Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
April 7, 2026 · 4 min read
Phishing in the Age of AI: Deepfakes, Voice Cloning and Tailored Lures
The telltale signs people were trained to spot, such as bad grammar and generic greetings, are disappearing. How social engineering is changing, what recent cases show, and how organizations should adapt training and controls.
Read moreMarch 24, 2026 · 5 min read
Securing Operational Technology and Embedded Systems
Control systems, weapons platforms and embedded devices run the physical world, and they cannot be secured the same way as office networks. What makes them different, and how to test and harden them without disrupting operations.
Read moreMarch 17, 2026 · 5 min read
From IATT to ATO: Getting a System Authorized Without Delays
Authorization schedules slip for predictable reasons. A practical guide to the path from interim authorization to test through an authority to operate, and how to keep it on track.
Read moreMarch 10, 2026 · 4 min read
Nation-State Targeting of the Defense Industrial Base
Defense contractors hold technology and access that foreign intelligence services want. Why the defense industrial base is targeted, the techniques public advisories describe, and the defenses that matter most.
Read moreFebruary 24, 2026 · 5 min read
Securing AI Systems: Prompt Injection, Data Poisoning and Model Theft
AI and machine learning systems introduce attack surfaces that traditional security testing was not designed for. A plain-language guide to how AI systems are attacked, and the frameworks and controls that help defend them.
Read moreFebruary 17, 2026 · 4 min read
Mobile Devices as an Attack Vector for Government Users
Phones carry email, messages, credentials and location for people who hold sensitive roles. How adversaries target mobile devices, what recent government guidance recommends, and practical protections for high-risk users.
Read moreFebruary 10, 2026 · 5 min read
The Risk Management Framework, Step by Step
The Risk Management Framework governs how federal and Department of War systems are secured and authorized. A plain-language walk through its seven steps, with the artifacts and decisions at each one.
Read moreFebruary 3, 2026 · 4 min read
Ransomware Playbooks: How Modern Attacks Unfold, Stage by Stage
Ransomware is rarely a single event. It is the final stage of an intrusion that may have lasted days or weeks. How modern ransomware operations work, where defenders can interrupt them, and how to prepare for the worst.
Read moreJanuary 27, 2026 · 5 min read
Hiring Cleared Cyber Talent: Options for Programs Under Pressure
Cleared cybersecurity professionals are among the hardest people to hire. How programs can meet staffing needs through direct hiring, staff augmentation and development, and what DoDM 8140.03 means for qualification.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.