
.avif)
Nicholas Thomson
Blog posts by Nicholas Thomson
Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Tyro CISO Arun Singh on developer trust as a finite resource, and what happens when supply chain attacks force teams to spend it
Top Pentera alternatives for automated penetration testing
Compare the top Pentera alternatives for automated pentesting in 2026. See where Aikido Security, XBOW, Horizon3, Hadrian, RunSybil, Terra, and Astra fit best.
The practical checklist for defending against supply chain attacks
Thirty prioritized defenses against the recent wave of software supply chain attacks. Graded critical, high, or medium.
What is a dependency firewall?
A dependency firewall blocks malicious open-source packages before they install. Learn how they work and how Aikido Safe Chain stops supply chain attacks.
Top Burp Suite alternatives for web application security testing
Compare the top Burp Suite alternatives for DAST and AI pentesting, including Aikido, Caido, ZAP, and Invicti.
Top Chainguard alternatives 2026
Comparing the best Chainguard alternatives in 2026, from Aikido Security to Docker Hardened Images, Minimus, RapidFort, and Echo.
Top Koi alternatives in 2026
Looking for a Koi Security alternative after the Palo Alto acquisition? Compare competitors on device protection, platform breadth, and pricing.
Code is being written everywhere, and the device is the only constant
Developers are coding everywhere. AI agents, Slack bots, and MCP servers have made the developer device the biggest security blindspot.
Top 5 Tenable Nessus alternatives in 2026
Tenable Nessus is a powerful scanner, but powerful tools that nobody uses don't make software more secure. Compare five alternatives built for how engineering teams actually work.
What MDM can't protect on developer machines (and what to do about it)
MDM tools like Jamf and Kandji are essential but they don't see npm installs, IDE extensions, or AI coding tools. Here's what's actually unprotected on your developer machines and how to close the gap.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

