Blog

By Eric Corcoran, Posted in Technology Week in Review

Monday 10/5 As AI agents take on a greater role across the enterprise, building trust requires a clear approach to risk, security, and governance. Join Gotham CTO Ken Phelan at the 2026 WLDA AI Summit on Friday, October 30, at the New York Stock Exchange. Ken will lead a discussion with Straiker CEO Ankur Shah and BMO EVP and Head of Financial Crime and Security Larry Zelvin on building trust in the agentic enterprise. Click the link below to learn more and register: https://wlda.tech/2026-wlda-summit-a... read more.

  • October 09, 2026

By Pablo Vidal, Posted in Security

In my last post I wrote about how AI has changed day-to-day perimeter work: policy cleanup, onboarding new services, all the documentation around a change. This time I want to talk about the part of the job where speed matters most: the moment something looks wrong and you need to know, right now, whether it's real, how far it went, and what to block. If you read Ken Phelan's recent post, Twenty-Three Hours, you already know the story. We patched our remote-access gateways on a Saturday, and about 23 hours... read more.

  • October 08, 2026

By Steve Gold, Posted in Security

In Dune: Part Two, Paul Atreides does not treat every alliance the same way. The Fremen are strategic partners with deep access to his plans and survival. The Spacing Guild controls critical infrastructure that nothing in the known universe moves without. House Corrino is a threat dressed up as diplomacy. Paul classifies each relationship by what it controls and what risk it carries, because treating them equally would get him killed. Your vendor ecosystem works exactly the same way. What Is Classify Servi... read more.

  • October 06, 2026

By Brian Wagner, Posted in Security

I've always been a huge fan of Reddit. It's real people talking about real things. You follow the topics you care about and you often hear the news there before anywhere else. So on Saturday, September 26, when I started seeing chatter about an unpublished NetScaler® vulnerability, I had to dig in. The more I read, the more interested I got. Organizations were shutting down their NetScalers, and the vendor hadn't said anything yet. That evening I was at the wedding of one of my favorite people. Betwee... read more.

  • October 05, 2026

By Ken Phelan, Posted in Security

Sixteen months ago, I wrote about a fort. Fort Pulaski was state of the art in 1847. Eleven-foot walls, an eight-foot moat, and a full mile of open water between it and any ground an army could stand on. Then the Union showed up with rifled cannons nobody had planned for, and thirty hours later it was over. The lesson is that innovation favors the attacker, and that the right posture for a defender isn't prediction. It's humility. I closed that piece with one word. Resiliency. That's a fine word. It's a... read more.

  • October 01, 2026

By Ken Phelan, Posted in Security

On a Saturday in late September, we patched our remote-access gateways. Routine stuff. A vendor had published fixes for two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, and we pushed the fixed build to both nodes that afternoon. Ten minutes of downtime. Nobody noticed. About 23 hours later, the attackers showed up. Some background. These two bugs weren't new to the attackers. They were already being exploited as zero-days before the vendor published a fix. The bad guys had a head start. Th... read more.

  • September 30, 2026

By Steve Gold, Posted in Security

In Netflix's The Diplomat (2023), Ambassador Kate Wyler does not wing her relationships with foreign governments. She operates inside a framework of protocols, obligations, and documented agreements. When a crisis hits, she knows exactly what her options are and what the rules of engagement require. Without that framework, every new incident becomes a scramble. Your vendor relationships work the same way. When something goes sideways with a service provider, a documented policy tells you exactly what to do... read more.

  • September 29, 2026

By Eric Corcoran, Posted in Technology Week in Review

Monday 9/21 Two zones or three? A design framework for zone-resilient Azure workloads (Microsoft) Zone resiliency is not a property you switch on for an entire workload. It’s a set of decisions you make component by component. Some components are fully protected across two zones. Some genuinely need a third. And for a growing number, Azure manages zone redundancy for you, and the best decision is to let it. This post is about how to tell the difference. https://azure.microsoft.com/en-us/blog/two-zo... read more.

  • September 25, 2026

By Jason Santamaria, Posted in Security

There's a scene near the end of Indiana Jones and the Last Crusade where an ancient knight, guarding a cave full of chalices, tells Indy to pick the real Holy Grail out of dozens of convincing fakes. "Choose wisely," he warns, "for while the true Grail will bring you life, the false Grail will take it." Indy studies the room, a plain wood cup versus gilded goblets, and picks the humble one. He's right. The villain who grabs the jewel-encrusted one moments later is not, and it does not end well for him. It'... read more.

  • September 25, 2026

By Steve Gold, Posted in Security

You’re running late for an appointment. No coffee, no breakfast, the outfit is not, exactly, what you were hoping for.  You need to make up time, so you start looking for it wherever you can find it. You approach an intersection with a stop sign, glance both ways, and roll right through without fully stopping. Congratulations. You are now a GRC expert. You knew the rule. You know how to be compliant. You made a calculated decision to accept the risk anyway because the odds felt good and the pay... read more.

  • September 22, 2026