SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started

Blog

Practical guides on vulnerability management, compliance, and cybersecurity for European organizations.

Your AI coding agent ships an actively exploited vulnerability. Your scanner says it's clean Vulnerability management ★ Latest

Your AI coding agent ships an actively exploited vulnerability. Your scanner says it's clean

I aimed our scanner at something almost nobody checks: the container images AI coding agents run inside. The current latest images ship a git flaw CISA lists as actively exploited, patched for months, and most scanners won't tell you. Here's why, and what to do about it.

Denis Sota · · 13 min read
Guides

How We Benchmarked SentriKat Against Grype and Trivy

On a real production inventory, of the fixable OS-package CVEs that Grype and Trivy both agree on, SentriKat detects 97.3% (818 consensus CVEs), with fewer backport false positives. Here is the method, the numbers, and the parts still in triage.

· 5 min read
NIS2

AI-DLP for SentriKat: stop secrets leaking into ChatGPT, Copilot and Claude

SentriKat now offers an optional AI-DLP endpoint layer, powered by our open-source Contextia engine. Here's what it is, why it matters, and how to turn it on.

· 4 min read
DORA

DORA Pillar 5: Information & Intelligence Sharing, Voluntary, but a Maturity Signal

DORA's fifth pillar (Article 45) encourages financial entities to share cyber threat information and intelligence among trusted communities. It's voluntary, but participating is a clear sign of a mature resilience programme.

· 2 min read
DORA

DORA Pillar 2: ICT Incident Management & Reporting, The Clock and the Classification

DORA's second pillar (Articles 17–23) requires financial entities to detect, classify and report major ICT-related incidents to their competent authority on a defined timeline. Here's the practical shape of it.

· 3 min read
DORA

DORA Pillar 1: ICT Risk Management, What Financial Entities Need

DORA's first pillar (Articles 5–16) requires a board-owned ICT risk-management framework. Here's what that means in practice for banks, insurers, investment firms and their critical functions.

· 2 min read
DORA

DORA Vulnerability Management for Financial Services: A Practical Guide

The Digital Operational Resilience Act requires ICT vulnerability management for financial entities. Learn DORA requirements, deadlines, and how to implement compliant vulnerability tracking.

· 4 min read
NIS2

NIS2 Effectiveness Assessment (Article 21(2)(f)): Proving Your Controls Work

NIS2 Article 21(2)(f) requires policies to assess whether your risk-management measures are actually effective. Present, on paper, isn't the same as working, here's how to show the difference.

· 3 min read
Product

Launching our free public security scanner, what it checks and why we built it

A free, non-intrusive security posture scan for any public domain. Five categories, a 0–100 score, a PDF report, and zero data retention. Here's what's under the hood.

· 8 min read
NIS2

NIS2 MFA & Secured Communications (Article 21(2)(j)): The Highest-Impact Control

NIS2 Article 21(2)(j) calls for multi-factor authentication and secured communications. MFA is the single most effective control against the account compromise behind most breaches, here's how to get it right.

· 2 min read
NIS2

NIS2 Cryptography & Encryption (Article 21(2)(h)): Policy, Not Just Padlocks

NIS2 Article 21(2)(h) requires policies on cryptography and, where appropriate, encryption. The measure isn't 'turn on HTTPS', it's having a deliberate, documented approach to protecting data.

· 2 min read
NIS2

NIS2 Cyber Hygiene & Security Training (Article 21(2)(g)): The Human Layer

NIS2 Article 21(2)(g) requires basic cyber hygiene practices and security-awareness training. It's the cheapest, highest-leverage measure on the list, here's a practical baseline.

· 3 min read
Compliance & SBOM

Security posture update, HttpOnly sessions, nonce-based CSP, SBOM pipeline

A transparent write-up of the April 2026 security hardening on sentrikat.com and portal.sentrikat.com: what we changed, why it matters, and what's next.

· 6 min read
Compliance & SBOM

What's New in SentriKat, SBOM Export, Compliance Reports, and Remediation Workflows

Sprint 4 and Sprint 5 add CRA-ready SBOM export (CycloneDX, SPDX, STIX), signed gap-analysis reports for PCI-DSS, ISO 27001 and SOC 2, full remediation assignments with SLA tracking, and multi-tracker integration with Jira, GitHub, GitLab and YouTrack.

· 4 min read
NIS2

NIS2 Business Continuity & Backups (Article 21(2)(c)): Tested, Not Assumed

NIS2 Article 21(2)(c) requires backup management, disaster recovery and crisis management. The word that matters is 'tested', a backup you've never restored is a hope, not a control.

· 3 min read
NIS2

SentriKat Early Access Is Now Open, All Plans Free, Limited Spots

We're opening SentriKat to 30 SaaS and 15 on-premises organizations for free. Full Pro features, no credit card, no time limit. Here's what you get and how to join.

· 4 min read
NIS2

NIS2 Incident Handling (Article 21(2)(b)): What You Actually Need

NIS2 requires essential and important entities to handle and report incidents on a strict timeline, 24-hour early warning, 72-hour notification, one-month final report. Here's what an incident-handling capability looks like in practice.

· 4 min read
NIS2

NIS2 Risk Analysis & Security Policies (Article 21(2)(a)): The Foundation

NIS2 Article 21(2)(a) requires a management-approved security policy and a maintained risk assessment. Here's what 'good enough' looks like for an essential or important entity, without the enterprise bureaucracy.

· 3 min read
Vulnerability management

SentriKat vs Tenable vs Qualys vs Rapid7: Which Vulnerability Scanner Is Right for You?

A detailed comparison of SentriKat with Tenable Nessus, Qualys VMDR, and Rapid7 InsightVM. Learn how a CISA KEV-focused approach differs from traditional full-spectrum vulnerability scanning.

· 5 min read
NIS2 IT

Gestione delle Vulnerabilità per PMI: Guida Pratica alla Conformità NIS2

La direttiva NIS2 richiede la gestione delle vulnerabilità per le PMI europee. Scopri cosa serve, come implementarla senza budget enterprise, e come SentriKat automatizza la conformità.

· 4 min read
Vulnerability management

Vulnerability Management for MSPs: How to Scale Across Multiple Clients

How managed service providers can deliver vulnerability management at scale using multi-tenant architecture, white-label branding, and CISA KEV-focused prioritization. A practical guide for MSPs.

· 5 min read
Vulnerability management

Vulnerability Management in Air-Gapped Environments: A Practical Guide

How to manage vulnerabilities in air-gapped and isolated networks. Learn about offline KEV tracking, manual knowledge base sync, and SentriKat's approach to vulnerability management without internet access.

· 5 min read
Vulnerability management

On-Premises vs Cloud Vulnerability Management: Why Data Sovereignty Matters

Should your vulnerability management tool be self-hosted or cloud-based? We compare on-premises and SaaS approaches for organizations that care about data sovereignty and GDPR compliance.

· 5 min read
NIS2

Why We Stopped Trusting a Single Vulnerability Database

SentriKat now fetches CVSS scores from 3 independent sources with automatic fallback. Here's why we built multi-source vulnerability intelligence and what the NVD backlog crisis means for your security posture.

· 5 min read
NIS2

What Is the ENISA European Vulnerability Database (EUVD)? A Practical Guide

ENISA EUVD is the European Union's vulnerability database mandated by NIS2 Article 12. Learn what it contains, how it compares to NVD and CISA KEV, and how SentriKat integrates it for EU vulnerability management.

· 5 min read
Vulnerability management

EPSS vs CVSS: How to Actually Prioritize Vulnerabilities in 2026

CVSS scores alone don't tell you what to fix first. Learn how EPSS (Exploit Prediction Scoring System) and the CISA KEV catalog provide real-world exploit context for better vulnerability prioritization.

· 5 min read
NIS2

What Is the CISA KEV Catalog and Why Your Business Should Track It

The CISA Known Exploited Vulnerabilities catalog lists CVEs actively used in cyberattacks. Learn what KEV is, how it differs from the NVD, and why tracking it is essential for NIS2 and DORA compliance.

· 5 min read
NIS2

NIS2 Vulnerability Management: What European SMBs Need to Know in 2026

NIS2 requires vulnerability handling for essential and important entities across the EU. Learn what Article 21 demands, how to demonstrate compliance, and practical tools for SMBs.

· 5 min read

Get started with SentriKat

Cloud or on-premises vulnerability management focused on what's actively exploited.