
Cybersecurity
Practical cybersecurity for teams that have to defend real environments, not slideware. Our analysts and advisors write about what actually moves risk — 24×7 detection and response, zero-trust architecture, identity and privileged access, exposure management, and the compliance frameworks your customers and auditors expect. Expect specifics you can act on, not vendor talking points.
What cybersecurity covers
Detection & response
24×7 SOC monitoring, managed detection and response (MDR/XDR), threat hunting, and incident response that contains threats instead of just alerting on them.
Zero trust & identity
Identity-first access, privileged access management, and segmentation that assume breach — plus the SIEM and analytics that make it visible.
Compliance & exposure
SOC 2, ISO 27001, HIPAA, and PCI DSS programs, penetration testing, and continuous vulnerability and attack-surface management.
Latest cybersecurity articles
Managed ITConnectWise Automate API: Customer Device Health Without Cross-Client Leaks
An Automate API login can see every client. How we built a customer-facing device health view on it without leaking machines between clients, plus the API quirks we hit.
CybersecurityWhy GA4 Undercounts Visitors From Some US States (and How to Check)
Google can hold GA4 page_view hits about five seconds in some US states, so short visits never count. What we measured, how we fixed it, and why our fix went stale.
CybersecurityHow to Actually Manage SOC 2, ISO 27001, and HIPAA Evidence
The hardest part of a SOC 2, ISO 27001, or HIPAA audit isn't the controls — it's the evidence. Why the spreadsheet-and-screenshots approach breaks, what a real evidence program looks like, and how to run one for free.
CybersecurityCalifornia Leads the Nation in Cybercrime Losses — and the Gap Is Widening
Californians reported $3.67 billion in cybercrime losses in 2025, up 44.7% in a single year — first in the nation. A short read on the headline findings from the California Cybersecurity Risk Report 2027.
CybersecuritySix Security Priorities for California Businesses in 2027
A short, evidence-based list drawn from the California Cybersecurity Risk Report 2027: identity controls, payment verification, patching, vendor risk, recoverable backups, and incident-response readiness — each tied to the data.
CybersecurityWhy Ransomware Targets Law Firms, Contractors, and Engineering Practices
Outside critical infrastructure, the businesses most often reporting ransomware are legal services (18%), contractors (17%), and engineering firms (10%) — a profile that matches California's small-business economy.
CybersecurityThe Six-Month Silence: California Breaches Take a Median 174 Days to Surface
intSignal Research analyzed 1,536 California breach notices: the median gap between a breach occurring and its notification is 174 days, and only 4.2% arrive within 30 days. What that exposure window means under SB 446.
CybersecurityOne Breach, 32 Notices: How Vendor Cascades Multiply Breach Risk in California
In California's breach register, a single third-party incident dated February 21, 2024 generated notices from 32 distinct organizations. The most frequent notifiers are data processors and administrative vendors — not household names.
CybersecurityOlder Californians and the $1.4 Billion: Elder Cyber-Fraud in the 2025 Data
Californians aged 60 and over reported $1.40 billion in internet-crime losses in 2025 — 38% of the state total on 19% of complaints. Why this is a business problem, not only a consumer one.
CybersecurityCryptocurrency Now Drives 57% of California's Cybercrime Losses
Complaints referencing cryptocurrency accounted for $2.10 billion in California losses in 2025 — 57% of everything the state reported losing, the highest of any state and above the national share.
CybersecurityBusiness Email Compromise Cost $3 Billion in 2025 — and It Runs on Your Payment Process
BEC produced $3.05 billion in reported U.S. losses in 2025 across 24,768 complaints, with wire or ACH the channel in 86% of those losses. Why the highest-leverage defense costs almost nothing.
CybersecuritySB 446 Starts the Clock: California's 30-Day Breach-Notification Deadline
California's SB 446 replaced the old 'most expedient time possible' standard with a fixed deadline: notify affected residents within 30 days of discovery. What the new clock requires of your business.
CybersecuritySOAR: Automating Security Operations Without Losing Control
SOAR promises faster response and fewer manual tasks, but automation applied carelessly amplifies mistakes. How to build playbooks that speed the SOC without taking humans out of the loop.
CybersecurityDeception Technology: Honeypots and Honeytokens That Catch Intruders
Most detection tries to spot bad activity inside a sea of legitimate traffic. Deception flips the logic: plant assets no real user should ever touch, and any interaction becomes a high-fidelity alert.
CybersecuritySoftware Supply Chain Security: SBOMs, Dependencies, and SLSA
Modern software is mostly other people's code, pulled through build systems you rarely inspect. How SBOMs, dependency hygiene, and the SLSA framework harden the path from source to production.
CybersecurityInsider Threat Programs: Detecting Risk From Within
The person with legitimate access is the hardest threat to detect, because their activity looks authorized. How to build an insider threat program that catches real risk without surveilling your workforce.
CybersecurityHow to Get 24/7 Security Monitoring Without Building a SOC
The real staffing and cost math behind an in-house 24/7 SOC—and why managed detection and response gets you round-the-clock monitoring faster.
CybersecurityDDoS Mitigation: Staying Online Under Attack
A distributed denial-of-service attack does not breach you — it drowns you in traffic until you fall over. How volumetric, protocol, and application-layer attacks work, and how to stay up when one hits.
CybersecurityPhishing-Resistant MFA: Moving Beyond OTP to Passkeys
SMS, TOTP, and push MFA still get phished by real-time relay, MFA fatigue, and SIM swap. Learn how FIDO2 passkeys break the attack and how to roll them out.
CybersecurityZero Trust in Practice: A Five-Step Rollout
Zero Trust is an architecture, not a product. A pragmatic five-step path to verify-explicitly without grinding your business to a halt.
CybersecurityPurple Teaming: Turning Red vs. Blue Into One Team
A red team that keeps its findings secret proves you can be breached but rarely makes you harder to breach. Purple teaming makes attack and defense collaborate so every exercise measurably improves detection.
CybersecurityA Practical Zero Trust Rollout for Mid-Market Companies
Zero Trust is a phased program, not a product. A realistic five-phase rollout for mid-market companies: identity first, then segmentation, then continuous verification.
CybersecurityData Encryption Explained: At Rest, In Transit, and In Use
Encryption protects data in three distinct states, each with different threats and different gaps. What at-rest, in-transit, and in-use encryption actually defend against — and why key management decides everything.
CybersecurityEDR vs. Antivirus: Why Endpoint Protection Had to Evolve
Signature antivirus cannot see fileless malware or LOLBins. Here is how behavioral EDR and managed detection changed endpoint protection, and how to choose.
Whether you’re planning a new initiative, hardening what you already run, or troubleshooting something that’s breaking, intSignal’s engineers own the tooling and the analysis so the outcome is measurable rather than best-effort. These articles reflect how we actually work with clients on cybersecurity — no vendor fluff, just what moves the needle. Explore the related services above, or talk to our team to scope a project or request an assessment.