<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Heimdal Security Blog</title>
	<atom:link href="https://heimdalsecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>A blog about all things internet security</description>
	<lastBuildDate>Tue, 22 Sep 2026 07:58:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>
	<item>
		<title>Slow is a design principle, not a delay</title>
		<link>https://heimdalsecurity.com/blog/ai-pacing-cybersecurity-defense/</link>
		
		<dc:creator><![CDATA[Jesper Frederiksen]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 05:22:58 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Data security]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88621</guid>

					<description><![CDATA[<p>Two things happened last week, one day apart, and almost nobody connected them.  On 11 September, the EU Cyber Resilience Act&#8217;s vulnerability reporting obligations came into force. Companies covered by the regulation now have to report actively exploited vulnerabilities within 24 hours and provide a fuller notification within 72.   On 12 September, Anthropic CEO Dario [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/ai-pacing-cybersecurity-defense/">Slow is a design principle, not a delay</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/ai-pacing-cybersecurity-defense/slow-is-a-design-principle-not-a-delay/</image><subtitle></subtitle>	</item>
		<item>
		<title>AI adoption that pays off is built around keeping humans in the driver&#8217;s seat</title>
		<link>https://heimdalsecurity.com/blog/ai-adoption-that-pays-off/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 09:51:39 +0000</pubDate>
				<category><![CDATA[AI Control]]></category>
		<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88570</guid>

					<description><![CDATA[<p>I&#8217;ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, &#8220;we&#8217;ve got Copilot, and it&#8217;s not great.&#8221; That gap between the hype and the reality is exactly where Samantha North operates. Sam runs an AI transformation agency, helping [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/ai-adoption-that-pays-off/">AI adoption that pays off is built around keeping humans in the driver&#8217;s seat</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/ai-adoption-that-pays-off/copy-of-new-blog-cover/</image><subtitle></subtitle>	</item>
		<item>
		<title>Phishing in 2026. Latest statistics and analysis</title>
		<link>https://heimdalsecurity.com/blog/phishing-statistics-analysis/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:30:18 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88375</guid>

					<description><![CDATA[<p>“You’ve been gifted a voucher!”. “Your account will be closed unless you act now”. “Late payment demand. Invoice # 207”. Phishing scams come in many shapes and sizes. And, in 2026, they remain, by far, the most common attack vector targeting both individuals and organizations. To help you understand the scale of the threat, I’ve [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/phishing-statistics-analysis/">Phishing in 2026. Latest statistics and analysis</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/phishing-statistics-analysis/phishing-statistics-analysis-2/</image><subtitle></subtitle>	</item>
		<item>
		<title>Shift Browser is signed adware that fingerprints your endpoint before it drops payload</title>
		<link>https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/</link>
		
		<dc:creator><![CDATA[Alexandru Gurgu]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 12:25:11 +0000</pubDate>
				<category><![CDATA[Advanced malware researches]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Forensics and threat hunting]]></category>
		<category><![CDATA[Threat center]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88334</guid>

					<description><![CDATA[<p>Heimdal&#8217;s MXDR team flagged a surge in detections tied to a program called Shift Browser on 2 September 2026. Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure. Shift Browser also runs a documented paid creator and affiliate marketing operation, though [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/">Shift Browser is signed adware that fingerprints your endpoint before it drops payload</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/shift-browser-signed-adware-fingerprints-endpoint-before-payload/adobe-express-file/</image><subtitle></subtitle>	</item>
		<item>
		<title>6 ThreatLocker alternatives that should make your shortlist</title>
		<link>https://heimdalsecurity.com/blog/threatlocker-alternatives/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 12:56:02 +0000</pubDate>
				<category><![CDATA[Comparisons]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88315</guid>

					<description><![CDATA[<p>There are a few reasons that MSPs start looking for ThreatLocker alternatives. You might have had enough of the friction with end users. The high levels of admin required to set policies for your different customers. Or that, while powerful, it can only handle certain kinds of security risks.  If so, we wrote this guide [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/threatlocker-alternatives/">6 ThreatLocker alternatives that should make your shortlist</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/threatlocker-alternatives/threatlocker-alternatives/</image><subtitle></subtitle>	</item>
		<item>
		<title>50+ insider threat statistics for 2026</title>
		<link>https://heimdalsecurity.com/blog/insider-threat-statistics/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 15:00:30 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88301</guid>

					<description><![CDATA[<p>In 2026, insider threats are probably a bigger risk than you think. In fact, they could cost your organization $19.5 million a year. But it’s not really a problem with hackers, spies, or malicious employees. Instead, it’s about negligence, training, and IT privileges. Often, the most expensive mistake is a stolen credential doing exactly what [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/insider-threat-statistics/">50+ insider threat statistics for 2026</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/insider-threat-statistics/insider-threats-statistics-2/</image><subtitle>Negligence, AI blind spots, and containment measures against insider threats</subtitle>	</item>
		<item>
		<title>The Planting Seeds philosophy. Selling into schools takes years, not quarters</title>
		<link>https://heimdalsecurity.com/blog/msp-school-sales/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 06:44:59 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88292</guid>

					<description><![CDATA[<p>It&#8217;s tempting for MSPs to write off event sponsorship in education as a waste of money. You sponsor an event, hand out flyers, follow up with an email, and hear nothing back. Rick Cowell says you&#8217;re judging it on the wrong timescale. Rick spent 20 years as a school network manager, and he founded the [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/msp-school-sales/">The Planting Seeds philosophy. Selling into schools takes years, not quarters</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/msp-school-sales/msps-schools/</image><subtitle></subtitle>	</item>
		<item>
		<title>What the DfE&#8217;s cyber security update means for multi-academy trusts</title>
		<link>https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 17:13:59 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88275</guid>

					<description><![CDATA[<p>Before dawn on 10 July 2024, one ransomware attack took down ten schools inside the same multi-academy trust at once. Every control that eventually stopped it was something the Department for Education&#8217;s own cyber security standard already asked for, well before the attack. That&#8217;s a case DfE has published on its own Cyber Security Hub, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/">What the DfE&#8217;s cyber security update means for multi-academy trusts</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/dfe-mat-featured-image-2c/</image><subtitle>MFA and patching just became all or nothing for every trust</subtitle>	</item>
		<item>
		<title>9 Proofpoint alternatives. Pros &#038; cons of the leading options</title>
		<link>https://heimdalsecurity.com/blog/proofpoint-alternatives/</link>
		
		<dc:creator><![CDATA[Livia Gyongyoși]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 09:27:17 +0000</pubDate>
				<category><![CDATA[Comparisons]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88261</guid>

					<description><![CDATA[<p>Proofpoint catches malicious traffic and blocks data exfiltration well, with solid coverage for business email compromise, phishing, and malware. But it&#8217;s built for the enterprise, and it shows. G2 reviewers flagged a steep learning curve and steep pricing, and suggested Proofpoint’s support would need improving. The platform&#8217;s also in flux. Proofpoint closed a $1.8 billion [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/proofpoint-alternatives/">9 Proofpoint alternatives. Pros &#038; cons of the leading options</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/proofpoint-alternatives/proofpoint-alternatives/</image><subtitle></subtitle>	</item>
		<item>
		<title>The risk awareness radar. A superpower every MSP needs to train</title>
		<link>https://heimdalsecurity.com/blog/build-risk-awareness-radar/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Thu, 06 Aug 2026 15:28:45 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=88015</guid>

					<description><![CDATA[<p>Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make people hand over exactly what the attacker needs. Last week I talked [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/build-risk-awareness-radar/">The risk awareness radar. A superpower every MSP needs to train</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/build-risk-awareness-radar/risk-awareness/</image><subtitle></subtitle>	</item>
		<item>
		<title>How Heimdal grew from a bold idea into a global cybersecurity platform</title>
		<link>https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/</link>
		
		<dc:creator><![CDATA[Morten Kjaersgaard]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:32:57 +0000</pubDate>
				<category><![CDATA[All things Heimdal]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87972</guid>

					<description><![CDATA[<p>Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept malicious activity and help protect machines before threats could take hold? That technology went on to compete at the Defcon CTF world [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/">How Heimdal grew from a bold idea into a global cybersecurity platform</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/how-heimdal-grew-global-cybersecurity-platform/heimdal-and-brigantia-ten-year-partnership-2/</image><subtitle></subtitle>	</item>
		<item>
		<title>MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</title>
		<link>https://heimdalsecurity.com/blog/media-arena-malvertising-report/</link>
		
		<dc:creator><![CDATA[Alexandru Gurgu]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:21:38 +0000</pubDate>
				<category><![CDATA[Threat center]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87918</guid>

					<description><![CDATA[<p>If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn&#8217;t complete until 29 seconds. By the time the alert fired, [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/media-arena-malvertising-report/">MediaArena malvertising: why a quarantine isn&#8217;t the end of the incident</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/media-arena-malvertising-report/mediaarena-blog-cover/</image><subtitle>By Alexandru Gurgu, Threat Intelligence Security Analyst, Heimdal</subtitle>	</item>
		<item>
		<title>Tools Change. Teach People How to Keep Up</title>
		<link>https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/</link>
		
		<dc:creator><![CDATA[Adam Pilton]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:51:27 +0000</pubDate>
				<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[MSP Security Playbook]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87960</guid>

					<description><![CDATA[<p>&#8220;Make everyone one percent better and it compounds across the team.&#8221; That&#8217;s the line Joe Head wrote about his own job and when I read it back to him, he didn&#8217;t hesitate. &#8220;That is 100% the objective,&#8221; he said. Joe runs AI adoption for an 80-person team as the only AI automation specialist in the [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/">Tools Change. Teach People How to Keep Up</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/ai-strategy-insights-joe-head/ai-strategy-insights/</image><subtitle>Why MSP Leaders Should Refuse to Build Their AI Strategy Around Any Single Tool</subtitle>	</item>
		<item>
		<title>4 Best Managed EDR Solutions &#038; Service Suppliers (and how to choose)</title>
		<link>https://heimdalsecurity.com/blog/best-managed-edr-services/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 10:25:54 +0000</pubDate>
				<category><![CDATA[EDR]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87948</guid>

					<description><![CDATA[<p>There are several cybersecurity companies that offer managed EDR services in 2026. Here&#8217;s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the past 15 years, endpoint detection and response (EDR) has gone from niche to a mainstream security solution. [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/best-managed-edr-services/">4 Best Managed EDR Solutions &#038; Service Suppliers (and how to choose)</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/best-managed-edr-services/edr-featured-image-selection/</image><subtitle></subtitle>	</item>
		<item>
		<title>Top 4 Best SOC Platforms 2026 &#8211; Provider Comparison</title>
		<link>https://heimdalsecurity.com/blog/best-soc-platforms/</link>
		
		<dc:creator><![CDATA[Danny Mitchell]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 15:52:54 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://heimdalsecurity.com/blog/?p=87941</guid>

					<description><![CDATA[<p>Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. There are many cybersecurity tools that an SOC can use, and there are many vendors selling comparable products. The [&#8230;]</p>
<p>The post <a href="https://heimdalsecurity.com/blog/best-soc-platforms/">Top 4 Best SOC Platforms 2026 &#8211; Provider Comparison</a> appeared first on <a href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>
]]></description>
		
		
		
		<image>https://heimdalsecurity.com/blog/best-soc-platforms/soc-featured-image-selection/</image><subtitle></subtitle>	</item>
	</channel>
</rss>
