Security Insights

Practical cybersecurity guidance, threat intelligence, and industry perspectives from the Helm team.

From the Helm Blog

August 20, 2026
Device Codes: Good for Streaming and Good for Hackers

Device code phishing uses no fake login page and defeats phishing-resistant MFA. How it works, and how to block it in Microsoft 365 and G...

Read Article →
August 17, 2026
Facebook Account Hacked? What to Do

Changing your Facebook password doesn't evict an attacker. Here's the full recovery sequence: sessions, connected apps, Page admins, and ...

Read Article →
August 4, 2026
HIPAA Compliance Isn't a Certification: It's a Self-Attested Promise

There's no HIPAA certificate to earn. Compliance is a self-attested claim enforced after the fact, unlike HITRUST, a real but voluntary c...

Read Article →
July 29, 2026
Stop Buying Findings. Start Buying Readiness.

Big-firm gap analyses hand you a findings PDF and an invoice. Cyber CPR builds the plan, runs the tabletop, and leaves you actually ready...

Read Article →
July 27, 2026
Most MFA Can Be Phished. Here's How to Save Your SaaS

SMS and TOTP MFA can be phished. How phishing-resistant authenticators, conditional access, and the right license tier actually stop it.

Read Article →
July 22, 2026
The New HIPAA Security Rule Is Delayed to 2027 — What Healthcare Orgs Should Do Now

HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — ...

Read Article →
July 20, 2026
The First 24 Hours After a Business Email Compromise

Fraudulent wire or compromised inbox? What to do in the first 24 hours of a business email compromise — the bank call, the evidence, and ...

Read Article →

From the Newsletter

Read all articles and subscribe for weekly insights.

Subscribe on Substack →

Topics We Cover

🚨
Incident Response

Breach analysis, response lessons, and IR best practices

🔍
Threat Intelligence

Emerging attack techniques and threat actor TTPs

🤖
AI Security

Securing AI tools, prompt injection, and AI governance

📋
Compliance

HIPAA, NIST, and practical compliance guidance