What we've learned testing other people's security.
Straight-talk articles on penetration testing, vulnerability assessment, and security decisions - plus the news and regulatory shifts shaping Gaming, Fintech, and Insurance across the markets we serve.
August 2026 Patch Tuesday: The Vulnerabilities Worth Losing Sleep Over
421 CVEs, 62 rated critical, and at least one already being actively exploited - a rundown of what actually matters from this month's Microsoft security update.
Ransomware Just Had Its Biggest Year on Record - Even as Payments Fall
7,551 publicly disclosed ransomware victims, 61 new threat groups, and ransomware now in 48% of all breaches - but median ransom payments are dropping.
The UK's Cyber Security and Resilience Bill Has Cleared the Commons
The biggest overhaul of UK cyber regulation since 2018 completed its Commons stages on 25 June 2026 and has entered the House of Lords, with fines of up to £17 million on the table.
The ShinyHunters Oracle Campaign Is a Vendor-Risk Wake-Up Call
A single unpatched Oracle PeopleSoft flaw let one extortion group claim over 100 victims across sectors. Here's the practical checklist it should prompt.
A Breach at the NAIC Shows How Fast Insurance-Sector Risk Can Cascade
The National Association of Insurance Commissioners' own PeopleSoft environment was hit as part of a wider ShinyHunters extortion campaign - a reminder that industry infrastructure is a target too.
Prompt Injection Is Now the Top AI Security Risk. Most Enterprises Aren't Ready.
OWASP ranks prompt injection as the #1 AI security risk, agent-related breaches now average $4.7 million, and only a third of organisations have deployed dedicated defenses.
The Steam Breach That Wasn't Valve's Fault - And Why That's the Point
Valve confirmed a data exposure affecting European Steam hardware buyers after attackers hit CEVA Logistics, one of its shipping partners - a textbook third-party breach.
A Small Insurer's Breach Shows Why Size Doesn't Buy You Safety
Beacon Mutual, a Rhode Island workers' compensation insurer, disclosed a week-long unauthorized access incident exposing Social Security and financial account numbers.
Why 2026 Is the Year Game Security Had to Grow Up
AI-generated exploits, near-indistinguishable phishing, and attacks timed to major live events are pushing gaming and iGaming platforms toward encryption and audit standards once reserved for banks.
Deepfake Voice Cloning Is Now a Board-Level Fraud Risk for Banks
Three to five seconds of audio is now enough to clone a voice convincingly. Deepfake-related fraud losses topped $410 million in the first half of 2025 alone.
What the UK Gambling Commission Actually Checks in a Security Audit
Remote gambling operators licensed in the UK must pass an annual third-party security audit against ISO 27001 sections - here's what that actually covers.
NYDFS Part 500 Has No More Grace Periods Left
New York's cybersecurity regulation for financial services is now in full enforcement alongside PCI DSS 4.0.1 and DORA - with MFA and vendor oversight as shared priorities.
PCI DSS 4.0.1 and DORA Are Now Fully Enforced. Grace Periods Are Over.
2026 is the year the transition periods run out: PCI DSS 4.0.1, the EU's DORA, and NYDFS Part 500 are all in full enforcement, with real penalties attached.
Canada's Bill C-8 Will Force Mandatory Cybersecurity on Critical Sectors
Bill C-8 - the Critical Cyber Systems Protection Act - introduces mandatory cybersecurity requirements for critical infrastructure operators, alongside a coming overhaul of PIPEDA.
Australia's Fintech Sector Just Had Two Very Different Wake-Up Calls
A landmark $2.5 million Federal Court penalty against FIIG Securities, and a 141GB breach at lender Vroom by YouX, both landed in early 2026.
South Africa's Information Regulator Is Getting More Assertive on POPIA
A formal POPIA monitoring exercise launched in February 2026, on the back of two R5 million fines and a growing list of enforcement notices against major organisations.
The SEC's Cyber Disclosure Rule Has Entered Its Enforcement Era
2026 brings a new SEC enforcement unit and real scrutiny of Form 8-K cyber disclosures - even as the rule's long-term future is debated in Washington.
Understanding Penetration Testing: What Organizations Need to Know
A comprehensive guide to penetration testing for IT leaders and decision-makers, covering what it is, why it matters, and how to prepare for your first engagement.
API Security: Common Vulnerabilities and How to Test for Them
APIs are the backbone of modern applications but present unique security challenges. Learn about common API vulnerabilities and testing approaches.
Preparing for Your First Penetration Test: A Checklist for IT Leaders
Getting ready for your organization's first penetration test? This practical checklist helps IT leaders prepare effectively and maximize the value of their security assessment.