Field notes, threat breakdowns and practical guidance from the MBCTG team.
Five US agencies warn attackers are using AI-generated scripts to hit internet-exposed Siemens S7 PLCs. What AA26-231A found, and what to do now.
OWASP's 2026 LLM Top 10 ranked risk using real incident data for the first time. Excessive Agency jumped from 6th to 3rd — here's why that matters.
Dragos logged 1,140 industrial ransomware incidents in Q2 2026, manufacturing hit hardest. Most attacks never touched OT — IT disruption alone was enough.
A 300-person company with a four-person IT team isn't understaffed by accident — it's understaffed by design. Here's where the coverage actually breaks.
MFA secures human logins, but much of OT never authenticates at all. Here's why your most critical assets need more than a second factor.
Building management systems are quietly becoming the soft underbelly of the corporate network. Here's why a BMS compromise is now everyone's problem — and what to do about it.
The Cyber Resilience Act applies to any connected product sold into the EU, US-made or not. Here's what changes by September 2026 and what's still ahead in 2027.
NIST CSF 2.0 adds a sixth function and puts governance on equal footing with technical controls. Here's what changed and where to start.
Accelerating customer success through secure AI adoption and cloud modernization.