Product updates, security insights, and compliance guides
Categories
HIPAA Security Rule Delayed to 2027. Your Exposure Wasn't.
HHS pushed the Security Rule overhaul to July 2027. What that means for a 2026 remediation budget, and why your exposure did not move.
Shadow AI Is an Egress Path You Have No Record Of
Shadow AI appeared in 43% of breaches this year, up from 20%. Those breaches cost more and one in five drew a regulatory fine.
Can You Prove Your Security Configuration Wasn't Changed?
Tamper-evident logging makes deletion detectable, not just alteration. Why per-record hashes miss the attack that actually happens, and where the record has to live.
S3 Object Lock: Why Governance Mode Is Not Immutability
Governance mode lets privileged users delete locked objects. Compliance mode does not. Why the difference decides whether your audit logs are evidence.
Why One Cyber Incident Means Reports to Multiple Regulators
Fifteen federal regulations require financial firms to report cyber incidents, from eight agencies. What harmonization is, and why it hasn't arrived.
You Can't Buy Your Way Out of Vendor Sprawl
Every new tool you add is another seam. Key sprawl, vendor sprawl, and data sprawl create the gaps where breaches actually start — not inside the consoles you are watching, but between them. The structural answer is consolidation, not another point solution.
What Happens to Hospital Data When a Billing Software Vendor Gets Breached?
When a healthcare software vendor is breached, the exposure extends to every file, credential, and record its customers hold. The Craneware incident shows why, and what a health system can verify on its own without waiting for the vendor's timeline.
SANS Top 5 Attack Techniques All Use AI — What This Means for File Transfer
For the first time, every technique in the SANS Institute's annual Top 5 carries an AI dimension. AI-powered attackers can go from intrusion to domain admin in eight minutes. Legacy file transfer infrastructure built on static SSH keys and monolithic architectures cannot survive this threat landscape.
Why I Built MnemoShare
In 2023, the MOVEit breach became painfully personal. It forced me to confront something I had seen for decades: we keep accepting fragile security models where failure is catastrophic. MnemoShare is my answer to that experience.
Ephemeral Credentials for Healthcare Data Exchange
Long-lived credentials are the primary attack vector in healthcare data breaches. Ephemeral credentials — short-lived tokens bound to verified identities — reduce the blast radius of compromise from months to minutes.
SOC 2 Audit Logging for File Transfers: What Auditors Actually Check
SOC 2 Type II auditors examine whether your file transfer audit logs are complete, tamper-evident, and independently verifiable. Most MFT platforms fail at least one of these criteria. Here is what evidence-grade audit logging looks like.
How to Replace SFTP Keys with Short-Lived Certificates
SSH keys are permanent by default. Replacing them with short-lived certificates bound to verified identities eliminates credential sprawl and reduces the blast radius of compromise to minutes instead of months.
Zero Trust Managed File Transfer: Beyond the Perimeter
Legacy MFT platforms were built for perimeter-based security. Zero trust file transfer means no standing credentials, identity verification at every access, and audit trails that assume breach. Here is what that looks like in practice.
HIPAA-Compliant File Transfer Without SFTP
SFTP has been the default for moving PHI between organizations for decades. But SSH keys and minimal audit logging create compliance gaps that auditors increasingly flag. Here is how to move regulated healthcare data without SFTP.