home.social

#grc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #grc, aggregated by home.social.

fetched live
  1. Nationwide investigation launched into wind farms after major wildfire #GRC: Greek fire investigators have launched a nationwide investigation into wind farm installations following a prosecutor’s order issued in connection with the major wildfire that began in Boeotia and spread into western Attica. The Directorate for Combating Arson Crimes has been instructed to examine whether wind energy facilities across the country are operating with the… wind-watch.org/news/2026/08/12 #windpower #windenergy

  2. Understanding the CMMC Pause: Key Changes and Action Steps

    On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements. The move was memorialized in a memo dated July 10, 2026, signed by DoW Chief Information Officer Kirsten Davies. Those requirements had been scheduled to take effect on November 10, 2026, and would have pushed many contracts handling Controlled Unclassified Information (CUI) into mandatory third-party C3PAO assessments.

    The stated goal is straightforward: reduce compliance barriers for small, medium, and non-traditional businesses so the Defense Industrial Base can expand faster under the Department’s current acquisition priorities.
    A 60-day CMMC Reform Task Force review is now underway, including a public Request for Information seeking industry input on cost drivers and administrative burden. Phase I self-assessment requirements remain firmly in place.

    This is not a free pass.
    It’s a pause on one layer of bureaucracy — not a suspension of the underlying security obligations.

    What Actually Changed (and What Didn’t)

    Suspended

    • The November 2026 transition to Phase II — third-party Level 2 assessments as a condition of award in many cases.
    • Pending and future CMMC implementation milestones (including Phase III and IV) that would have required C3PAO or DIBCAC assessments.
    • During the review period, contracting officers are limited to requiring only Level 1 (Self) or Level 2 (Self) assessments in new procurements.
    • Existing contracts that already contain Phase II language will have that language removed by modification, either before the next option period or at the next scheduled administrative update.

    Still fully in force

    • Phase I self-assessments and annual affirmations in SPRS.
    • DFARS 252.204-7012 obligations to protect covered defense information and implement NIST SP 800-171 controls.
    • Contractual cybersecurity requirements that primes flow down to subcontractors.
    • The Department of Justice’s Civil Cyber-Fraud Initiative, which continues to treat inaccurate self-assessments and false claims seriously.

    The official release is worth reading in full: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements. The SBA has also publicly backed the move, arguing the prior framework was pushing small firms out of the defense supply chain.

    In short: the certification theater got paused. The requirement to actually protect the data did not.

    What Contractors and Subcontractors Should Do This Month

    1. Don’t stop your security work.
      Use the breathing room. Many teams were racing toward a November deadline that no longer exists in its previous form. That race produced a lot of checkbox activity. Now’s the time to swap checkboxes for durable controls.
    2. Re-run a realistic readiness assessment.
      Update your SPRS score and your internal gap analysis against NIST SP 800-171. If you used a simple calculator earlier this year — I published one that turns a short questionnaire into a readiness score, estimated SPRS, missing controls, and a three-year cost projection — pull it back up and refresh the inputs. See: Building a CMMC Readiness Calculator That People Can Actually Finish.
    3. Treat continuous compliance as the real requirement.
      Annual self-assessments and point-in-time evidence dumps are fragile. The reform language itself points toward “scalable, resilient cybersecurity measures” — which reads as continuous monitoring and automated evidence collection, not another round of spreadsheets and screenshot marathons.
    4. Watch your primes.
      A Phase II pause at the Department level doesn’t automatically relax every subcontract. Large primes often impose flow-down requirements stricter than the current minimum, and many won’t move as fast as the Department did.
    5. Document the affirming official and the continuous compliance process.
      Phase I still requires a named senior official to affirm ongoing compliance in SPRS. Make sure that process is real, not aspirational — and that it’s written down somewhere your next audit (or your next enterprise customer’s security questionnaire) can find it.

    Why This Matters Even If You’re Not a Defense Contractor

    The same pattern is playing out across enterprise sales and cyber insurance. Buyers and underwriters increasingly expect SOC 2 Type II, continuous control monitoring, and proof that security isn’t a once-a-year project. The CMMC pause is a signal that purely bureaucratic compliance regimes are being questioned across the board. The companies that win are the ones that treat security and compliance as an operating system, not an annual fire drill.

    A few related pieces if you want to go deeper:

    The Opportunity Hidden Inside the Pause

    The Department’s own language talks about lowering certification-related burdens while preserving the underlying cybersecurity baseline. That’s exactly the gap continuous, AI-assisted compliance platforms are built to fill.

    Instead of treating the next 60–90 days as a chance to relax, treat them as a chance to:

    • Close your highest-risk control gaps.
    • Automate evidence collection so the next self-assessment — or the eventual reformed assessment, whatever shape it takes — isn’t a scramble.
    • Move from “we can pass an audit” to “we can demonstrate continuous control effectiveness.”

    Small and mid-sized teams will never match the headcount of a Fortune 500 security organization.
    The realistic path is better tooling and tighter integration between IT operations, threat detection, and compliance evidence — not more headcount you can’t hire.
    Pstt… that is why we built EspressoLabs’ CMMC service.

    Practical Next Steps This Week

    • Pull your latest SPRS entry and your last self-assessment.
    • Identify the three controls that would most improve your actual security posture — not just your score.
    • Confirm who your Affirming Official is, and that the continuous compliance process behind them is documented, not assumed.
    • If you sell into enterprise or government, map which customers or primes still require third-party assessments regardless of the Department’s pause.
    • Revisit any readiness calculator or gap analysis you already have and update the numbers.

    The suspension is real.
    So is the underlying requirement to protect sensitive information. The companies that use this window to build durable, automated controls will be in a stronger position no matter what the reform produces — a lighter CMMC, a different framework, or just a longer Phase I period.

    The ones that treat it as a reason to relax will still be scrambling when the next contract, or the next customer security questionnaire, shows up.

    If you want a quick, no-sales readiness snapshot, the calculator I published earlier is still up and takes only a few minutes.
    Use the pause productively.

    Rate this:

    #AI #AIAutomation #CMMC #Compliance #DOD #DOW #GRC #startups
  3. Understanding the CMMC Pause: Key Changes and Action Steps

    On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements. The move was memorialized in a memo dated July 10, 2026, signed by DoW Chief Information Officer Kirsten Davies. Those requirements had been scheduled to take effect on November 10, 2026, and would have pushed many contracts handling Controlled Unclassified Information (CUI) into mandatory third-party C3PAO assessments.

    The stated goal is straightforward: reduce compliance barriers for small, medium, and non-traditional businesses so the Defense Industrial Base can expand faster under the Department’s current acquisition priorities.
    A 60-day CMMC Reform Task Force review is now underway, including a public Request for Information seeking industry input on cost drivers and administrative burden. Phase I self-assessment requirements remain firmly in place.

    This is not a free pass.
    It’s a pause on one layer of bureaucracy — not a suspension of the underlying security obligations.

    What Actually Changed (and What Didn’t)

    Suspended

    • The November 2026 transition to Phase II — third-party Level 2 assessments as a condition of award in many cases.
    • Pending and future CMMC implementation milestones (including Phase III and IV) that would have required C3PAO or DIBCAC assessments.
    • During the review period, contracting officers are limited to requiring only Level 1 (Self) or Level 2 (Self) assessments in new procurements.
    • Existing contracts that already contain Phase II language will have that language removed by modification, either before the next option period or at the next scheduled administrative update.

    Still fully in force

    • Phase I self-assessments and annual affirmations in SPRS.
    • DFARS 252.204-7012 obligations to protect covered defense information and implement NIST SP 800-171 controls.
    • Contractual cybersecurity requirements that primes flow down to subcontractors.
    • The Department of Justice’s Civil Cyber-Fraud Initiative, which continues to treat inaccurate self-assessments and false claims seriously.

    The official release is worth reading in full: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements. The SBA has also publicly backed the move, arguing the prior framework was pushing small firms out of the defense supply chain.

    In short: the certification theater got paused. The requirement to actually protect the data did not.

    What Contractors and Subcontractors Should Do This Month

    1. Don’t stop your security work.
      Use the breathing room. Many teams were racing toward a November deadline that no longer exists in its previous form. That race produced a lot of checkbox activity. Now’s the time to swap checkboxes for durable controls.
    2. Re-run a realistic readiness assessment.
      Update your SPRS score and your internal gap analysis against NIST SP 800-171. If you used a simple calculator earlier this year — I published one that turns a short questionnaire into a readiness score, estimated SPRS, missing controls, and a three-year cost projection — pull it back up and refresh the inputs. See: Building a CMMC Readiness Calculator That People Can Actually Finish.
    3. Treat continuous compliance as the real requirement.
      Annual self-assessments and point-in-time evidence dumps are fragile. The reform language itself points toward “scalable, resilient cybersecurity measures” — which reads as continuous monitoring and automated evidence collection, not another round of spreadsheets and screenshot marathons.
    4. Watch your primes.
      A Phase II pause at the Department level doesn’t automatically relax every subcontract. Large primes often impose flow-down requirements stricter than the current minimum, and many won’t move as fast as the Department did.
    5. Document the affirming official and the continuous compliance process.
      Phase I still requires a named senior official to affirm ongoing compliance in SPRS. Make sure that process is real, not aspirational — and that it’s written down somewhere your next audit (or your next enterprise customer’s security questionnaire) can find it.

    Why This Matters Even If You’re Not a Defense Contractor

    The same pattern is playing out across enterprise sales and cyber insurance. Buyers and underwriters increasingly expect SOC 2 Type II, continuous control monitoring, and proof that security isn’t a once-a-year project. The CMMC pause is a signal that purely bureaucratic compliance regimes are being questioned across the board. The companies that win are the ones that treat security and compliance as an operating system, not an annual fire drill.

    A few related pieces if you want to go deeper:

    The Opportunity Hidden Inside the Pause

    The Department’s own language talks about lowering certification-related burdens while preserving the underlying cybersecurity baseline. That’s exactly the gap continuous, AI-assisted compliance platforms are built to fill.

    Instead of treating the next 60–90 days as a chance to relax, treat them as a chance to:

    • Close your highest-risk control gaps.
    • Automate evidence collection so the next self-assessment — or the eventual reformed assessment, whatever shape it takes — isn’t a scramble.
    • Move from “we can pass an audit” to “we can demonstrate continuous control effectiveness.”

    Small and mid-sized teams will never match the headcount of a Fortune 500 security organization.
    The realistic path is better tooling and tighter integration between IT operations, threat detection, and compliance evidence — not more headcount you can’t hire.
    Pstt… that is why we built EspressoLabs’ CMMC service.

    Practical Next Steps This Week

    • Pull your latest SPRS entry and your last self-assessment.
    • Identify the three controls that would most improve your actual security posture — not just your score.
    • Confirm who your Affirming Official is, and that the continuous compliance process behind them is documented, not assumed.
    • If you sell into enterprise or government, map which customers or primes still require third-party assessments regardless of the Department’s pause.
    • Revisit any readiness calculator or gap analysis you already have and update the numbers.

    The suspension is real.
    So is the underlying requirement to protect sensitive information. The companies that use this window to build durable, automated controls will be in a stronger position no matter what the reform produces — a lighter CMMC, a different framework, or just a longer Phase I period.

    The ones that treat it as a reason to relax will still be scrambling when the next contract, or the next customer security questionnaire, shows up.

    If you want a quick, no-sales readiness snapshot, the calculator I published earlier is still up and takes only a few minutes.
    Use the pause productively.

    Rate this:

    #AI #AIAutomation #CMMC #Compliance #DOD #DOW #GRC #startups
  4. GRC Platforms vs. Managed Compliance: Understanding the Gaps

    TL;DR

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:
    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform

    If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.

    That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.

    What GRC platforms like Vanta and Drata actually solve

    Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:

    • Pull control status from the tools you already run via read-only integrations
    • Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
    • Automate evidence collection so audit season isn’t a fire drill
    • Alert you when something drifts out of policy

    For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.

    The quiet assumption baked into that model

    Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.

    The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.

    When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:

    1. Triage it
    2. Actually go fix it (device by device, user by user)
    3. Confirm the fix took
    4. Make sure it doesn’t regress next sprint

    For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.

    This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.

    Naming the other model: managed enforcement

    There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.

    The pitch, generalized across this category, usually includes:

    • Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
    • Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
    • 24/7 monitoring of the actual environment, not just what connected tools self-report
    • Automated or human-assisted remediation when something drifts
    • Incident response bundled in, rather than “bring your own IR retainer”
    • One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together

    For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.

    What a CISO should actually diligence before choosing either path

    This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:

    If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):

    • Do you have a named owner for every control category who will actually close findings, not just watch them?
      What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
      Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?

    If you’re leaning toward a managed compliance/enforcement service:

    • Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
    • Can they show you audit history and named references from companies in your size band and framework, not just logos?
    • What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
    • How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
    • Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
    • Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?

    Neither model is inherently safer.
    A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.

    The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.

    The one-line version

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:

    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?

    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Curious where you actually stand?

    If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.

    Rate this:

    #AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2
  5. GRC Platforms vs. Managed Compliance: Understanding the Gaps

    TL;DR

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:
    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform

    If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.

    That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.

    What GRC platforms like Vanta and Drata actually solve

    Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:

    • Pull control status from the tools you already run via read-only integrations
    • Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
    • Automate evidence collection so audit season isn’t a fire drill
    • Alert you when something drifts out of policy

    For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.

    The quiet assumption baked into that model

    Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.

    The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.

    When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:

    1. Triage it
    2. Actually go fix it (device by device, user by user)
    3. Confirm the fix took
    4. Make sure it doesn’t regress next sprint

    For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.

    This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.

    Naming the other model: managed enforcement

    There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.

    The pitch, generalized across this category, usually includes:

    • Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
    • Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
    • 24/7 monitoring of the actual environment, not just what connected tools self-report
    • Automated or human-assisted remediation when something drifts
    • Incident response bundled in, rather than “bring your own IR retainer”
    • One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together

    For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.

    What a CISO should actually diligence before choosing either path

    This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:

    If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):

    • Do you have a named owner for every control category who will actually close findings, not just watch them?
      What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
      Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?

    If you’re leaning toward a managed compliance/enforcement service:

    • Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
    • Can they show you audit history and named references from companies in your size band and framework, not just logos?
    • What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
    • How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
    • Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
    • Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?

    Neither model is inherently safer.
    A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.

    The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.

    The one-line version

    A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
    Before you sign either contract, make someone in the room answer this out loud:

    when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?

    If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.

    Curious where you actually stand?

    If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.

    Rate this:

    #AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2
  6. The Game III: The Incinerator
    Legacy syntax is the only thing standing between you and the next level. Are your CF skills sharp enough or will you end up in the Incinerator?

    #CyberSecurity #PowerShell #CFML #AI #Networking #SQL #Cloud #GRC #Gaming #Technology #Python #ZeroTrust #DevSecOps #FinOps #Programming

    Link: blackcatwhitehatsecurity.com/t

  7. The Game III: The Incinerator
    Legacy syntax is the only thing standing between you and the next level. Are your CF skills sharp enough or will you end up in the Incinerator?

    #CyberSecurity #PowerShell #CFML #AI #Networking #SQL #Cloud #GRC #Gaming #Technology #Python #ZeroTrust #DevSecOps #FinOps #Programming

    Link: blackcatwhitehatsecurity.com/t

  8. The Game III: The Incinerator
    Legacy syntax is the only thing standing between you and the next level. Are your CF skills sharp enough or will you end up in the Incinerator?

    #CyberSecurity #PowerShell #CFML #AI #Networking #SQL #Cloud #GRC #Gaming #Technology #Python #ZeroTrust #DevSecOps #FinOps #Programming

    Game Link: blackcatwhitehatsecurity.com/t