7 tabletop exercise mistakes that sabotage incident response

This article discusses common mistakes organizations make when conducting tabletop exercises for incident response. It highlights the importance of clear objectives, realistic scenarios, and involving diverse stakeholders to ensure these simulations effectively test preparedness for cyber incidents.

Dragos Acquires xIoT Security Firm Phosphorus

Dragos has acquired xIoT security firm Phosphorus. This acquisition is expected to enhance asset visibility, device intelligence, and automated remediation workflows for Dragos customers.

Today’s 220-1201 CompTIA A+ Pop Quiz: It works on almost anything

This article presents a pop quiz specifically for the CompTIA A+ 220-1201 certification exam, focusing on a topic applicable to a wide range of IT systems. It is hosted on Professor Messer's website, known for providing free IT certification training resources.

The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

Managed Service Providers (MSPs) are evolving beyond basic vCISO (virtual Chief Information Security Officer) tools, which previously focused on assessments, advisory, and reporting. The industry is shifting towards 'Security Growth Platforms' to meet the expanding needs of MSPs and Managed Security Service Providers (MSSPs).

6 critical security gaps every CISO must address

A significant portion of CISOs admit their organizations are not adequately protecting data or are unprepared for cyberattacks, indicating critical security gaps. The article outlines six key areas CISOs must address, including a perception gap where security is still viewed primarily as an IT problem rather than a business resilience issue.

Press Release: CSO30 ASEAN & Hong Kong Awards 2026 open for nominations

The CSO30 ASEAN & Hong Kong Awards are now open for nominations for 2026, recognizing cybersecurity leaders and teams for their contributions to regional resilience. The awards aim to highlight impactful achievements in strengthening cyber posture, influencing strategic decisions, and building ecosystem partnerships.

Friday Squid Blogging: Another Squid

This post, titled "Friday Squid Blogging: Another Squid," serves as a recurring informal update and discussion thread for readers of Schneier on Security. It mentions a "West Country legend" named Squid and encourages readers to discuss other security news stories not covered by the author.

Name That Toon: Mark of (Cybersecurity) Progress

Dark Reading is celebrating its 20th anniversary by asking readers to submit cybersecurity-related captions for a cartoon. The initiative aims to reflect on the progress and evolution of the cybersecurity industry over the past two decades.

Asia's Cyber Insurance Market Shows Signs of Life

The cyber insurance market in Asia has historically struggled to gain traction due to various challenges. However, recent indications suggest a potential resurgence and growth in this sector across the region.

Cybersecurity trends in SEC filings

Public companies are now required by the SEC to include a section in their annual 10-K filings detailing their cybersecurity risk management, strategy, governance, and incidents. This article analyzes these filings, focusing on the top 200 S&P companies, to understand how senior executives are reporting on their cybersecurity posture and to identify trends. The research specifically examines the role of the Chief Information Security Officer (CISO) and their reporting structure.

Snowflake buys Natoma to help freeze out rogue agents

Snowflake has acquired Natoma, a data security startup focused on preventing unauthorized access and data leakage. This acquisition aims to bolster Snowflake's security offerings, particularly in protecting sensitive data from rogue agents and insider threats.

Geordie Raises $30 Million for AI Security and Governance Platform

Geordie, a company focused on AI security and governance, has successfully raised $30 million in a funding round. The round was led by Balderton Capital, with participation from Crosspoint Capital and existing investors General Catalyst and Ten Eleven Ventures.

Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security

This article discusses how the cyber insurance industry is compelling organizations to quantify their security risks. It explores what cyber insurance policies typically cover and highlights how this focus on risk assessment can ultimately improve overall cybersecurity posture.

Nordic CISOs Handle Rising Cyber Threats Remarkably Well

A survey of CISOs in Nordic countries indicates that most are not experiencing an increase in the severity or frequency of cyberattacks compared to two years ago. This resilience is observed despite the growing prevalence and capabilities of artificial intelligence in the threat landscape.

Gartner EPP MQ-17

Gartner has released its 2023 Magic Quadrant for Endpoint Protection Platforms (EPP), a report evaluating vendors in the endpoint security market. The report assesses vendors based on their ability to execute and completeness of vision. Sophos is recognized for its strengths in the market.

Professor Messer’s SY0-701 Security+ Study Group – May 2026

Professor Messer is offering a Security+ Success Bundle that includes downloadable course notes and practice exams to help individuals prepare for the CompTIA Security+ exam. This resource is designed to supplement his free video series and test users' knowledge of the exam objectives.

Today’s 220-1202 CompTIA A+ Quiz: Sit and stay

Professor Messer is offering a free quiz for the CompTIA A+ 220-1202 certification. This quiz is designed to help individuals test their knowledge and prepare for the exam. The post links back to Professor Messer's IT certification training courses.

How to guarantee a speaker gig: Hack the system. Literally

This article provides a humorous and metaphorical guide to "hacking" a call-for-proposal (CFP) platform to secure a speaker gig at a conference. It uses cybersecurity analogies to explain how to manipulate the system and craft a compelling submission.

Today’s 220-1201 CompTIA A+ Pop Quiz: A bit metallic

This article presents a pop quiz for the CompTIA A+ 220-1201 certification exam, focusing on a specific topic within the exam material. It is part of a series of free training resources offered by Professor Messer.

Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading

This article is a tribute to Tim Wilson, co-founder and former editor-in-chief of Dark Reading, who passed away five years ago. It reflects on his significant contributions to building and elevating the cybersecurity media site as it enters its third decade.

HackerOne takes an axe to its bug bounty rewards

Bug bounty platform HackerOne has significantly reduced its payouts for critical and high-severity vulnerability discoveries. This move comes as part of a broader restructuring aimed at financial sustainability and reflects a shift in how bug bounty programs are incentivized.

AI Agents Are Shifting Identity Security Budget Dynamics

The proliferation of AI agents in enterprises necessitates new approaches to managing, securing, and governing their identities. Research indicates that the budget allocation for AI agent identity management differs significantly from traditional Identity and Access Management (IAM) projects.

Today’s SY0-701 CompTIA Security+ Pop Quiz: A forest of data

This article presents a pop quiz focused on the SY0-701 CompTIA Security+ certification exam, specifically covering the topic of 'A forest of data'. It is designed to help individuals prepare for their Security+ certification.

Today’s 220-1202 CompTIA A+ Pop Quiz: We need more light

This article presents a pop quiz for the CompTIA A+ 220-1202 certification exam, focusing on topics that require clarification. It aims to help individuals preparing for the certification test by providing practice questions.

Socket Raises $60 Million at $1 Billion Valuation

Socket, a security company focused on protecting open-source software supply chains, has announced it has raised $60 million in funding, bringing its valuation to $1 billion. The company plans to use this investment to enhance its firewall technology, develop certified patches, expand protection features, introduce new products, and grow its team.

Infosecurity Europe

Infosecurity Europe, a major cybersecurity event, is scheduled to take place in Barcelona from June 4-6, 2024. The event will feature keynotes, panel discussions, and networking opportunities focusing on current and future cybersecurity challenges.

GitHub scales back bug bounties, reminds users security is their responsibility too

GitHub is modifying its bug bounty program, shifting from cash rewards to swag for low-impact vulnerability reports and emphasizing user responsibility for security. The platform has seen a surge in submissions, partly due to AI tools, leading to a need to filter out less significant reports and focus on genuine security risks.

Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution

This article reflects on two decades of cybersecurity evolution, highlighting shifts from perimeter defense to assume-breach strategies. It warns that despite advancements like AI and cloud adoption, organizations are still neglecting fundamental security hygiene, leaving them vulnerable to sophisticated attacks.

Today’s 220-1201 CompTIA A+ Pop Quiz: I can see it much better

Professor Messer is offering a free pop quiz for the CompTIA A+ 220-1201 certification exam. This quiz is designed to help individuals test their knowledge and prepare for the certification. The resource is provided through his IT certification training courses.

Why the best security investment a board can make in 2026 isn’t another tool

Many organizations repeatedly purchase new security tools to address perceived gaps, yet struggle with fundamental visibility issues. This cyclical approach, driven by a desire to appear proactive, often fails to improve overall security posture because the core problem of understanding assets, access, and activity remains unaddressed. True risk reduction comes from comprehensive visibility rather than an accumulation of specialized tools.

Cyber Pioneers Ponder Past as Prologue

Several prominent cybersecurity figures, including Robert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier, reflect on their past columns for Dark Reading. They discuss how their insights from the past 20 years remain relevant to the current cybersecurity landscape.

SecurityScorecard Snags Driftnet to Level Up Threat Intelligence

SecurityScorecard has acquired Driftnet to enhance its threat intelligence capabilities, particularly in understanding third-party ecosystems. This acquisition aims to provide greater visibility into supply chains, which are increasingly targeted by attackers.