<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>ThinSky Blog</title>
    <link>https://thinsky.com/blog/</link>
    <description>Senior-engineer perspective on open-source security operations, managed SOC, vCISO, and DevSecOps.</description>
    <language>en-ca</language>
    <item>
      <title>Who Shared What With Which AI? Most Organisations Can&apos;t Answer</title>
      <link>https://thinsky.com/blog/ai-gateway-data-residency-auditable-controls/</link>
      <guid>https://thinsky.com/blog/ai-gateway-data-residency-auditable-controls/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Shadow AI is already in your organisation. Why AI use needs data residency, privacy, and an audit trail — and how a supervised AI gateway delivers them.</description>
    </item>
    <item>
      <title>Your SMB Cyber Quote Is Probably 3× Too Big</title>
      <link>https://thinsky.com/blog/your-smb-cyber-quote-is-probably-3x-too-big/</link>
      <guid>https://thinsky.com/blog/your-smb-cyber-quote-is-probably-3x-too-big/</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>Most SMB cybersecurity proposals recommend eight or nine products. A right-sized open-source stack needs four — sometimes three. Here is which ones, and why.</description>
    </item>
    <item>
      <title>CAIQ vs SIG: Which Questionnaire Should You Maintain?</title>
      <link>https://thinsky.com/blog/caiq-vs-sig-questionnaire/</link>
      <guid>https://thinsky.com/blog/caiq-vs-sig-questionnaire/</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <description>What the CAIQ is, how it overlaps with the SIG and SIG Lite, when buyers send each one, and whether you need to maintain both.</description>
    </item>
    <item>
      <title>SIG Lite vs SIG Core: Which One Did the Buyer Actually Send?</title>
      <link>https://thinsky.com/blog/sig-lite-vs-sig-core/</link>
      <guid>https://thinsky.com/blog/sig-lite-vs-sig-core/</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <description>What&apos;s different between SIG Lite and SIG Core, how to tell which one you&apos;ve received, and how long each takes to answer honestly.</description>
    </item>
    <item>
      <title>What Is a SIG Questionnaire? A Plain-English Guide for Vendors</title>
      <link>https://thinsky.com/blog/what-is-a-sig-questionnaire/</link>
      <guid>https://thinsky.com/blog/what-is-a-sig-questionnaire/</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <description>What the SIG questionnaire actually is, who publishes it, what&apos;s inside it, and the realistic options when a buyer sends you one before they&apos;ll sign.</description>
    </item>
    <item>
      <title>Security Questionnaires Are a Sales Problem, Not Compliance</title>
      <link>https://thinsky.com/blog/security-questionnaires-without-the-panic/</link>
      <guid>https://thinsky.com/blog/security-questionnaires-without-the-panic/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>Why vendor security questionnaires stall deals, why aspirational answers backfire at audit time, and how an answer library turns panic into routine.</description>
    </item>
    <item>
      <title>Okta Pricing in 2026: Real Costs and a Flat-Rate Way Out</title>
      <link>https://thinsky.com/blog/sso-freedom-from-okta-pricing/</link>
      <guid>https://thinsky.com/blog/sso-freedom-from-okta-pricing/</guid>
      <pubDate>Wed, 03 Dec 2025 00:00:00 GMT</pubDate>
      <description>Okta&apos;s per-user pricing climbs past $100K/yr at 500 users. How managed Keycloak gives you SSO, MFA, and lifecycle at a flat rate. 2026 cost comparison.</description>
    </item>
    <item>
      <title>Keycloak vs Okta: Identity Management Without Per-User Fees</title>
      <link>https://thinsky.com/blog/identity-management-without-nightmares/</link>
      <guid>https://thinsky.com/blog/identity-management-without-nightmares/</guid>
      <pubDate>Mon, 01 Dec 2025 00:00:00 GMT</pubDate>
      <description>Keycloak vs Okta: how open-source IAM ends per-user pricing. Honest feature comparison, cost math, and what a managed Keycloak migration involves.</description>
    </item>
    <item>
      <title>OpenVAS vs Qualys: What Vulnerability Scanning Should Cost</title>
      <link>https://thinsky.com/blog/vulnerability-scanning-wont-break-bank/</link>
      <guid>https://thinsky.com/blog/vulnerability-scanning-wont-break-bank/</guid>
      <pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate>
      <description>An honest cost comparison of OpenVAS, Qualys and Tenable for small Canadian businesses — what managed OpenVAS covers, what it costs, and where it doesn&apos;t fit.</description>
    </item>
    <item>
      <title>Velociraptor vs CrowdStrike Falcon: Incident Response Cost</title>
      <link>https://thinsky.com/blog/incident-response-without-crowdstrike-bill/</link>
      <guid>https://thinsky.com/blog/incident-response-without-crowdstrike-bill/</guid>
      <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
      <description>Velociraptor vs CrowdStrike Falcon: an honest feature and cost comparison, plus when managed Velociraptor handles incident response for less.</description>
    </item>
    <item>
      <title>2024 Cybersecurity Budget: Where SMB Money Goes</title>
      <link>https://thinsky.com/blog/2024-cybersecurity-budget-reality-check/</link>
      <guid>https://thinsky.com/blog/2024-cybersecurity-budget-reality-check/</guid>
      <pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate>
      <description>Where does your 2024 cybersecurity budget actually go? See the leaks — shelfware, overlap, vendor-driven buys — and how SMBs cover a full stack for less.</description>
    </item>
    <item>
      <title>Velociraptor Digital Forensics: DFIR for Small Business</title>
      <link>https://thinsky.com/blog/digital-forensics-for-rest-of-us/</link>
      <guid>https://thinsky.com/blog/digital-forensics-for-rest-of-us/</guid>
      <pubDate>Sat, 25 Oct 2025 00:00:00 GMT</pubDate>
      <description>What DFIR actually is, how the open-source Velociraptor platform works, and what a managed deployment looks like for a Canadian small business.</description>
    </item>
    <item>
      <title>The Canadian Cybersecurity Advantage</title>
      <link>https://thinsky.com/blog/canadian-cybersecurity-advantage/</link>
      <guid>https://thinsky.com/blog/canadian-cybersecurity-advantage/</guid>
      <pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate>
      <description>Why working with a Canadian security provider matters: PIPEDA, Quebec Law 25, the US CLOUD Act, and what data sovereignty means for your security stack.</description>
    </item>
    <item>
      <title>Teleport vs CyberArk (2026): An Honest Comparison</title>
      <link>https://thinsky.com/blog/cyberark-users-quietly-switching/</link>
      <guid>https://thinsky.com/blog/cyberark-users-quietly-switching/</guid>
      <pubDate>Wed, 08 Oct 2025 00:00:00 GMT</pubDate>
      <description>Teleport vs CyberArk in 2026 — where each wins, renewal-cost framing and a 60-day CyberArk migration roadmap. Honest comparison from ThinSky.</description>
    </item>
    <item>
      <title>Zero Trust vs VPN: What Zero Trust Actually Requires</title>
      <link>https://thinsky.com/blog/zero-trust-not-just-buzzword/</link>
      <guid>https://thinsky.com/blog/zero-trust-not-just-buzzword/</guid>
      <pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate>
      <description>What zero trust architecture actually means, why VPN-based castle-and-moat security fails, and how Teleport implements real zero trust access.</description>
    </item>
    <item>
      <title>Open Source Security for Enterprises: Costs &amp; Stack</title>
      <link>https://thinsky.com/blog/open-source-eating-enterprise-security/</link>
      <guid>https://thinsky.com/blog/open-source-eating-enterprise-security/</guid>
      <pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate>
      <description>Open source security for enterprises in 2026: tool-by-tool stack (Wazuh, Keycloak, OpenVAS), honest cost ranges vs commercial SIEM/EDR/IAM, and how to migrate.</description>
    </item>
    <item>
      <title>SonarQube vs Veracode: DevSecOps at a Fraction of the Cost</title>
      <link>https://thinsky.com/blog/devsecops-without-enterprise-price/</link>
      <guid>https://thinsky.com/blog/devsecops-without-enterprise-price/</guid>
      <pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate>
      <description>Veracode&apos;s true multi-year cost vs managed SonarQube. What SonarQube covers (SAST), what it doesn&apos;t (DAST/SCA), and when the savings make sense.</description>
    </item>
    <item>
      <title>Automated Penetration Testing: The Smart Way to Test</title>
      <link>https://thinsky.com/blog/automated-pentesting-smart-way/</link>
      <guid>https://thinsky.com/blog/automated-pentesting-smart-way/</guid>
      <pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate>
      <description>How automated penetration testing works, what it costs, how it complements an annual manual pentest, and how authorised testing stays safe and legal.</description>
    </item>
    <item>
      <title>Hardcoded Secrets in Code: How to Find Them First</title>
      <link>https://thinsky.com/blog/your-code-has-secrets/</link>
      <guid>https://thinsky.com/blog/your-code-has-secrets/</guid>
      <pubDate>Mon, 18 Aug 2025 00:00:00 GMT</pubDate>
      <description>How API keys and credentials end up in git repositories, the real public incidents they caused, and how automated secrets scanning catches them pre-commit.</description>
    </item>
    <item>
      <title>Paying 5x Too Much for SIEM? Cut the Bill</title>
      <link>https://thinsky.com/blog/paying-5x-too-much-siem/</link>
      <guid>https://thinsky.com/blog/paying-5x-too-much-siem/</guid>
      <pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate>
      <description>Paying 5x too much for SIEM? See why Splunk runs six figures while managed Wazuh delivers core SIEM for a fraction — and how to switch. Get the breakdown.</description>
    </item>
    <item>
      <title>Phishing Training for Employees: Cost, ROI, What Works</title>
      <link>https://thinsky.com/blog/employees-biggest-security-risk/</link>
      <guid>https://thinsky.com/blog/employees-biggest-security-risk/</guid>
      <pubDate>Thu, 12 Jun 2025 00:00:00 GMT</pubDate>
      <description>Why annual security-awareness slideshows fail, how phishing simulations change behaviour, and what per-user training really buys. No hype.</description>
    </item>
  </channel>
</rss>
