Exploring today's threats. Preparing for tomorrow's unknowns.

A publication about cybersecurity, risk, technology, and the ever-changing landscape in between. Thoughtful analysis. Practical advice. Continuous learning.

Question of the Month

Should ransomware payments be prohibited, even if refusing to pay could permanently disrupt critical services?

Join the conversation

Latest Article

One of the concepts that repeatedly tripped me up while studying for the Certified Information Systems Security Professional exam was the difference between due care and due diligence. At first, the distinction seemed simple. One term involved deciding what an organization should do, while the other involved actually doing it. Then I would read another practice question, both answers would sound reasonable, and suddenly the distinction disappeared. It reminded me of the famous Spider-Man meme where two nearly identical characters point at each other. Due care. Due diligence. Which one is which again? The frustrating part was that I could explain both concepts in a conversation and still second-guess myself during a test. Because the terms are closely related—and are sometimes used differently outside certification materials—it is easy to understand why they become tangled together.
Title Image: Why I Keep Getting Due Diligence and Due Care Mixed Up ; Attack Surface Unknown
Stay Ahead of the Unknown
Subscribe to our newsletter for the latest cybersecurity insights, articles, and updates from Attack Surface Unknown.

Featured Article

Bug bounty programs can be an important extension of an organization’s cybersecurity program. They give independent security researchers an opportunity to examine applications in ways that internal teams and automated tools may not. More importantly, they can uncover vulnerabilities before someone with malicious intent finds them. As a cybersecurity practitioner, I find public bug bounty reports especially valuable. They provide real-world examples that can help security teams, business leaders, and clients better understand how vulnerabilities are discovered, how seemingly minor weaknesses can create meaningful risk, and what organizations can learn from the disclosure process. This article may become the first in a series examining noteworthy bug bounty reports: what the researcher found, how the vulnerability worked, how the organization responded, and what lessons others can take from it.
Artificial intelligence is changing how organizations collect, process, analyze, and act on data. It is also forcing businesses to reconsider whether their existing privacy and security controls are prepared for systems that can operate with increasing speed, scale, and independence. The central challenge is not simply whether an organization uses AI. The greater concern is whether the organization understands what its AI systems can access, what those systems are permitted to do, and whether their actual behavior matches documented policies. That gap between policy and operational reality may become one of the most significant risk management issues of the decade. Organizations have spent years developing privacy notices, access-control policies, data-retention standards, and incident response procedures. However, AI systems introduce new questions that many of those policies were not originally written to address.
As a small YouTube channel creator, you’ve invested time, creativity, and energy into growing your channel. Unfortunately, cyber threats are a growing risk in the digital creator space, especially for channels with limited resources. You might think that only big accounts are targeted, but threat actors see smaller creators as easier targets—and the consequences of a breach can be devastating. In this guide, we’ll explore practical cybersecurity strategies to protect your YouTube channel, focusing on low-cost solutions tailored for small creators.
One of the concepts that repeatedly tripped me up while studying for the Certified Information Systems Security Professional exam was the difference between due care and due diligence. At first, the distinction seemed simple. One term involved deciding what an organization should do, while the other involved actually doing it. Then I would read another practice question, both answers would sound reasonable, and suddenly the distinction disappeared. It reminded me of the famous Spider-Man meme where two nearly identical characters point at each other. Due care. Due diligence. Which one is which again? The frustrating part was that I could explain both concepts in a conversation and still second-guess myself during a test. Because the terms are closely related—and are sometimes used differently outside certification materials—it is easy to understand why they become tangled together.

Resource Spotlight

YouTube Channel

Simply Cyber

Practical cybersecurity education for anyone who wants to level up their skills.

Charting the Duality

Every new technology creates both opportunity and exposure. We examine the evolving attack surface from both sides—how adversaries may exploit it and how defenders can prepare.
Stay Ahead of the Unknown
Subscribe to our newsletter for the latest cybersecurity insights, articles, and updates from Attack Surface Unknown.

Stay Ahead of the Unknown

Subscribe to our newsletter for the latest cybersecurity insights, articles, and updates from Attack Surface Unknown.

Sign Up to Our Newsletters

Subscribe to receive the latest cybersecurity articles, practical insights, and curated resources from Attack Surface Unknown.