When Attackers Are Faster Than the Patch
Between disclosure and exploitation of a vulnerability, only days often pass today. The State of Vulnerabilities Report 2026 reveals what matters now.
Between disclosure and exploitation of a vulnerability, only days often pass today. The State of Vulnerabilities Report 2026 reveals what matters now.
A virtual CISO takes over the security expertise in medium-sized businesses. However, certain responsibilities under Paragraph 38 of the BSIG (Federal…
CISO Mandate 2026: Which decision-making, veto, and escalation rights must be documented in writing so that it's clear who can act during an incident.
Supply chain risks according to NIS2 and DORA: Why the vendor questionnaire isn't enough and how a TPRM program with tiering, a register, and …
The KRITIS umbrella law has been in effect since March 2026 and makes physical resilience mandatory.
Service accounts can survive disabled services for years. This is why OWASP considers it the number one NHI risk and how CISOs can identify …
ISO 27001 is often considered proof of compliance with NIS2. However, the BSI takes a different view.
Cloud security: CrowdStrike expands Project QuiltWorks with AWS. What the alliance against AI-driven attacks accomplishes and what teams must do…
SearchLeak turned Microsoft 365 Copilot into a data leak via a link. What parameter injection teaches about Copilot governance and AI security.
The NIS2 oversight has begun: the BSI registration deadline has passed, and the authority is now reviewing and imposing sanctions.