Articles In Security

By Steve Gold, Posted in Security

In The Bear, every station in the kitchen has a different job, a different set of skills, and a completely different set of things that can go wrong. You do not train the pastry chef the same way you train the expeditor. You do not pull the sous chef aside to explain how to plate a salad. Everyone needs to know the basics, but the role-specific skills are what keep the kitchen from catching fire. Your security training program works the same way. What Is Conduct Role-Specific Security Awareness and Skills... read more.

  • September 15, 2026

By Steve Gold, Posted in Security

In Succession, every power move and every backstab eventually came back to one question: what's on the record? When things went sideways for the Roys, the only way to reconstruct the truth was to go back to the tape. Someone, somewhere, had kept a log of what happened. CIS Safeguard 13.6 is your network's version of that tape. What Is CIS Safeguard 13.6? Network traffic flow logs are records of every connection that crosses your network. Source IP, destination IP, port, protocol, bytes transferred, timest... read more.

  • September 08, 2026

By Ken Phelan, Posted in Infrastructure, Security, Support

A few weeks ago I wrote a post called "It's Not the Model." The short version: frontier AI is finding vulnerabilities at industrial scale, the capability will land on every platform eventually, and the scarce resource isn't the model — it's the ability to absorb what the model finds. The reactions came in two flavors. Half the room heard "the sky is falling." The other half said "the sky was always falling, why are we talking about it now?" Both halves are wrong, and it's worth being precise about w... read more.

  • September 03, 2026

By Steve Gold, Posted in Security

In the 2022 Andor series, the Rebel network operates on strict need-to-know access. Operatives who break protocol lose their connection to the network entirely, not as punishment, but as operational necessity. If your credentials or your compliance are in question, the network shuts you out before you become the breach. That's exactly the model CIS Safeguard 13.5 asks you to build for your remote users. What Is Manage Access Control for Remote Assets? CIS Safeguard 13.5 is about making sure remote access... read more.

  • September 01, 2026

By Steve Gold, Posted in Security

In Severance, the employees of Lumon Industries live in a world of strict compartmentalization. Your work self cannot access what your personal self knows, and you certainly cannot wander into another department's floor without authorization. Every boundary is enforced at the threshold, with no exceptions. That is exactly what good network traffic filtering looks like. What Is Perform Traffic Filtering Between Network Segments? Traffic filtering between network segments means controlling what can talk to... read more.

  • August 25, 2026

By Steve Gold, Posted in Security

In Andor (2022), the rebel intelligence cell at Ferrix doesn't wait for the Empire to announce its arrival. They funnel every signal, every movement, every comm transmission into a single command center and watch the whole network in real time. The moment something looks wrong, someone knows. That is exactly what a Network Intrusion Detection System does for your enterprise, and CIS Safeguard 13.3 says you should have one. What Is Deploy a Network Intrusion Detection Solution? A Network Intrusion Detectio... read more.

  • August 18, 2026

By Steve Gold, Posted in Security

In HBO's The Last of Us (2023), the cordyceps fungus does its most dangerous work quietly, at the individual host level, before anyone realizes what is happening. By the time the network-level symptoms appear, containment is already a long shot. The parallel to cybersecurity is uncomfortable but exact. Host-based intrusion detection is about catching the infection on the machine where it starts, before it moves anywhere else. What Is Deploy a Host-Based Intrusion Detection Solution? A host-based intrusion... read more.

  • August 11, 2026

By Steve Gold, Posted in Security

When the oxygen tank ruptured on Apollo 13, mission control didn't learn about it from a single alarm. They learned about it from a constellation of anomalies: pressure readings, power fluctuations, thruster telemetry, all converging on one floor in Houston at the same time. That centralized view of every system on the spacecraft is what gave the team the context they needed to understand what was happening. Individual data points told a partial story. The correlation told the truth. That is exactly what C... read more.

  • August 04, 2026

By Ken Phelan, Posted in Security

You've sat at this dinner. Eight security leaders around a table, good wine, better steak, and a conversational register I've come to think of as the auditor voice. Everyone has a mature program. Everyone's board is engaged. Everyone is "well positioned" on AI. By dessert you start to wonder whether your dinner companions are interviewing for their next role or rehearsing for their next examination — because nobody talks like that to people they trust. Here's the thing: I don't blame them. The perfo... read more.

  • August 03, 2026

By Steve Gold, Posted in Security

In The Bourne Identity, Jason Bourne is a CIA operative, one of their best. But the moment he goes off the grid and stops authenticating through official CIA channels, something critical happens: the CIA loses the ability to support him, track him, or protect the mission. They can't help what they can't see. Resources dry up. Oversight vanishes. The whole operational picture breaks down because one asset is running without accountability to the infrastructure designed to support, and protect, him. Your rem... read more.

  • July 28, 2026