by Ron Samson | | Cybersecurity, Managed Security, Network Security
Cybersecurity due diligence is a deal-value discipline Mergers and acquisitions teams are accustomed to testing financial statements, customer concentration, intellectual property, and legal exposure. Cybersecurity deserves the same rigor because it can create...
by Ron Samson | Aug 24, 2026 | SIEM and Log Management, Threat Detection and Response
Third-Party Access Is a Business Requirement, Not an Exception Vendors need access to systems for legitimate reasons: maintaining production applications, supporting cloud platforms, processing payroll, servicing industrial equipment, reviewing financial records, or...
by Ron Samson | | Email Security, Managed Security, Network Security
PCI DSS 4.0 monitoring is now an operating model, not an audit exercise For merchants, PCI DSS 4.0 changes the security-monitoring conversation from “do we collect logs?” to “can we prove that our controls detect, investigate, and respond to meaningful events in the...
by Ron Samson | Aug 23, 2026 | Endpoint Security, Threat Detection and Response
The endpoint gap: prevention is not incident response Antivirus is necessary, but it cannot run an incident alone. A blocked file is useful, but it is not containment. Security leaders must determine whether adversaries established access elsewhere already. They need...
by Ron Samson | | Email Security, Managed Security, Network Security
A firewall change is not just a network task Firewall rules are often treated as routine administration: open a port for a supplier, permit a cloud workload, publish a new application, or temporarily allow an engineer to troubleshoot a connection. In practice, every...