RESEARCH
Threat Thursday: June 4th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. This week's stories have a clear pattern: attackers didn't find obscure entry points or novel techniques but instead went after the things you were already using and already trusting. As always, ...
Communicating Risk
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
Value That Converts: Why Your vCSO Pitch Keeps Getting Pushed to IT

You walked out of that meeting feeling like a closer. Your credentials were on point. You covered the whole stack: EDR, SIEM, MDR, quarterly risk assessments, tabletop exercises, NIST alignment. Your vCSO offering was solid. You even had a phased ...
Dark Web Monitoring & Threat Intelligence
Part 2: Congratulations, Your Password Manager Made the News (Again)

If you caught Part 1 last week, you know the shape of what TeamPCP has been running since December 2024: one supply chain campaign, still expanding, with credentials stolen over a year ago still being spent today. Part 2 is ...
Part 1: Congratulations, Your Password Manager Made the News (Again)

You've probably seen the headlines. Bitwarden compromised. Trivy compromised. Checkmarx tools compromised. A handful of other developer tools before that. Each one got its own news cycle, its own advisory, its own "here's what to do if you're affected" post. ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Human Layer Security
The Deepfake Was Convincing. So Was My Backpack.

Why Social Engineering Still Works, Why AI is Making it Sharper, and the One Habit that Stops it In early 2024, an employee at Arup, a global engineering firm, joined a video call with several colleagues, including someone who appeared ...
The Invisible Workforce

The Shadow AI Running Inside Your Clients' Environments and How MSPs Can Get Ahead of It It's Monday morning. A client's controller is on the phone. She spent Friday afternoon cleaning up the vendor list inside their accounting platform's new ...
Your AI Agent Visits Websites on Your Behalf. Attackers Are Leaving It Notes.

The last two years of AI adoption inside businesses have followed a pretty consistent pattern. A team tries a tool, it saves them time, word gets around, and suddenly half the company is using something IT didn't approve. Now those ...
More Articles
The Portal Problem: Are You Still Driving a Horse and Buggy?
I was talking to an MSP the other day who said, “The portal’s slow. I can’t ever find what I need.” So I asked him, “When’s the last time you logged in?” His answer? A few months ago. Holy cow. ...
New California Audit Law Just Put Your MSP on the Hook. Here’s How to Turn It Into Recurring Revenue
If your clients process sensitive data, your MSP is now part of the legal conversation. On July 24, 2025, California finalized new rules that require businesses processing high-risk personal information to undergo annual, independent cybersecurity audits. This isn’t just for ...
Your Copilot Might Be Working for the Other Side
Let’s play a game. Imagine you hire a new assistant. Bright. Helpful. Always eager to please. You ask it to pull a report. It delivers. You ask it to summarize last quarter’s numbers. Done in seconds. Now imagine that same ...
The Dangerous Assumptions You’re Making
Your clients are making assumptions about you right now. They assume you’ve got their security handled. They assume you’re gathering the evidence. They assume you’ve already written their incident response plan. But here’s the problem: they’re wrong. I was on ...
The Silent Killer in Your MSP: Ambiguity
You think you’re being clear. You told the client they needed MFA. You recommended better backups. You flagged that firewall. But when things go sideways—when data’s lost, insurance denies the claim, or the lawyers come knocking—they don’t remember your recommendations. ...
The #1 Role Every MSP Must Embrace Before a Competitor Replaces You
Your Clients Don’t Need Another IT Vendor. They Need a Cybersecurity Leader. If you’re still selling managed services like it’s 2015, you’re already losing. The MSP market has shifted. The stakes are higher. Clients aren’t asking how many tickets you ...
AI Is About to Cost You More Than You Think
Here’s the thing nobody wants to say out loud: Your employees are already using AI tools—whether you’ve approved them or not. And some of those tools? They’re fantastic productivity boosters. Others are ticking legal, compliance, and PR time bombs that ...
The Policy That Could Save Your MSP from a Lawsuit and Why You're Likely Ignoring It
Most MSPs think cybersecurity starts with tools—firewalls, MDR, backups. But there’s a silent killer in your stack: the lack of an Acceptable Use Policy (AUP). You probably have one. Maybe it’s buried in your documentation platform. Maybe your client signed ...
Why You Might Want to Reconsider Your WISP for Every Single Client
Why This Isn’t Just About Checking a Compliance Box If you’re running an MSP, you’ve probably heard about Written Information Security Plans (WISPs). Maybe you’ve even created one—for certain clients, in certain industries, under certain regulations. But here’s the question: ...
AI Acceptable Use Policy: The Shield Every MSP Must Build Before AI Builds a Case Against You
Artificial intelligence is no longer a distant experiment reserved for Silicon Valley. It’s here, woven into the daily workflows of businesses large and small. AI helps teams write reports, analyze data, answer questions, generate code, and even draft marketing campaigns. ...
Lawsuits, Loopholes, and Liability: The Cyber Insurance Disaster Waiting to Bankrupt Your Business
Why Didn’t the Chicken Cross the Road? Because it was stuck litigating whether the crosswalk was closed on January 1. The punchline’s cute, but the lawsuit is real—and the stakes are no joke. In December 2024, Harrison Poultry Inc. suffered ...
You’re Not Selling Security. You’re Selling a Defense Strategy.
Let’s have a come-to-Jesus moment. Your clients think they’re secure because they’ve got antivirus, backups, and a firewall that hasn’t been patched since the Obama administration. You know they’re not. But they don’t. And that’s your biggest opportunity. Enter Cyber ...


