top of page
The Red Thread Newsletter


The Red Thread Weekly Wrapup: Issue #21
Categories: IT Risk Management | Information Security | Penetration Testing I spent part of this week reviewing how several recent security incidents developed, and the same problem kept appearing: time. Not technology. Not a lack of security products. Time. An attacker now has the ability to move from an exposed entry point to sensitive systems in hours. A public proof of concept can turn a patching decision into an emergency. A forgotten vendor integration can preserve acce
Sep 46 min read


The Red Thread Weekly Wrapup: Issue #20
Categories: IT Risk Management | Information Security | Penetration Testing I was reviewing a technology risk discussion this week when the conversation turned to artificial intelligence. The question was familiar: “Can we trust the tool?” That is no longer the right question. The better question is: “What can the tool reach, what can it change, and who is accountable when it makes the wrong decision?” The stories from August 24 through 27 made the answer difficult to ignore.
Aug 287 min read


The Red Thread Weekly Wrapup: Issue #19
Categories: IT Risk Management | Information Security | Vulnerability Scanning I spent part of this week reviewing incidents that, on the surface, looked unrelated. One involved product lifecycle management software. Another involved Azure tenants. A third traced back to an open-source security scanner. The fourth involved vulnerabilities that had already been patched but were still finding their way into active attacks. The common thread was clear: attackers were not breakin
Aug 215 min read


The Red Thread Weekly Wrapup: Issue #18
Categories: IT Risk Management | Information Security | Vulnerability Scanning This week, I was reviewing the way leadership teams describe their technology risk when I noticed a familiar pattern: third-party software was treated as procurement’s responsibility, vulnerability scanning was treated as an IT routine, and the perimeter was treated as a firewall problem. That separation no longer reflects how organizations are attacked. Over my 26 years in cybersecurity, I have wa
Aug 146 min read


The Red Thread Weekly Wrapup: Issue #17
Categories: IT Risk Management | Information Security | Penetration Testing Over my twenty-six years in this industry, I have learned that regulatory deadlines and technical flashpoints rarely arrive in neat isolation. This week brought a heavy collision of strict regulatory enforcement and sophisticated supply chain turbulence that demands a clear-eyed look from leadership teams who thought they had plenty of breathing room before confronting modern digital risks. The most s
Aug 72 min read


The Red Thread Weekly Wrapup: Issue #16
Categories: IT Risk Management | Information Security | Penetration Testing Author: Red Spider Security Team I was thinking about a scene from this week's post, "The Green Dashboard Delusion: Why Your Compliance Scorecard Isn't Making You Safer," because I have seen some version of it too many times. The CEO is at the front of the room. The slide deck is polished. The dashboard is green across the board. A few heads nod. Someone says it looks like the company is in good shape
Jul 313 min read


The Red Thread Weekly Wrapup: Issue #15
Categories: IT Risk Management | Information Security | Penetration Testing Author: Red Spider Security Team I was sitting in a board meeting earlier this week, listening to a CFO describe their IT department as a Swiss Army knife. On the surface, it sounded like a compliment. They had one person who could fix the printer, reset a password, and supposedly manage the entire security posture of a fifty-million-dollar enterprise. But as I looked at the dark circles under that IT
Jul 245 min read


The Red Thread Weekly Wrapup: Issue #14
Categories: IT Risk Management | Information Security | Penetration Testing I was recently reviewing a contract for a mid-market manufacturing firm that had just hired their first dedicated security lead. They were proud of the move, and they should be. But when I looked at the job description, it covered everything from firewall management and cloud architecture to PCI compliance and employee training. It was a classic example of a problem I see across almost every industry
Jul 24 min read


The Red Thread Weekly Wrapup: Issue #13
Categories: IT Risk Management | Information Security | Penetration Testing I have spent 26 years watching the same patterns repeat across different technologies, and this week was a loud reminder of why the gear you trust most is often your biggest blind spot. When we buy a firewall or a high-end security appliance, there is a psychological shift that happens in the boardroom. We check a box. We assume the perimeter is held by a silent, infallible sentry. But the reality is
Jun 264 min read
bottom of page