Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
October 7, 2026 · 4 min read
Tabletop Exercises That Actually Prepare Your Team
An incident response plan that has never been practiced will fail in ways nobody expected. Tabletop exercises find those failures in a conference room instead of during a real attack. How to design, run and follow up on exercises that build real readiness.
Read moreOctober 5, 2026 · 4 min read
Logging That Actually Helps an Investigation
When an incident happens, the first question is what the attacker did. The answer is only as good as the logs you kept. Which logs matter most, how long to keep them, what OMB M-21-31 requires of federal agencies, and how to make logs useful before you need them.
Read moreOctober 3, 2026 · 4 min read
Zero Trust from Strategy to Practice
Zero trust has moved from buzzword to mandate. Federal agencies and the Department of War are working toward defined zero trust targets. What zero trust actually means, how the DoD pillars fit together, and where to start.
Read moreOctober 2, 2026 · 5 min read
Phishing-Resistant MFA: Why Some Second Factors Are Better Than Others
Multifactor authentication stops most password attacks, but attackers have learned to steal one-time codes and abuse push notifications. What makes MFA phishing-resistant, what federal policy requires, and how to roll it out without disrupting the mission.
Read moreOctober 1, 2026 · 5 min read
Cybersecurity Awareness Month: Four Habits That Still Stop Most Attacks
October is Cybersecurity Awareness Month. Most successful attacks still begin with a weak password, a missing patch or a convincing message. Four everyday habits, and how organizations can make them stick beyond October.
Read moreSeptember 15, 2026 · 4 min read
Drones as a Security Risk: What Facility Security Teams Should Know
Small unmanned aircraft are cheap, capable and widely available. How drones create physical and cyber risk for facilities and operations, what organizations can and cannot legally do about them, and how to start assessing exposure.
Read moreSeptember 8, 2026 · 4 min read
Why Annual Penetration Tests Aren't Enough Anymore
A once-a-year penetration test shows your security on the days it was performed. Environments now change weekly. How continuous and change-driven testing closes the gap, and how to decide what your organization needs.
Read moreJune 23, 2026 · 5 min read
GOTS vs. COTS in Classified Solutions: Choosing and Integrating the Right Mix
Classified solutions increasingly combine government and commercial technology. How government off-the-shelf and commercial off-the-shelf components differ, where each fits, and what it takes to integrate and accredit them together.
Read moreApril 28, 2026 · 5 min read
What to Look for in a Penetration Testing Report
The report is the product of a penetration test, and quality varies enormously. How to judge whether a report gives you verified findings, real attack paths and a clear plan, or just a reformatted scan.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.