CMMC Final Rule: How to Achieve Compliance

Defense contractors have anticipated the full implementation of CMMC (Cybersecurity Maturity Model Certification) for some time now. On September 10, 2025, the Federal Register published the DFARS Final Rule, giving defense procurement officers the power to require CMMC compliance—both in new contracts and renewals of existing contracts. In other words, CMMC compliance is now required for any contractor[…] Read

Published by Ross Filipek, Corsica Technologies

Windows 10 End of Life: Upgrade Paths for Enterprises

It’s that time again. The Windows operating system is becoming EOL (end of life). Everyone from small businesses to enterprises is looking for the right upgrade path from Windows 10 to Windows 11. Whether you’re on your own or working with a managed IT services provider, it’s time to determine how you’ll keep your computers secure[…] Read

Published by Garrett Wiesenberg, Corsica Technologies

vCISO Services: Staying Secure for Less

The average cost of a data breach is $4.88M, according to IBM. Meanwhile, the cyberthreat landscape continues to evolve at an alarming pace. It’s not enough to implement MFA (multifactor authentication) and hope for the best. Cybersecurity requires expert thought leadership—and that starts in the C-suite. Yet not every organization can justify hiring a CISO (Chief[…] Read

Published by Ross Filipek, Corsica Technologies

Cracking the Puzzle: Unveiling the Flaws of Insecure Design

Sometimes as a penetration tester, you instantly know there is an issue. However, simply explaining the security flaw isn’t sufficient, and you need to show why it’s an issue and how to exploit it!   This is a narrative following a desktop application penetration test, doing just that.  Firstly, it was noted that while the Desktop[…] Read

Published by Michael Jepson, Cybaverse

AI Strategy: 7 Real-World Examples That Drive Business Value

Your AI journey starts here. Artificial intelligence is transforming how businesses operate, compete, and grow. Whether you’re just beginning to explore AI’s potential or looking to refine your existing approach, developing a comprehensive AI strategy is essential for success in today’s digital landscape. What could AI look like for your business? Where can you leverage AI for[…] Read

Published by Brian Harmison, Corsica Technologies

How AI Is Changing the Modern SOC Forever

A recent article in The Hacker News discussed the emergence of SOC 3.0—the latest iteration of the modern SOC (Security Operations Center). The SOC of the future will use sophisticated AI tools to detect and respond to threats at scale. Whether you use SOC as a service or run your own SOC internally, it’s essential to understand these[…] Read

Published by Ross Filipek, Corsica Technologies

Penetration Testing Services 101

Penetration Testing Services 101 Are you easy to hack? That’s the big question. Yet many organizations don’t even know where their weaknesses lie. Penetration testing (AKA pen testing) solves this problem. This is a service provided by a company that specializes in cybersecurity and ethical hacking. The goal of the exercise is simple: Try to breach a[…] Read

Published by Breanna Brown, Corsica Technologies

SOC as a Service 101

As cyberattacks become more and more sophisticated, organizations of all sizes need to monitor and respond to threats in real time. Yet it’s incredibly expensive to hire and manage your own 24/7/365 cybersecurity team. SOC as a service provides a welcome alternative. You get all the power of a SOC (security operations center) without the cost[…] Read

Published by Breanna Brown, Corsica Technologies

A Guide to JSON Web Tokens (JWTs)

Not too long ago, JSON Web Tokens (JWTs) were widely regarded as a go-to solution for authentication, praised for their security, scalability, and simplicity. However, today, the penetration testing team at CybaVerse—along with other security researchers—frequently uncovers high and critical vulnerabilities in their implementations. The thing is automated scanners don’t typically pick up JWT misconfigurations[…] Read

Published by Michael Jepson, Cybaverse

The Rise of Single-Vendor SASE Solutions

In 2024, the cyber threat landscape has grown increasingly complex and perilous, characterized by a surge in sophisticated ransomware attacks and the proliferation of AI-driven threats. These advanced attacks are not only more targeted but also more frequent, challenging organizations to adapt swiftly and robustly to safeguard their networks and data.The Shift in Cybersecurity StrategiesAs[…] Read

Published by Jordi Vilanova, Cloudtango