Security Insights

Practical cybersecurity guidance, threat intelligence, and industry perspectives from the Helm team.

From the Helm Blog

September 2, 2026
Standing Access Is the Blast Radius

The attacker in a SaaS data theft never escalates privilege. They inherit it. How JIT, PIM, and SCIM group provisioning cut the blast rad...

Read Article →
September 2, 2026
SSO Is Not a Complete SaaS Security Program

Health-ISAC warns that ShinyHunters is turning valid SSO logins into cloud-scale data theft. The five gates an attacker has to clear, and...

Read Article →
September 2, 2026
Network Limits and the Logs You Have to Buy

Salesforce Login IP traps, Snowflake and Databricks Private Link, and the audit logs your license tier quietly leaves out. Part three of ...

Read Article →
August 20, 2026
Device Codes: Good for Streaming and Good for Hackers

Device code phishing uses no fake login page and defeats phishing-resistant MFA. How it works, and how to block it in Microsoft 365 and G...

Read Article →
August 17, 2026
Facebook Account Hacked? What to Do

Changing your Facebook password doesn't evict an attacker. Here's the full recovery sequence: sessions, connected apps, Page admins, and ...

Read Article →
August 4, 2026
HIPAA Compliance Isn't a Certification: It's a Self-Attested Promise

There's no HIPAA certificate to earn. Compliance is a self-attested claim enforced after the fact, unlike HITRUST, a real but voluntary c...

Read Article →
July 29, 2026
Stop Buying Findings. Start Buying Readiness.

Big-firm gap analyses hand you a findings PDF and an invoice. Cyber CPR builds the plan, runs the tabletop, and leaves you actually ready...

Read Article →
July 27, 2026
Most MFA Can Be Phished. Here's How to Save Your SaaS

SMS and TOTP MFA can be phished. How phishing-resistant authenticators, conditional access, and the right license tier actually stop it.

Read Article →
July 22, 2026
The New HIPAA Security Rule Is Delayed to 2027 — What Healthcare Orgs Should Do Now

HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — ...

Read Article →
July 20, 2026
The First 24 Hours After a Business Email Compromise

Fraudulent wire or compromised inbox? What to do in the first 24 hours of a business email compromise — the bank call, the evidence, and ...

Read Article →

From the Newsletter

Read all articles and subscribe for weekly insights.

Subscribe on Substack →

Topics We Cover

🚨
Incident Response

Breach analysis, response lessons, and IR best practices

🔍
Threat Intelligence

Emerging attack techniques and threat actor TTPs

🤖
AI Security

Securing AI tools, prompt injection, and AI governance

📋
Compliance

HIPAA, NIST, and practical compliance guidance