Blog
-
Picking the Security Certification That Actually Unsticks Your Deals
A prospect sends over their vendor security questionnaire, and buried between “MFA policy” and “vendor management” sit three checkboxes sales can’t explain. SOC 2, ISO 27001, and the Cybersecurity Maturity Model Certification (CMMC). Are they the same thing? Interchangeable? A scam? None of the above. All three show up in questionnaires because procurement teams keep…
-
Privilege Dies in the Distribution List
…and other lessons from modern incident response Somewhere between the ransom note arriving in your inbox and opposing counsel eyeing your forensic report, your incident stopped being a technical problem. A ransomware crew posts your data, and a reporter calls before your security team has finished figuring out which accounts were compromised. At that point…
-
The £958 Million Workaround
Two consulting firms ran surveys about AI in the workplace this year and, read together, they describe organizations at war with themselves. FTI Consulting polled 1,600 senior decision-makers at large companies across seven markets and found that 60% had slowed, paused, or pulled back a planned AI deployment in the past twelve months. Deloitte, in…
-
How a Data Breach Cost Palomar Health Medical Group Ten Times What Prevention Would Have
On May 5, 2024, Palomar Health Medical Group (PHMG) found a ransom note sitting on its network alongside encrypted systems. Threat actors had been inside since April 23, copying files for twelve days. By September 4, 2025, the final tally stood at 1,132,116 people whose Social Security numbers, medical histories, payment card data, and in…
-
47% Of Companies Skip Their Own AI Governance Rules
Almost every large US company has an AI governance policy, and nearly half of them ignore it when deployment speed matters more. That’s the headline finding from the inaugural EY US AI Risk and Governance Survey, which polled 202 senior AI decision-makers at publicly traded companies with at least $1 billion in annual revenue. Ninety-eight…
-
Ten Weeks After the Money Arrived, Two Retiring Servers Got Popped
On April 30, 2025, Clearlake Capital finalized a majority investment in Modernizing Medicine (“ModMed”), valuing the specialty healthcare software-as-a-service (SaaS) company at $5.3 billion. Ten weeks later, on July 9, an unauthorized party accessed two servers inside ModMed’s infrastructure. These weren’t production systems powering the electronic health records (EHR) used by 40,000 providers. They were…
-
The Notetaker Doesn’t Work for You
Somewhere in Texas there’s a boardroom that wishes it had checked its meeting software settings. On August 28, 2026, Vice Chancellor Lori Will of the Delaware Court of Chancery (my favorite Court of Chancery!) ended a proxy fight at Empery Digital, a Bitcoin treasury company headquartered in Texas, by ruling that its board had no…
-
Why Your Security Proposal Died in Thirty Seconds
It’s sitting in a shared drive somewhere right now, gathering digital dust. Fourteen pages of well-researched risk analysis, a defensible budget request, and a routing slip with three approvals already collected. The fourth signature never came, and nobody can tell you exactly why. That’s the part nobody puts in the case study, because the honest…
-
The Price Tag On Safe Fleet’s Data Breach
When someone steals personnel files on 7,478 current and former employees, the invoice doesn’t arrive all at once. It dribbles in over two and a half years, disguised as legal fees, settlement payouts, credit monitoring subscriptions, and administrator invoices. Safe Fleet Holdings, the Missouri-based fleet safety manufacturer that Oak Hill Capital sold to Clarience Technologies…
-
Did Perplexity Tell the Ninth Circuit the Truth About Comet for iOS?
Perplexity AI secured a unanimous appellate victory this summer, but about seven weeks later, Amazon filed a First Amended Complaint accusing Perplexity of lying about how its agent works. The Ninth Circuit had vacated Amazon’s preliminary injunction and told the lower court that agentic software acts as a tool for users, not an independent actor…