Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Making Tines 3B

Description: Tines 3B is an AI-native environment that gives every team the power to build agents, apps, and automations with AI, and gives IT and security the control to govern that work safely across the business. Here, Eoin Hinchy (Co-founder and CEO), Stephen O'Brien (Head of Product), Eoghan Reid (Lead Product Designer), and Rosie Ellison (Product Manager) share the story behind building Tines 3B, and the mission driving it: making automation 100x simpler and 100x faster, without compromising on AI governance or control.

Introducing Tines 3B

Your teams are moving fast with AI — but is IT and Security able to see what's actually being built? IT and AI leaders are facing a career-defining challenge right now: AI-generated code and shadow AI spreading faster than anyone can track. Introducing Tines 3B — a single, secure environment that gives employees the freedom to build with AI, and gives IT and security the control to govern that work safely.

How a Network-First Strategy Buys Time for Patching

What can organizations do when a critical vulnerability can't be patched right away? In this video, Daniel dos Santos, VP of Research, explains how a network-first approach can reduce exploitability by restricting access to vulnerable services while remediation is underway. By limiting reachability, security teams can reduce risk and give patching teams the time they need to test and deploy fixes.

Don't Wait for a Crisis: Rehearse Your Zero-Day Response

How do you prepare for a zero-day attack before one impacts your organization? In this video, Daniel dos Santos explains why security teams should use past vulnerabilities and real-world attack scenarios to rehearse response plans. By testing decisions, controls, communications, and recovery actions—not just documentation—organizations can build confidence and improve readiness for future threats.

America's New Security Doctrine: Hardening Digital and Supply Chain Borders

In the span of six weeks this summer, the United States government issued three separate security directives that, on the surface, appear to address completely different problems. One tightens how federal agencies patch software vulnerabilities. Another creates a government-industry clearinghouse to triage AI-discovered bugs. The third restructures how defense contractors source the raw materials that go into missiles, aircraft, and military electronics. Different agencies. Different languages.

UK vs Europe: comparing the physical threat landscape facing the rail sector

Rail networks sit at the intersection of critical national infrastructure and daily public life, making them a persistent target for protest, industrial action, infrastructure crime and, in parts of Europe, suspected sabotage tied to geopolitical tensions. This analysis from CYJAX sets out the physical threat picture in the UK alongside that of the wider continent.

Torq SOC Brain: The AI SOC That Learns, Not Just Remembers

Back in June, I wrote a blog making the case that agentic triage alone isn’t an AI SOC. The way I see it, that’s like saying triage is the only responsibility of a SOC team. But as we know, the SOC’s responsibilities extend far beyond that, and these triage-only solutions don’t investigate threats, contain them, or close cases. That work is still left to the SOC team; the bottleneck is just shifting.

TITAN AI Demo Series: What a Mature TPRM Program Looks Like with TITAN MAX

Most Third-Party Risk Management (TPRM) programs can be compliance-driven and reactive. A mature program looks different. See what threat-informed TPRM with continuous monitoring looks like in SecurityScorecard's Demo Tuesday series. Vendor engagement drives real remediation. Your team spends time on risk decisions instead of manual busywork. TITAN MAX pairs the TITAN AI platform with SecurityScorecard's expert team to run these workflows on your behalf Continuous monitoring through a dedicated Vendor Risk Operations Center Faster questionnaire cycle times, without adding headcount.

Black Hat FOMO? Dojo AI Demo

On this episode of Masters of Data, we take you inside the Dojo AI demo we're bringing to the show floor at Black Hat. We walk through the SOC Analyst Agent, Mobot, and MCP back to back. SOC Analyst Agent triages every tier one alert down to the one that actually matters, and Mobot picks up from there, running the investigation in plain English to track down other phishing victims and lateral movement. We also show how MCP pulls that same insight into Claude or Slack. SOC leads tired of alert fatigue and analyst burnout will want the numbers here: 100% of tier one alerts triaged automatically, and 25 hours a week back per person.