Security Operations & Management
Top Stories
-
Tip
27 Jul 2026
A CISO's guide to security data lakes
A security data lake gives organizations a centralized repository of security information, but it can pose governance and operational risks. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
08 Jul 2026
CISO's guide to hiring for the right cybersecurity skills
The cybersecurity talent gap won't be solved by head count alone. CISOs need to fundamentally rethink how they recruit, how they retain talent and what skills they really need. Continue Reading
-
Feature
06 Jul 2026
The AI vulnerability storm is here: Is your security program ready?
AI platforms are poised to accelerate vulnerability discovery and exploitation faster than humans can manage. It's time for CISOs to rethink their security strategies. Continue Reading
-
Tip
02 Jul 2026
Perimeter to posture: A roadmap to zero trust maturity
Transforming an organization to take on a zero-trust posture is no small affair. A phased, thoughtful approach can bolster security while supporting business outcomes. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
30 Jun 2026
The agentic AI 'lethal trifecta': What CISOs should know
The very capabilities that make an AI agent useful also make it dangerous. Here's what CISOs should know about the agentic AI lethal trifecta, and what they should do about it. Continue Reading
By- John Burke, Nemertes Research
-
Feature
26 Jun 2026
How agentic AI threat intelligence aids NGO cyber defense: Case study
NGOs often lack the resources and expertise to defend against modern threat actors. Learn how one nonprofit is harnessing agentic AI threat intelligence to flip the script. Continue Reading
-
Feature
15 Jun 2026
Florida public sector training on SimSpace cyber range: Case study
Cyber ranges, once the domain of national defense agencies, are becoming more widely accessible. In the public sector, the state of Florida is leading the charge. Continue Reading
By- Alissa Irei, Senior Site Editor
-
Video
15 Jun 2026
Cyber insurance forces companies to rethink risk management
In this edition of the Reporters' Notebook video series, our cybersecurity reporters explore why cyber insurance is forcing organizations to quantify risk. Continue Reading
By- Richard Livingston, Site Editor
-
News
08 Jun 2026
CISO role changes as cyber-risk appetites in the C-suite grow
As cybersecurity fears in the C-suite wane, the cyber-risk appetites of executives and boards are changing. Find out what it means for cybersecurity spending and the CISO role. Continue Reading
By- Richard Livingston, Site Editor
-
News
03 Jun 2026
Lost in translation: Cybersecurity board reporting for CISOs
Cybersecurity board reports don't always land. At the Security and Risk Management Summit 2026, Gartner analysts suggested a novel way to communicate cyber-risk to corporate directors. Continue Reading
By- Richard Livingston, Site Editor
-
Opinion
02 Jun 2026
How to prepare security controls for future AI regulations
With so many competing compliance requirements related to AI, how could any CISO comply with all of them? Learn how to reconcile your AI strategy with the regulatory landscape. Continue Reading
By- Bernard Woo
-
Feature
29 May 2026
EO 14390 raises stakes for enterprise cybersecurity
Reframing cybercrime as a national security issue, EO 14390 could lead to stronger links between government and the private sector. Find out what it means for enterprise security. Continue Reading
By- Richard Livingston, Site Editor
-
News
29 May 2026
First month of Mythos Preview testing exposes 10K flaws
Anthropic's Mythos Preview exposed 10,000-plus security flaws at tech giants in one month, revealing both opportunities and risks for the future of cybersecurity. Continue Reading
By- Phil Sweeney, Industry Editor
-
Feature
26 May 2026
Security platformization vs. best-of-breed: Risks and benefits
With tool sprawl pushing costs and complexity to a breaking point, the choice between unified security platforms and best-of-breed tools has never been more critical. Continue Reading
-
Tip
20 May 2026
Taking care of business: The CISO's role in a cyber crisis
CISOs have a broad range of responsibilities. But when a crisis occurs, they become the de facto leader, entrusted with both technical and business outcomes. Continue Reading
By- Paul Kirvan
- Sharon Shea, Executive Editor
-
Tip
18 May 2026
SOC vs. MDR: What CISOs need to consider
Security operations centers and managed detection and response providers differ in how they manage threats. What's the best way to choose between a SOC and MDR service? Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Tip
13 May 2026
Transform SIEM rules with behavior-based threat detection
Outdated SIEM rules can hamstring enterprises as they try to safeguard their operations. Use a proactive, strategic approach that's grounded in actual attack behavior instead. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
13 May 2026
CISO's guide: How to test an incident response plan
Creating an incident response plan is only the beginning. Regular testing will help ensure it doesn't fall apart during a real cybersecurity event. Continue Reading
By -
Tip
09 May 2026
The breakup: Why CISOs are decoupling data from their SIEMs
Breaking up is hard to do -- but some CISOs find that decoupling SIEMs from security log data feeds is worth it. Learn about the benefits and challenges. Continue Reading
By- John Burke, Nemertes Research
-
Tip
07 May 2026
How to construct an effective security controls evaluation
Some CISOs believe their security controls are sufficient, but reach that conclusion without any method for measuring their effectiveness. There's a much better way. Continue Reading
By- Ed Moyle, SecurityCurve
-
Tip
30 Apr 2026
What every CISO should consider before a SIEM migration
Before starting a SIEM migration, the security team must identify the data, rules, workflows and policies they need to transition to the new tool or service. Here's how to get started. Continue Reading
By- John Burke, Nemertes Research
-
Tip
30 Apr 2026
CISO's guide to centralized vs. federated security models
CISOs must juggle flexibility, consistency and risk when considering the enterprise's security structure. Discover the benefits and drawbacks of different security models. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
27 Apr 2026
How to fix cybersecurity's agentic AI identity crisis
AI agents are transforming enterprise operations, but their autonomy poses critical security challenges. Learn how to secure these powerful digital actors. Continue Reading
By- Matthew Smith, Seemless Transition LLC
-
News
24 Apr 2026
News brief: AI woes continue for security leaders
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading. Continue Reading
By -
Feature
23 Apr 2026
Is SOAR dead or alive? Sort of
Orchestration and automation capabilities remain critical elements in effective cyber defense. Just don't expect to hear much about SOAR anymore. Continue Reading
-
Video
17 Apr 2026
At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government
Depending on whom you ask, AI could mean the end of the world as we know it, or the beginning of a new era of ease and enlightenment in the SOC. Learn more in this video discussion. Continue Reading
By- Alissa Irei, Senior Site Editor
-
News
17 Apr 2026
News brief: Microsoft security vulnerabilities revealed
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading. Continue Reading
By -
Feature
15 Apr 2026
Inside the SOC that secured RSAC 2026 Conference
Take a behind-the-scenes look at the technology and teamwork that went into creating the security operations center that protected attendees, vendors and staff at RSAC 2026. Continue Reading
By- Sharon Shea, Executive Editor
-
Feature
14 Apr 2026
How to improve the SOC analyst experience -- and why it matters
Burned-out security analysts miss threats, take longer to investigate incidents and are more likely to quit. Here's how CISOs can improve the SOC analyst experience. Continue Reading
-
Tip
09 Apr 2026
Next-generation firewall buyer's guide for CISOs
NGFWs are crucial tools for modern security operations, but CISOs need to understand the often complex deployment, maintenance and budgeting implications. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Feature
08 Apr 2026
RSAC 2026: Cyber insurance and the rise of ransomware
At RSAC 2026, John Kindervag proposed the idea that the rise of the cyber insurance industry has motivated ransomware threat actors to escalate their attacks and ask for more. Continue Reading
By- Richard Livingston, Site Editor
-
Tip
06 Apr 2026
Meaningful metrics demonstrate the value of cyber-resiliency
Cyber-resilience metrics translate raw technical performance into real business outcomes. The right analytics can enhance more than just security operations. Continue Reading
By -
Tip
02 Apr 2026
5 top SOC-as-a-service providers and how to evaluate them
SOCaaS simplifies security operations. Compare five providers and key evaluation criteria, including tools, automation, threat intelligence and compliance. Continue Reading
By- John Burke, Nemertes Research
-
Feature
27 Mar 2026
Watch your words: Tim Brown's advice for CISOs
During RSAC 2026, Tim Brown discussed the SolarWinds breach, his SEC indictment and the critical need for communication policies. Continue Reading
By- Sharon Shea, Executive Editor
-
Tip
17 Mar 2026
Boost SOC efficiency with Python security automation
Resource-strapped SOCs need better incident response, threat hunting and report generation. Explore how automating tasks with Python makes life easier for security teams. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
16 Mar 2026
Calculating the ROI of AI in cybersecurity
Investing in AI tools can benefit an organization's security posture. Understanding and quantifying those improvements, however, poses a real challenge. Continue Reading
By- Ashwin Krishnan, StandOutin90Sec
-
Feature
11 Mar 2026
SIEM isn't dead, its place in the SOC is just evolving
Despite the predictions that SIEM is going away, its role is actually evolving. Learn why SIEM tools remain essential to enterprise security operations. Continue Reading
-
Feature
05 Mar 2026
Should a CISO have an MBA?
Cybersecurity leaders are often asked to weigh in more frequently on business decisions. This could give MBA-holding CISOs a more visible seat at the table. Continue Reading
-
Tip
03 Mar 2026
How to reduce false positive alerts and increase cybersecurity
False positives in cybersecurity detection tools drain resources and distract from real threats. Once CISOs understand the root causes of false positives, they can implement strategies to reduce them. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Feature
05 Feb 2026
10 types of information security threats for IT teams
Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Tip
29 Jan 2026
CERT vs. CSIRT vs. SOC: What's the difference?
What's in a name? In incident response parlance, there are subtle -- and sometimes confusing -- distinctions among a CERT, a CSIRT, a CIRT and a SOC. Continue Reading
By- Ed Moyle, SecurityCurve
-
Tip
20 Jan 2026
Use the CIA triad to shape security automation use cases
Automating IT security with the CIA triad framework helps improve scalability, reduce misconfigurations and enhance threat detection and remediation. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
14 Jan 2026
Vibe coding security risks and how to mitigate them
Vibe coding with generative AI is transforming software development, accelerating innovation and introducing new security risks to manage. Continue Reading
By- Matthew Smith, Seemless Transition LLC
-
Feature
12 Jan 2026
Cybersecurity conferences to attend in 2026
Discover the top cybersecurity conferences of 2026 to sharpen skills, network with peers, learn the latest industry trends and stay ahead of emerging threats. Continue Reading
By- Sharon Shea, Executive Editor
-
Tip
05 Jan 2026
Real-world AI voice cloning attack: A red teaming case study
Thanks to AI, social engineering campaigns are becoming more effective than ever. In this red team case study, see how voice cloning helped trick a seasoned business user. Continue Reading
By -
Tip
18 Dec 2025
DevSecOps vs. SecDevOps: Which is better for your organization?
How far left should security shift? DevSecOps and SecDevOps both integrate security into DevOps but differ conceptually and practically. Learn which model suits your needs. Continue Reading
By- Matthew Smith, Seemless Transition LLC
-
Tip
24 Nov 2025
5 steps for a smooth SIEM implementation
SIEM migration doesn't have to be chaotic. Smart planning and phased deployment can prevent a rocky rollout and pave the way for a smooth transition. Here's your roadmap. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Tip
23 Oct 2025
SIEM benefits and features in the modern SOC
Security information and event management has evolved significantly since it was first introduced 20 years ago. Today's SIEMs offer a wide range of capabilities. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Tip
08 Oct 2025
Top 15 IT security frameworks and standards explained
Several IT security frameworks and standards exist to help protect company data. Here's advice for choosing the right ones for your organization. Continue Reading
By -
Tip
25 Aug 2025
Red teams and AI: 5 ways to use LLMs for penetration testing
Red teams can harness the power of LLMs for penetration testing. From session analysis to payload crafting, discover five ways AI transforms security testing. Continue Reading
By- Ed Moyle, SecurityCurve
-
Tip
18 Aug 2025
Shift left with these 11 DevSecOps best practices
By starting small, automating selectively and making security the easiest path forward, organizations can improve DevOps security without sacrificing development speed. Continue Reading
-
Feature
08 Aug 2025
Experts weigh in on securing AI effectively
Using AI comes with security risks. Learn what the top attack vectors and privacy threats are, then discover how to mitigate them through proper strategy, monitoring and more. Continue Reading
By- Brenda L. Horrigan, Executive Managing Editor
-
Definition
07 Aug 2025
What is COMSEC (communications security)?
Communications security (COMSEC) is the prevention of unauthorized access to telecommunications traffic or to any written information that is transmitted or transferred. Continue Reading
By- Paul Kirvan
- Ben Cole, Executive Editor
-
Video
05 Aug 2025
AI security: Top experts weigh in on the why and how
AI is everywhere, so security focus on this new technology is essential. In this podcast episode, three top security experts review the risks and discuss ways to mitigate them. Continue Reading
By -
Video
01 Aug 2025
An explanation of purple teaming
Purple teaming unites offensive red teams and defensive blue teams to share knowledge, find vulnerabilities and strengthen security through structured frameworks and playbooks. Continue Reading
By- Sharon Shea, Executive Editor
- Sabrina Polin, Managing Editor
- Tommy Everson, Assistant Editor
-
Feature
28 Jul 2025
How to become a bug bounty hunter
With the right strategy, tools and skills, software testers and security researchers can earn extra income as bug bounty hunters. Continue Reading
By- Rob Shapland
- Alissa Irei, Senior Site Editor
-
Tip
25 Jul 2025
How to implement security control rationalization
Security control rationalization helps CISOs reduce cybersecurity tool sprawl, cut spending and improve efficiency -- all without compromising protection. Continue Reading
By- Dave Shackleford, Voodoo Security
-
Tip
23 Jul 2025
Top DevSecOps certifications and trainings for 2025
DevOps Institute, Practical DevSecOps, EXIN and EC-Council are among the organizations that offer DevSecOps certifications and trainings for cybersecurity professionals. Continue Reading
-
Definition
15 Jul 2025
What is cybersecurity?
Cybersecurity is the practice of protecting systems, networks and data from digital threats. Continue Reading
By- Kinza Yasar, Technical Writer
- Sharon Shea, Executive Editor
- Alexander S. Gillis, Technical Writer and Editor
-
Tip
09 Jul 2025
Security log management tips and best practices
Learn how to conduct security log management that provides visibility into IT infrastructure activities and traffic, improves troubleshooting and prevents service disruptions. Continue Reading
By- Ed Moyle, SecurityCurve
- Michael Cobb
-
Definition
09 Jul 2025
What is a CISO as a service (CISOaaS)?
CISO as a service, or CISOaaS, is the outsourcing of CISO (chief information security officer) and information security leadership responsibilities to a third-party provider. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Ben Lutkevich, Site Editor
-
Feature
08 Jul 2025
Phishing prevention: How to spot, stop and respond to scams
From email scams to BEC attacks, phishing is one of the biggest fish organizations must fry. Get advice on how to identify, prevent and respond to phishing schemes. Continue Reading
By- Sharon Shea, Executive Editor
-
Tip
30 Jun 2025
Cybersecurity outsourcing: Strategies, benefits and risks
For companies battling data breaches and cyberattacks, MSSPs can offer lower costs, better reliability, broader experience and more -- if organizations define their needs well. Continue Reading
-
Tip
27 Jun 2025
12 DevSecOps tools to secure each step of the SDLC
DevSecOps tools integrate security throughout development. These 12 options enhance workflows from coding to deployment without slowing teams down. Continue Reading
-
Definition
27 Jun 2025
What is a virtual CISO (vCISO)? Does your business need one?
The virtual chief information security officer (vCISO) is a C-suite-level security professional or service provider who offers CISO-level expertise on a part-time, remote or contractual basis. Continue Reading
-
Tip
27 Jun 2025
How to build a cybersecurity RFP
Crafting a cybersecurity RFP requires clear goals, precise questions and vendor vetting. Follow these guidelines to streamline the process and meet your company's security needs. Continue Reading
-
Tutorial
23 Jun 2025
Update Kali Linux to the latest software repository key
Kali Linux users might encounter errors when they update or download new software, exposing systems to security threats. A new repository key will eliminate those problems. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tutorial
17 Jun 2025
Kali vs. ParrotOS: Security-focused Linux distros compared
Network security doesn't always require expensive software. Two Linux distributions -- Kali Linux and ParrotOS -- can help enterprises fill in their security gaps. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Tip
16 Jun 2025
5 essential programming languages for cybersecurity pros
Coding is an important skill across almost every technology discipline, and cybersecurity is no exception. Learn about the top programming languages for security professionals. Continue Reading
By- Mike Chapple, University of Notre Dame
-
Video
02 Jun 2025
The DOGE effect on cyber: What's happened and what's next?
In this webinar, part of 'CISO Insights' series, cybersecurity experts debate the pros and cons of the Department of Government Efficiency's actions and the impact on their field. Continue Reading
By -
Tip
29 May 2025
Security risks of AI-generated code and how to manage them
Application security teams are understandably worried about how developers use GenAI and LLMs to create code. But it's not all doom and gloom; GenAI can help secure code, too. Continue Reading
-
Tip
21 May 2025
How to choose a cloud key management service
Amazon, Microsoft, Google, Oracle and cloud-agnostic vendors offer cloud key management services. Read up on what each offers and how to choose the right KMS for your company. Continue Reading
By- Dave Shackleford, Voodoo Security
-
Definition
09 May 2025
What is a security operations center (SOC)?
A security operations center (SOC) is a command center facility in which a team of information technology (IT) professionals with expertise in information security (infosec) monitors, analyzes and protects an organization from cyberattacks. Continue Reading
By- Kinza Yasar, Technical Writer
- Paul Kirvan
- Sarah Lewis
-
Opinion
24 Apr 2025
Change is in the wind for SecOps: Are you ready?
Attackers have historically had time on their side, outpacing defenders who have struggled to keep up. Agentic AI appears poised to change the game. Continue Reading
By- Dave Gruber, Principal Analyst
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Tip
21 Apr 2025
How to create a CBOM for quantum readiness
Quantum is on the horizon -- is your organization ready to migrate to post-quantum cryptographic algorithms? Make a CBOM to understand where risky encryption algorithms are used. Continue Reading
By -
Tip
20 Feb 2025
Penetration testing vs. vulnerability scanning: What's the difference?
Confused by the distinctions between penetration testing and vulnerability scanning? You're not alone. Learn the key differences between the two and when to use each. Continue Reading
By- Kyle Johnson, Technology Editor
- Andrew Froehlich, West Gate Networks
-
Tip
19 Feb 2025
9 tips for migrating between managed SOC providers
Switching between managed SOCs can be daunting, but with proper planning, organizations can successfully navigate it. One important tip: Document everything. Continue Reading
By- Jerald Murphy, Nemertes Research
-
Definition
07 Feb 2025
What is physical security and how does it work?
Physical security protects personnel, hardware, software, networks, facilities and data from physical actions and events that could cause serious loss or damage to an enterprise, agency or institution. Continue Reading
By- Mary E. Shacklett, Transworld Data
- Michael Cobb
-
Tip
05 Feb 2025
How to build an effective purple team playbook
Enterprises across a wide variety of vertical industries can benefit from purple team exercises that harness red and blue teams toward a common goal: reducing vulnerabilities. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
-
Opinion
23 Jan 2025
Too many 'point'less tools: Platformization is better
Will 2025 be the year organizations ditch multiple point products and take a platform approach? Enterprise Strategy Group analyst Tyler Shields thinks it should be. Continue Reading
By- Tyler Shields, Omdia
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
News
22 Jan 2025
Cyber Safety Review Board axed in DHS cost-cutting move
Benjamine C. Huffman, acting secretary of the Department of Homeland Security under Trump, terminates the memberships for all DHS advisory committees, including the CSRB. Continue Reading
By- Alexander Culafi, Senior News Writer, Dark Reading
-
Tip
22 Jan 2025
10 cybersecurity certifications to boost your career in 2025
A consensus of industry professionals rank these 10 security certifications as the most coveted by employers and security pros -- plus links to 10 vendor security certifications. Continue Reading
By- Steve Zurier, ZFeatures
-
Tip
14 Jan 2025
Top 12 online cybersecurity courses for 2025
Our panel of experts picked the best free and paid online cybersecurity courses for professionals looking to advance their careers and for newbies breaking into the field. Continue Reading
By- Steve Zurier, ZFeatures
-
Feature
13 Jan 2025
9 secure email gateway options for 2025
Finding the best email security gateway is vital to protect companies from cyberattacks. Here's a look at some current market leaders and their standout features. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Tip
13 Jan 2025
10 must-have cybersecurity skills for career success in 2025
Looking to advance your cybersecurity career? Here are the skills you need to win a CISO job, land a threat hunter gig and snag other security positions in high demand. Continue Reading
By- Steve Zurier, ZFeatures
-
Tip
17 Dec 2024
The 10 best cloud security certifications for IT pros in 2025
Certifications can help security pros prove their baseline knowledge of infosec topics. Consider adding these top cloud security certifications to your arsenal. Continue Reading
By- Sharon Shea, Executive Editor
-
Tip
12 Nov 2024
SIEM vs. SOAR vs. XDR: Evaluate the key differences
SIEM, SOAR and XDR each possess distinct capabilities and drawbacks. Learn the differences among the three, how they can work together and which your company needs. Continue Reading
By -
News
06 Nov 2024
CISA on 2024 election security: 'Good news' for democracy
CISA Director Jen Easterly says that despite disruptions including bomb threats in multiple states, Election Day 2024 was a success story from a security standpoint. Continue Reading
By- Alexander Culafi, Senior News Writer, Dark Reading
-
Tip
30 Oct 2024
Top AI security certifications to consider
AI security certifications, much like AI itself, are evolving. Does it make sense to go through the time and money to obtain a credential, given how quickly the field is changing? Continue Reading
By- Jerald Murphy, Nemertes Research
- Sharon Shea, Executive Editor
-
Feature
29 Oct 2024
How to configure and customize Kali Linux settings
Learning how to use Kali Linux for ethical hacking and penetration testing? Read step by step how to configure and customize the distribution. Continue Reading
By- Kyle Johnson, Technology Editor
- Packt Publishing
-
Feature
28 Oct 2024
Types of cybersecurity controls and how to place them
A unilateral cybersecurity approach is ineffective in today's threat landscape. Learn why organizations should implement security controls based on the significance of each asset. Continue Reading
By- Isabella Harford, TechTarget
- Packt Publishing
-
Definition
09 Oct 2024
What is OPSEC (operations security)?
OPSEC (operations security) is an analytical process that military, law enforcement, government and private organizations use to prevent sensitive or proprietary information from being accessed inappropriately. Continue Reading
By- Robert Sheldon
- Linda Rosencrance
- Ben Cole, Executive Editor
-
Tip
07 Oct 2024
How to use security as code to achieve DevSecOps
Security as code helps organizations achieve DevSecOps and shift-left security. Learn about SaC's benefits, challenges and implementation best practices. Continue Reading
By -
Tutorial
04 Oct 2024
How to conduct firewall testing and analyze test results
A misconfigured firewall can wreak havoc throughout your organization. Firewall testing to ensure rules are written correctly and that any changes are validated is critical. Continue Reading
By- Damon Garn, Cogspinner Coaction
-
Podcast
30 Sep 2024
Risk & Repeat: Inside the Microsoft SFI progress report
The first Secure Future Initiative progress report highlighted improvements to Microsoft's security posture. But the company still faces major SecOps challenges. Continue Reading
By- Rob Wright, Senior News Director, Dark Reading
-
Tip
23 Sep 2024
ASPM vs. ASOC: How do they differ?
Application security posture management and application security orchestration and correlation tools both aim to secure applications but use different methodologies. Continue Reading
By- Dave Shackleford, Voodoo Security
-
Opinion
28 Aug 2024
Why is SecOps becoming both easier and more difficult?
While SecOps has become easier in some ways, enterprises still struggle with areas such as data volumes, threat intelligence analysis and security alert volume and complexity. Continue Reading
By- Jon Oltsik, Analyst Emeritus
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Opinion
23 Aug 2024
Security teams need to prioritize DSPM, review use cases
New research showed data resilience is a top priority for security teams, as data security posture management grows to help manage and protect data and improve GenAI. Continue Reading
By- Todd Thiemann, Principal Analyst
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
News
14 Aug 2024
GitHub Copilot Autofix tackles vulnerabilities with AI
GitHub says Copilot Autofix drastically reduced the median time to remediate vulnerabilities in beta testing from 90 minutes for manual fixes to 28 minutes with the GenAI tool. Continue Reading
By- Rob Wright, Senior News Director, Dark Reading
-
Tip
12 Aug 2024
EDR testing: How to validate EDR tools
Cutting through an EDR tool's marketing hype is difficult. Ask vendors questions, and conduct testing before buying a tool to determine if it solves your organization's pain points. Continue Reading
By -
News
07 Aug 2024
Veracode highlights security risks of GenAI coding tools
At Black Hat USA 2024, Veracode's Chris Wysopal warned of the downstream effects of how generative AI tools are helping developers write code faster. Continue Reading
By- Arielle Waldman, Features Writer, Dark Reading
-
Definition
31 Jul 2024
What is cyber attribution?
Cyber attribution is the process of tracking and identifying the perpetrator of a cyberattack or other cyber operation. Continue Reading