Skip To Main Content
David Balaban on Muck Rack

David Balaban

Verified
  • Cybersecurity Expert, Journalist, Editor, Freelance
Amsterdam
Covers:  tech, security
David Balaban is a computer security researcher with over 17 years of experience in malware analysis and antivirus software evaluation.

David Balaban’s Journalist Portfolio

View as a grid

Why we must stop slapping the AI label on every area of security

Why we must stop slapping the AI label on every area of security

SC Media — Cybersecurity doesn't need more vague intelligence claims - ask the hard questions about what these new AI tools actually do.

Why regulated industries can't afford to skip data privacy for their AI projects

Why regulated industries can't afford to skip data privacy for their AI projects

SC Media — Security teams in heavily regulated industries can't afford to make data privacy a "nice-to-have" option.

79% of companies say they're ready to detect AI bots, 23% actually are

79% of companies say they're ready to detect AI bots, 23% actually are

SC Media — Here's how we can close the AI bot detection gap in a way that works.

How to Build Mobile Apps that Meet Industry Security Requirements

How to Build Mobile Apps that Meet Industry Security Requirements

SecureWorld — Learn how to develop mobile apps that comply with industry security standards, ensuring data protection and minimizing compliance risks.

A 6-step guide for responding to the Foxconn ransomware/supply chain incident

A 6-step guide for responding to the Foxconn ransomware/supply chain incident

SC Media — Here's how to develop a more effective response to supply chain attacks.

Why the Most Capable AI Model Is Rarely the Right Choice for Your App

Why the Most Capable AI Model Is Rarely the Right Choice for Your App

Unite.AI — There's a certain comfort in selecting the most powerful model. When you're building an AI-powered product, it feels responsible (almost logical) to pick the most powerful model available. GPT-4o. Claude Opus. Gemini Ult...

How to make CTEM operational versus aspirational

How to make CTEM operational versus aspirational

SC Media — Here's seven ways to get the most out of CTEM.

6 steps to harden security programs for the Claude Mythos surge

6 steps to harden security programs for the Claude Mythos surge

SC Media — My opinion on what security teams should do in the wake of Claude Mythos, Anthropic's new frontier model.

Seven ways to secure enterprise virtual desktops

Seven ways to secure enterprise virtual desktops

SC Media — Here's a round-up of recommendations to keep your company's VDI setup secure in 2026, and likely beyond.

How to secure real‑time carbon tracking in factories

How to secure real‑time carbon tracking in factories

SC Media — Time to start treating sustainability telemetry as OT data.

Kubernetes Cost Savings and Security Debt | CSA

Kubernetes Cost Savings and Security Debt | CSA

Cloud Security Alliance Blog — Kubernetes cost savings can create security debt; guardrails, auditable changes, and shared metrics help manage risk.

Why regulated industries need architectural defenses against prompt injection

Why regulated industries need architectural defenses against prompt injection

SC Media — Here's how teams can mitigate the damage when a prompt injection succeeds.

How AI Deepfakes Are Fueling Synthetic Identity Fraud in Enterprises

How AI Deepfakes Are Fueling Synthetic Identity Fraud in Enterprises

SecureWorld — AI-powered deepfakes and synthetic identities are revolutionizing fraud attacks on enterprises, necessitating much stronger verification controls.

Why AI Is Making It Harder Than Ever to Know What to Worry About in Cybersecurity

Why AI Is Making It Harder Than Ever to Know What to Worry About in Cybersecurity

Unite.AI — Artificial intelligence has transformed cybersecurity. Security operations centers now process more telemetry, detect anomalies faster, and automate repetitive investigations. On paper, this should represent a golden era for cyber defense. In practice, many teams feel more overwhelmed than ever. Detection capabilities have improved dramatically, but clarity has not.

Five ways security teams can combat hyper-volumetric DDoS attacks

Five ways security teams can combat hyper-volumetric DDoS attacks

SC Media — Learn 5 tips to stand resilient against the growing tsunami of hyper-volumetric DDoS attacks.

Zero Trust Field Guide for Physical Hosts | CSA

Zero Trust Field Guide for Physical Hosts | CSA

Cloud Security Alliance Blog — A field guide for applying Zero Trust to bare metal: identity, attestation, and evidence-driven controls at the host edge.

Why identity has become the path to cloud security

Why identity has become the path to cloud security

SC Media — Learn how cloud security really works, and what most companies get wrong.

Rollback attacks: Don’t let disaster recovery become an exploit path

Rollback attacks: Don’t let disaster recovery become an exploit path

SC Media — As security teams downgrade their systems to earlier versions as part of incident response, they should mind the scourge of rollback attacks that may reintroduce old vulnerabilities.

A CCM‑Aligned Playbook for BYOD in 2025 | CSA

A CCM‑Aligned Playbook for BYOD in 2025 | CSA

Cloud Security Alliance Blog — Decide between three patterns - streamed desktops (VDI/DaaS), per‑app access via ZTNA and application proxies, and local secure enclaves - mapped to CCM v4.

In IoT Security, AI Can Make or Break

In IoT Security, AI Can Make or Break

The SecureWorld Sessions — Explore how AI can enhance or jeopardize IoT cybersecurity, with strategic actions CISOs should take to safeguard connected devices and networks.

Six ways to protect C-suite execs from OSINT exploits

Six ways to protect C-suite execs from OSINT exploits

SC Media — An analysis of how adversarial OSINT on C-suite can create risks for the whole organization, and what to do about it.

Beyond VDI: Security Patterns for BYOD and Contractors in 2025

Beyond VDI: Security Patterns for BYOD and Contractors in 2025

tripwire.com — Virtual desktop infrastructure (VDI) can centralize risk, but it can also centralize failure, expand the admin plane, and add latency that users will work around.

Self-Custody vs. Third-Party Storage: How Should You Store Your Crypto

Self-Custody vs. Third-Party Storage: How Should You Store Your Crypto

Benzinga — Get the lowdown on the pros and cons of two different ways to store crypto assets, namely self-custody and third-party storage.

Testing AI SaaS: Automation Strategies for Scalable Multi-Tenant Systems

Testing AI SaaS: Automation Strategies for Scalable Multi-Tenant Systems

Unite.AI — Artificial intelligence is now built directly into many SaaS platforms, and that shift has created a new testing challenge. These systems don't just run code, they generate predictions, adapt to fresh data, and serve thousands of customers at once. If the supporting infrastructure is multi-tenant, the pressure gets even more intense.
Show More