Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
June 16, 2026 · 4 min read
Insider Threats in Cleared Environments
Some of the most damaging compromises of classified and sensitive information have come from people with legitimate access. How insider threat programs work for cleared organizations, the indicators they watch for, and the technical controls that support them.
Read moreJune 9, 2026 · 5 min read
STIGs Without the Pain: Implementing and Sustaining DISA Baselines
Security Technical Implementation Guides harden systems against real attacks, but applying them by hand, system by system, never lasts. How to build STIG compliance that survives upgrades and inspections.
Read moreJune 2, 2026 · 4 min read
Identity Is the New Perimeter: Token Theft, MFA Fatigue and Session Hijacking
As organizations move to cloud services and remote work, attackers increasingly target identities rather than networks. The techniques used to defeat passwords and multifactor authentication, and how to build identity defenses that hold.
Read moreMay 26, 2026 · 5 min read
Protecting Critical Program Information: A Program Protection Primer
Some technologies give U.S. forces an edge that adversaries are determined to take. How programs identify critical program information, assess threats to it, and build protection into the system and its supply chain.
Read moreMay 19, 2026 · 4 min read
Adversarial Use of AI: What's Real and What's Hype
Claims about AI-powered attacks range from sober to sensational. What public threat reporting actually shows about how adversaries use AI, what remains overstated, and how defenders should respond.
Read moreMay 12, 2026 · 5 min read
Preparing for a CORA Inspection
Cyber Operational Readiness Assessments look at whether a network is actually defensible, not only whether it is documented. How to prepare, what inspectors focus on, and how to avoid the most common failures.
Read moreMay 5, 2026 · 4 min read
Software Supply Chain Attacks: From Poisoned Packages to Compromised Updates
When attackers compromise software before it reaches you, your own trusted update process delivers the attack. How supply chain attacks work, what landmark incidents taught the industry, and the defenses that apply to buyers and builders.
Read moreApril 28, 2026 · 5 min read
What to Look for in a Penetration Testing Report
The report is the product of a penetration test, and quality varies enormously. How to judge whether a report gives you verified findings, real attack paths and a clear plan, or just a reformatted scan.
Read moreApril 14, 2026 · 5 min read
Continuous Monitoring After the ATO: Staying Authorized
An authorization to operate is a snapshot of risk on one day. Continuous monitoring keeps that picture current, and done well it makes reauthorization far less painful.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.