Logo
Monitor Illustration
Blog

News, Article, and Solution in Cybersecurity Realms.

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 7 minutes read

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

Professor IllustrationAndroid IllustrationMonitors Illustration

Recent Highlights

Stop Treating the Cybersecurity Skills Gap as One Big Gap
Cybersecurity

Stop Treating the Cybersecurity Skills Gap as One Big Gap

ITSEC AsiaITSEC Asia
|
Sep 21, 2026 3 minutes read

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it. Hire more people. Train more graduates. Upskill employees. Fine. Train them in what? NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states. The interesting part isn’t the funding figure. It’s the design. Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities. In other words, training starts with the capability that’s missing. ONE SHORTAGE CAN HIDE SEVERAL GAPS Consider three organizations hiring cybersecurity talent. A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and

AI Agents Change What Security Teams Need to Know
Cybersecurity

AI Agents Change What Security Teams Need to Know

ITSEC AsiaITSEC Asia
|
Sep 18, 2026 3 minutes read

NIST is building an AI agent workflow for one of cybersecurity’s most widely used public resources. On 17 September, its Information Technology Laboratory presented work on an agentic workflow designed to help enrich vulnerability information in the National Vulnerability Database. NIST says the project is intended to help the NVD cope with the increasing scale and complexity of disclosed vulnerabilities, and the webinar covered its architecture, implementation issues and early results. The project illustrates a broader change. AI is moving from producing information toward performing multi-step tasks. NIST describes AI agents as systems capable of autonomous actions that can interact with external systems and internal data. For cybersecurity professionals, that means another layer of skills is arriving. SECURITY HAS TO FOLLOW THE ACTION A conventional AI application might receive a prompt and return an answer. An agent may have access to tools, data and permissions that allow it to continue working. That changes the questions a security professional needs to ask. * What systems can the agent access? * Which actions can

A SOC Can’t Detect What It Never Learned to See
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

ITSEC AsiaITSEC Asia
|
Sep 17, 2026 3 minutes read

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened. That sounds like the beginning of detection work. In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation. If that work is poor, even an excellent analyst is starting with missing pages. An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2. That’s a useful model for SOC training. VISIBILITY IS A SKILL SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response. Those capabilities

Editor's Choice

Understanding the Diverse Sources and Platforms of Threat Intelligence

Juli 21, 2023

Jenkins + Gitlab + Sonarqube + Maven Integration: DevOps Configuration

Juli 11, 2023

Automated Suricata-to-ATT&CK Mapper using Machine Learning

Juli 21, 2023

Setup Basic Hacking Lab Infrastructure

Juli 21, 2023

Binary Analysis With RetDec and SYNOPSYS Code-DX

Juli 21, 2023

Streamlining Suricata / Snort Signature Development with Dalton

Juli 21, 2023
No article found

Receive weekly
updates on new posts

Subscribe