Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

State of Application Security

Our View from the Front Lines of Technical Assessments Kroll analyzed five years of penetration testing data. Of the trends that emerged, we focus on three in this report: the static application security testing (SAST)/software composition analysis (SCA) plateau, the need for more attention around authentication and authorization, and the security health divergence, which shows that regulation is not a reliable predictor of attack surface health.

Agentic AI-Assisted Penetration Testing: AI Scale. Human Precision

When Mythos launched, headlines warning of its potential dangers were prolific. For security risk leaders, it felt like a watershed moment, one that signaled that AI had arrived, but simultaneously raised widespread concern about risk. Many wanted to understand how real the risk was for their organization and what should be done about it.

Anatomy of a Cyber Incident: Why Recovery Fails When Personas Aren't Aligned

Despite their complexities, cyber incidents often start in a very similar manner. There is a helpdesk ticket that appears routine, a slightly unusual login attempt or a system that might just need a restart. By the time an organization formally declares an incident, the attacker has likely already been inside for hours, sometimes longer, moving quietly through cloud platforms, SaaS applications and identity systems long before anyone notices the warning signs.

A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework

From September 11, 2026, any manufacturer, importer or distributor of hardware and software products with digital elements made available on the EU market must comply with the Cyber Resilience Act (CRA). The harmonized standards under the CRA are still being drafted, and the first will not be finalized before manufacturers need to act.

SEC Advances Crypto Asset Capital Formation Framework

On August 18, 2026, the SEC proposed Regulation Crypto Assets1, a new regulatory framework intended to create a tailored registration exemption regime for certain crypto asset offerings while maintaining core investor protection requirements. The proposal represents a significant evolution in the SEC's approach to digital assets and could provide the clearest pathway to date for crypto issuers seeking to raise capital in the United States.