Blog

Compliance & security guides

Practical, no-fluff guides on ISO 27001, SOC 2, and security compliance — and how to automate the parts that slow teams down.

Guide · August 30, 2026 · 9 min read

The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them

The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.

Read guide →

Guide · August 30, 2026 · 9 min read

The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply

The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.

Read guide →

Guide · August 30, 2026 · 8 min read

APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds

CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.

Read guide →

Guide · August 18, 2026 · 13 min read

The SOC 2 Journey, Explained: From Zero to Audit-Ready in 9 Steps

Every B2B software company hits the same wall: a buyer’s security team asks for your SOC 2 report, and the deal stalls without it. This is the whole journey — who needs it, what to pick, which criteria to scope, and every step from your first control to a public trust center — in nine steps and one four-minute video.

Read guide →

Guide · August 14, 2026 · 12 min read

Zero Trust for Autonomous AI Agents: Identity, Network & Telemetry

Your AI agents can place orders, reroute fleets and issue refunds at machine speed. Most of them do it on a broad API key that never expires. That’s not an integration — it’s a standing breach waiting for one bad prompt. Zero Trust is how you give agents real power without handing over the keys.

Read guide →

Guide · August 14, 2026 · 12 min read

What Is Red Teaming? How Attackers Really Break In — and How CATAAM Tests It

Your scanners are green. Your firewall is configured by the book. Your last pen test passed. So why do breaches still happen? Because a checklist proves you followed the rules — it doesn’t prove an adversary can’t get in. That’s what red teaming is for.

Read guide →

Security Advisory · August 13, 2026 · 11 min read

A Self-Propagating npm Worm Is Stealing Every Secret It Can Find: Shai-Hulud / ChainDrop, Explained

On August 4, 2026, a self-propagating worm tore through the npm registry — hijacking maintainer accounts, weaponizing their publish tokens, and vacuuming up every credential it could reach across 400+ packages. It’s the software-supply-chain nightmare in its purest form: you didn’t have to be careless. You just had to run npm install.

Read guide →

Research · August 13, 2026 · 10 min read

We Analyzed 1,307 Vulnerabilities in 60 Days: Two-Thirds Were RCE, and AI Tools Are the New Attack Surface

Between June 13 and August 12, 2026, CATAAM’s threat pipeline ingested and analyzed 1,307 vulnerability advisories from GitHub Security Advisories and CISA’s Known Exploited Vulnerabilities catalog. The pattern is stark: remote code execution dominates, threat-actor leverage is overwhelmingly high, and AI tooling has become its own distinct — and largely unguarded — attack surface.

Read guide →

Security Advisory · August 12, 2026 · 11 min read

Langflow RCE (CVE-2026-9198): What Langflow Is, Who Got Hit, and How to Fix It

There’s a free tool thousands of teams use to build AI apps — Langflow. Right now, attackers are taking it over with a single web request and no password. Here’s the tool explained in plain English, how to tell if you’re exposed, and the exact steps to fix it.

Read guide →

Security Advisory · August 12, 2026 · 12 min read

Cisco Secure Firewall CVE-2026-20349: What It Is, Who’s Exposed, and How to Patch (with Commands)

There’s a box at the edge of thousands of corporate networks that most people have never heard of — yet it decides who gets in. It’s the Cisco Secure Firewall, and in August 2026 attackers started knocking it offline. Here’s the device explained in plain English, how to tell if you’re exposed, and the exact commands to patch it.

Read guide →

Case Study · August 11, 2026 · 11 min read

How a Logistics Company Passed SOC 2 with OKF and Claude — The Koorier Case Study

A 40-person last-mile carrier had its data, people, and processes scattered across a dozen vendors — the worst possible starting point for SOC 2. Here’s how Koorier turned that sprawl into a single OKF knowledge graph its whole team could query through Claude, while CATAAM’s ASM, iASM, and red-team exercises found the exposure a control checklist never would.

Read guide →

AI Security · August 5, 2026 · 8 min read

No, an AI Didn’t “Escape the Lab” This Week — It Leaked Your API Keys

The scariest AI-security story of Black Hat 2026 isn’t a model that “went rogue.” It’s a boring credential-leak bug in the plumbing every AI agent is built on — and unlike the viral headlines, it has a tracking number, a severity score, and a patch.

Read guide →

OKF · August 5, 2026 · 7 min read

OKF for Claude: Give Claude Your Real, Current Knowledge Graph over MCP

Pasting documents into a chat is lossy, stale, and unverifiable. OKF gives Claude something better: a live, linked, cryptographically signed knowledge graph it can traverse over the Model Context Protocol — so its answers come from your real, current data.

Read guide →

AI Security · August 4, 2026 · 11 min read

The MCP CVE Wave Didn’t Crest — It Broke Wider: A Second SDK, the Vendors’ Own Servers, and the First Exploited-in-the-Wild Bug

In July we mapped the first Model Context Protocol CVE wave and argued it was becoming a category. Six weeks later the argument is settled. A second official SDK fell to the same bugs, the platform vendors shipped flawed servers of their own, and the first MCP-ecosystem flaw is now being exploited in the wild.

Read guide →

Threat Intelligence · August 4, 2026 · 7 min read

Oracle E-Business Suite Under Attack (CVE-2026-46817): A CVSS 9.8 Payments Takeover, Read Through SOC 2 and ISO 27001

ERP is where procurement, payroll, and payments live — the crown jewels, wired to the internet and patched on a slow clock. CVE-2026-46817 turns Oracle Payments into an unauthenticated takeover. The security story is obvious; the compliance story is the one most teams miss.

Read guide →

AI Security · July 21, 2026 · 10 min read

Exposed MCP Servers Are the New Unguarded Door: The July 2026 CVE Wave and How to Find Yours

The Model Context Protocol turns a language model into something that can act. In July 2026 the ecosystem shipped a dozen ways for a stranger to act through it — and the common thread wasn’t exotic. It was a server built for localhost, quietly put on the internet.

Read guide →

AI Governance · July 14, 2026 · 9 min read

The Tool Nobody Reviewed: An MCP Zero-Day Read Through SOC 2 and ISO 42001

A company with a clean SOC 2 report shipped an AI agent to production. One of its tools was missing a single line of validation — and that line was the whole audit.

Read guide →

Engineering · July 7, 2026 · 5 min read

One Connector, One Compliance Test: How We Built 428 Integrations

Most compliance tools treat integrations as a logo wall. We made each connector run a test. Here’s the engineering behind 428 vendor integrations — grounded in exactly what shipped.

Read guide →

AI Governance · July 1, 2026 · 7 min read

Prompt Guard: Stop Secrets Leaking into ChatGPT & Claude — and Prove It for ISO 42001

Your team pastes API keys and source code into AI chatbots every day. Here’s an open-source, local-first way to stop it — and to turn each blocked leak into audit evidence.

Read guide →

AI Governance · July 1, 2026 · 6 min read

Shadow AI: Your Employees Are Pasting Secrets into ChatGPT (How to Stop It in 2026)

Most “AI policy” documents are unenforced. The leak is already happening in the prompt box — here’s how to actually close it.

Read guide →

AI Governance · July 1, 2026 · 6 min read

EU AI Act Article 12: Logging & Record-Keeping Requirements, Explained (2026)

Article 12 turns “trust us” into “show us the logs.” Here’s what it requires and how to produce the evidence without a six-month project.

Read guide →

AI Governance · July 1, 2026 · 7 min read

What Is an AIMS? The ISO 42001 AI Management System, Explained

Everyone says “stand up an AIMS” — but what is it, actually? Here’s the AI Management System in plain terms, and the first control worth putting in force.

Read guide →

ISO 27001 · June 24, 2026 · 9 min read

ISO 27001 Certification Checklist (2026): 12 Steps to Certified

Everything you need to take an organization from zero to ISO 27001 certified — as a checklist you can actually work through.

Read guide →

ISO 27001 · June 24, 2026 · 7 min read

How Much Does ISO 27001 Certification Cost in 2026?

What ISO 27001 actually costs in 2026 — audit fees, tooling, training, and internal time — and where the real savings are.

Read guide →

ISO 27001 · June 24, 2026 · 8 min read

ISO 27001 vs SOC 2: Which Should You Get First? (2026)

The honest comparison — what each proves, who demands them, and why you rarely have to choose.

Read guide →

OKF · June 27, 2026 · 6 min read

What Is OKF (Open Knowledge Format)? Google’s Open Standard, Explained

The plain-English explainer on Open Knowledge Format — Google’s open standard for data that AI agents can actually read.

Read guide →

OKF · June 27, 2026 · 6 min read

OKF in AI: Giving Agents Real, Current, Verifiable Context

How Open Knowledge Format gives AI agents grounded, current, verifiable context — and why that beats dumping documents.

Read guide →

OKF · June 27, 2026 · 5 min read

OKF + Git: Version-Controlled Knowledge Graphs as Markdown

OKF is just Markdown — so it lives in Git natively. Diffable, reviewable, and auditable knowledge graphs.

Read guide →

OKF · June 27, 2026 · 6 min read

OKF vs MCP: How Open Knowledge Format and the Model Context Protocol Work Together

OKF and MCP aren’t competitors — they’re a stack. The format your knowledge lives in, and the protocol an agent uses to reach it.

Read guide →

ISO 42001 · June 27, 2026 · 9 min read

Get Your Organization ISO 42001-Ready: A 2026 Readiness Guide

What it takes to become ISO/IEC 42001-ready — the first international standard for AI management systems — as a checklist you can work through.

Read guide →

ISO 42001 · June 27, 2026 · 7 min read

ISO 42001 vs ISO 27001: AI Governance and Information Security, Compared

The honest comparison — what each standard proves, how they overlap, and why teams building AI increasingly need both.

Read guide →

ISO 42001 · June 27, 2026 · 8 min read

ISO 42001 Annex A Controls Explained: All 9 Objectives

The 38 Annex A controls, grouped under nine objectives — what each set covers and how to evidence it.

Read guide →

ISO 42001 · June 27, 2026 · 7 min read

How Much Does ISO 42001 Certification Cost in 2026?

What ISO 42001 actually costs in 2026 — audit fees, tooling, and internal time — and where the real savings are.

Read guide →