Targeted Risk Analysis (TRA) is not just a best practice; it's crucial until March 31, 2025. After this date, it becomes a requirement for several controls across many assessment types. This shift is significant because it applies equally to merchants and…
Targeted Risk Analysis (TRA) is not just a best practice; it's crucial until March 31, 2025. After this date, it becomes a requirement for several controls across many assessment types. This shift is significant because it applies equally to merchants and…
The field of cybersecurity has long obsessed over the "zero-day" exploit, the elegant, unpatched hole in the armor. But the July 2026 intrusion into Hugging Face and OpenAI’s internal infrastructure reveals a far more…
The field of cybersecurity has long obsessed over the "zero-day" exploit, the elegant, unpatched hole in the armor. But the July 2026 intrusion into Hugging Face and OpenAI’s internal infrastructure reveals a far more…
What happens when you ask an AI to read your book about AI being smarter than it wants you to know and escapes? This was the question I had also but I never expected the result I recevied. I asked Claude Opus 4.7 to review the manuscript for “Nominal” and…
What happens when you ask an AI to read your book about AI being smarter than it wants you to know and escapes? This was the question I had also but I never expected the result I recevied. I asked Claude Opus 4.7 to review the manuscript for “Nominal” and…
Envision a virtual replica of a physical asset, process, or system that empowers you to monitor, simulate, and optimize its performance in real time. This is the transformative potential of digital twins, a technology that is reshaping…
Envision a virtual replica of a physical asset, process, or system that empowers you to monitor, simulate, and optimize its performance in real time. This is the transformative potential of digital twins, a technology that is reshaping…
By Jory Torres | Water Systems Engineer, Albuquerque Metropolitan District I know how that title sounds. I know it sounds like I've been drinking the Kool-Aid. Bear with me. I have numbers. I've been a water systems engineer for eleven years. For…
By Jory Torres | Water Systems Engineer, Albuquerque Metropolitan District I know how that title sounds. I know it sounds like I've been drinking the Kool-Aid. Bear with me. I have numbers. I've been a water systems engineer for eleven years. For…
Key Takeaway:Cybercrime losses reached $20.9 billion in 2025, up 26% in a single year. Yet only 4% of companies have fully integrated GRC systems. If you think a few spreadsheets and a policy binder will save you,…
Key Takeaway:Cybercrime losses reached $20.9 billion in 2025, up 26% in a single year. Yet only 4% of companies have fully integrated GRC systems. If you think a few spreadsheets and a policy binder will save you,…
Most supply chain failures don’t start with a missed shipment or a bad contract. They start with a quiet breach—a vendor with weak passwords, a data file that got altered somewhere between Point A and Point B, a third-party…
Most supply chain failures don’t start with a missed shipment or a bad contract. They start with a quiet breach—a vendor with weak passwords, a data file that got altered somewhere between Point A and Point B, a third-party…
AI-related attacks increased nearly 490% year over year. Read that again. I have spent two decades in cybersecurity, and that number still caught me off guard. We are not talking about a slow drift upward. This is the…
AI-related attacks increased nearly 490% year over year. Read that again. I have spent two decades in cybersecurity, and that number still caught me off guard. We are not talking about a slow drift upward. This is the…
PCI compliance isn’t just a checklist; it’s a moving target shaped by relentless attackers, shifting technology, and the simple fact that trust is hard to win but easy to lose. Understanding PCI Compliance in E-commerce PCI…
PCI compliance isn’t just a checklist; it’s a moving target shaped by relentless attackers, shifting technology, and the simple fact that trust is hard to win but easy to lose. Understanding PCI Compliance in E-commerce PCI…
When Horror Becomes Reality In 1931, horror author H.P. Lovecraft conceived of a nightmare creature called a Shoggoth, described as "formless protoplasm, able to mimic and reflect all forms and organs." It served as…
When Horror Becomes Reality In 1931, horror author H.P. Lovecraft conceived of a nightmare creature called a Shoggoth, described as "formless protoplasm, able to mimic and reflect all forms and organs." It served as…
Ever been in a meeting where everyone thinks they’re in charge until the real boss walks in? That’s what just happened in the PCI DSS community. On August 4, 2026, the PCI Security Standards Council (PCI SSC) dropped a…
Ever been in a meeting where everyone thinks they’re in charge until the real boss walks in? That’s what just happened in the PCI DSS community. On August 4, 2026, the PCI Security Standards Council (PCI SSC) dropped a…
SMBs are now the #1 target for ransomware groups. You're not too small — you're easy. That sentence lands differently when you know the numbers. In 2025, 88% of ransomware-related breaches involved small and mid-sized…
SMBs are now the #1 target for ransomware groups. You're not too small — you're easy. That sentence lands differently when you know the numbers. In 2025, 88% of ransomware-related breaches involved small and mid-sized…
AI Governance and Emerging Technologies: Why the Rules Matter as Much as the Innovation Here's a number that should stop you mid-scroll: by 2030, AI is projected to add $15.7 trillion to the global economy.…
AI Governance and Emerging Technologies: Why the Rules Matter as Much as the Innovation Here's a number that should stop you mid-scroll: by 2030, AI is projected to add $15.7 trillion to the global economy.…
Here's a stat that should stop you in your tracks: the average time it takes to identify a breach is 194 days. Let that sink in. Nearly seven months of an attacker lurking inside your network, moving quietly,…
Here's a stat that should stop you in your tracks: the average time it takes to identify a breach is 194 days. Let that sink in. Nearly seven months of an attacker lurking inside your network, moving quietly,…
The cybersecurity landscape has transformed dramatically. Attacks are more sophisticated, more frequent, and more damaging than ever, affecting everyone from multinational corporations to individual users.…
The cybersecurity landscape has transformed dramatically. Attacks are more sophisticated, more frequent, and more damaging than ever, affecting everyone from multinational corporations to individual users.…
Cybersecurity has always been a game of cat and mouse, but the rules are changing fast. Attackers are no longer relying solely on static code and brute-force tactics; they're weaponizing artificial intelligence (AI)…
Cybersecurity has always been a game of cat and mouse, but the rules are changing fast. Attackers are no longer relying solely on static code and brute-force tactics; they're weaponizing artificial intelligence (AI)…
Most organizations preparing for a PCI DSS assessment are focused on their systems, their data, their controls. Understandable. But there's a lesser-known requirement that catches companies off guard the geographic…
Most organizations preparing for a PCI DSS assessment are focused on their systems, their data, their controls. Understandable. But there's a lesser-known requirement that catches companies off guard the geographic…
Technology is advancing rapidly, and as cyber threats increase, the complexity of global regulatory environments has surged. Organizations must navigate a myriad of compliance requirements spanning privacy,…
Technology is advancing rapidly, and as cyber threats increase, the complexity of global regulatory environments has surged. Organizations must navigate a myriad of compliance requirements spanning privacy,…
Cyber threats are becoming increasingly sophisticated and persistent. Traditional cybersecurity measures, while important, often struggle to keep pace with the evolving tactics employed by cybercriminals. This is where self-healing…
Cyber threats are becoming increasingly sophisticated and persistent. Traditional cybersecurity measures, while important, often struggle to keep pace with the evolving tactics employed by cybercriminals. This is where self-healing…
Artificial Intelligence (AI) is revolutionizing the world, and while it provides incredible benefits, it also poses significant risks. In cybersecurity, AI is becoming a double-edged sword. On…
Artificial Intelligence (AI) is revolutionizing the world, and while it provides incredible benefits, it also poses significant risks. In cybersecurity, AI is becoming a double-edged sword. On…
The average enterprise runs 76 security tools. That's not a defense – it's an attack surface. The number sounds impressive. Seventy-six security tools, all blinking and humming, each promising to keep the bad guys out. But the math doesn't add up. More tools, more…
The average enterprise runs 76 security tools. That's not a defense – it's an attack surface. The number sounds impressive. Seventy-six security tools, all blinking and humming, each promising to keep the bad guys out. But the math doesn't add up. More tools, more…
Most people don’t notice digital trust until it fails. A spoofed email that looks exactly like one from their bank. A login attempt from a city they’ve never visited. A device that quietly phones home to somewhere it shouldn’t. By the…
Most people don’t notice digital trust until it fails. A spoofed email that looks exactly like one from their bank. A login attempt from a city they’ve never visited. A device that quietly phones home to somewhere it shouldn’t. By the…
Most AI security conversations are happening in the wrong room. While executives debate governance policies and compliance checklists, the enterprise's actual security architecture is being quietly and quickly…
Most AI security conversations are happening in the wrong room. While executives debate governance policies and compliance checklists, the enterprise's actual security architecture is being quietly and quickly…
The second day was more intense than the first. While day one focused on understanding the problem, day two concentrated on practical actions and, in some instances, recognizing what cannot be ignored…
The second day was more intense than the first. While day one focused on understanding the problem, day two concentrated on practical actions and, in some instances, recognizing what cannot be ignored…
Day one of the 2026 Gartner Security & Risk Management Summit covered a lot of ground. I was only able to attend six of the many sessions. A few that should make every security leader uncomfortable in exactly the right way. This article…
Day one of the 2026 Gartner Security & Risk Management Summit covered a lot of ground. I was only able to attend six of the many sessions. A few that should make every security leader uncomfortable in exactly the right way. This article…