top of page

The York Blog
Search


Securing AI Agents: Is Your Enterprise Security Architecture Ready for the Digital Workforce?
By Mahfuzur Rahman | SecYork Technology Artificial intelligence is moving beyond answering questions, summarizing documents, and generating content. AI agents can increasingly search corporate information, read email, interact with business applications, call application programming interfaces, update records, trigger workflows, and execute actions on behalf of employees and business processes. That changes the cybersecurity problem. Traditional enterprise security architectu
Aug 199 min read


M&A Cybersecurity Due Diligence: What Buyers Need to Know Before the Deal Closes
By Mahfuzur Rahman | SecYork Technology Mergers and acquisitions are usually evaluated through financial performance, market opportunity, operational fit, and expected synergies. Cybersecurity can influence every one of those assumptions. A target company may bring valuable customers, technology, intellectual property, and talent. It may also bring unresolved incidents, unsupported systems, excessive privileged access, fragile infrastructure, regulatory exposure, and remediat
Aug 108 min read


7 Vendor Management Mistakes That Create Cybersecurity Risk in 2026
By Mahfuzur Rahman | SecYork Technology Organizations rarely operate alone. Cloud providers, SaaS platforms, managed service providers, consultants, software suppliers, payment processors, and business partners may all connect to company systems or handle sensitive data. That connectivity creates efficiency—but it also extends the attack surface beyond the organization’s direct control. A vendor does not need unrestricted network access to create serious risk. A compromised s
Jul 286 min read


Top 5 Cloud Security Misconfigurations in 2025
By Mahfuzur Rahman | SecYork Technology Cloud computing has become the backbone of digital transformation — yet in 2025, security misconfigurations remain the silent driver of major breaches. Despite mature DevSecOps pipelines and improved posture-management tools, misconfigurations still account for over 70% of cloud data exposures worldwide. At SecYork , we assess multi-cloud ecosystems across AWS, Azure, and Google Cloud. Over and over, we find that incidents rarely start
Oct 28, 20253 min read


SBOM: The Blueprint of Software Security – What It Is, Why It Matters, and How It Strengthens Vendor Risk Management
By Mahfuzur Rahman | SecYork Technology Introduction In today’s software-driven world, security risks don’t just come from hackers — they often lurk deep inside the software we use every day. From open-source libraries to third-party components, modern applications are built like layered puzzles, and even one insecure piece can expose the whole system. This is where SBOM — Software Bill of Materials — becomes a critical part of cybersecurity and vendor governance. Think of a
Oct 21, 20253 min read


TPM in the Modern Cloud Era: Building Trust from Chip to Cloud”
By Mahfuzur Rahman | SecYork Technology Introduction In today’s threat landscape, where identity, integrity, and encryption define the backbone of enterprise security, the Trusted Platform Module (TPM) plays a crucial role in anchoring hardware trust. Originally designed as a physical chip embedded in computing devices, TPM has now evolved into virtual and cloud-native forms — ensuring that trust begins before the operating system even starts . At SecYork , we believe that e
Oct 5, 20253 min read
bottom of page