Security Insights
Practical cybersecurity guidance, threat intelligence, and industry perspectives from the Helm team.
From the Helm Blog
There's no HIPAA certificate to earn. Compliance is a self-attested claim enforced after the fact, unlike HITRUST, a real but voluntary c...
Big-firm gap analyses hand you a findings PDF and an invoice. Cyber CPR builds the plan, runs the tabletop, and leaves you actually ready...
SMS and TOTP MFA can be phished. How phishing-resistant authenticators, conditional access, and the right license tier actually stop it.
HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — ...
Fraudulent wire or compromised inbox? What to do in the first 24 hours of a business email compromise — the bank call, the evidence, and ...
From the Newsletter
458 packages. 5 ship to production. The rest are attack surface.
A serverless pipeline that watches RSS feeds, summarizes new posts with an LLM, and emails subscribers, built entirely with Azure Logic Apps, Terraform, and no long-lived secrets.
Vulnerability management hinges on good architecture practices. AI-powered vulnerability discovery doesn't solve for this in any meaningful way.
The Vercel incident is a good reminder: do you actually control what OAuth apps can access your Google Workspace?
Textbook PyPI supply chain attack, now targeting AI infrastructure. Treat your LLM stack like any other production dependency.
Read all articles and subscribe for weekly insights.
Subscribe on Substack →Topics We Cover
Breach analysis, response lessons, and IR best practices
Emerging attack techniques and threat actor TTPs
Securing AI tools, prompt injection, and AI governance
HIPAA, NIST, and practical compliance guidance