Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
October 6, 2026 · 4 min read
Backups That Survive Ransomware
Ransomware operators know backups are the main reason victims refuse to pay, so they hunt for them first. How attackers target backups, what makes a backup resilient, and why a restore you have never tested is only a hope.
Read moreOctober 4, 2026 · 4 min read
Prioritizing Vulnerabilities with KEV, EPSS and CVSS
Every scan produces more vulnerabilities than any team can fix at once. Severity scores alone point you at the wrong ones. How to combine CISA's Known Exploited Vulnerabilities catalog, the Exploit Prediction Scoring System and CVSS with your own context to fix what matters first.
Read moreSeptember 1, 2026 · 4 min read
Hostile Drones: Reconnaissance, Payloads and Signal Interception
Armed conflicts and incidents at military and critical sites have shown how quickly drones evolve from curiosity to threat. The patterns emerging from public reporting, and what they mean for organizations protecting sensitive facilities and operations.
Read moreAugust 11, 2026 · 4 min read
Wireless and RF Attack Surfaces Organizations Overlook
Radio signals do not stop at the fence line. The wireless attack surfaces organizations often miss, including Wi-Fi, Bluetooth, cellular, satellite and industrial radio, and how to assess and reduce them.
Read moreJuly 28, 2026 · 4 min read
Cloud Misconfigurations Attackers Exploit Most
In the cloud, a single setting can expose an entire dataset or grant an attacker control of an environment. The misconfigurations attackers look for first, why they keep happening, and how to find and prevent them.
Read moreJuly 7, 2026 · 4 min read
Threat Hunting 101: Hypothesis-Driven Hunting with MITRE ATT&CK
Threat hunting assumes an attacker may already be inside and goes looking. How to structure hunts around testable hypotheses, the data you need, and how to turn every hunt into lasting detections.
Read moreJune 16, 2026 · 4 min read
Insider Threats in Cleared Environments
Some of the most damaging compromises of classified and sensitive information have come from people with legitimate access. How insider threat programs work for cleared organizations, the indicators they watch for, and the technical controls that support them.
Read moreJune 2, 2026 · 4 min read
Identity Is the New Perimeter: Token Theft, MFA Fatigue and Session Hijacking
As organizations move to cloud services and remote work, attackers increasingly target identities rather than networks. The techniques used to defeat passwords and multifactor authentication, and how to build identity defenses that hold.
Read moreMay 19, 2026 · 4 min read
Adversarial Use of AI: What's Real and What's Hype
Claims about AI-powered attacks range from sober to sensational. What public threat reporting actually shows about how adversaries use AI, what remains overstated, and how defenders should respond.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.