Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
November 4, 2025 · 5 min read
Red, Blue and Purple Teams Explained
Red teams attack, blue teams defend, and purple teams make both better. What each does, how they differ from penetration testing, and how to choose the right exercise for your organization's maturity.
Read moreOctober 28, 2025 · 5 min read
DFARS 252.204-7012 Incident Reporting: The 72-Hour Clock
Defense contractors must report cyber incidents affecting covered defense information within 72 hours, preserve evidence, and support investigation. What triggers the clock, what to report, and how to be ready before it starts.
Read moreOctober 21, 2025 · 4 min read
Living off the Land: How Attackers Hide Using Your Own Tools
Some of the most capable threat actors bring almost no malware. They use the administration tools already on your systems. How living-off-the-land techniques work, why they evade traditional defenses, and how to detect them.
Read moreOctober 14, 2025 · 5 min read
The 14 NIST SP 800-171 Families in Plain Language
A practical tour of the 110 requirements that protect Controlled Unclassified Information: what each control family asks for, what assessors look for, and where organizations most often fall short.
Read moreOctober 7, 2025 · 5 min read
Standing Up a Classified Network: Lessons from the Field
Classified networks fail in predictable ways: late facility approvals, designs that cannot be accredited, and sustainment that erodes after the first inspection. Practical lessons for program offices and contractors.
Read moreSeptember 23, 2025 · 5 min read
Penetration Test vs. Vulnerability Scan: What Your Organization Actually Needs
Scans and penetration tests are often confused, and sometimes sold as the same thing. What each one does, what each one misses, and how to combine them into a program that finds real risk.
Read moreSeptember 16, 2025 · 5 min read
Pre-Positioning in Critical Infrastructure: What Public Advisories Tell Us
U.S. agencies have warned that state-sponsored actors are hiding inside critical infrastructure networks, not to steal data but to be ready to disrupt. What the advisories say, why it matters beyond infrastructure operators, and how to look for it.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.