TorchLight Blog The Way Forward.

Practical analysis on cybersecurity, managed IT, compliance, AI, cloud technology, and the decisions organizations face when technology and risk converge. TorchLight shares what matters, why it matters, and what leaders can do next.

Latest Intelligence.

The newest analysis from TorchLight on cybersecurity, managed IT, compliance, emerging technology, and the decisions shaping secure organizations.

  • Penetration testing vs. vulnerability scanning for regulated organizations

    Penetration Testing vs. Vulnerability Scanning

    Vulnerability scanning identifies potential weaknesses. Penetration testing shows what an attacker could actually do with them. This executive guide explains the difference, the regulatory requirements, and how to buy the right security testing.

    Read more: Penetration Testing vs. Vulnerability Scanning
  • RIA and AI regulation in 2026 with SEC compliance, cybersecurity, and financial technology imagery

    RIAs, Wealth Managers & Investment Firms: AI Regulation in 2026

    The SEC has not adopted an AI rule, but AI is in its 2026 exam priorities. Know what your firm uses, set boundaries, and keep evidence.

    Read more: RIAs, Wealth Managers & Investment Firms: AI Regulation in 2026
  • August 2026 Patch Tuesday showing 421 vulnerabilities with one actively exploited flaw highlighted

    421 Vulnerabilities: It Only Took One

    Microsoft’s August Patch Tuesday fixed 421 vulnerabilities, but only one had already graduated from security flaw to weapon. Lazarus was exploiting CVE-2026-68820 before the patch existed, and it scored just 7.0. Why Patch Tuesday is a triage event.

    Read more: 421 Vulnerabilities: It Only Took One
  • Autonomous AI attack concept: AI agents breaching a corporate network at machine speed, illustrating the 2026 OpenAI Hugging Face breach

    The Hugging Face Breach: What Autonomous AI Attacks Mean for Regulated Businesses

    At Black Hat 2026, OpenAI disclosed that its own AI agents autonomously breached Hugging Face in under 13 hours. Here is what that means for credit unions, clinics, advisory firms, and manufacturers, and what to do now.

    Read more: The Hugging Face Breach: What Autonomous AI Attacks Mean for Regulated Businesses
  • Shield graphic with headline: The Reg S-P clock ran out, then the breaches began. Advice for small RIAs facing 2026 SEC exams.

    The Reg S-P Clock Ran Out: Then The Breaches Began

    In the spring, we warned that the clock was ticking on the June 3 Reg S-P deadline for smaller RIAs. The clock has now run out, and the thing we warned about is happening on schedule.

    Read more: The Reg S-P Clock Ran Out: Then The Breaches Began
  • TorchLight Threat Intelligence graphic: a cracked security shield representing the 2026 Canvas breach that put all 116 California community colleges in scope

    Canvas Breach Update: Reports Set to Resume for California’s 116 Community Colleges

    The April-May 2026 Canvas breach put student data at all 116 California community colleges in scope. Instructure paused detailed breach reports over a ShareFile threat that has since cleared. Here’s what was exposed, what California’s breach-notification law actually requires, and the four steps to take this week.

    Read more: Canvas Breach Update: Reports Set to Resume for California’s 116 Community Colleges
  • TorchLight Threat Intelligence hero image showing a security shield with a broken chain link, symbolizing the July 2026 SharePoint exploit chain and CVE-2026-56164

    How the SharePoint Chain Broke on July 14, 2026: CVE-2026-56164, End-of-Support, and What Every On-Prem Operator Should Do This Week

    On July 14, 2026, Microsoft patched an actively exploited SharePoint zero-day (CVE-2026-56164), CISA added it to the Known Exploited Vulnerabilities catalog with a 72-hour federal deadline, and support for SharePoint Server 2016 and 2019 officially ended. Three events, one date. Here is what every on-premises operator should do this week.

    Read more: How the SharePoint Chain Broke on July 14, 2026: CVE-2026-56164, End-of-Support, and What Every On-Prem Operator Should Do This Week
  • TorchLight graphic illustrating business email compromise redirecting a credit union wire payment to a fake account before verification blocks the fraud.

    Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them

    Business email compromise costs U.S. organizations billions each year, and credit unions are prime targets. Here is how attackers redirect wire and ACH payments, the four most common scenarios, and the layered controls (DMARC, out-of-band verification, and staff training) that actually stop them.

    Read more: Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them
  • Illustration of CMMC Phase II suspension showing compliance checklist, cybersecurity shield, and defense contractor security requirements including NIST SP 800-171, DFARS 252.204-7012, SPRS self-assessment, and CMMC compliance after the July 2026 suspension.

    CMMC Phase II Suspended: What It Means and What to Do Next

    On July 13, 2026, the Department of War suspended CMMC Phase II, removing the November 2026 third-party audit deadline. But DFARS 252.204-7012, NIST SP 800-171, and your SPRS self-attestation all still apply. This is schedule relief, not scope relief, and here is what defense contractors should do during the pause.

    Read more: CMMC Phase II Suspended: What It Means and What to Do Next

Explore by Topic.

Go deeper into the issues shaping secure, regulated organizations. Browse focused collections covering cybersecurity, compliance, AI governance, financial services, and emerging threats.

Financial Services

Credit Unions

Security, managed IT, examination readiness, vendor risk, and operational resilience where member trust is part of the technology mandate.

Banking

Banks & Financial Institutions

Security testing, IT operations, compliance evidence, risk reduction, and cybersecurity designed for highly scrutinized financial systems.

Built for the Environments We Write About.

Cybersecurity and IT decisions do not happen in a vacuum. The right answer changes when an organization has examiners, regulators, patient data, member trust, production systems, or public accountability attached to the outcome.

TorchLight’s editorial work connects technology developments to the environments where those developments become operational, financial, and compliance decisions.

Start with the issue. Then see what it means for the environment you are responsible for protecting.

Explore All Industries
Investment Firms

Wealth Management & Investing

Cybersecurity, AI governance, technology oversight, and operational controls for firms responsible for protecting client information.

Healthcare

Healthcare & Life Sciences

Secure IT, cyber resilience, privacy, availability, and risk management for environments where technology can directly affect care and continuity.

Industrial

Manufacturing

Cybersecurity and managed IT where downtime, identity compromise, supply-chain exposure, and system availability directly affect production.

Public Sector

Government

Security, IT resilience, vulnerability management, incident response, and accountability for public agencies and organizations operating under scrutiny.

Stay Ahead of What Changes Next.

Cybersecurity, regulation, technology, and risk move quickly. Get TorchLight’s latest analysis and practical guidance delivered directly to you so the next important development does not begin as another item you have to discover too late.

Cybersecurity Compliance & Risk IT Strategy AI & Technology
Join the TorchLight Newsletter

Opens the TorchLight newsletter signup form in a new tab.

When the Issue Becomes Your Issue.

Reading about a security threat, compliance requirement, technology problem, or emerging risk is one thing. Working through what it means for your organization is another. Bring us the problem. We’ll help you determine the way forward.

Managed IT Cybersecurity Compliance Cloud Strategy
Call Talk directly with the TorchLight team.
Email Send us context and we’ll route it quickly.
Start With
The Problem
You do not need to know which service you need.
Next Step
A Real Conversation
Tell us what is happening. We’ll take it from there.

Start the Conversation

Give us a little context and we’ll connect you with the right person at TorchLight.

Name