// Insights

Threat intelligence and field notes from the SOC.

Practical writing for security leaders, IR practitioners, and the engineers who keep production secure.

◎
THREAT INTEL

The 2026 ransomware playbook: AI-augmented negotiation

Nation-state-affiliated crews are using LLMs to draft victim-tailored ransom demands. Here is how the attack lifecycle has shifted, and four detections that catch it.

Jun 1, 2026
◎
ZERO TRUST

Why your VPN is the new attack surface

Legacy VPN concentrators remain the most-targeted ingress point in IR engagements we ran in Q1. A practical migration plan to ZTNA.

May 24, 2026
◎
AI SECURITY

Prompt injection is not the threat. Agentic over-reach is.

Most LLM hardening guides obsess over prompts. The real risk is what your agent is allowed to do once compromised. A threat model.

May 17, 2026
◎
MDR

Inside our SOC: how we cut MTTC to 47 seconds

A walk-through of our autonomous triage stack — what the AI handles, what humans escalate, and where we stop the model from acting unsupervised.

May 9, 2026
◎
COMPLIANCE

NIST CSF 2.0: what actually changed, and what to do first

The new "Govern" function is more than a label. Six concrete actions for security leaders inheriting CSF 2.0 obligations.

Apr 30, 2026
◎
INCIDENT RESPONSE

Forty hours that decide everything: the first 48 of a ransomware response

A field-tested timeline of decisions, communications, and technical actions that determine whether an incident becomes a crisis.

Apr 22, 2026