13 September 2026 · Governance · Cybersecurity · 5 min read
A decade-old Shellshock finding should trigger questions about asset ownership, deferred remediation, compensating controls, exception expiry and the business dependency keeping vulnerable technology alive.
Read article →
9 September 2026 · Identity Security · Cybersecurity · 6 min read
MFA remains essential, but session tokens, recovery processes, help-desk verification, device trust and step-up controls determine whether authenticated access should remain trusted.
Read article →
8 September 2026 · Operational Resilience · Cybersecurity · 7 min read
Moving a scan to midnight can protect immediate operations without fixing the underlying weakness. Mature organisations use controlled realism to test detection, containment, continuity and recovery.
Read article →
7 September 2026 · Cybersecurity · Leadership · 6 min read
As technical knowledge becomes more accessible, Malaysia’s everyday ability to translate across cultures, align different perspectives and build trust can become a distinctive cybersecurity capability.
Read article →
16 August 2026 · Cybersecurity · Threat Detection · 5 min read
Fast attackers trigger alarms. Patient attackers can quietly learn the environment, preserve access and wait until their position becomes most valuable.
Read article →
15 August 2026 · Artificial Intelligence · Cybersecurity · 6 min read
AI may not create a new attack chain; it can remove the delays between familiar stages and force defence, identity and architecture to operate faster.
Read article →
13 August 2026 · Cybersecurity · Security Architecture · 5 min read
Security maturity is not measured by how many products remain in the stack, but by whether every retained tool still has a defined purpose and measurable value.
Read article →
12 August 2026 · Digital Trust · Cybersecurity · 5 min read
More accounts, content and engagement can conceal a quieter decline in authentic participation as people discover publicly but increasingly engage in private.
Read article →
10 August 2026 · Cybersecurity · Leadership · 5 min read
Security is shaped by thousands of choices across architecture, operations, governance and leadership—not by technology alone.
Read article →
7 August 2026 · Cybersecurity · Security Architecture · 5 min read
The real attack surface includes dormant packages, services, drivers and kernel modules that attackers can reach even when organisations never intended to use them.
Read article →
6 August 2026 · Cybersecurity · Leadership · 4 min read
Technical skills may secure the opportunity. Judgement determines whether others trust you with greater responsibility.
Read article →
5 August 2026 · Cybersecurity · Leadership · 6 min read
The best cybersecurity leaders distribute judgement, create career paths and prepare successors instead of making the organisation dependent on them.
Read article →
4 August 2026 · Cybersecurity · Security Architecture · 4 min read
Every control can fail. Resilient security architecture uses independent layers to contain failure before it becomes business disruption.
Read article →
3 August 2026 · Cybersecurity · Governance · 4 min read
Shadow IT is driven by productivity. The real security problem begins when technology use and information movement become invisible and ungoverned.
Read article →
2 August 2026 · Cybersecurity · Governance · 4 min read
A signed risk acceptance records a conscious decision to proceed. The exposure and accountability still remain with the organisation.
Read article →
29 July 2026 · Cybersecurity · Careers · 4 min read
Certifications should support a deliberate cybersecurity career strategy built on direction, practical experience, reputation and curiosity.
Read article →
27 July 2026 · Cybersecurity · Leadership · 5 min read
Cybersecurity leadership is expanding from managing people and technology to governing humans, machines and AI agents under one framework of trust.
Read article →
25 July 2026 · Cybersecurity · Security Operations · 7 min read
A practical checklist for preserving detection coverage, historical evidence and monitoring readiness throughout a SIEM migration.
Read article →
24 July 2026 · Cybersecurity · Security Architecture · 3 min read
Good security architecture begins by challenging assumptions behind trust, access, data flows, controls and recovery.
Read article →
23 July 2026 · Cybersecurity · Security Architecture · 5 min read
Security architecture brings trust, controls and resilience together so the business can operate confidently.
Read article →
23 July 2026 · Cybersecurity · Security Operations · 3 min read
A SIEM migration changes how an organisation sees threats and must be governed as a period of elevated security risk.
Read article →
22 July 2026 · Cybersecurity · Security Architecture · 2 min read
Security controls protect technology. Security architecture protects the business by designing trust, resilience and outcomes.
Read article →
21 July 2026 · Cybersecurity · Security Architecture · 2 min read
Great security architects understand how attackers think, so they can design systems that remain resilient when trust fails.
Read article →
20 July 2026 · Cybersecurity · Leadership · 7 min read
The future cyber community must combine offensive curiosity with trust, resilience, responsibility and the ability to protect organisations.
Read article →
19 July 2026 · Cybersecurity · Digital Trust · 4 min read
Cybersecurity is evolving from protecting systems to engineering the trust relationships that allow organisations to innovate safely.
Read article →
17 July 2026 · Cybersecurity · Identity Security · 5 min read
The security perimeter has moved from network location to identity, permissions and continuously evaluated trust.
Read article →
16 July 2026 · Cybersecurity · Security Architecture · 5 min read
Connectivity is not trust. Explore why security architecture must make trust boundaries and controls visible, not merely data flows.
Read article →
15 July 2026 · Cybersecurity · Security Architecture · 5 min read
Security should enable organisations to create value safely—not become the bottleneck that drives risk outside governance.
Read article →
14 July 2026 · Cybersecurity · Security Architecture · 6 min read
Best practices are valuable, but strong security architecture begins with the risk and required outcome—not the same prescribed control for every environment.
Read article →
10 July 2026 · AI Security · Cybersecurity · 9 min read
AI coding agents are rapidly becoming part of developer workflows. The key security question is not how intelligent they are, but what they are allowed to access, execute, and change.
Read article →
9 July 2026 · Cybersecurity · Security Architecture · 3 min read
AirDrop and Quick Share highlight a difficult security trade-off: frictionless experiences often require systems to process information before trust is fully established.
Read article →
7 July 2026 · Cybersecurity · Active Directory · Security Architecture · 4 min read
A working Active Directory is not necessarily a resilient one. Explore six architectural principles that distinguish operational health from true cyber resilience.
Read article →
4 July 2026 · Zero Trust · Cybersecurity · 4 min read
Zero Trust is often misunderstood as “trust nobody” or simply another security product. Its true purpose is limiting the consequences when trust decisions prove wrong.
Read article →
29 June 2026 · Cybersecurity · Operational Resilience · 3 min read
Major incidents often begin as ordinary work. Explore why familiarity, routine exceptions, and ignored near misses create the conditions for failure.
Read article →
25 June 2026 · Cybersecurity · 4 min read
Is the absence of a cyberattack really evidence of strong security? Only one of the three possible explanations should inspire confidence.
Read article →
19 June 2026 · Cybersecurity · Leadership · 3 min read
A reflection on independence, incentives, vendor dependency, and the need for stronger internal cyber judgment.
Read article →
16 June 2026 · Cybersecurity · Leadership · Digital Trust · 4 min read
Explore the difference between imagined, borrowed, and earned confidence, and why it matters to security leaders.
Read article →
7 June 2026 · Cybersecurity · Leadership · 3 min read
Why cybersecurity fails when certainty replaces curiosity, and why challenging assumptions is a vital security control.
Read article →
31 August 2025 · Cybersecurity · Leadership · 4 min read
Certification is valuable evidence, but cybersecurity hiring must assess demonstrated capability, judgment, experience and potential.
Read article →
12 April 2025 · Cybersecurity · Security Operations · 4 min read
More security telemetry does not always mean better security. Explore why the modern SOC must optimise for signal, not alert volume.
Read article →
19 March 2025 · Cybersecurity · Leadership · 4 min read
Behind every security control is a person. Explore why collaboration, culture, ownership, and human sustainability are essential to cyber resilience.
Read article →
18 February 2025 · Cybersecurity · Leadership · 6 min read
A CISO’s experience becomes most valuable when it is adapted to the organisation’s actual authority, accountability and operating model.
Read article →
23 May 2024 · Cybersecurity · Threat Intelligence · 4 min read
Not every breach claim is a real compromise. Explore how honeypots and deception technology can turn attacker activity into defensive intelligence.
Read article →