Threat analysis, guidance and product news
Practical reads on cyber risk, compliance and threat intelligence from the FortaRisks team.
RSS feed- Compliance
CPCSC Level 1: the guide for Canadian defence suppliers
The Canadian Program for Cyber Security Certification is becoming mandatory for defence contracts. What Level 1 covers, the 13 ITSP.10.171 requirements, and where to start.
June 19, 2026 · 4 min read - Guidance
SD-WAN security issues and concerns: what they are and how to address them
A practical guide to SD-WAN security issues and concerns: controller exposure, internet-facing edge devices, misconfiguration, and how to fix them.
June 16, 2026 · 6 min read - AI
AI phishing and deepfake BEC are now the default, not the edge case
More than 80% of phishing emails now carry AI-generated content, and synthetic voice is showing up in the biggest wire-fraud cases. The old tells are gone. Here is what still holds up.
June 12, 2026 · 3 min read - Threat Intelligence
This week in cyber: SD-WAN under attack, and ransomware comes for energy and manufacturing
A CVSS 10 SD-WAN flaw with rogue peers in the wild, a fresh Cisco zero-day, and ransomware crews hitting a Canadian energy services firm and a UK machinery maker. The week's signal for critical-infrastructure teams, minus the noise.
June 8, 2026 · 3 min read - Third-Party Risk
Radiology, Oncology, DocketWise: Three Breaches in One Week That Reshape Your Healthcare and Legal Third-Party Risk
Three US healthcare and legal breaches in one week prove your real exposure runs through your vendors' vendors. A 30-day third-party risk loop.
May 29, 2026 · 4 min read - Threat Intelligence
Defender and Apex One Under Fire: When the Antivirus Becomes the Attacker's Weapon
CISA added three endpoint-security zero-days to KEV in 72 hours. Why defense tools are now prime targets, plus a 6-step EDR remediation loop.
May 26, 2026 · 3 min read - Third-Party Risk
Canvas, 275 Million Records: What This Breach Forces You to Rethink in Third-Party Risk
The ShinyHunters attack on Canvas exposes a SaaS concentration problem, not just a vendor one. Three board questions and a 6-step third-party loop.
May 19, 2026 · 3 min read - AI
AI vs AI: Why Your Cyber Defense Must Also Be AI-Augmented
Attackers now wield AI like Mythos, so defense must be AI-augmented too. Five defensive use cases that work in 2026, and what AI should never do.
May 15, 2026 · 3 min read - AI
Mythos Explained to the Board: 5 Strategic Questions Before Your Next Committee
Anthropic's Mythos finds and exploits software flaws in hours. Why that makes AI risk a board topic, and 5 questions to ask your CISO this week.
May 8, 2026 · 2 min read
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.