Security briefings you can actually keep.
91 free security briefings. Every topic ships as a detailed infographic and a PDF field reference you can download, print and share. No sign-up.
10 categories, 91 topics.
AI Security and Governance
- AI Governance and Risk Management — Every AI model an organization builds, buys, or embeds — from vetted platforms to shadow tools employees adopt on their own — carries risk traditional software review was never built to catch. Governance turns unmanaged AI use into an accountable program.
- LLM and AI Application Security — Connecting a model to tools and data turns its output into action — guardrails contain what a manipulated model can actually do, since the model itself cannot reliably tell trusted instructions from attacker input.
- Shadow AI and BYO-AI Risk — The same AI vendor's free and enterprise tiers can carry entirely different data training and retention terms. The risk isn't whether an AI tool is reputable — it's which agreement is actually in place when an employee pastes sensitive data into it.
- Predictive Modeling — Predictive models turn telemetry into probabilities — that a sign-in is hijacked, that a CVE will be exploited, that a host is beaconing. A score is a forecast with an error rate, not a verdict; the program around it decides whether it helps.
Application and Software Security
- Software Supply Chain Security (Original edition) — Modern software is assembled, not written from scratch — most of a codebase is open-source dependencies nobody on the team wrote. Supply chain security tracks what's actually inside that assembly and locks down the pipeline that builds and ships it.
- Application Security (AppSec) — Vulnerabilities are cheapest to fix before code ships — AppSec builds security checks directly into the development pipeline, catching flaws in code, dependencies, and configuration before they reach production.
- API Security — Every API is a direct line into application logic and data — unauthenticated, unmonitored, or undocumented endpoints turn that convenience into an open door for attackers to walk through.
- DevSecOps and CI/CD Pipeline Security — Shipping fast and shipping secure aren't in conflict — the fastest pipelines catch vulnerabilities before they reach a build artifact, not after a production incident.
- API Rate Limiting and Bot Abuse — A botnet defeats a per-IP rate limit just by spreading out — the real control isn't how many requests come from one address, it's whether the traffic behaves like the automation it actually is.
- GraphQL Security — A single GraphQL request can nest, alias, and multiply its way to the computational cost of thousands — the danger isn't how many requests arrive, it's how much any one of them is actually allowed to ask for.
- Webhook and Event-Driven API Security — A webhook flips the usual direction of trust — the receiver has to authenticate a push it never asked for, and the sender has to make sure that push can't be pointed anywhere it shouldn't reach.
- Software Supply Chain Security (Later edition) — Most of what ships in modern software was never directly chosen by anyone who built it — the supply chain attack surface lives in the dependencies of dependencies, and in the build pipeline that assembles them, not just the code a team actually wrote.
Banking, Payments and Financial Regulation
- PCI DSS and Payment Card Security — PCI DSS governs any system that stores, processes, or transmits cardholder data — compliance is a continuous state validated at a point in time, not a permanent guarantee, and a poorly scoped assessment can miss most of the real environment.
- SWIFT Customer Security Programme — SWIFT's own network has never been the point of failure in a major payment fraud incident — the customer's local messaging environment consistently is, which is exactly the gap the Customer Security Programme exists to close.
- FFIEC and GLBA Safeguards Rule — GLBA's Safeguards Rule sets the federal legal requirement to protect customer financial data; FFIEC's examination handbook is how bank regulators actually check whether that requirement is being met. A policy document that was never operationalized satisfies neither.
- Wire and ACH Transfer Fraud — Almost every successful wire or ACH fraud hinges on one moment: a payment instruction change that looks legitimate enough to act on without independent verification. Once a transfer executes, it's effectively irrevocable — the control has to work before the money moves, not after.
- Real-Time Payments Security — FedNow and the RTP network settle payments in seconds, 24/7/365 — eliminating the hours-long clearing window that gives wire transfers a chance at fraud interdiction. Once a real-time payment is authorized, prevention has already happened or it hasn't happened at all.
- AML and Transaction Monitoring Security — Transaction monitoring watches ongoing flows for patterns — structuring, layering, unusual velocity — that a single-transaction fraud control was never built to see. But the monitoring system is itself infrastructure, and a rule an insider can quietly disable is a control that was never really there.
- Core Banking Systems Security — Every mobile app, ATM, and card swipe ultimately reads from and writes to a core banking system that, at much of the industry, still runs on decades-old COBOL and mainframe technology. Modern APIs increasingly wrap that core, but wrapping it isn't replacing it — the legacy platform's risk profile doesn't disappear.
- ATM and POS Terminal Security — ATMs and POS terminals are the physical hardware where card-present fraud actually happens — skimmers on the card slot, cameras over the keypad, malware on the machine itself. EMV chip cryptography stops cloning, but it doesn't stop a device attacker from capturing data or an ATM from being commanded to dispense cash directly.
- Card Network Tokenization — A network token looks like a real card number to existing payment infrastructure, but it maps back to the actual PAN only inside the card network's own vault. Domain restriction and a fresh cryptogram per transaction are what make a stolen token nearly worthless outside the exact context it was issued for.
- Open Banking and API Security — PSD2 requires banks to expose account data and payment initiation to licensed third parties through APIs, with the customer's explicit consent. The security model shifts from a closed system to a verified, scoped, and cryptographically authenticated one — not an open door.
- Payment Gateway and Processor Security — A single card payment passes through a gateway, a processor, an acquiring bank, the card network, and an issuing bank before it's actually approved. Each hop is a distinct system with its own security responsibilities, and authorization is only the first of three separate events before money actually moves.
- Digital Wallet and Mobile Payment Security — Mobile wallets keep payment credentials off the general operating system entirely — in a dedicated secure chip, or in short-lived cloud tokens that limit what's ever actually stored on the device. A provisioned token still isn't enough to pay; a live biometric or passcode check happens at every transaction.
- Central Bank Digital Currency (CBDC) Security — A central bank digital currency turns monetary issuance into a distributed technical system — the security question shifts from protecting data to protecting the integrity of money itself, where a single compromised key can mean unauthorized currency, not just a leak.
- EU DORA (Digital Operational Resilience Act) — DORA turns ICT risk into a board-owned, directly-regulated discipline across the EU financial sector — and for the first time gives supervisors direct reach into the technology vendors, like cloud providers, that financial institutions depend on.
- NYDFS Cybersecurity Regulation (23 NYCRR 500) — New York's cybersecurity rule ties compliance directly to a named executive's signature — the CISO and highest-ranking officer personally certify the program each year, turning a paperwork exercise into individual accountability.
- NAIC Insurance Data Security Model Law — The NAIC Model Law only becomes real once a state enacts it — a licensee's actual obligations are set by a patchwork of individual state statutes, not a single uniform national rule.
- Basel Committee Operational Resilience and Cyber Risk Principles — Basel's principles measure success by whether a critical operation keeps running through disruption, not by whether disruption was prevented — and the principles themselves carry no legal force until a national regulator writes them into binding rules.
- SEC Cybersecurity Disclosure Rule (2023) — The SEC doesn't mandate how a company secures its systems — it mandates that investors find out, within four business days of a materiality call, when something material happens.
Cloud and Container Security
- Cloud Security Posture Management (CSPM) — Cloud environments change by the hour — new resources, new permissions, new exposure. CSPM continuously scans configurations against security baselines, catching the misconfigurations and posture drift that firewalls and endpoint tools were never built to see.
- Container and Kubernetes Security (Original edition) — Containers ship in minutes and multiply across clusters just as fast — a single vulnerable image or misconfigured pod can spread the exposure everywhere it's deployed before anyone notices.
- Cloud Access Security Broker (CASB) — Data now moves through dozens of cloud apps IT never approved — a broker sits at that chokepoint to see, control, and secure traffic that firewalls and endpoint agents never touch.
- SaaS Security Posture Management (SSPM) — Every SaaS app is its own security perimeter with its own settings — SSPM continuously checks that perimeter against a baseline, instead of trusting that whoever configured it got it right once.
- Cloud Infrastructure Entitlement Management (CIEM) — Cloud IAM roles and service accounts are almost always granted far more access than they ever actually use. That gap between granted and used permissions is exactly what defines a compromised identity's blast radius — and it's invisible to tools that only check resource configuration.
- Container and Kubernetes Security (Later edition) — Kubernetes ships permissive by default, not secure by default — flat pod networking, unscoped RBAC, and unencrypted secrets are the starting point, not a misconfiguration someone introduced later.
Cryptography and Encryption
- Post-Quantum Cryptography — Cryptographic algorithms designed to resist attacks from a cryptographically relevant quantum computer. RSA and ECC remain safe today, but harvest-now-decrypt-later capture means the migration has to start before that computer ever exists.
- Encryption and Key Management — The algorithm is the easy part — the real risk lives in how keys are generated, stored, rotated, and destroyed across their entire working lifecycle.
- Data Encryption in Transit and TLS — Data crossing a network is only as safe as the channel encrypting it — TLS proves the connection is authentic and unreadable before a single application byte moves.
- Quantum Key Distribution — Quantum key distribution uses the physics of single photons, not computational difficulty, to exchange encryption keys — any attempt to intercept the key measurably disturbs it, but everything else in the network still depends on ordinary security discipline.
- Post-Quantum Cryptography Migration — A quantum computer capable of breaking today's public-key cryptography doesn't exist yet — but adversaries are already harvesting encrypted traffic to decrypt the moment one does, which is why migration has to start now.
Governance, Risk and Privacy
- Data Governance — The framework of policies, roles, and controls that decide who can access data, how it's classified, and how long it's kept. Without governance, a strong security stack still can't answer whether this data should exist.
- Third-Party Risk Management — The discipline of vetting, tiering, contracting, and continuously monitoring every vendor, supplier, and partner that touches your data or systems. A signed contract proves obligation — it never proves compliance.
- Fourth and Nth-Party Risk — The risk introduced by your vendors' own vendors — and everything downstream of them. Your direct vendor may be secure; the subprocessor two tiers down that you've never heard of is where the actual exposure lives.
- Security Metrics, KPIs and Board Reporting — A board doesn't need every alert — it needs to know whether risk is going up or down and what it will cost to change that, translated out of security jargon and into business terms.
- GDPR and Global Privacy Regulation — GDPR applies to any organization processing an EU resident's personal data, regardless of where that organization is actually based. Consent is only one of six lawful bases, and defaulting to it for everything often creates more compliance risk, not less.
Identity and Access Security
- Passkeys — Phishing-resistant authentication built on public-key cryptography. The secret never leaves the user's device, never crosses the network, and cannot be replayed by an attacker who captures the traffic.
- Identity and Access Management (IAM) — Every account, role, and permission an organization grants is a potential path in — and the accounts nobody remembers to review are the ones attackers find first. IAM turns identity from a one-time provisioning task into a continuously governed control.
- Privileged Access Management (PAM) — Every admin credential, service account, and root password is a high-value target — and standing privileged access is often the shortest path from one compromised login to full domain control. PAM replaces persistent admin rights with vaulted, time-bound, monitored elevation.
- Password Managers and Browser-Saved Risk — A password saved in the browser is only as safe as the device it lives on — a password manager decides whether that credential survives when the device doesn't.
- Secrets Management and Credential Sprawl (Original edition) — An API key hardcoded once doesn't expire when the project ends — it stays valid in code, logs, and forgotten scripts until someone finds it, or someone else does.
- Non-Human Identity and Machine-to-Machine Auth — Every API key, service account, and workload identity is a credential nobody logs into — non-human identity governance treats machine credentials with the same rigor as human ones, because attackers already do.
- Identity Threat Detection and Response (ITDR) — Attackers increasingly log in rather than break in, authenticating with stolen valid credentials and tokens that never touch a monitored endpoint. ITDR watches the identity infrastructure itself for the specific patterns credential theft produces, since nothing else is built to catch it.
- OAuth 2.0 and OpenID Connect Security — OAuth 2.0 was built to authorize, not to authenticate — treating a successful token exchange as proof of identity, instead of validating OpenID Connect's purpose-built ID token, is the mistake underneath most real-world OAuth failures.
- Secrets Management and Credential Sprawl (Later edition) — A secret doesn't stay secret because it's hard to find — it stays secret because someone is actively managing where it lives, how long it's valid, and when it gets rotated, none of which happens by default.
- Active Directory and Kerberos Security — Active Directory holds domain identities; Kerberos turns authentication into reusable tickets. Protect the accounts, hosts, and keys behind that trust: a valid ticket is not proof of a safe session.
- Active Directory Certificate Services (AD CS) Security — Active Directory Certificate Services issues credentials for users, devices, and services. Protect who can obtain a certificate, which identity it represents, and where its private key can be used.
- NTLM Relay and Authentication Hardening — NTLM relay forwards a live authentication exchange to a service that accepts it as the victim. The attacker need not know the password: reduce NTLM use and enforce protection at every receiving service.
- Break-Glass Accounts and Emergency Access — Break-glass accounts restore administrative access when normal sign-in, federation, or privilege activation fails. A recovery path must survive the failed dependency, protect its credentials, and leave evidence of every use.
- Windows LAPS — Windows LAPS gives every device its own local administrator password, rotates it on a schedule, and backs it up to Active Directory or Microsoft Entra ID where only authorized roles can read it. It exists because one shared local admin password turns a single compromised machine into all of them.
- Active Directory Delegation Security — Delegation is how Active Directory hands power to someone else: rights over objects through access control lists, and the ability to act as a user through Kerberos. Both live in attributes rather than group memberships, and attackers hunt them because few teams review them.
Network and Infrastructure Security
- Zero Trust Architecture (Original edition) — A security model where no user, device, or network flow is trusted by default — inside the perimeter or outside it. Every request is verified, authorized, and continuously re-evaluated before access is granted.
- VPN Security and Exposure — VPN gateways are internet-facing, always-on, and rarely patched on schedule — making them one of the most exploited entry points into corporate networks. From split-tunneling misconfigurations to unpatched appliance CVEs, a poorly governed VPN becomes the front door attackers actually use.
- Network Segmentation and Microsegmentation — A flat network lets one compromised device reach everything else — microsegmentation contains the blast radius so a breach cannot spread into the next zone.
- DNS Security — Every connection starts with a name lookup — DNS security makes sure that lookup can't be silently redirected, poisoned, or turned into a covert exfiltration channel.
- OT and ICS Security — Operational technology runs the physical world — valves, turbines, breakers, pumps — so a compromise isn't just a data-loss event. Safety and availability outrank confidentiality here, and the controls that work in IT can crash the equipment they're meant to protect.
- 5G and Telecom Network Security — 5G's shared, software-defined core turns network slicing and inter-carrier signaling into the new attack surface — isolation between slices and trust between carriers must be continuously verified, not just assumed by design.
- Zero Trust Architecture (Later edition) — Zero trust replaces a single perimeter check with continuous verification of every request — network location stops implying trust, and identity, device posture, and policy decide access instead.
- Network and Domain Lookups — Five lookups answer almost every question about a name or an address: who is accountable for it, what it resolves to, whether packets reach it, what it presents when they do, and how it is configured. Each one proves something narrow, and the usual mistake is reading more into it than it says.
Threat Detection and Incident Response
- Ransomware — Malware that encrypts data and holds it hostage for payment. Modern campaigns steal data before they encrypt it — turning a single intrusion into extortion, business disruption, and reputational damage.
- Vulnerability Management — The continuous process of finding, prioritizing, and closing weaknesses before adversaries can use them. A CVSS score alone doesn't tell you what to fix first — exploitability and business context do.
- Attack Surface Management — Every internet-facing asset an organization exposes — domains, subdomains, cloud services, and forgotten infrastructure — mapped continuously, not once a year. You cannot secure what you do not know you own.
- Incident Response and Tabletop Exercises — A breach is not primarily a technology event — it's a decision-making event under pressure. Incident response turns a chaotic first hour into a rehearsed playbook, and tabletop exercises make sure that playbook actually works before it's needed for real.
- Business Continuity and Disaster Recovery — Outages, disasters, and attacks are a matter of when, not if — the difference is how fast the organization gets back up. Business continuity keeps critical operations running through disruption, and disaster recovery restores the systems behind them within a defined, tested window.
- Endpoint Detection and Response (EDR-XDR) — Antivirus asks whether a file matches a known bad signature — EDR and XDR ask whether behavior looks malicious. They watch what processes actually do on the endpoint, then correlate that activity across identity, email, and cloud to catch what static signatures miss.
- Security Operations and SIEM — Attack signals don't announce themselves — they hide inside millions of logs across endpoints, network, and cloud every day. SIEM correlates that noise into the alerts analysts can actually act on.
- Penetration Testing and Red Teaming — Vulnerability scans tell you what's wrong — a red team tells you what an attacker can actually do with it, chained together toward a real objective.
- Threat Intelligence and Threat Hunting — An IOC feed without context tells you what happened somewhere else — it does not tell you what is already inside your own environment, right now.
- SOAR and Security Automation — SOAR connects detection tools to automated response actions through codified playbooks — it makes a well-understood response faster and more consistent, but a playbook only automates the judgment that was already built into it.
- Digital Forensics and Incident Response — DFIR reconstructs what actually happened on a compromised system from the artifacts it left behind — evidence that isn't captured before it's overwritten or powered away is gone permanently, no matter how skilled the analyst.
- Endpoint Detection and Response (EDR and XDR) — A signature can only catch what's already been seen before — modern detection has to watch what a process actually does, and increasingly, whether the detection agent itself is still alive to watch it.
- Asset Risk Scoring — An asset risk score ranks what to fix first by combining what the asset is worth, how exposed it is, and how likely a threat is to reach it. The arithmetic is easy; the inventory, the criticality labels and the exposure facts behind it are the hard part.
Workforce, Endpoint and Data Protection
- Insider Threat Management — The riskiest actor in your environment might already have valid credentials, legitimate access, and no reason to raise an alarm — because they're an employee, not an outsider. Insider threat management turns access and behavior signals into early warning before damage is done.
- Data Loss Prevention (DLP) — Sensitive data doesn't stay where it starts — it moves through email, cloud drives, USB ports, and chat apps every day. DLP finds that data wherever it lives and stops it from leaving through the wrong channel.
- Mobile Device Management and BYOD Security — A personal phone with corporate email on it is corporate attack surface — MDM decides whether that surface is managed or invisible.
- Business Email Compromise (BEC) and Email Security — A single convincing email can move money or credentials out the door — BEC succeeds by impersonating trust, not by breaking encryption or planting malware.
- Phishing and Security Awareness Training — A single click can undo every other control — awareness training only works when it changes behavior under pressure, not just completion rates on a slide deck.
- Deepfake and Voice-Cloning Fraud — A voice or face is no longer proof of identity — a few seconds of public audio or video is enough to generate a convincing clone, so verification has to move to a channel synthetic media can't reach.
- Physical Security and Badge Cloning — A legacy proximity badge broadcasts an unencrypted ID that a cheap reader can capture through a wallet in seconds. But the cheapest, most effective physical intrusion technique doesn't need any badge technology weakness at all — it just needs someone to hold the door.
- Browser Security and Extension Risk — The browser now holds authenticated sessions for email, cloud storage, and every SaaS app an employee uses, all in one place. A stolen session cookie is functionally a completed login and MFA challenge combined — and an extension with broad permissions can read it directly.
- Email Authentication (SPF, DKIM, DMARC) — SPF can pass on a completely different domain than the one shown in the visible From field. DMARC exists specifically to close that gap, requiring the authenticated domain to actually align with what the recipient sees — without it, a spoofed email can pass every individual check.