research
Why “Free” Gartner Alternatives Don’t Work for B2B Technical Buying (and What I Built Instead)
The "free Gartner alternative" framing hides a structural conflict: every "free" platform monetises by selling to the vendors it ranks. Here is why that breaks B2B buying, and what works instead ...
Why “Free” Gartner Alternatives Don’t Work for B2B Technical Buying (and What I Built Instead)
The "free Gartner alternative" framing hides a structural conflict: every "free" platform monetises by selling to the vendors it ranks. Here is why that breaks B2B buying, and what works instead ...
Exposing DPRK Employment Fraud Operations
Nisos Exposing DPRK Employment Fraud Operations Nisos assesses with high confidence that a Democratic People’s Republic of Korea (DPRK) state-sponsored cell conducted industrial-scale employment fraud against US companies... The post Exposing DPRK ...
DMARC Implementation in Japanese Higher Education: Status and Challenges
In this DMARC adoption study, we analyzed parent domains in Japan’s higher education landscape and the challenges IT teams face in securing their domains ...
How DMARC Helps Detect Organized SPF Abuse Schemes
In this article, our Service Delivery Specialist Steven Iacoviello discusses how criminals are targeting dangling CNAMES and DNS entry errors to hijack domains for phishing exploits.   In our daily work of helping ...
State of CIAM 2026: 14 Trends from 200+ Vendor Changelogs
An annual research piece based on 12 months of monitoring 200+ CIAM vendor changelogs. The 14 trends shaping customer identity in 2026 and the vendors leading each shift ...
DMARC Adoption: FIFA World Cup 2026Â
In this edition of our DMARC adoption research, we are considering the FIFA World Cup ecosystem and how national teams, league clubs, sponsors, and host supporters are faring with domain security as ...
Ant traps, fraud graphs, and the cost of blocking too soon
I recently had an ant problem in my apartment.At first, it looked simple. We saw ants coming through the window of one room. After looking around for a while, we found two ...
30 Cybersecurity Search Engines Every Researcher Should Bookmark
A curated, categorised guide to 30 search engines that security researchers actually use: Shodan, Censys, Dehashed, ExploitDB, and the rest ...
SMS verification abuse at scale: releasing our open source disposable phone number list
A few weeks ago, we released an open source list of disposable email domains observed in real abuse activity: https://github.com/castle/disposable-email-domainsThe goal was simple: make it easier for defenders to identify and operationalize ...

