In August 2025, Canada’s House of Commons confirmed a data breach in which an attacker exploited a recent Microsoft vulnerability to access a database containing employee […]
In late July 2025, active exploitation of on-premises Microsoft SharePoint Server put a large number of organizations into incident-response mode almost overnight. The exploit chain, widely […]
Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. […]
In June 2025, the federal government introduced Bill C-8, An Act respecting cyber security, reviving the cyber-security framework that had been developing in the previous Parliament. […]
Ask incident responders where modern breaches begin and the answer is remarkably consistent: identity. Across the first half of 2025, from credential-driven SaaS breaches to ransomware […]
Buying security tools is easy. Knowing whether they will actually catch an attacker is harder, and far more important. Purple teaming, where offensive and defensive work […]
Many Canadian small and mid-sized businesses treat privacy and security compliance as something that concerns only large, regulated enterprises. In 2025 that assumption is increasingly costly. […]
Every incident investigation eventually comes down to one question: what does the evidence show? Too often the honest answer is that the evidence was never collected. […]
Through the first half of 2025, AI moved from answering questions to taking actions. Agentic systems that can browse, call APIs, run code, and chain steps […]