Browse all articles

Advisory & Planning
5 Lessons Learned from the Biggest 2025 Cybersecurity Breaches

2025 continued the trend of high-volume cyber breaches, not because defenders were facing entirely new problems, but because familiar weaknesses kept failing at scale. The volume of reported breaches remained exceptionally high

Justin Fimlaid May 25, 2026 ∙ 9 min read
Advisory & Planning
The Failsafe Fallacy: Why Public Sector Organizations Need a Safe-to-Fail Mindset

Most public sector security teams are trying to build something that doesn't exist: an environment where nothing goes wrong. They invest in the latest tools, pass compliance audits, block thousands of threats a month, and report the numbers up the chain. Leadership hears exactly what they want to hear, “we are protected.” But that's the problem. Cybersecurity vs. Cyber Resilience: Two Different Goals Cybersecurity and cyber resilience are not the same thing. Most organizations treat them like they are. Cybersecurity is about keeping threats out. Firewalls, endpoint protection, MFA, patch management: these are all cybersecurity controls. They're necessary. But they...

Kyle Smith May 14, 2026 ∙ 5 min read
Advisory & Planning
24/7 Security Monitoring Becoming the Baseline for States Nationwide

Picture your state's IT security team on a Tuesday afternoon. They're talented, overextended, and genuinely committed to protecting the systems that millions of constituents depend on. At 5:01 p.m., they log off. The alerts keep firing. The logs keep generating. And somewhere overseas, an adversary who cares nothing about your labor agreements is just getting started. This is not a scare tactic. It is the operational reality that compliance frameworks, state labor law, and basic threat intelligence all point toward simultaneously. When you stack the regulatory mandates on top of the workforce realities on top of the 24/7 nature of...

Justin Fimlaid May 1, 2026 ∙ 8 min read
Advisory & Planning
Applying 2025 Lessons Learned to 2026 Readiness for Iran-Linked Cyber Conflict Spillover

Why the 2025 playbook is suddenly the right playbook for 2026: The Middle East-driven risk story going into the rest of 2026 is not “brand new cyber warfare.” It is familiar weaknesses being exploited with escalation dynamics (disruption, coercion, signaling) that look more like crisis behavior than ordinary cybercrime. An April 2026 joint advisory from the Federal Bureau of Investigation, National Security Agency, Environmental Protection Agency, Department of Energy, United States Cyber Command, and the Cybersecurity and Infrastructure Security Agency warns that Iran-affiliated APT actors are exploiting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) from Rockwell Automation,...

Justin Fimlaid April 19, 2026 ∙ 9 min read
Advisory & Planning
Creating Asymmetric Advantage: Neuroscience and the Electronic Battlefield

This isn’t a piece about advocating for one gender over another, and it’s certainly not about identity. It’s about cognition and how people think, perceive, decide and coordinate — and how the ways we think and decide shape victory or defeat on the modern battlefield.  Every person carries a unique cognitive fingerprint, shaped by the way they were raised, the beliefs they hold, the lessons they’ve learned, and the environments that tested them. No two people process risk, creativity, or adversity in exactly the same way. After decades in leadership — in boardrooms, on operations floors, and inside crisis response...

Justin Fimlaid February 4, 2026 ∙ 39 min read