Blog

By Jason Santamaria, Posted in Security

There's a scene near the end of Indiana Jones and the Last Crusade where an ancient knight, guarding a cave full of chalices, tells Indy to pick the real Holy Grail out of dozens of convincing fakes. "Choose wisely," he warns, "for while the true Grail will bring you life, the false Grail will take it." Indy studies the room, a plain wood cup versus gilded goblets, and picks the humble one. He's right. The villain who grabs the jewel-encrusted one moments later is not, and it does not end well for him. It'... read more.

  • September 25, 2026

By Eric Corcoran, Posted in Technology Week in Review

Monday 9/21 Two zones or three? A design framework for zone-resilient Azure workloads (Microsoft) Zone resiliency is not a property you switch on for an entire workload. It’s a set of decisions you make component by component. Some components are fully protected across two zones. Some genuinely need a third. And for a growing number, Azure manages zone redundancy for you, and the best decision is to let it. This post is about how to tell the difference. https://azure.microsoft.com/en-us/blog/two-zo... read more.

  • September 25, 2026

By Steve Gold, Posted in Security

You’re running late for an appointment. No coffee, no breakfast, the outfit is not, exactly, what you were hoping for.  You need to make up time, so you start looking for it wherever you can find it. You approach an intersection with a stop sign, glance both ways, and roll right through without fully stopping. Congratulations. You are now a GRC expert. You knew the rule. You know how to be compliant. You made a calculated decision to accept the risk anyway because the odds felt good and the pay... read more.

  • September 22, 2026

By Bert Amodol, Posted in Security

There's a scene in every heist movie where the security guard stares at a bank of monitors, sipping lukewarm coffee, absolutely certain that nothing interesting is going to happen tonight. That guard is every SOC analyst I've ever met. Except now the thing sneaking past the cameras isn't a guy in a ski mask. It's a language model that can write, iterate, and adapt faster than any human red team I worked with twenty years ago. AI handed attackers a new tool and a new tempo. The real problem isn’t tha... read more.

  • September 21, 2026

By Eric Corcoran, Posted in Technology Week in Review

Tuesday 9/8 CIS Safeguard 13.6: Collect Network Traffic Flow Logs https://www.gothamtg.com/blog/cis-safeguard-136-collect-network-traffic-flow-logs Wednesday 9/9 Most staffing firms match resumes to job descriptions. We match technical talent to real technical environments. Why? Staffing at Gotham isn't standalone. It's built on the same technical foundation as our Professional Services organization. Our recruiters aren't screening in a vacuum. They're backed by a team that lives inside tech stacks and... read more.

  • September 18, 2026

By Ken Phelan, Posted in Infrastructure, Security

This post was AI-assisted — researched and drafted with Claude, which should surprise exactly no one given who I am. The arguing and editing are mine. If it's wrong, blame me, not the machine. AI is raging in your organization right now. Not piloting. Not "under evaluation by a cross-functional committee." Raging. Every employee has tried it, most of them are using it daily, and the results look like every other distribution of human performance you've ever seen. A bell curve. Let me walk you throug... read more.

  • September 16, 2026

By Steve Gold, Posted in Security

In The Bear, every station in the kitchen has a different job, a different set of skills, and a completely different set of things that can go wrong. You do not train the pastry chef the same way you train the expeditor. You do not pull the sous chef aside to explain how to plate a salad. Everyone needs to know the basics, but the role-specific skills are what keep the kitchen from catching fire. Your security training program works the same way. What Is Conduct Role-Specific Security Awareness and Skills... read more.

  • September 15, 2026

By Steve Gold, Posted in Security

In Succession, every power move and every backstab eventually came back to one question: what's on the record? When things went sideways for the Roys, the only way to reconstruct the truth was to go back to the tape. Someone, somewhere, had kept a log of what happened. CIS Safeguard 13.6 is your network's version of that tape. What Is CIS Safeguard 13.6? Network traffic flow logs are records of every connection that crosses your network. Source IP, destination IP, port, protocol, bytes transferred, timest... read more.

  • September 08, 2026

By Timothy Karl, Posted in Infrastructure

Microsoft made Azure Virtual Desktop (AVD) Hybrid generally available on September 1, 2026. It lets you run desktop hosts in your own datacenter while Microsoft manages the AVD service in Azure. That’s good news if data residency, latency, or compliance rules have kept you off cloud-hosted AVD. Key Benefits Microsoft still runs the core service. You don’t manage a connection broker or gateway. Use the hardware you already have. Works with your own hypervisor or dedicated physical servers. ... read more.

  • September 04, 2026

By Eric Corcoran, Posted in Technology Week in Review

Monday 8/31 Rethink Hybrid Identity: It Is Not the Destination (HYPR) Hybrid identity persists not because modern workforces require it, but because many organizations continue to support legacy applications, legacy infrastructure, legacy authorization models, and operational processes that predate cloud computing. The continued existence of those dependencies should not be mistaken for validation of hybrid identity as a long-term strategy. https://www.hypr.com/blog/rethink-hybrid-identity-it-is-not-the-... read more.

  • September 04, 2026