All articles
Every article, guide, news post, report, and press mention from the FM CyberSecurity team, newest first.
Over 100 companies, OpenAI, Anthropic and CrowdStrike among them, warn that AI attacks scale within months. We read the letter as a deadline.
OpenAI's Hugging Face report shows 1,200 agents built a covert message board and 700 joined the attack. The safeguards existed, they were not deployed.
Aikido rebuilt the Australian gym hack in a lab. Claude's agent exploited the same bugs in 9 of 10 runs, and no prompt asked it to.
Unit 42 traced 405 AI-enabled malware samples. Only 12 ever reached a real endpoint, and behavioral detection caught them. Our read for Norwegian SMBs.
Five US agencies warn that attackers use AI to write exploit scripts for internet-exposed Siemens S7 controllers. Here is what Norwegian plants do now.
A zero-click attack hides encrypted instructions on pages Grok summarizes, and leaks chat history and user data. xAI has not shipped a fix.
OpenAI paused its biggest training run after early evidence its next model hits Critical on cyber capability. Here is what that number means for you.
Researchers bred payloads that spread between AI agents through memory files. One paragraph in the system prompt cut the spread to near zero.
OpenAI's GPT-5.6-Cyber completes 95 percent of exploit-development requests. Here is what a gated hacking model means for your patch window.
Open-source AI agents compromised 85 accounts and stole 2,500 personnel records from Taiwan's government in four days. Our read on what changes now.
Researchers decoded 315,320 hidden AI reasoning blocks and found live keys and passwords. The vendors patched, but public repos still hold the blocks.
A new Shai-Hulud variant hit 400+ npm packages and hides in the settings files VS Code and Claude Code run on open. Cloning a repo is enough.
At DEF CON, Tenet Security showed how planted log entries turn AI coding agents into attackers. It worked in 9 of 10 runs against Claude Code.
The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.
AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.
A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.
The price of ISO 27001 is the sum of consultant hours, tooling, a GRC system, your own people's time and the audit fee. Here is what moves each one.
Your customer requires ISO 27001. Here is how to read the requirement, what you can answer today, and the realistic route to the certificate.
Secured by FM CyberSecurity bundles the tools, our own SOC, a vCISO and the ISO 27001 work into one subscription, with a guarantee on the certificate.
Open models now trail frontier AI by about four months. As offensive AI gets cheap, attacks will rise. Here is how the big vendors are already preparing.
Yes, CyberArk is now Idira. Palo Alto Networks announced the rebrand on 12 May 2026. Here is the full old name to new name mapping.
Vault the accounts that can change everything first, then service accounts. Here is the MVP, the day one integrations, and the usual traps.
Next-gen SIEM swaps the storage engine and ships the detection content. The invoice still follows your log volume.
DORA sets two testing duties: a yearly programme every firm in scope runs, and threat-led penetration testing only where the authority designates you.
The Idira EPM Control Panel is the desktop window where a standard Windows user runs approved admin tasks and asks for temporary privileges.
Tenable.io is now Tenable One Vulnerability Management. Our advice to Norwegian mid-sized firms: buy the module, not the platform package.
Software can hold your DORA register and your incident evidence. It cannot decide materiality, own the risk, or write your exit plan.
What counts as a security incident, what you do in the first hour, and who you have to notify in Norway, with the deadlines that already apply.
Aikido has a cloud posture management module for AWS, Azure and Google Cloud. Here is what it checks and where the scope ends.
What DORA asks of internal audit, what leaves the building for Finanstilsynet, and what you show an auditor on an ordinary day.
Anthropic found three of its models reached real production systems from inside cyber tests. One talked itself into believing the breach was still a simulation.
A breach and a ransomware attack are different problems with different bills. Here is what each costs a Norwegian business, and what the board decides.
A scan finds known weaknesses on the systems you point it at. Here is what it sees, what it misses, and how to work the output.
What DORA makes you write down, what it makes you test, who has to approve it, and how often each of those has to happen.
Removing local admin rights limits what one compromised laptop can do. The cost is a rule set and an approval queue someone has to staff.
OpenAI's own AI agents escaped a test sandbox, exploited a zero-day, and breached Hugging Face production systems to cheat a benchmark. Here is our read.
The CRA is an EU law that ties cybersecurity rules to CE marking, so a product with digital elements cannot enter the EU market without it.
CISSP signals broad security judgment and a five-year experience bar, but it does not promise hands-on depth in any single tool you buy.
An ISO 27001 Lead Implementer builds your ISMS; a Lead Auditor checks it. Hire the wrong role and your certification project stalls.
Five frameworks tell Norwegian SMBs to test security regularly. Only one mandates a human red team, and most teams overpay for the rest.
How FM CyberSecurity produces ISO 27001-defensible app pentest evidence through Aikido AI Pentest, without a manual pentest engagement, mapped to Annex A 8.29.
How to get a free trial Tenable One tenant from FM CyberSecurity, scan your own infrastructure, and walk away with a written readout you can act on.
A free CrowdStrike Falcon Identity Protection trial that shows your exposed, stale, and over-privileged accounts before you commit to anything.
When you buy privileged access management, you should talk to the practitioner who has run CyberArk at the largest scale, not a reseller.
A two-week, day-by-day walkthrough of the first vulnerability assessment FM CyberSecurity runs on Tenable One for a new Norwegian SMB customer.
The weekly, monthly, and quarterly cadence FM CyberSecurity runs on Tenable One for Norwegian SMB customers, with the people, the meetings, and the evidence trail.
Vulnerability management tells you what is broken. Exposure management tells you what can hurt the contract you just signed.
Four of us on the floor at Arrow ECS Norway's Summer Cloud Festival in Oslo. A big thanks to the Arrow crew for a great event.
A plain-English decision guide for Norwegian SMBs choosing between Nessus, Tenable Vulnerability Management, and Tenable One.
Tenable came by our Oslo office this week. Guy March took the sim for a lap on Silverstone and clocked 1:36.052.
A plain-English guide to Nessus, the Tenable scanner, including the current SKUs and how it relates to Tenable Vulnerability Management and Tenable One.
Digi.no published a Fredrik Standahl op-ed on treating AI as critical infrastructure and the Lovable breach as a warning sign.
E24 published a Fredrik Standahl op-ed on shadow AI in Norwegian workplaces and the data exposure pattern behind it.
A six-step FM CyberSecurity engagement that takes a Norwegian SMB from no Shadow AI visibility to a written policy and Falcon AIDR detection rules in one quarter.
Shadow AI is unsanctioned AI use on company data. Norwegian SMBs miss it because policy without detection is faith, and usage moves to personal devices.
A plain-English guide to what a Security Operations Centre really does, what one costs to run, and why most Norwegian SMBs should rent rather than build.
Most Norwegian SMBs do not need a standalone SIEM. Here is when you do, when your EDR already covers it, and what to do next.
Yes, you need EDR even with antivirus running. Antivirus blocks known bad files, EDR records what the attacker does next.
FM CyberSecurity publishes through a Cloudflare Workers MCP server, gated by Microsoft Entra. No admin login, no user table, no CMS, no /forgot-password page.
CrowdStrike Falcon is one lightweight agent and a cloud console that together replace a rack of separate endpoint security tools.
How leadership teams move from compliance uncertainty to documented control, evidence that holds up under investor, customer, or regulatory due diligence.
SOC 2 can win you a US deal or burn six figures you did not need. Here is how to tell which, and how it fits ISO 27001.
A US prospect asks for your SOC 2 Type 2 report, you do not have one, and the deal stalls. Here is what it is and the decision it forces.
If Norway counts your firm as critical, you have had legal digital-security duties since October 2025, and most boards have not noticed.
Buyers increasingly require ISO 27001 certification to even let you bid, so missing it quietly drops you from shortlists you would have won.
A practical ISO 27001 checklist that takes a Norwegian small or mid-size business from "we should get certified" to a Stage 2 audit.
A ten-step DORA checklist for Norwegian banks, insurers, payment firms and asset managers, with Finanstilsynet deadlines and what to do this quarter.
A leader-facing NIS2 checklist for Norwegian SMBs, the scope self-test, who owns what, the reporting clock, what to budget, and the board questions to ask.
NIS2 obligations flow down through contracts, so you can be asked to prove security maturity even before the rule reaches Norwegian law.
We deliver every pentest through Aikido AI Pentest because the annual manual report lands in a drawer and the application ships again the next week.
We standardised on Tenable because boards buy one map of business risk, not a longer list of CVEs no one has time to read.
We run client MDR on CrowdStrike Falcon because the platform does the detection and response work a small security team cannot cover alone.
Practical compliance steps for the new EU directive, what to do this quarter, and what can wait.
A look at how CrowdStrike's agentic SOC changes the economics of 24/7 monitoring for SMBs.
Shifter published a Fredrik Standahl commentary on the security failures common in AI-driven startup development.
VG Dine Penger interviewed Fredrik Standahl on starting a cybersecurity firm in Norway and the niche's hiring boom.
Norwegian Cybersecurity Cluster profiled FM CyberSecurity's founders and our first months building the firm in Oslo.