Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
September 8, 2026 · 4 min read
Why Annual Penetration Tests Aren't Enough Anymore
A once-a-year penetration test shows your security on the days it was performed. Environments now change weekly. How continuous and change-driven testing closes the gap, and how to decide what your organization needs.
Read moreSeptember 1, 2026 · 4 min read
Hostile Drones: Reconnaissance, Payloads and Signal Interception
Armed conflicts and incidents at military and critical sites have shown how quickly drones evolve from curiosity to threat. The patterns emerging from public reporting, and what they mean for organizations protecting sensitive facilities and operations.
Read moreAugust 25, 2026 · 5 min read
Security Control Assessments: What an Independent Assessor Actually Tests
Examine, interview and test. How independent assessors decide whether security controls really work, and how to prepare your people, documents and systems for each method.
Read moreAugust 18, 2026 · 5 min read
CMMC Level 2 Self-Assessment vs. Third-Party Assessment: Which Applies to You?
With the Phase 2 third-party requirement suspended, Level 2 self-assessments carry more weight than ever. How the two paths differ, and how to prepare so either one goes smoothly.
Read moreAugust 11, 2026 · 4 min read
Wireless and RF Attack Surfaces Organizations Overlook
Radio signals do not stop at the fence line. The wireless attack surfaces organizations often miss, including Wi-Fi, Bluetooth, cellular, satellite and industrial radio, and how to assess and reduce them.
Read moreJuly 28, 2026 · 4 min read
Cloud Misconfigurations Attackers Exploit Most
In the cloud, a single setting can expose an entire dataset or grant an attacker control of an environment. The misconfigurations attackers look for first, why they keep happening, and how to find and prevent them.
Read moreJuly 21, 2026 · 5 min read
FedRAMP Readiness: What Cloud Providers Need Before Starting
FedRAMP is changing fast under FedRAMP 20x and the 2026 Consolidated Rules. What stays constant for cloud providers, what is new, and how to prepare before engaging an assessor.
Read moreJuly 7, 2026 · 4 min read
Threat Hunting 101: Hypothesis-Driven Hunting with MITRE ATT&CK
Threat hunting assumes an attacker may already be inside and goes looking. How to structure hunts around testable hypotheses, the data you need, and how to turn every hunt into lasting detections.
Read moreJune 23, 2026 · 5 min read
GOTS vs. COTS in Classified Solutions: Choosing and Integrating the Right Mix
Classified solutions increasingly combine government and commercial technology. How government off-the-shelf and commercial off-the-shelf components differ, where each fits, and what it takes to integrate and accredit them together.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.