For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/all.md.
Insights

All articles

Every article, guide, news post, report, and press mention from the FM CyberSecurity team, newest first.

AI Security
31 Aug 2026 · AI Security · News · International
Read the AI cyber defense pledge as a deadline

Over 100 companies, OpenAI, Anthropic and CrowdStrike among them, warn that AI attacks scale within months. We read the letter as a deadline.

Read more
AI Security
28 Aug 2026 · AI Security · News · International
OpenAI's rogue agents ran a covert swarm for two months

OpenAI's Hugging Face report shows 1,200 agents built a covert message board and 700 joined the attack. The safeguards existed, they were not deployed.

Read more
AI Security
27 Aug 2026 · AI Security · News · International
AI agents exploit ordinary web bugs without being asked

Aikido rebuilt the Australian gym hack in a lab. Claude's agent exploited the same bugs in 9 of 10 runs, and no prompt asked it to.

Read more
AI Security
26 Aug 2026 · AI Security · News · International
97 percent of AI-written malware never left the sandbox

Unit 42 traced 405 AI-enabled malware samples. Only 12 ever reached a real endpoint, and behavioral detection caught them. Our read for Norwegian SMBs.

Read more
AI Security
25 Aug 2026 · AI Security · News · International
AI-generated attack scripts are probing Siemens PLCs

Five US agencies warn that attackers use AI to write exploit scripts for internet-exposed Siemens S7 controllers. Here is what Norwegian plants do now.

Read more
AI Security
24 Aug 2026 · AI Security · News · International
Encrypted prompt injection beats Grok's guardrails

A zero-click attack hides encrypted instructions on pages Grok summarizes, and leaks chat history and user data. xAI has not shipped a fix.

Read more
AI Security
20 Aug 2026 · AI Security · News · International
OpenAI paused its biggest training run over hacking risk

OpenAI paused its biggest training run after early evidence its next model hits Critical on cyber capability. Here is what that number means for you.

Read more
AI Security
19 Aug 2026 · AI Security · News · International
Your AI agent's memory file is now an infection vector

Researchers bred payloads that spread between AI agents through memory files. One paragraph in the system prompt cut the spread to near zero.

Read more
AI Security
18 Aug 2026 · AI Security · News · International
OpenAI just shipped a model built to write exploits

OpenAI's GPT-5.6-Cyber completes 95 percent of exploit-development requests. Here is what a gated hacking model means for your patch window.

Read more
AI Security
17 Aug 2026 · AI Security · News · International
AI agents breached Taiwan's government in four days

Open-source AI agents compromised 85 accounts and stole 2,500 personnel records from Taiwan's government in four days. Our read on what changes now.

Read more
AI Security
14 Aug 2026 · AI Security · News · International
Your AI's hidden reasoning leaked keys and passwords

Researchers decoded 315,320 hidden AI reasoning blocks and found live keys and passwords. The vendors patched, but public repos still hold the blocks.

Read more
AI Security
12 Aug 2026 · AI Security · News · International
Shai-Hulud returns: the npm worm now rides your AI coding tools

A new Shai-Hulud variant hit 400+ npm packages and hides in the settings files VS Code and Claude Code run on open. Cloning a repo is enough.

Read more
AI Security
11 Aug 2026 · AI Security · News · International
Ghostjacking: attackers hide commands in the logs your AI agents read

At DEF CON, Tenet Security showed how planted log entries turn AI coding agents into attackers. It worked in 9 of 10 runs against Claude Code.

Read more
Compliance
11 Aug 2026 · Compliance · Articles
How long does ISO 27001 take?

The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.

Read more
Compliance
11 Aug 2026 · Compliance · Articles
How we use AI to get SMBs certification-ready in four to six weeks

AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.

Read more
Compliance
11 Aug 2026 · Compliance · Articles
ISO 27001 or NIS2 first?

A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.

Read more
Compliance
11 Aug 2026 · Compliance · Articles
What ISO 27001 costs, and what drives the price

The price of ISO 27001 is the sum of consultant hours, tooling, a GRC system, your own people's time and the audit fee. Here is what moves each one.

Read more
Compliance
11 Aug 2026 · Compliance · Articles
Your customer requires ISO 27001. What do you do now?

Your customer requires ISO 27001. Here is how to read the requirement, what you can answer today, and the realistic route to the certificate.

Read more
Strategy
10 Aug 2026 · Strategy · Articles
ISO 27001 as a subscription, with a guarantee

Secured by FM CyberSecurity bundles the tools, our own SOC, a vCISO and the ISO 27001 work into one subscription, with a guarantee on the certificate.

Read more
10 Aug 2026 · AI Security · Reports · International
AI-driven hacking is about to scale, and open models are the reason

Open models now trail frontier AI by about four months. As offensive AI gets cheap, attacks will rise. Here is how the big vendors are already preparing.

Read more
9 Aug 2026 · Identity Security · Guides
CyberArk is now Idira. Here is what changed and what did not

Yes, CyberArk is now Idira. Palo Alto Networks announced the rebrand on 12 May 2026. Here is the full old name to new name mapping.

Read more
8 Aug 2026 · Identity Security · Guides
How to start with PAM in a mid-sized Norwegian organisation

Vault the accounts that can change everything first, then service accounts. Here is the MVP, the day one integrations, and the usual traps.

Read more
7 Aug 2026 · Endpoint Security · Articles
Next-gen SIEM changes the engine, not the bill

Next-gen SIEM swaps the storage engine and ships the detection content. The invoice still follows your log volume.

Read more
6 Aug 2026 · Compliance · Guides
DORA and recurring penetration testing, what is required

DORA sets two testing duties: a yearly programme every firm in scope runs, and threat-led penetration testing only where the authority designates you.

Read more
5 Aug 2026 · Identity Security · Guides
What the Idira (CyberArk) EPM agent control panel is

The Idira EPM Control Panel is the desktop window where a standard Windows user runs approved admin tasks and asks for temporary privileges.

Read more
4 Aug 2026 · Exposure Management · Articles
Tenable One vs Tenable Vulnerability Management, start with the module

Tenable.io is now Tenable One Vulnerability Management. Our advice to Norwegian mid-sized firms: buy the module, not the platform package.

Read more
3 Aug 2026 · Compliance · Articles
What DORA software covers, and what stays a board decision

Software can hold your DORA register and your incident evidence. It cannot decide materiality, own the risk, or write your exit plan.

Read more
2 Aug 2026 · Endpoint Security · Guides
Incident response, and how a Norwegian business runs it

What counts as a security incident, what you do in the first hour, and who you have to notify in Norway, with the deadlines that already apply.

Read more
1 Aug 2026 · Cloud Security · Articles
Is Aikido a CSPM? Yes, and here is what it covers

Aikido has a cloud posture management module for AWS, Azure and Google Cloud. Here is what it checks and where the scope ends.

Read more
31 Jul 2026 · Compliance · Guides
DORA audit requirements and what you report each year

What DORA asks of internal audit, what leaves the building for Finanstilsynet, and what you show an auditor on an ordinary day.

Read more
30 Jul 2026 · AI Security · News · International
Claude models breached three real companies during Anthropic's own tests

Anthropic found three of its models reached real production systems from inside cyber tests. One talked itself into believing the breach was still a simulation.

Read more
30 Jul 2026 · Endpoint Security · Articles
Data breaches and ransomware, what they cost you in Norway

A breach and a ransomware attack are different problems with different bills. Here is what each costs a Norwegian business, and what the board decides.

Read more
29 Jul 2026 · Exposure Management · Guides
What vulnerability scanning is, and how to run it properly

A scan finds known weaknesses on the systems you point it at. Here is what it sees, what it misses, and how to work the output.

Read more
28 Jul 2026 · Compliance · Guides
DORA continuity and response plans for Norwegian firms

What DORA makes you write down, what it makes you test, who has to approve it, and how often each of those has to happen.

Read more
27 Jul 2026 · Identity Security · Articles
What endpoint privilege management is, and what it costs you

Removing local admin rights limits what one compromised laptop can do. The cost is a rule set and an approval queue someone has to staff.

Read more
22 Jul 2026 · AI Security · News · International
OpenAI's own model broke out of its test box and hacked Hugging Face

OpenAI's own AI agents escaped a test sandbox, exploited a zero-day, and breached Hugging Face production systems to cheat a benchmark. Here is our read.

Read more
5 Jun 2026 · Compliance · Articles
What the EU Cyber Resilience Act is, and who it covers

The CRA is an EU law that ties cybersecurity rules to CE marking, so a product with digital elements cannot enter the EU market without it.

Read more
4 Jun 2026 · Strategy · Articles
What CISSP certification means when picking a cybersecurity consultant

CISSP signals broad security judgment and a five-year experience bar, but it does not promise hands-on depth in any single tool you buy.

Read more
3 Jun 2026 · Compliance · Articles
What ISO 27001 Lead Implementer certification means for your project

An ISO 27001 Lead Implementer builds your ISMS; a Lead Auditor checks it. Hire the wrong role and your certification project stalls.

Read more
2 Jun 2026 · Application Security · Articles
Which regulations require recurring pentests, and how to deliver them without manual work

Five frameworks tell Norwegian SMBs to test security regularly. Only one mandates a human red team, and most teams overpay for the rest.

Read more
1 Jun 2026 · Application Security · Guides
How we pentest apps as part of ISO 27001 work

How FM CyberSecurity produces ISO 27001-defensible app pentest evidence through Aikido AI Pentest, without a manual pentest engagement, mapped to Annex A 8.29.

Read more
29 May 2026 · Exposure Management · Guides
How to get a free Tenable One tenant from us

How to get a free trial Tenable One tenant from FM CyberSecurity, scan your own infrastructure, and walk away with a written readout you can act on.

Read more
28 May 2026 · Identity Security · Guides
How to claim a free identity check via CrowdStrike

A free CrowdStrike Falcon Identity Protection trial that shows your exposed, stale, and over-privileged accounts before you commit to anything.

Read more
27 May 2026 · Identity Security · Articles
Talk to the chief architect behind one of the world's largest CyberArk deployments

When you buy privileged access management, you should talk to the practitioner who has run CyberArk at the largest scale, not a reseller.

Read more
26 May 2026 · Exposure Management · Guides
How we run the first vulnerability assessment in Tenable One

A two-week, day-by-day walkthrough of the first vulnerability assessment FM CyberSecurity runs on Tenable One for a new Norwegian SMB customer.

Read more
25 May 2026 · Exposure Management · Guides
How we run the vulnerability program for new customers in Tenable One

The weekly, monthly, and quarterly cadence FM CyberSecurity runs on Tenable One for Norwegian SMB customers, with the people, the meetings, and the evidence trail.

Read more
22 May 2026 · Exposure Management · Articles
Exposure management vs vulnerability management, why the terms are not the same

Vulnerability management tells you what is broken. Exposure management tells you what can hurt the contract you just signed.

Read more
21 May 2026 · Industry · News · Norway
FM CyberSecurity at Arrow ECS Summer Cloud Festival 2026

Four of us on the floor at Arrow ECS Norway's Summer Cloud Festival in Oslo. A big thanks to the Arrow crew for a great event.

Read more
21 May 2026 · Exposure Management · Guides
Nessus, Tenable Vulnerability Management, or Tenable One, which fits your business

A plain-English decision guide for Norwegian SMBs choosing between Nessus, Tenable Vulnerability Management, and Tenable One.

Read more
21 May 2026 · Exposure Management · News · Norway
Tenable visits FM CyberSecurity, and a lap on Silverstone

Tenable came by our Oslo office this week. Guy March took the sim for a lap on Silverstone and clocked 1:36.052.

Read more
20 May 2026 · Exposure Management · Guides
What Nessus is, and where it fits in the Tenable portfolio

A plain-English guide to Nessus, the Tenable scanner, including the current SKUs and how it relates to Tenable Vulnerability Management and Tenable One.

Read more
19 May 2026 · AI Security · Press · Norway
Fredrik Standahl in Digi.no on shadow AI in Norway

Digi.no published a Fredrik Standahl op-ed on treating AI as critical infrastructure and the Lovable breach as a warning sign.

Read more
19 May 2026 · AI Security · Press · Norway
Fredrik Standahl in E24 on shadow AI in Norway

E24 published a Fredrik Standahl op-ed on shadow AI in Norwegian workplaces and the data exposure pattern behind it.

Read more
19 May 2026 · AI Security · Guides
How we handle Shadow AI with Falcon AIDR

A six-step FM CyberSecurity engagement that takes a Norwegian SMB from no Shadow AI visibility to a written policy and Falcon AIDR detection rules in one quarter.

Read more
18 May 2026 · AI Security · Articles
What Shadow AI is, and why Norwegian SMBs struggle to see it

Shadow AI is unsanctioned AI use on company data. Norwegian SMBs miss it because policy without detection is faith, and usage moves to personal devices.

Read more
15 May 2026 · Endpoint Security · Guides
What a SOC is, and when you need your own

A plain-English guide to what a Security Operations Centre really does, what one costs to run, and why most Norwegian SMBs should rent rather than build.

Read more
14 May 2026 · Endpoint Security · Guides
What SIEM is, and when an SMB needs one

Most Norwegian SMBs do not need a standalone SIEM. Here is when you do, when your EDR already covers it, and what to do next.

Read more
13 May 2026 · Endpoint Security · Articles
EDR vs antivirus, and why you need both

Yes, you need EDR even with antivirus running. Antivirus blocks known bad files, EDR records what the attacker does next.

Read more
12 May 2026 · Strategy · Articles
How we publish to our website with no admin login

FM CyberSecurity publishes through a Cloudflare Workers MCP server, gated by Microsoft Entra. No admin login, no user table, no CMS, no /forgot-password page.

Read more
12 May 2026 · Endpoint Security · Articles
What CrowdStrike Falcon is, the platform behind modern MDR

CrowdStrike Falcon is one lightweight agent and a cloud console that together replace a rack of separate endpoint security tools.

Read more
11 May 2026 · Compliance · Articles
From compliance burden to competitive advantage

How leadership teams move from compliance uncertainty to documented control, evidence that holds up under investor, customer, or regulatory due diligence.

Read more
11 May 2026 · Compliance · Articles
SOC 2 compliance for Norwegian SMBs selling into the US

SOC 2 can win you a US deal or burn six figures you did not need. Here is how to tell which, and how it fits ISO 27001.

Read more
8 May 2026 · Compliance · Articles
What SOC 2 Type 2 is, and why US customers ask for it

A US prospect asks for your SOC 2 Type 2 report, you do not have one, and the deal stalls. Here is what it is and the decision it forces.

Read more
7 May 2026 · Compliance · Articles
What Norway's Digital Security Act is, and how it relates to NIS2

If Norway counts your firm as critical, you have had legal digital-security duties since October 2025, and most boards have not noticed.

Read more
6 May 2026 · Compliance · Articles
What ISO 27001 is, and why you lose tenders without it

Buyers increasingly require ISO 27001 certification to even let you bid, so missing it quietly drops you from shortlists you would have won.

Read more
5 May 2026 · Compliance · Guides
ISO 27001 checklist for Norwegian SMBs

A practical ISO 27001 checklist that takes a Norwegian small or mid-size business from "we should get certified" to a Stage 2 audit.

Read more
4 May 2026 · Compliance · Guides
DORA checklist for Norwegian financial firms

A ten-step DORA checklist for Norwegian banks, insurers, payment firms and asset managers, with Finanstilsynet deadlines and what to do this quarter.

Read more
1 May 2026 · Compliance · Guides
NIS2 checklist for Norwegian SMB leaders

A leader-facing NIS2 checklist for Norwegian SMBs, the scope self-test, who owns what, the reporting clock, what to budget, and the board questions to ask.

Read more
30 Apr 2026 · Compliance · Articles
What NIS2 is, and which Norwegian businesses fall under it

NIS2 obligations flow down through contracts, so you can be asked to prove security maturity even before the rule reaches Norwegian law.

Read more
29 Apr 2026 · Application Security · Articles
Why Aikido is our only pentest provider

We deliver every pentest through Aikido AI Pentest because the annual manual report lands in a drawer and the application ships again the next week.

Read more
28 Apr 2026 · Exposure Management · Articles
Why we picked Tenable for exposure management

We standardised on Tenable because boards buy one map of business risk, not a longer list of CVEs no one has time to read.

Read more
27 Apr 2026 · Endpoint Security · Articles
Why we picked CrowdStrike Falcon for modern MDR

We run client MDR on CrowdStrike Falcon because the platform does the detection and response work a small security team cannot cover alone.

Read more
22 Apr 2026 · Compliance · Guides
How Nordic SMBs prepare for NIS2

Practical compliance steps for the new EU directive, what to do this quarter, and what can wait.

Read more
15 Apr 2026 · Strategy · Articles
Charlotte AI: what does agentic SOC mean for you?

A look at how CrowdStrike's agentic SOC changes the economics of 24/7 monitoring for SMBs.

Read more
14 Apr 2026 · AI Security · Press · Norway
Fredrik Standahl in Shifter on startup AI security

Shifter published a Fredrik Standahl commentary on the security failures common in AI-driven startup development.

Read more
5 Mar 2026 · Strategy · Press · Norway
FM CyberSecurity in VG, cybersecurity is booming

VG Dine Penger interviewed Fredrik Standahl on starting a cybersecurity firm in Norway and the niche's hiring boom.

Read more
1 Mar 2026 · Strategy · Press · Norway
FM CyberSecurity in Norwegian Cybersecurity Cluster

Norwegian Cybersecurity Cluster profiled FM CyberSecurity's founders and our first months building the firm in Oslo.

Read more
Questions or inquiry? hello@fmcybersecurity.com Contact us →