More alerts are making your team slower, and an outcome-based SOC fixes that

In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He sh… Continue reading More alerts are making your team slower, and an outcome-based SOC fixes that

The five step plan that cuts security budget waste

In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, a… Continue reading The five step plan that cuts security budget waste

The MDR renewal question: What changes when AI can handle the alerts

For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (… Continue reading The MDR renewal question: What changes when AI can handle the alerts

Your vendor’s vendor might be the real breach risk

In this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company … Continue reading Your vendor’s vendor might be the real breach risk

Why SBOMs, signing, and provenance still don’t tell you if software is safe

We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprise… Continue reading Why SBOMs, signing, and provenance still don’t tell you if software is safe

Week in review: Accenture data breach, great open-source cybersecurity tools

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work wi… Continue reading Week in review: Accenture data breach, great open-source cybersecurity tools

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers… Continue reading July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

Turning software supply chain security into a daily habit

In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day … Continue reading Turning software supply chain security into a daily habit

How to implement a continuous offensive security testing program

The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, t… Continue reading How to implement a continuous offensive security testing program

Your company already adopted AI and nobody is governing access

In this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon connects a free AI too… Continue reading Your company already adopted AI and nobody is governing access