Blog
Compliance & security guides
Practical, no-fluff guides on ISO 27001, SOC 2, and security compliance — and how to automate the parts that slow teams down.
Guide · August 30, 2026 · 9 min read
The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them
The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.
Read guide →Guide · August 30, 2026 · 9 min read
The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply
The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.
Read guide →Guide · August 30, 2026 · 8 min read
APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds
CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.
Read guide →Guide · August 18, 2026 · 13 min read
The SOC 2 Journey, Explained: From Zero to Audit-Ready in 9 Steps
Every B2B software company hits the same wall: a buyer’s security team asks for your SOC 2 report, and the deal stalls without it. This is the whole journey — who needs it, what to pick, which criteria to scope, and every step from your first control to a public trust center — in nine steps and one four-minute video.
Read guide →Guide · August 14, 2026 · 12 min read
Zero Trust for Autonomous AI Agents: Identity, Network & Telemetry
Your AI agents can place orders, reroute fleets and issue refunds at machine speed. Most of them do it on a broad API key that never expires. That’s not an integration — it’s a standing breach waiting for one bad prompt. Zero Trust is how you give agents real power without handing over the keys.
Read guide →Guide · August 14, 2026 · 12 min read
What Is Red Teaming? How Attackers Really Break In — and How CATAAM Tests It
Your scanners are green. Your firewall is configured by the book. Your last pen test passed. So why do breaches still happen? Because a checklist proves you followed the rules — it doesn’t prove an adversary can’t get in. That’s what red teaming is for.
Read guide →Security Advisory · August 13, 2026 · 11 min read
A Self-Propagating npm Worm Is Stealing Every Secret It Can Find: Shai-Hulud / ChainDrop, Explained
On August 4, 2026, a self-propagating worm tore through the npm registry — hijacking maintainer accounts, weaponizing their publish tokens, and vacuuming up every credential it could reach across 400+ packages. It’s the software-supply-chain nightmare in its purest form: you didn’t have to be careless. You just had to run npm install.
Read guide →Research · August 13, 2026 · 10 min read
We Analyzed 1,307 Vulnerabilities in 60 Days: Two-Thirds Were RCE, and AI Tools Are the New Attack Surface
Between June 13 and August 12, 2026, CATAAM’s threat pipeline ingested and analyzed 1,307 vulnerability advisories from GitHub Security Advisories and CISA’s Known Exploited Vulnerabilities catalog. The pattern is stark: remote code execution dominates, threat-actor leverage is overwhelmingly high, and AI tooling has become its own distinct — and largely unguarded — attack surface.
Read guide →Security Advisory · August 12, 2026 · 11 min read
Langflow RCE (CVE-2026-9198): What Langflow Is, Who Got Hit, and How to Fix It
There’s a free tool thousands of teams use to build AI apps — Langflow. Right now, attackers are taking it over with a single web request and no password. Here’s the tool explained in plain English, how to tell if you’re exposed, and the exact steps to fix it.
Read guide →Security Advisory · August 12, 2026 · 12 min read
Cisco Secure Firewall CVE-2026-20349: What It Is, Who’s Exposed, and How to Patch (with Commands)
There’s a box at the edge of thousands of corporate networks that most people have never heard of — yet it decides who gets in. It’s the Cisco Secure Firewall, and in August 2026 attackers started knocking it offline. Here’s the device explained in plain English, how to tell if you’re exposed, and the exact commands to patch it.
Read guide →Case Study · August 11, 2026 · 11 min read
How a Logistics Company Passed SOC 2 with OKF and Claude — The Koorier Case Study
A 40-person last-mile carrier had its data, people, and processes scattered across a dozen vendors — the worst possible starting point for SOC 2. Here’s how Koorier turned that sprawl into a single OKF knowledge graph its whole team could query through Claude, while CATAAM’s ASM, iASM, and red-team exercises found the exposure a control checklist never would.
Read guide →AI Security · August 5, 2026 · 8 min read
No, an AI Didn’t “Escape the Lab” This Week — It Leaked Your API Keys
The scariest AI-security story of Black Hat 2026 isn’t a model that “went rogue.” It’s a boring credential-leak bug in the plumbing every AI agent is built on — and unlike the viral headlines, it has a tracking number, a severity score, and a patch.
Read guide →OKF · August 5, 2026 · 7 min read
OKF for Claude: Give Claude Your Real, Current Knowledge Graph over MCP
Pasting documents into a chat is lossy, stale, and unverifiable. OKF gives Claude something better: a live, linked, cryptographically signed knowledge graph it can traverse over the Model Context Protocol — so its answers come from your real, current data.
Read guide →AI Security · August 4, 2026 · 11 min read
The MCP CVE Wave Didn’t Crest — It Broke Wider: A Second SDK, the Vendors’ Own Servers, and the First Exploited-in-the-Wild Bug
In July we mapped the first Model Context Protocol CVE wave and argued it was becoming a category. Six weeks later the argument is settled. A second official SDK fell to the same bugs, the platform vendors shipped flawed servers of their own, and the first MCP-ecosystem flaw is now being exploited in the wild.
Read guide →Threat Intelligence · August 4, 2026 · 7 min read
Oracle E-Business Suite Under Attack (CVE-2026-46817): A CVSS 9.8 Payments Takeover, Read Through SOC 2 and ISO 27001
ERP is where procurement, payroll, and payments live — the crown jewels, wired to the internet and patched on a slow clock. CVE-2026-46817 turns Oracle Payments into an unauthenticated takeover. The security story is obvious; the compliance story is the one most teams miss.
Read guide →AI Security · July 21, 2026 · 10 min read
Exposed MCP Servers Are the New Unguarded Door: The July 2026 CVE Wave and How to Find Yours
The Model Context Protocol turns a language model into something that can act. In July 2026 the ecosystem shipped a dozen ways for a stranger to act through it — and the common thread wasn’t exotic. It was a server built for localhost, quietly put on the internet.
Read guide →AI Governance · July 14, 2026 · 9 min read
The Tool Nobody Reviewed: An MCP Zero-Day Read Through SOC 2 and ISO 42001
A company with a clean SOC 2 report shipped an AI agent to production. One of its tools was missing a single line of validation — and that line was the whole audit.
Read guide →Engineering · July 7, 2026 · 5 min read
One Connector, One Compliance Test: How We Built 428 Integrations
Most compliance tools treat integrations as a logo wall. We made each connector run a test. Here’s the engineering behind 428 vendor integrations — grounded in exactly what shipped.
Read guide →AI Governance · July 1, 2026 · 7 min read
Prompt Guard: Stop Secrets Leaking into ChatGPT & Claude — and Prove It for ISO 42001
Your team pastes API keys and source code into AI chatbots every day. Here’s an open-source, local-first way to stop it — and to turn each blocked leak into audit evidence.
Read guide →AI Governance · July 1, 2026 · 6 min read
Shadow AI: Your Employees Are Pasting Secrets into ChatGPT (How to Stop It in 2026)
Most “AI policy” documents are unenforced. The leak is already happening in the prompt box — here’s how to actually close it.
Read guide →AI Governance · July 1, 2026 · 6 min read
EU AI Act Article 12: Logging & Record-Keeping Requirements, Explained (2026)
Article 12 turns “trust us” into “show us the logs.” Here’s what it requires and how to produce the evidence without a six-month project.
Read guide →AI Governance · July 1, 2026 · 7 min read
What Is an AIMS? The ISO 42001 AI Management System, Explained
Everyone says “stand up an AIMS” — but what is it, actually? Here’s the AI Management System in plain terms, and the first control worth putting in force.
Read guide →ISO 27001 · June 24, 2026 · 9 min read
ISO 27001 Certification Checklist (2026): 12 Steps to Certified
Everything you need to take an organization from zero to ISO 27001 certified — as a checklist you can actually work through.
Read guide →ISO 27001 · June 24, 2026 · 7 min read
How Much Does ISO 27001 Certification Cost in 2026?
What ISO 27001 actually costs in 2026 — audit fees, tooling, training, and internal time — and where the real savings are.
Read guide →ISO 27001 · June 24, 2026 · 8 min read
ISO 27001 vs SOC 2: Which Should You Get First? (2026)
The honest comparison — what each proves, who demands them, and why you rarely have to choose.
Read guide →OKF · June 27, 2026 · 6 min read
What Is OKF (Open Knowledge Format)? Google’s Open Standard, Explained
The plain-English explainer on Open Knowledge Format — Google’s open standard for data that AI agents can actually read.
Read guide →OKF · June 27, 2026 · 6 min read
OKF in AI: Giving Agents Real, Current, Verifiable Context
How Open Knowledge Format gives AI agents grounded, current, verifiable context — and why that beats dumping documents.
Read guide →OKF · June 27, 2026 · 5 min read
OKF + Git: Version-Controlled Knowledge Graphs as Markdown
OKF is just Markdown — so it lives in Git natively. Diffable, reviewable, and auditable knowledge graphs.
Read guide →OKF · June 27, 2026 · 6 min read
OKF vs MCP: How Open Knowledge Format and the Model Context Protocol Work Together
OKF and MCP aren’t competitors — they’re a stack. The format your knowledge lives in, and the protocol an agent uses to reach it.
Read guide →ISO 42001 · June 27, 2026 · 9 min read
Get Your Organization ISO 42001-Ready: A 2026 Readiness Guide
What it takes to become ISO/IEC 42001-ready — the first international standard for AI management systems — as a checklist you can work through.
Read guide →ISO 42001 · June 27, 2026 · 7 min read
ISO 42001 vs ISO 27001: AI Governance and Information Security, Compared
The honest comparison — what each standard proves, how they overlap, and why teams building AI increasingly need both.
Read guide →ISO 42001 · June 27, 2026 · 8 min read
ISO 42001 Annex A Controls Explained: All 9 Objectives
The 38 Annex A controls, grouped under nine objectives — what each set covers and how to evidence it.
Read guide →ISO 42001 · June 27, 2026 · 7 min read
How Much Does ISO 42001 Certification Cost in 2026?
What ISO 42001 actually costs in 2026 — audit fees, tooling, and internal time — and where the real savings are.
Read guide →