Galactic Research: Articles & Insights
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
AI Security
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Perfect AI Guardrails Are Impossible. That's Not an Excuse for Ignoring Them.

What a NIST Mathematician Proved, Why the Internet Got it Wrong, and What Your AI Security Program Should Look Like Years ago, running an MSSP, I had a vendor pitch us a next-gen firewall on a single promise: one hundred ...
Threat Intelligence
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 13th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 6th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
Could Your Business Survive a Cyberattack? (Most Can’t—and Won’t)
The US bombed Iranian nuclear facilities last week. The result? A “spectacular military success,” sure—followed immediately by the Department of Homeland Security warning that Iran’s state-backed hackers are now eyeballing American businesses ...
Is Your IT Provider Setting You Up for a Data Breach?
There’s something buried deep inside your Microsoft 365 environment that your IT provider isn’t telling you about. It’s not a bug. It’s not even a breach. It’s worse. It’s a design flaw—a loophole that allows a guest user (someone outside ...
Will Your Cyber Insurance Actually Pay Out?
I was on a call with a client when the million-dollar question dropped: “What steps can I take to guarantee my ...
Who’s Enforcing the Rules in Your Organization?
Ever stop and ask yourself: Who on my team is actually responsible for getting people to follow the rules when it comes to technology? Not the person who installs the firewall. Not the vendor who sends you invoices for cybersecurity ...
Are You Running an MSP or a Hardware Store?
Stop selling security like it’s the power tools aisle at your local hardware store. Start building a strategy. Start with a plan. Then pour the foundation. I got an email from a partner this week. It started with the usual ...
Shame. The Most Underrated Security Tool in Your Business.
It’s 3:17 AM in Tokyo. The city is asleep. I’m not. Jet lag has me wandering quiet streets, watching the world work without me—and wondering how security works when no one’s looking. Here’s what I’ve noticed: There are no fences. ...
“We’re Not Offering Cyber Liability Essentials to Our Clients…”
That’s what one of our MSP partners told me this week. Said it would make it “too easy” for their clients to not invest in real security. I almost choked on my coffee. Listen—I get the logic. You want your ...
“What’s the ROI on Security?” Here’s the Only Answer That Matters
At some point, every MSP hears it. A skeptical client, arms crossed, looking you dead in the eye: “I get it—but what’s the ROI on all this security?” To them, your security stack feels like an insurance policy they hope ...
Wait… Are You Saying Compliance Is Dead?
I got a message today that made me spit out my coffee. It started like this: “From the recent Tuesday webinars, it seems Galactic is moving away from providing compliance as a service…” Hold on. Nope. Not even close. Let ...
The Least Engaged Person on Your Team Is Your Biggest Security Risk
Last week, I flew 81 Galacticos into Nashville. It was our offsite—a day to plan, get sharp, and punch some holes in our own assumptions. We do something at these events called Galactic Shark Tank. It’s exactly what it sounds ...
What AI’s Really Doing in Your Office (And Why You Should Be Terrified)
Let me ask you something you probably don’t want to answer: Do you actually know what your team is doing with AI? Not what they say they’re doing. Not what you hope they’re doing. What they’re really doing—with your company’s ...
What Your Last IT Project Really Cost You
You did the thing every business does: You launched an IT project. Maybe it was a migration. Maybe a new app rollout. Maybe you just “upgraded some systems.” Great. You made the investment. You expected ROI. But here’s the question ...


