Skip to main content
AI is a tool meant to augment its user

AI is a Power Tool, Not a Pink Slip 

Progress tends to make people uneasy and is often met with resistance. Even something as seemingly innocuous as the introduction of writing more than 5,000 years ago drew criticism that it would diminish memory and other cognitive abilities. At the time, Socrates argued that writing was a tool that created the illusion of understanding without true knowledge.

Today, similar skepticism surrounds artificial intelligence, intensified by anxiety over widespread job loss. But the purpose of AI is not to make humans obsolete. Like writing, which documented knowledge and boosted our capacity to learn, create, and solve problems, AI is also meant to amplify human productivity and potential.

Continue reading

MITRE ATT&CK logo on a blue abstract background

The MITRE ATT&CK® Framework: It’s More Than TTPs

When most cybersecurity professionals think of the MITRE ATT&CK® framework, they think of TTPs—tactics, techniques, and procedures. These terms have become shorthand for how attackers operate and are often used to guide detection and response strategies. But ATT&CK is more than just a static list of hacker moves. The framework is structured around interconnected building blocks known as objects that describe adversary behaviors, tools, mitigations, and other elements. More importantly, these objects have meaningful relationships between them, which turns ATT&CK into a dynamic, contextual map of the threat landscape.

Continue reading

Different network traffic represented by computer, server and file icons all connected by network lines

Understanding North-South vs East-West Network Traffic

Why It Matters in Securing Your Network 

Not all network traffic is the same. Depending on where it’s headed and where it came from, network traffic can behave differently and pose different security challenges. Some threats come from the outside or involve sensitive data being exfiltrated out of the network, which is north-south traffic. Other threats move quietly within the network itself, spreading laterally through east-west traffic. 

Continue reading

Computer showing predictive analytics at the user's fingertips

The Power of Predictive Analytics in Cybersecurity

In cybersecurity, reacting quickly is good, but anticipating what’s coming next is even better.  

What are Predictive Analytics? 

Predictive analytics combine network data and threat intelligence with machine learning techniques and natural language processing to anticipate an attacker’s next moves.

How does it work? Algorithms analyze mountains of data—network traffic, login patterns, file sizes, IP addresses, and more. If something unusual occurs, predictive models flag the activity as suspicious.

But these models don’t just tell you what’s happening now, they tell you what will likely happen next. Attackers don’t break into a network and immediately begin stealing data. Instead, they typically follow a recognizable sequence of behaviors before reaching their final objective.

For example, if a user who never runs PowerShell starts executing a script, gathers login credentials, and accesses machines they don’t typically use, predictive analytics can link these behaviors and recognize them as the early stages of a potential data exfiltration attack. Next steps will likely involve data collection, connecting to an external system, and stealing data.

Continue reading

A shield representing network security

The Case for Network Detection and Response in Cybersecurity

Why Traditional Security Tools Aren’t Enough

Network Visibility:  

Cyberattacks are evolving, as attackers get smarter at slipping past traditional security tools like firewalls and antivirus software. Blocking threats at the perimeter or relying solely on endpoint security is no longer sufficient. Every device connected to your network and every user interaction creates an opportunity for an attack. Yet, conventional security solutions are often blind to what’s happening within the network itself. 

Companies need a way to detect and respond to attackers who have already slipped through the cracks. Whether they are using modified malware to bypass signature-based detection or exploiting vulnerabilities that haven’t been patched, today’s threats need a smarter approach. 

The Future of Cybersecurity is in the Network 

Lack of network visibility is one of the biggest cybersecurity challenges that businesses face. If you can’t see what’s happening on your network, you can’t protect it effectively. Attackers will always find ways around firewalls and endpoint security, but they can’t hide their activities on the network. That’s why network detection and response (NDR) is becoming the last line of defense

NDR solutions provide real-time, network-wide visibility, allowing security teams to pinpoint threats that bypass perimeter and endpoint defenses. By continuously monitoring network traffic, NDR can detect malicious activity before a breach turns into a full-scale incident. 

Every Action Leaves a Trail—If You Know Where to Look 

Every action on a network—whether legitimate or malicious—leaves behind evidence. Hackers create a digital footprint through lateral movement, data exfiltration, and suspicious access patterns. The challenge is knowing where to look and how to interpret this activity. 

NDR leverages artificial intelligence, machine learning, and behavioral analytics to distinguish between normal and suspicious network behavior. It continuously adapts to what’s normal for your network and flags deviations, enabling security teams to act before damage is done. 

IoT and OT Security: A Growing Visibility Challenge 

Endpoint security tools monitor individual devices by installing software agents on each one, but this approach falls short when it comes to Internet of Things (IoT) devices and operational technology (OT) systems. Many IoT devices—such as security cameras and printers—lack the processing power and operating systems needed to run endpoint security software. 

Similarly, OT systems, which include a wide range of devices with proprietary operating systems, are often incompatible with traditional security tools.  

This means that most security solutions can’t see the activity on these IoT and OT networks, but NDR solutions can if the devices operate over standard IP protocols. Since NDR analyzes all network traffic without requiring agents, it can detect anomalies in IoT and OT environments, such as unexpected data transmissions or unauthorized device communications. 

Why CYBERSPAN is a Smart NDR Solution for SMBs 

Small and medium-sized businesses (SMBs) are prime targets for cyberattacks but often lack dedicated security teams. By focusing on network activity—where threats inevitably leave traces—CYBERSPAN ensures that SMBs can detect, investigate, and respond to cyber threats before they become full-blown incidents.  

CYBERSPAN offers an intelligent, easy-to-use NDR solution that provides enterprise-grade protection without requiring a large security budget or staff. Here’s why CYBERSPAN stands out: 

  • Agentless Deployment – No need to install software on every device; CYBERSPAN passively monitors network traffic. 
  • AI-Powered Detection – Uses advanced machine learning models to detect anomalies, identify threats, and predict future attacks. 
  • Comprehensive Visibility – Secures IT, OT, and IoT environments, covering devices traditional endpoint solutions can’t monitor. 
  • Actionable Insights – Provides clear, easy-to-understand threat reports with recommended mitigations. 
  • Minimal Maintenance – Designed for businesses without dedicated cybersecurity teams; CYBERSPAN requires little upkeep. 

The Bottom Line 

Traditional security tools alone cannot keep up with modern cyber threats. NDR solutions like CYBERSPAN provide the real-time visibility, as well as advanced analytics, and proactive defense needed to protect businesses from evolving threats. 

A Fun Dive into Machine Learning: Wrapping Up the 2024 NFL Season

A Look Back at the Performance of My NFL Game Prediction Machine Learning Model

The Background

A few years ago, I started an internship project at IG Labs combining my love of football with data science, and it soon became a real challenge—could my machine learning model stand up to public scrutiny for the 2024 NFL season?

I designed the model to predict NFL game winners using open-source data on team statistics and betting odds from several gambling services. Over the years, I’ve maintained and tweaked the model, which delivered a 65% accuracy rate going into the 2024 season. The details on my model can be found here.

As a fun experiment, IG Labs published my model’s weekly predictions on our social media. Now, with the season wrapped up, it’s time to review the model’s performance, highlight some interesting takeaways, and evaluate some changes to the model for next season.

The Results

While some weeks were rough—Week 3’s dreadful prediction accuracy of 37.5% comes immediately to mind—my model’s overall performance for this season was significantly better than years past.

Painful memories…but my model redeemed itself!

Overall, the model’s record for the 2024 season was 205-82 on predictions—an accuracy rate of 71.4% (72.3% including the Super Bowl)!

The Highlights

Team Accuracy

One of the standout achievements of the model was to perfectly predict the Kansas City Chiefs’ season—including their Super Bowl defeat. Its performance for the Denver Broncos was similarly strong at 88.2%, only missing two of the teams ten wins, while correctly forecasting all seven of their losses.

The model also correctly predicted all of the wins for the Los Angeles Chargers, Cincinatti Bengals, Baltimore Ravens, and San Francisco 49ers, as well as all of the Denver Broncos’ losses.

Conversely, the model struggled with the Pittsburgh Steelers, with a 55.6% accuracy rate in predicting the team’s wins and losses—only picking four of the team’s ten wins. Its performance with the New York Jets and Dallas Cowboys wasn’t much better: 58.8%.

It also failed to pick any of the wins—albeit few—for the New York Giants, New England Patriots, and Tennessee Titans. Likewise, it missed all of the losses for the Philadelphia Eagles and the Detroit Lions.

Note: data includes post season games and the Super Bowl

Post Season Predictions

The model also made playoff seed predictions each week. The AFC seed picks were strong, especially the Kansas City Chiefs as the #1 seed and the Houston Texans at #4. As well, the Buffalo Bills and Baltimore Ravens were almost equally represented as the #2 and #3 seeds. The NFC landscape was a bit trickier, though, with the exception of the Philadelphia Eagles, who were the #2 seed for 10 weeks.

The model also made weekly predictions for the Conference Champions and the Super Bowl winner.

The model heavily favored the Chiefs, Ravens, and Bills for the AFC Champion, picking each team seven, six, and five times respectively. For the NFC Champion, the model was more dispersed in its picks, with the Eagles being the favorite for six weeks of the season, followed by the Lions for 4 weeks

Super Bowl Predictions

The model’s Super Bowl matchups varied a lot from week to week, but its projected winners were fairly consistent. The actual winners—the Philadelphia Eagles—were picked as winners four times, while the losing Kansas City Chiefs were picked six times.

The Buffalo Bills and Baltimore Ravens were each projected to win the Super Bowl four times during the season.

Changes for Next Season

This was the first season I incorporated betting data, and it was a big success! It improved accuracy by about 6% and, even though this is an accomplishment, I think the way betting data is utilized can be better.

To start, the week’s games were predicted every Thursday (since the earliest game every week is Thursday). If the betting data were to change drastically between Thursday and Sunday, it would not be reflected in the model. Discovering a consistent time to add in all the betting data in relation to the game could improve the model’s accuracy.

A more significant change I’ll be implementing is to only apply the data to one of the models. The NFL Model is three separate models working independently, all using the same data. One model predicts total points, one model predicts a winner, and one model predicts a point differential. If the projected winning team does not align with the team that is projected to get more points, the more extreme guess is used.

As the season progressed, my model’s predictions became less distinguishable from the betting odds. That being, the team that was the betting favorite to win would be predicted to win almost every time. There are only three instances since week 10 that the model correctly predicted the outcome of a game that went against the betting odds—89% of all incorrect predictions occurred on games where the betting favorite did not win.

To fix this, next season I will only feed betting data to the model dealing with the point differential, while keeping the model that predicts a winner separate. Hopefully, this will shake things up a little bit and give my model a better chance of guessing the upsets.

Overall, this year’s models performed reasonably well—72.3% accurate—so I get to keep my job! Working with the models throughout the season also provided me with great insights into how they operate and how the input data can influence the resulting predictions. Even though the games and excitement are over for now, I’ll continue to think of other modifications during the off-season to improve next year’s performance.

command button stating "Generate" ready for prompt engineering

The Role of Prompt Engineering in LLMs

As many of us have seen in recent years, our digital landscape has changed considerably as language models have become integral to new sectors. These changes have begun to revolutionize how businesses operate and how individuals interact with technology. These new models are capable of understanding and generating human-like text, with models reaching higher accuracy every day. As their influence expands, so does the importance of prompt engineering, a new practice focused on optimizing user inputs to elicit precise and relevant outputs from language models.

Continue reading