Ken here from Cyberse. Welcome to Secure (with Context), your no-BS guide to smarter security decisions.
Twice a month, we’ll:
✅ Cut through vendor hype
✅ Help you discover creators
✅ Provide free tools to help you buy and build with confidence
...with a touch of the jaded-dark-humor that you can only get from a fellow cybersecurity practitioner.
👋 Want to share this newsletter?
🎆 A new year does not mean a quiet time for attackers.
Cyberattacks consistently spike in late December and early January when teams are out of office, routines are relaxed, and monitoring is lighter. Ransomware groups know this and often time attacks when response is slow.
The start of the year is the perfect moment to sanity check security basics before business ramps back up.
✅ Patch critical systems before full operations resume. Delaying updates over the holidays often carries risk into January.
✅ Confirm backups are current and test restores now, not after an incident.
✅ Enforce MFA across all accounts, especially admin and remote access.
✅ Review password hygiene and disable stale or unused accounts.
✅ Share a short phishing reminder with the team. Shipping notices, invoices, and gift card scams remain common in January.
Make sure there is a clear on call escalation path, even if staffing is still light. Emergency contacts and access should be verified, not assumed.
If continuous monitoring is not realistic during holiday periods, a managed provider can help cover visibility gaps.
It is also a good time to confirm that key vendors and service providers patched their systems and reviewed their own holiday coverage.
Cybersecurity at year end is not just operational hygiene. It is risk reduction with real ROI.
A strong start to the year protects revenue, customer trust, and momentum.
Start the year alert, prepared, and a step ahead of attackers.
🚀 Many teams are asking whether their cybersecurity budget is actually creating measurable value.
Our free 20 question benchmarking model can help you get clarity.
It gives you a clear view of how your program compares to similar organizations and highlights where your current investments create the strongest return.
It also provides tailored insights based on your tools and user base so you can communicate impact with more confidence.
If you want a quick way to understand whether your spend aligns with outcomes, this model is a simple place to start.
Source: Benchmark Your Cybersecurity Program Today
December was another hectic month! I attended my first ever AWS re:Invent to catch up with a few friends, partners and investors, squeezed in one last Singapore trip (5 times in 2025) to kickoff new partnerships, and wrapped up spending time with family in Cabo, Mexico… whew.
2025 really taught me how unpredictable life can be- I barely knew where I’d be in the world each month. As many of you know, my personal life has grown amazingly too and that’s brought a new sense of perspective and focus as I look ahead.
Here are my 2026 goals:
Channel more “flow”; double down on winning bets
Run more “experiments”; cut losses faster
Be a tad more unhinged 😉
Looking forward to 2026!
The more we talk with teams around the world, the clearer it gets: cybersecurity in 2026 is about focus, trust, and teamwork.
Budgets may be tighter, but collaboration has never been stronger.
Let’s keep sharing what works, learning from each other, and building security programs that really make a difference.
👋 Got thoughts? Hit reply. I read every message.
Ken Yao
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.