# Business Security

Cybersecurity risk management for businesses.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence

DevFeed: [How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence](<https://devfeed.tech/articles/third-party-risk-assessments-how-confluent-helps-you-move-faster-with-confidence-26724.md>)

Original publisher: [Read original article](<https://www.confluent.io/blog/third-party-risk-assessments-or-how-confluent-helps-you-move-faster-with-confidence/>)

Author: Bethany Carter

Published: 2026-09-15T16:40:06Z

Content type: article

Language: en

Sources: [Confluent: Data in motion](<https://devfeed.tech/sources/confluent-data-in-motion.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [apra](<https://devfeed.tech/tags/apra.md>), [automated](<https://devfeed.tech/tags/automated.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [confluent](<https://devfeed.tech/tags/confluent.md>), [confluent-cloud](<https://devfeed.tech/tags/confluent-cloud.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [identity](<https://devfeed.tech/tags/identity.md>), [iso](<https://devfeed.tech/tags/iso.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Confluent explains how its Trust Center provides third-party risk assessment reports to support vendor security, resilience, compliance, procurement, and customer due diligence. The article describes assessments including ProcessUnity Global Risk Exchange and control mapping to customer frameworks.

### Source excerpt

Confluent's Trust Center simplifies vendor risk reviews with CyberGRX, CyberVadis, SIG, CAIQ, and TruSight/KY3P assessments.

## AI floods security teams with flaws -- business context sets priorities

DevFeed: [AI floods security teams with flaws -- business context sets priorities](<https://devfeed.tech/articles/ai-floods-security-teams-with-flaws-business-context-sets-priorities-8490.md>)

Original publisher: [Read original article](<https://thenewstack.io/vulnerability-prioritization-business-context/>)

Author: Megan Carnegie

Published: 2026-09-10T12:00:00Z

Content type: article

Language: en

Sources: [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [business](<https://devfeed.tech/tags/business.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [i-o-mergent](<https://devfeed.tech/tags/i-o-mergent.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsor-i-o-mergent](<https://devfeed.tech/tags/sponsor-i-o-mergent.md>), [sponsored](<https://devfeed.tech/tags/sponsored.md>), [sponsored-post](<https://devfeed.tech/tags/sponsored-post.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that security teams should prioritize vulnerabilities using business context rather than scanner severity alone, because automated findings can overwhelm limited engineering capacity.

### Source excerpt

A security researcher testing a 300-person B2B company with a global footprint discovered an internet-exposed database with weak authentication during The post AI floods security teams with flaws -- business context sets priorities appeared first on The New Stack.

## How to build an exposure management program the business trusts: Lessons from Tenable's CSO

DevFeed: [How to build an exposure management program the business trusts: Lessons from Tenable's CSO](<https://devfeed.tech/articles/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenable-s-cso-8265.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso>)

Author: Robert Huber

Published: 2026-08-27T14:30:00Z

Content type: tutorial

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data](<https://devfeed.tech/topics/data.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [visualization](<https://devfeed.tech/tags/visualization.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Tenable's article explains how an exposure management program can reduce security tool sprawl, unify fragmented security data, improve visibility across the attack surface, and connect cyber-risk metrics with business priorities. It also discusses the challenges of maintaining security and speed while organizations rapidly adopt AI.

### Source excerpt

Discover how Tenable's shift to an AI-driven exposure management program helped Tenable's CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. Key takeaways Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations' cyber risk. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board's main question: "Are we secure?" What is trust in cybersecurity? And more importantly, how do you earn it? Here's a hint: It's not easy, especially in this AI era. As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance -- an agile yet cyber secure business -- had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl. In this blog, I'll explain how exposure management helped my team: Tackle security tool sprawl Bridge operational and data silos Take a more proactive approach to security Attain visibility and control over Tenable's attack surface Continuously and precisely assess our cyber risk posture The operational impact of security data silos and tool sprawl For years, the cybersecurity industry's answer to every new threat or policy mandate was simple: Buy another tool, which in many -- maybe most -- organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to so

## A letter to the Discord community in Brazil

DevFeed: [A letter to the Discord community in Brazil](<https://devfeed.tech/articles/a-letter-to-the-discord-community-in-brazil-193.md>)

Original publisher: [Read original article](<https://discord.com/blog/a-letter-to-the-discord-community-in-brazil>)

Author: Stanislav Vishnevskiy

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Discord Blog](<https://devfeed.tech/sources/discord-blog.md>)

Topics: [Discord](<https://devfeed.tech/topics/discord.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [brazil](<https://devfeed.tech/tags/brazil.md>), [developers](<https://devfeed.tech/tags/developers.md>), [discord](<https://devfeed.tech/tags/discord.md>), [features](<https://devfeed.tech/tags/features.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

Discord explains that it is complying with an order from Brazil's National Data Protection Authority to suspend screensharing and video calls for Brazilian users. The letter discusses efforts to restore access, cooperation with authorities, and the impact on Brazil's communities, gamers, developers, and small businesses.

### Source excerpt

On the order from Brazil's ANPD to suspend screensharing and video features in the country, how we're complying, and our commitment to our community in Brazil.

## Canon 3X: Explore/Expand/Extract

DevFeed: [Canon 3X: Explore/Expand/Extract](<https://devfeed.tech/articles/canon-3x-explore-expand-extract-39973.md>)

Original publisher: [Read original article](<https://newsletter.kentbeck.com/p/canon-3x-exploreexpandextract>)

Author: Kent Beck

Published: 2026-07-30T13:04:07Z

Content type: opinion

Language: en

Sources: [Software Design: Tidy First?](<https://devfeed.tech/sources/software-design-tidy-first.md>)

Topics: [implementation](<https://devfeed.tech/topics/implementation.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [implementation](<https://devfeed.tech/tags/implementation.md>), [management](<https://devfeed.tech/tags/management.md>), [project-management](<https://devfeed.tech/tags/project-management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Kent Beck explains the 3X framework of Explore, Expand, and Extract, arguing that each phase of a product or company's growth requires different approaches to finance, teams, project management, technology, risk management, implementation, marketing, and sales.

### Source excerpt

I've started a series of Canon articles where I explain my ideas as plainly & unambiguously as possible--no analogies, no persuasion, just the facts.

## The foundation of security compliance for financial services businesses

DevFeed: [The foundation of security compliance for financial services businesses](<https://devfeed.tech/articles/the-foundation-of-security-compliance-for-financial-services-businesses-1918.md>)

Original publisher: [Read original article](<https://1password.com/blog/foundation-of-security-compliance-for-financial-services>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-06-16T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business](<https://devfeed.tech/tags/business.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains why small and medium-sized financial services businesses need a strong security and compliance foundation. It highlights rising cyberattack and ransomware risks, limited security resources, credential management challenges, and the way AI adoption can increase SaaS sprawl, shadow IT, policy violations, and attack sophistication.

### Source excerpt

One of the less surprising findings of the 2026 Verizon Data Breach Incident Report (DBIR) is the fact that incidents targeting the Financial and Insurance sector are on the rise. As they put it, "This sector continues to be a favorite among attackers, which isn't surprising given that its core business is handling money." For small-to-medium businesses (SMBs) in the financial services sector, the DBIR paints an even more dire picture. The report notes that SMBs face the same threats and breach patterns of larger organizations, but are also disproportionately impacted by attacks; 96% of ransomware victims were SMBs. In short: businesses in the financial services industry who are still building their foundation, or who possess limited security resources, are caught between a rock and a hard place. They operate within one of the most heavily targeted sectors for cyberattack, and are held to enterprise-level security standards by regulators and clients alike, but they're operating with startup-level security resources. For lean security and IT teams to make the most of those limited resources, they need to focus on what they can afford. That means getting the fundamentals right for a strong and impactful security foundation. The highest-leverage fundamental is, of course, credential management. Top security challenges for financial services organizations Small IT and security teams in the financial services industry are faced with high expectations when it comes to security. Unfortunately, they also experience significant challenges when it comes to securing credentials. AI is accelerating SaaS and credential sprawl JP Morgan Chase's recent research report, Understanding the use of AI among small businesses, finds that not only are a growing number of small businesses adopting AI, when they do, they also tend to implement a greater number and variety of AI tools. It's not hard to understand why this is the case; AI's ability to automate processes and improve productivi

## Unpacking SMB cyber-readiness - and what makes or breaks it

DevFeed: [Unpacking SMB cyber-readiness - and what makes or breaks it](<https://devfeed.tech/articles/unpacking-smb-cyber-readiness-and-what-makes-or-breaks-it-8342.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/smb-cyber-readiness-what-makes-breaks-it/>)

Author: Tomáš Foltýn

Published: 2026-06-10T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [breach](<https://devfeed.tech/tags/breach.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [canada](<https://devfeed.tech/tags/canada.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [europe](<https://devfeed.tech/tags/europe.md>), [incident](<https://devfeed.tech/tags/incident.md>), [japan](<https://devfeed.tech/tags/japan.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [survey](<https://devfeed.tech/tags/survey.md>), [training](<https://devfeed.tech/tags/training.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines SMB cyber-readiness through findings from the ESET SMB Cyber Readiness Index 2026. It reports that 45% of surveyed SMBs experienced a cyber-incident in the previous twelve months, while many respondents expressed confidence in their resilience. The article highlights a persistent gap between perceived preparedness and basic precautions, with insurance requirements, compliance pressure, and cybersecurity awareness training helping organizations prepare.

### Source excerpt

A company that's expecting a cyberattack but hasn't actively prepared for it risks making the hardest decisions at the worst possible moment

## Cybercriminals: the 'auditors' you never hired

DevFeed: [Cybercriminals: the 'auditors' you never hired](<https://devfeed.tech/articles/cybercriminals-the-auditors-you-never-hired-8331.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cybercriminals-auditors-never-hired/>)

Author: Steven Connolly

Published: 2026-06-09T08:50:00Z

Content type: opinion

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [blog-post](<https://devfeed.tech/tags/blog-post.md>), [breach](<https://devfeed.tech/tags/breach.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>)

### AI overview

The article examines normalcy bias in cybersecurity and argues that organizations may mistake the absence of obvious alerts for safety. It connects delayed responses and normalized breach risk with the continued rise in significant cyber incidents, citing figures from the NCSC Annual Review 2025.

### Source excerpt

Every organisation gets audited. The question is who does the auditing.

## Why security makes or breaks M&As, with Matt O'Leary

DevFeed: [Why security makes or breaks M&As, with Matt O'Leary](<https://devfeed.tech/articles/why-security-makes-or-breaks-m-as-with-matt-o-leary-1976.md>)

Original publisher: [Read original article](<https://1password.com/blog/why-security-makes-or-breaks-mandas-with-matt-oleary>)

Author: info@1password.com (Dave Lewis)

Published: 2026-05-06T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [business](<https://devfeed.tech/tags/business.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [deals](<https://devfeed.tech/tags/deals.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [product-engineering](<https://devfeed.tech/tags/product-engineering.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This Chasing Entropy episode examines how security diligence affects acquisitions and strategic partnerships. Matt O'Leary explains that companies inherit a target's technology, processes, legal exposure, and security weaknesses, making serious technology or cybersecurity risks potential deal breakers. The discussion also covers partnership risk, shared trust, and the need to align corporate development with product, engineering, and security leadership.

### Source excerpt

Listen to this episode on Apple Podcasts null Listen now Listen to this episode on Spotify null Listen now Security is tied to business operations in many (often unappreciated) ways, but the connection is rarely more visible or consequential than during an acquisition or partnership. In those deals, a company stakes its reputation and finances on another company, and a lapse in security can throw the whole thing into chaos. That's the subject of this episode of Chasing Entropy, in which Dave Lewis talks with Matt O'Leary, 1Password's Vice President of Corporate Development and Strategic Partnerships. They discuss what changes about M&As and partnerships when security is tied directly to the product, the brand, and the deal itself. Caveat emptor in M&As O'Leary's core idea is simple: when a company makes an acquisition, it inherits the whole business, not just the part that looked attractive in the pitch. That includes the technology, the team, the process gaps, the legal exposure, and any security weaknesses that were not obvious at first glance. O'Leary makes the case that strong dealmaking starts with risk discipline, because a transaction only creates value if the company can integrate what it buys without importing problems that slow everything down. He also explains that good corporate development starts with the roadmap, not the deal. An acquisition makes sense when it helps the company move faster than building on its own. That is why corp dev has to stay tightly aligned with product, engineering, and security leadership. In a cybersecurity company, technical diligence carries extra weight. If a target has a serious security or technology issue, that is not a detail to clean up later. It is a reason to walk away. Go as deep as you possibly can, before you cut the proverbial check...If there is any major issue with the technology, if there is any significant exposure to cybersecurity risks in a company we are targeting, those are deal killers." - Matt O'Leary Th

## Supply chain dependencies: Have you checked your blind spot?

DevFeed: [Supply chain dependencies: Have you checked your blind spot?](<https://devfeed.tech/articles/supply-chain-dependencies-have-you-checked-your-blind-spot-8343.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/supply-chain-dependencies-have-you-checked-your-blind-spot/>)

Author: Tony Anscombe

Published: 2026-04-16T12:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Resilience](<https://devfeed.tech/topics/resilience.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [operations](<https://devfeed.tech/tags/operations.md>), [outage](<https://devfeed.tech/tags/outage.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines supply chain dependencies as hidden sources of cyber and business risk for small and medium-sized businesses. It explains how third-party vulnerabilities, malicious attacks, and operational outages can disrupt operations and cause financial, reputational, legal, compliance, and data-related harm. It recommends mapping dependencies and strengthening resilience and business continuity.

### Source excerpt

Your biggest risk may be a vendor you trust. How can SMBs map their third-party blind spots and build operational resilience?

## A cunning predator: How Silver Fox preys on Japanese firms this tax season

DevFeed: [A cunning predator: How Silver Fox preys on Japanese firms this tax season](<https://devfeed.tech/articles/a-cunning-predator-how-silver-fox-preys-on-japanese-firms-this-tax-season-8328.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season/>)

Author: Dominik Breitenbacher Takahiro Sajima

Published: 2026-03-27T07:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [finance](<https://devfeed.tech/tags/finance.md>), [government](<https://devfeed.tech/tags/government.md>), [japan](<https://devfeed.tech/tags/japan.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

Silver Fox is conducting a targeted spearphishing campaign against Japanese manufacturers and other businesses during tax-filing and organizational-change season. The attackers use convincing tax- and HR-themed emails, links, and attachments to exploit expected business communications and increase the likelihood of compromise.

### Source excerpt

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

## What cybersecurity actually does for your business

DevFeed: [What cybersecurity actually does for your business](<https://devfeed.tech/articles/what-cybersecurity-actually-does-for-your-business-8345.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/what-cybersecurity-actually-does-for-your-business/>)

Author: Tomáš Foltýn

Published: 2026-03-06T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Security](<https://devfeed.tech/topics/security.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains that cybersecurity quietly protects business continuity through processes and controls that prevent technical incidents from becoming business crises. It examines the difficulty of proving security's value when nothing goes wrong, especially as security budgets face competing priorities and declining growth. The article argues that focusing only on avoided disasters understates security's everyday role and can encourage risky conclusions from limited past success.

### Source excerpt

The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed

## How SMBs use threat research and MDR to build a defensive edge

DevFeed: [How SMBs use threat research and MDR to build a defensive edge](<https://devfeed.tech/articles/how-smbs-use-threat-research-and-mdr-to-build-a-defensive-edge-8334.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/how-smbs-use-threat-research-mdr-build-defensive-edge/>)

Author: Ben Tudor

Published: 2026-03-05T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [operations](<https://devfeed.tech/tags/operations.md>), [publications](<https://devfeed.tech/tags/publications.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [small-business](<https://devfeed.tech/tags/small-business.md>), [soc](<https://devfeed.tech/tags/soc.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

The article explains how small and midsize businesses can use managed detection and response (MDR) to access proactive threat monitoring, hunting, and expert cybersecurity capabilities without building an elite in-house SOC. It also describes how threat research and intelligence inform MDR workflows, combining advanced technology with human expertise.

### Source excerpt

We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses

## Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity

DevFeed: [Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity](<https://devfeed.tech/articles/locks-socs-and-a-cat-in-a-box-what-schrodinger-can-teach-us-about-cybersecurity-8335.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/locks-socs-cat-box-what-schrodinger-can-teach-us-about-cybersecurity/>)

Author: Steven Connolly

Published: 2025-12-11T10:00:00Z

Content type: opinion

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [marketing](<https://devfeed.tech/tags/marketing.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

The article uses Schrödinger's cat as an analogy for the uncertainty facing organisations that lack visibility into their security environment. It argues that organisations should assume threats may already be present and strengthen their cybersecurity strategy through internal threat hunting, monitoring, and appropriate security tools.

### Source excerpt

If you don't look inside your environment, you can't know its true state - and attackers count on that

## Oversharing is not caring: What's at stake if your employees post too much online

DevFeed: [Oversharing is not caring: What's at stake if your employees post too much online](<https://devfeed.tech/articles/oversharing-is-not-caring-what-s-at-stake-if-your-employees-post-too-much-online-8336.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/oversharing-is-not-caring-stake-employees-post-too-much-online/>)

Author: Phil Muncaster

Published: 2025-12-01T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Business Security](<https://devfeed.tech/topics/business-security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developers](<https://devfeed.tech/tags/developers.md>), [github](<https://devfeed.tech/tags/github.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [work](<https://devfeed.tech/tags/work.md>)

### AI overview

The article explains how employees' work-related posts on LinkedIn, GitHub, Instagram, X, and company websites can expose corporate information. Threat actors may use details about roles, relationships, technologies, repositories, events, vendors, and business activity to build convincing spearphishing or business email compromise attacks that steal credentials or deliver malware.

### Source excerpt

From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.

## Zero Trust VPN and networking guide for business security teams

DevFeed: [Zero Trust VPN and networking guide for business security teams](<https://devfeed.tech/articles/zero-trust-vpn-and-networking-guide-for-business-security-teams-31201.md>)

Original publisher: [Read original article](<https://tailscale.com/learn/zero-trust-vpn>)

Published: 2025-09-23T18:03:01Z

Content type: tutorial

Language: en

Sources: [Learn on Tailscale](<https://devfeed.tech/sources/learn-on-tailscale.md>)

Topics: [zero trust networking](<https://devfeed.tech/topics/zero-trust-networking.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [tailscale](<https://devfeed.tech/topics/tailscale.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Google](<https://devfeed.tech/topics/google.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [google](<https://devfeed.tech/tags/google.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [networking](<https://devfeed.tech/tags/networking.md>), [okta](<https://devfeed.tech/tags/okta.md>), [security](<https://devfeed.tech/tags/security.md>), [teams](<https://devfeed.tech/tags/teams.md>), [vpn](<https://devfeed.tech/tags/vpn.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This guide explains Zero Trust networking as an approach that verifies users and devices for each access request, applies least privilege and segmentation, and limits lateral movement. It compares this model with traditional VPN access and describes how Tailscale uses identity, device posture, authorization, SSO, and SSH features to support Zero Trust principles.

### Source excerpt

Learn how Zero Trust works and why it beats traditional VPNs for business security. Get implementation tips, compare solutions, and discover how to limit access without killing productivity.

## The Human Side of Cybersecurity: Lessons From Yahoo's Director of Security GRC

DevFeed: [The Human Side of Cybersecurity: Lessons From Yahoo's Director of Security GRC](<https://devfeed.tech/articles/the-human-side-of-cybersecurity-lessons-from-yahoo-s-director-of-security-grc-4485.md>)

Original publisher: [Read original article](<https://www.toptal.com/executive-guidance/podcasts/the-human-side-of-cybersecurity>)

Author: ZOHRA IBRAHIMI, INFORMATION SECURITY PRACTICE LEAD @ TOPTAL

Published: 2025-01-12T23:00:00Z

Content type: article

Language: en

Sources: [Toptal Blog](<https://devfeed.tech/sources/toptal-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [business](<https://devfeed.tech/tags/business.md>), [communication](<https://devfeed.tech/tags/communication.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [culture](<https://devfeed.tech/tags/culture.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [executive](<https://devfeed.tech/tags/executive.md>), [governance](<https://devfeed.tech/tags/governance.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [security](<https://devfeed.tech/tags/security.md>), [speakers](<https://devfeed.tech/tags/speakers.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

This Executive Guidance podcast episode examines the human side of cybersecurity leadership. Steven Asifo of Yahoo and Zohra Ibrahimi of Toptal discuss how clarity, communication, culture, governance, risk management, and compliance can help security leaders support business goals while reducing cyber risk, including in regulated and AI-enabled environments.

### Source excerpt

As organizations face growing cyber risk and regulatory pressure, security leaders are being asked to do more than protect systems: They must enable the business. In this episode of the Executive Guidance podcast, Steven Asifo, Director of Security GRC at Yahoo, joins Zohra Ibrahimi, Toptal's Information Security Practice Lead, to discuss how clarity, communication, and culture are redefining modern security leadership.

## Empowering women in security: The impact of mentorship

DevFeed: [Empowering women in security: The impact of mentorship](<https://devfeed.tech/articles/empowering-women-in-security-the-impact-of-mentorship-7904.md>)

Original publisher: [Read original article](<https://snyk.io/blog/empowering-women-in-security-the-impact-of-mentorship/>)

Author: Erin Cullen

Published: 2024-11-27T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [career-development](<https://devfeed.tech/tags/career-development.md>), [career-growth](<https://devfeed.tech/tags/career-growth.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [industry](<https://devfeed.tech/tags/industry.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [series](<https://devfeed.tech/tags/series.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This article explores how mentorship and allyship can help women enter and advance in cybersecurity. It highlights supportive leaders, non-traditional career paths, advocacy for promotions and raises, and the importance of confidence, collaboration, and professional networks in building a more inclusive security community.

### Source excerpt

In the Women Leading Security series, Snyk CMO Jonaki Egenolf spoke with influential leaders about challenges and opportunities in the journey toward a more inclusive cybersecurity industry.

## Latacora Partners with Vanta as a Managed Service Provider

DevFeed: [Latacora Partners with Vanta as a Managed Service Provider](<https://devfeed.tech/articles/latacora-vanta-howdy-managed-service-partner-29181.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2024/09/09/latacora-vanta-howdy-msp/>)

Published: 2024-09-09T16:30:00Z

Content type: release

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [partner](<https://devfeed.tech/tags/partner.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vanta](<https://devfeed.tech/tags/vanta.md>)

### AI overview

Latacora announces a partnership with Vanta as a managed service provider. The arrangement combines Latacora's security expertise with Vanta's compliance platform and offers monthly billing, extended compliance support, and planned integrations.

### Source excerpt

Exciting news! Latacora is teaming up with Vanta to supercharge your compliance game. We now combine Latacora's security expertise with Vanta's compliance platform to help you reach your compliance goals faster than ever. As a Vanta managed service provider (MSP), Latacora can help you tackle your compliance goals quickly and efficiently, freeing you to focus on growing your business and building trust with your customers. Here's the scoop on why using Vanta through Latacora is a game-changer:

## Snyk AppRisk Pro: A holistic approach to application risk management

DevFeed: [Snyk AppRisk Pro: A holistic approach to application risk management](<https://devfeed.tech/articles/snyk-apprisk-pro-a-holistic-approach-to-application-risk-management-7903.md>)

Original publisher: [Read original article](<https://snyk.io/blog/empower-application-risk-management-with-snyk-apprisk/>)

Author: Daniel Berman

Published: 2024-05-01T12:55:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-apprisk](<https://devfeed.tech/topics/snyk-apprisk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [data analytics](<https://devfeed.tech/topics/data-analytics.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [Development](<https://devfeed.tech/topics/development.md>), [dynatrace](<https://devfeed.tech/topics/dynatrace.md>), [Backstage](<https://devfeed.tech/topics/backstage.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [backstage](<https://devfeed.tech/tags/backstage.md>), [blog](<https://devfeed.tech/tags/blog.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [developer-productivity](<https://devfeed.tech/tags/developer-productivity.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [dynatrace](<https://devfeed.tech/tags/dynatrace.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gitguardian](<https://devfeed.tech/tags/gitguardian.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [observability](<https://devfeed.tech/tags/observability.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>)

### AI overview

Snyk announces Snyk AppRisk Pro, an application security posture management offering for managing and scaling application security programs. It combines application visibility and discovery, security coverage management, and risk-based prioritization with runtime intelligence, developer-context integrations, extended security coverage, and application analytics for tracking program performance and risk.

### Source excerpt

Find out how Snyk AppRisk Pro, our application security posture management (ASPM) solution, is designed to empower your application risk management programs.

## How Executives Can Use Threat Modeling

DevFeed: [How Executives Can Use Threat Modeling](<https://devfeed.tech/articles/how-executives-can-use-threat-modeling-36830.md>)

Original publisher: [Read original article](<https://shostack.org/blog/how-executives-can-use-threat-modeling/>)

Author: Adam

Published: 2022-03-18T00:00:00Z

Content type: tutorial

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [ceo](<https://devfeed.tech/tags/ceo.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>)

### AI overview

This article explains how executives can use threat modeling to make more informed business and cybersecurity decisions. It defines threat modeling as a structured process for identifying what could go wrong, deciding how to respond, and reviewing whether the response was effective. It introduces a four-question framework and illustrates it with a smartphone software update example.

### Source excerpt

You don't have to be technical, but you can't make informed decisions about your business without threat modeling.

## Infrastructure Access Considerations for Financial Services

DevFeed: [Infrastructure Access Considerations for Financial Services](<https://devfeed.tech/articles/infrastructure-access-considerations-for-financial-services-29711.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/infrastructure-access-financial-services/>)

Author: info@goteleport.com (Carlos Mena)

Published: 2021-12-22T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [soc2](<https://devfeed.tech/topics/soc2.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [banking](<https://devfeed.tech/tags/banking.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [security-incidents](<https://devfeed.tech/tags/security-incidents.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

This blog discusses cybersecurity threats facing Financial Services companies, including increasing attacks, data breaches, financial losses, and the time required to detect and contain incidents. It focuses on infrastructure access considerations and measures companies can take to address these risks.

### Source excerpt

This blog presents data highlighting the threat that Financial Services companies face due to insecure infrastructure and what they can do about it.

## Recommended Reads on IT Security, Cybersecurity, and Organizational Resilience

DevFeed: [Recommended Reads on IT Security, Cybersecurity, and Organizational Resilience](<https://devfeed.tech/articles/interesting-monday-reads-36842.md>)

Original publisher: [Read original article](<https://shostack.org/blog/interesting-monday-reads-20170814/>)

Author: Adam

Published: 2017-08-14T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [IT\_Security](<https://devfeed.tech/topics/it-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [culture](<https://devfeed.tech/tags/culture.md>), [it-security](<https://devfeed.tech/tags/it-security.md>), [management](<https://devfeed.tech/tags/management.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [weather](<https://devfeed.tech/tags/weather.md>)

### AI overview

A curated selection of long, thought-provoking reads covering IT security, cybersecurity risk management for the U.S. government, and company culture for handling failure.

### Source excerpt

Each of these is long and thought-provoking and worth savoring.

## Introducing Cyber Portfolio Management

DevFeed: [Introducing Cyber Portfolio Management](<https://devfeed.tech/articles/introducing-cyber-portfolio-management-36847.md>)

Original publisher: [Read original article](<https://shostack.org/blog/introducing-cyber-portfolio-management/>)

Author: Adam

Published: 2017-02-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [challenges](<https://devfeed.tech/tags/challenges.md>), [communication](<https://devfeed.tech/tags/communication.md>), [management](<https://devfeed.tech/tags/management.md>), [portfolio](<https://devfeed.tech/tags/portfolio.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [talk](<https://devfeed.tech/tags/talk.md>)

### AI overview

The article introduces Cyber Portfolio Management, a proposed approach to driving effective security programs by managing distributed security portfolios and improving communication between security and business teams. It also discusses a related RSA talk, audio and slides, and an upcoming ebook draft.

### Source excerpt

[no description provided]

[Next page](<https://devfeed.tech/topics/business-security.md?cursor=WyIyMDE3LTAyLTIxVDAwOjAwOjAwKzAwOjAwIiwgIjllNzkxODY3LWMzYjQtNDRiZi1iODFiLTRmZTQxZmYxMjQyZSJd>)