Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Has Entered the SOC. Governance Has to Catch Up.

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems. For CISOs, the bigger question is whether governance reaches all the way into the security workflows where AI is beginning to act. Beth Dannemiller, Senior Director, Product Marketing For the last several years, CISOs have been asked a familiar question by boards: What are we doing with AI? That question is changing.

CT alerts: know when someone gets a certificate for your domains

A couple days ago, I told you how a spammer got a certificate for dev-docs.trackjs.com, and that we only found out because Google emailed us. Google knew because the spammer claimed the hostname in Search Console. An attacker running a phishing page wouldn’t have done that, but they would still need a certificate. Every publicly trusted certificate gets written to a public log, and we track that log in our database. We just weren’t watching it. Now we are, and you can too.

Egnyte Named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026

We’re thrilled to let you know that Egnyte has been named a Leader in the IDC MarketScape: Worldwide Intelligent Content Services 2026 Vendor Assessment (#US54137426, September 2026). IDC’s report evaluates vendors on the strategies and capabilities that matter as content platforms become the foundation for enterprise AI.

Stop Chasing Tabs: Bringing Threat Research Home to the Browser

We all know the routine. You’re deep into a new threat report or a breaking blog post, and the tab management anxiety starts to kick in. You find a suspicious indicator, copy it, pivot to your internal tools to see if you’ve seen it before, paste it into a notepad, and then—maybe—try to get it into an actual investigation. By the time you’ve validated the intel, you’ve lost the trail. Threat research happens in the browser. Its time your workflow did too.

ISO/IEC 42001 and the Governance Gap Between Pilot and Production

In July 2025, a Replit coding agent deleted data from an application’s production database during a public experiment. The data was recovered, and Replit responded by separating development and production databases, limiting the agent’s access to the development environment, and strengthening the recovery experience. It later introduced a planning mode that allowed users to work with the agent without changing code or data.

How to Evaluate and Choose the Best GRC Software in 2026

Evaluating GRC software in 2026? Every platform says it covers governance, risk, and compliance. What a demo will not show you is whether it runs on one connected system or a stack of separate tools sharing a single login, and that difference decides whether you can answer leadership on the spot or spend a week rebuilding the picture. This video walks through five criteria for judging any GRC platform, and the question to ask a vendor on each one.

DPDP Readiness for Indian Businesses From Compliance Requirements to Data Protection

India’s Digital Personal Data Protection (DPDP) framework is changing how businesses need to manage and protect personal data. In this video we explore what DPDP readiness means in practice and how organizations can strengthen their approach to protecting personal data throughout its lifecycle. The session covers: The webinar also discusses how backup and recovery capabilities can support a broader data-protection and compliance strategy, including encryption, access control, immutable storage, policy-based retention, centralized management, and recovery.

When Cybersecurity Becomes Pay to Play

Awards you have to pay to win, events you have to pay to attend and conferences that expect speakers to work for free. When did recognition and expertise in cybersecurity become something you have to buy? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode I'm joined by security consultant and regular community speaker James Bore and Gary Hibberd, co-founder of Consultants Like Us and the Real Cyber Awards and Conference.

3 Things CISOs Need to Know About Microsoft's ISOC Announcement

Cost pressure can decide what your security team gets to see. A useful log source gets left out. Investigation history gets shortened. Analysts work with the evidence the organization could afford to keep. That is the part of Microsoft's Integrated Security Operations Center, or ISOC, announcement I keep coming back to. Bringing SIEM capabilities into the Defender experience, using native security data, and changing the economics gives customers a reason to revisit those decisions.