Galactic Research: Articles & Insights
Threat Thursday: September 17th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what …
AI Security
Four Controls for AI Tools That Can't Defend Themselves

A weather plugin, a stolen conversation, and the case for enforcing security outside the model I recently spent an afternoon on a public challenge range, one of those practice environments security researchers use to test …
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want …
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and …
Threat Intelligence
Threat Thursday: September 17th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what …
Threat Thursday: September 10th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what …
Threat Thursday: September 3rd, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what …
Security Education
How Cl0p Breached Shell, GE, and Philips Through One Flaw

A ransomware crew turned mass extortion into an assembly line. The victims found out months later. Ask anybody to picture a ransomware attack and you'll get roughly the same movie. Screens locking up across the …
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto …
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall …
Strategy & Leadership
OpenAI Warned About AI Cyberattacks. Now What?

What the letter says, what came after it, and how to talk about it without turning it into a sales pitch On August 27, OpenAI published an open letter on global cyber defense. More than …
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about …
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An …
All Articles
Part 1: Incident Response: Panic is Not a Phase, It's a Symptom
Why Incident Response Fails Before the Incident Starts Most organizations think they’re “doing incident response” because they bought a tool. Or three. Maybe they even survived an incident once or twice, so clearly they’re fine …
They Already Have an IT Department. Good. That’s Why You Should Call.
Last night I was at dinner with the CEO of an MSP. Good operator. Growing. Adding clients. Doing the work. We were walking around his town before dinner talking about the usual founder stuff. Processes. …
AI, Cyber Liability, and the Evidence Your Insurance Carrier Will Demand
You trust your IT team. Or your outsourced IT company to completely run and secure your systems. You should. That is their job. But here is the question no one asks until it is too …
Agentic AI at the Edge: Opportunity, Autonomy & the Coming Legal Minefield
You’ve probably heard executives gush about autonomous AI agents, the shiny new productivity booster that can automate workflows faster than you can say “zero-trust.” But what they don’t hype is how agentic AI turns your …
Notepad++ Compromise: What you need to know
The recent Notepad++ compromise should make you pause for a moment because the Chrysalis backdoor is exactly the type of malware those of in the industry lose sleep over. Rapid7’s write-up on the Chrysalis backdoor …
The New Frontier: Securities Class Actions Triggered by Cybersecurity Failures
Cybersecurity risk isn’t just about limiting data loss anymore, it’s increasingly about legal exposure at the highest corporate level. A recent massive data breach at Coupang, one of South Korea’s largest online retailers, may fundamentally change how publicly traded companies and their …
Your Statement of Work Is Your Security Program Playbook, Not Paperwork
Most MSPs treat the Statement of Work like something you do after the sale. A formality. A box to check. That mindset is exactly why scope creeps, expectations get fuzzy, and security ends up feeling …
Cyber Lawsuits Are the New Cyber Threat: What Every MSP Needs to Know About Economic Loss and Legal Exposure
In 2024, class action lawsuits cost businesses over $42 billion globally. But for MSPs, the costliest threat isn’t ransomware—it’s litigation. And the legal doctrines you're relying on to protect you? They're not nearly as safe …
Stop Building Custom Security Programs. They Will Burn You.
Every MSP has lived this moment. A client calls and says they want a “custom” security program. They want their policies to sound like them. They want controls that are “unique to their workflow.” They …
How MSPs Can Lead Clients Through CMMC Implementation
Introduction With the Department of War (née Department of Defense)’s Implementation of CMMC 2.0 now set to begin on November 10, 2025, MSPs have a strategic window to position themselves as trusted cybersecurity and compliance …
Why Treating AI Like Your IT Doctor Is Putting Your Business at Risk
Right now, millions of people are experimenting with AI tools as if they were personal doctors. They type in their symptoms, ask for a diagnosis, and walk away with treatment advice—all without ever seeing a …
The Annual Tradition of Forgetting Everything We Learned About Cybersecurity
Because nothing says “security first” like annual PowerPoint fatigue. Well, it’s that time of year again. Pumpkin-spiced coffee, ghosts and goblins, trees turning colors, and holiday ads airing entirely too early. Oh yeah, and Cybersecurity …


