PROCIRCULAR BLOG

Educating your business on the importance of cybersecurity

CMMC Phase 2 is Paused - The Homework is Still Due.

Posted by Keegan Paisley on Jul 17, 2026 2:30:43 PM

On July 13th, 2026, the DoW CIO released a statement mandating a pause in the Phase 2 rollout of the Cybersecurity Maturity Model Certification (CMMC) program, which was scheduled to go into effect on November 10th of 2026. Additionally, the article announced a 60-day review period of the program aimed at reducing red tape and barriers to entry for SMBs, along with a public Request for Information (RFI). Further public memos have been published outlining clarifications and implementation specifics for the statement, including outlines for interim actions for Department contractors and requirements for necessary contract revisions.

Read More

Topics: Government & Public Sector, Manufacturing, Compliance & Governance

Monitoring the Canvas Incident

Posted by Aaron R. Warner on May 7, 2026 8:08:22 PM

Many of you have seen the headlines about the breach at Instructure, the company behind the Canvas learning management system used by 41% of higher education institutions in North America and thousands of K-12 districts. Here's what's known, and what your institution should be doing about it.

Read More

Topics: Incident Response, Ransomware, Compliance & Governance, AI & Emerging Technology

Shadow AI: The Risk Your Security Tools Can’t See

Posted by Aaron R. Warner on May 7, 2026 7:45:00 AM

What shadow AI really looks like inside a normal workday

Shadow AI is any AI tool, feature, or integration your organization uses without clear approval, security review, or monitoring, but it still touches real business data. It’s the AI sidebar in your CRM, the browser extension a manager added, or an “assist” feature turned on by a vendor.

Read More

Topics: Hospitals & Health Care Systems, Compliance & Governance, AI & Emerging Technology

The 10-Petabyte Heist: The Recent China Supercomputing Breach Means

Posted by Aaron R. Warner on Apr 9, 2026 4:55:05 PM

If you've been in cybersecurity long enough, you develop a reflex: dramatic claims usually aren't true. So when a tweet started circulating in early April 2026 alleging 10 petabytes of data had been stolen from China's National Supercomputing Center in Tianjin—including defense documents and missile research—my reaction was the same as most practitioners: prove it. This brings us to the crucial question: did it really happen?

Read More

Topics: Data Protection & Privacy, Penetration Testing, Monitoring & Detection, Compliance & Governance

Lessons from Strkyer: Dual Controls, Multi-Admin Approval & Recent Cyberattacks

Posted by Keegan Paisley on Mar 18, 2026 3:13:06 PM

Written by Willie Zhang and Keegan Paisley

On March 11th, medical technology manufacturer Stryker disclosed a cybersecurity incident affecting its internal IT systems. The attack caused a global disruption to the company's Microsoft environment. Stryker activated its incident response process and brought in outside cybersecurity specialists.

Read More

Topics: Incident Response, Hospitals & Health Care Systems, Compliance & Governance

  • There are no suggestions because the search field is empty.

ProCircular is a Full-Service Information Security Firm

We are passionate about helping businesses navigate the complex world of information security, and our blog is another great source of inforamtion. We can assist you no matter where you are in your security maturity journey:

  • Breached or hit with ransomware?
  • Don't know where to start? 
  • Looking to confirm your security with a third party?

Secure your future with ProCircular.

Recent Posts

Subscribe to Email Updates