<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Jacob Masse: Cybersecurity Blog</title>
    <link>https://jacobmasse.com/blog/</link>
    <atom:link href="https://jacobmasse.com/blog/feed.xml" rel="self" type="application/rss+xml" />
    <description>Practical writing on SOC 2, ISO 27001, penetration testing, security operations, and building secure products, for startup founders and engineering teams.</description>
    <language>en</language>
    <lastBuildDate>Fri, 08 Aug 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>How Much Does SOC 2 Cost for a Canadian Startup?</title>
      <link>https://jacobmasse.com/blog/soc2-cost-canadian-startup.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/soc2-cost-canadian-startup.html</guid>
      <pubDate>Fri, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>A realistic 2026 breakdown of what SOC 2 actually costs a Canadian startup, auditor fees, tooling, and readiness, plus where teams waste money and how to keep the total down.</description>
    </item>
    <item>
      <title>Do You Need a Penetration Test for SOC 2?</title>
      <link>https://jacobmasse.com/blog/do-you-need-a-pentest-for-soc2.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/do-you-need-a-pentest-for-soc2.html</guid>
      <pubDate>Wed, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description>Whether SOC 2 technically requires a penetration test, why auditors and enterprise customers expect one anyway, and what a pentest for compliance should actually include.</description>
    </item>
    <item>
      <title>Fractional CISO vs Full-Time CISO: When Each Makes Sense</title>
      <link>https://jacobmasse.com/blog/fractional-ciso-vs-full-time.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/fractional-ciso-vs-full-time.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description>A practical guide to choosing between a fractional (virtual) CISO and a full-time hire, the cost difference, what each is right for, and the signals that tell you it is time to switch.</description>
    </item>
    <item>
      <title>Why I Advise Cybersecurity Startups (And What That Actually Means)</title>
      <link>https://jacobmasse.com/blog/why-i-advise-cybersecurity-startups.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/why-i-advise-cybersecurity-startups.html</guid>
      <pubDate>Fri, 07 May 2026 00:00:00 GMT</pubDate>
      <description>I am now formally advising and consulting for early-stage cybersecurity startups. Here is what I actually do, why I do it, and what I look for.</description>
    </item>
    <item>
      <title>What SOC 2 Actually Means for Startups</title>
      <link>https://jacobmasse.com/blog/what-soc2-actually-means-for-startups.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/what-soc2-actually-means-for-startups.html</guid>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <description>SOC 2 Type II across 76 controls, 5-layer PR approval flows, and what founders consistently get wrong about compliance. Lessons from the field.</description>
    </item>
    <item>
      <title>I Found a Kill Switch in the Mirai Botnet</title>
      <link>https://jacobmasse.com/blog/mirai-botnet-kill-switch.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/mirai-botnet-kill-switch.html</guid>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <description>The story behind CVE-2024-45163: how I discovered a remote unauthenticated denial-of-service vulnerability in the Mirai botnet&#x27;s command and control server.</description>
    </item>
    <item>
      <title>Your Startup Doesn&#x27;t Need a CISO Yet</title>
      <link>https://jacobmasse.com/blog/your-startup-doesnt-need-a-ciso-yet.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/your-startup-doesnt-need-a-ciso-yet.html</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description>What early-stage companies actually need for security versus what they think they need. Based on 20+ client engagements.</description>
    </item>
    <item>
      <title>The Operational Side of Cybersecurity Nobody Talks About</title>
      <link>https://jacobmasse.com/blog/operational-side-of-cybersecurity.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/operational-side-of-cybersecurity.html</guid>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <description>Security is not just pentesting and red teams. It is compliance, delivery management, cloud partnerships, audit readiness, and the boring work that actually keeps organizations safe.</description>
    </item>
    <item>
      <title>DDoS Mitigation Lessons from Building AttackEngine</title>
      <link>https://jacobmasse.com/blog/ddos-mitigation-lessons-attackengine.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/ddos-mitigation-lessons-attackengine.html</guid>
      <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
      <description>What I learned building AttackEngine, an anti-DDoS SaaS that went from bootstrapped product to acquisition in under a year. Traffic fingerprinting, real-time detection, and multi-channel alerting.</description>
    </item>
    <item>
      <title>Pentest Your Own Product Before Someone Else Does</title>
      <link>https://jacobmasse.com/blog/pentest-your-own-product.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/pentest-your-own-product.html</guid>
      <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
      <description>A practical guide for founders and dev teams on penetration testing your own product. What to test, how to think about it, and when to bring in external testers.</description>
    </item>
    <item>
      <title>Compliance is a Product Feature, Not a Checkbox</title>
      <link>https://jacobmasse.com/blog/compliance-is-a-product-feature.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/compliance-is-a-product-feature.html</guid>
      <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
      <description>Why treating SOC 2 and security audits as product features changes how you close enterprise deals. Lessons from building a 76-control compliance program at Humera.</description>
    </item>
    <item>
      <title>Running a Security Audit Across 60+ Assets</title>
      <link>https://jacobmasse.com/blog/security-audit-60-assets.html</link>
      <guid isPermaLink="true">https://jacobmasse.com/blog/security-audit-60-assets.html</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
      <description>The practical process of auditing domains, servers, and API keys across a growing organization. How to scope, what tools to use, and how to deliver findings that actually get fixed.</description>
    </item>
  </channel>
</rss>
