scaling Cloud Security Without Adding Complexity

For years, managed service providers (MSPs) have secured customer cloud environments through periodic reviews of each tenant. That approach worked when a customer ran two or three cloud applications. As organizations adopt more SaaS applications, the number of environments, identities, and configurations to monitor also increases. The challenge is already visible.

Quantifying Cyber Risk With No Incident History

A company too young or too small to have an incident history still has to answer the underwriter at renewal, the enterprise customer running a security review, and the board asking what the exposure is. The usual objection is that quantification needs a baseline and there is none. ‍ The objection rests on a mistaken assumption about how these models work.

One Domain, Two Tenants, Only One Governed

An organization licenses ChatGPT Enterprise. An employee opens a second browser profile, signs into the personal account already logged in there, and pastes a customer extract into it. Same laptop, same managed browser, same corporate egress, same person, same web address. ‍ Every control in the path reads that session as ordinary and correct, because by every attribute any of them can see, it is.

SACR's New ECP Framework: What It Means for AI and Data Security

A new report from Software Analyst Cyber Research (SACR), The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security, outlines a new era of endpoint security shaped by AI agents, copilots, SaaS applications, browser-based workflows, and increasingly autonomous activity. The report introduces Endpoint Control and Prevention (ECP) as a framework for understanding this shift and the new security capabilities it requires.

The Best IT and Cyber Risk Management Software

When you search for IT risk management software, the results rarely agree on what the category is. Product pages pitch enterprise governance, risk, and compliance (GRC) suites. Tool roundups mix project trackers with cyber platforms, and review aggregators combine tools that solve different problems. If you're a security analyst or CISO trying to shortlist platforms, that ambiguity costs you weeks and often ends in a proof of concept with the wrong vendor.

Intel Chat: OpenAI's Astra hits Critical, DEF CON phishing, Philippine nuclear breach [346]

Intel Chat with Matt Bromiley and Chris Luft. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.