Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
January 20, 2026 · 5 min read
Building a Cryptographic Inventory: The First Step to Quantum Readiness
You cannot migrate cryptography you cannot find. How to discover where cryptography is used across networks, software, certificates and devices, what to record, and how to turn the inventory into a migration plan.
Read moreJanuary 13, 2026 · 5 min read
POA&Ms Done Right: Turning Gaps into a Credible Remediation Plan
A Plan of Action and Milestones is where compliance programs prove they are serious. How to write POA&M items that assessors and authorizing officials trust, and what CMMC allows.
Read moreJanuary 6, 2026 · 4 min read
Edge Devices Under Attack: VPNs, Firewalls and Gateways
The devices that guard the perimeter have become a favorite target. Why VPNs, firewalls, routers and gateways are exploited so often, what recent advisories describe, and how to defend devices you often cannot inspect.
Read moreDecember 16, 2025 · 5 min read
Incident Response Readiness: The First 72 Hours
The decisions made in the first hours of a cyber incident shape everything that follows. What to prepare before an incident, what to do hour by hour once one begins, and the mistakes that make recovery harder.
Read moreDecember 9, 2025 · 6 min read
Scoping CUI: How to Shrink Your Compliance Boundary
The single biggest lever on the cost of NIST SP 800-171 and CMMC compliance is scope. How to find where CUI really lives, categorize assets, and design an enclave that is smaller, cheaper and easier to defend.
Read moreDecember 2, 2025 · 5 min read
Harvest Now, Decrypt Later: Why Post-Quantum Planning Starts Today
Encrypted data stolen today could be decrypted once cryptographically relevant quantum computers exist. What the threat is, what NIST and NSA have published, and the first steps every organization should take.
Read moreNovember 25, 2025 · 5 min read
Why Cyber Ranges Belong in Every Training Program
Cyber skills are perishable, and practicing on production networks is neither safe nor legal. How cyber ranges give teams realistic, repeatable practice, and why field-deployable ranges matter for teams that operate far from a classroom.
Read moreNovember 18, 2025 · 6 min read
Writing a System Security Plan That Survives Assessment
The System Security Plan is the first document an assessor reads and the one most often found wanting. Here is what a strong SSP contains and how to keep it true.
Read moreNovember 11, 2025 · 4 min read
Veterans in Cybersecurity: Why Mission Experience Translates
Cybersecurity is an adversarial, high-stakes discipline, and military service prepares people for exactly that. Why veterans thrive in cyber careers, how organizations can recruit and support them, and why it matters to CDT.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.