Before I was a lowly CEO, 22 of my 34 years in tech were spent as a customer of cybersecurity services, and the lack of capable MSSPs played a major role in my decision to start ProCircular. It's a topic near and dear to my heart: most cybersecurity firms or MSSPs leave clients wanting, and frequently, CISO teams end up training their cyber vendors. Incredibly frustrating.
Before I was a lowly CEO, 22 of my 34 years in tech were spent as a customer of cybersecurity services, and the lack of capable MSSPs played a major role in my decision to start ProCircular. It's a topic near and dear to my heart: most cybersecurity firms or MSSPs leave clients wanting, and frequently, CISO teams end up training their cyber vendors. Incredibly frustrating.
Topics: Company News, cybersecurity, MSSP
AI-Native Security Starts With the Basics You Already Know
Fahmida Y. Rashid wrote a 20-year retrospective for Dark Reading (May 2026). If you sit on a board or approve security budgets, it's the clearest explanation I've seen in a long time of how we got here.
CMMC Phase 2 is Paused - The Homework is Still Due.
On July 13th, 2026, the DoW CIO released a statement mandating a pause in the Phase 2 rollout of the Cybersecurity Maturity Model Certification (CMMC) program, which was scheduled to go into effect on November 10th of 2026. Additionally, the article announced a 60-day review period of the program aimed at reducing red tape and barriers to entry for SMBs, along with a public Request for Information (RFI). Further public memos have been published outlining clarifications and implementation specifics for the statement, including outlines for interim actions for Department contractors and requirements for necessary contract revisions.
Topics: Government & Public Sector, Manufacturing, Compliance & Governance
Russia's FSB is scanning routers this week - Get faster than the bear.
If you run security for a hospital system, a bank, a college, or a manufacturer, a new government advisory deserves ten minutes this week.
On July 13, NSA, CISA, FBI, and DC3, joined by partners across the Five Eyes and Europe, released "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting" (AA26-194A). It documents a decade-plus campaign by Russia's FSB Center 16 against networking devices. The sectors it names as most at risk are financial services, healthcare and public health, energy, communications, the defense industrial base, and government, especially at the state and local levels.
Topics: Vulnerabilities, Penetration Testing, Monitoring & Detection, Security Advisory
Many of you have seen the headlines about the breach at Instructure, the company behind the Canvas learning management system used by 41% of higher education institutions in North America and thousands of K-12 districts. Here's what's known, and what your institution should be doing about it.
Topics: Incident Response, Ransomware, Compliance & Governance, AI & Emerging Technology