Control D

Control D Security teams waste entire days debugging systems instead of using the full capabilities of DNS — the first mile of security. Most security stacks are bloated.

Trusted by companies like Pinnacle ICT, Data Net Solutions, and public venues such as Massey Hall and Roy Thomson Hall. Control D is DNS Security Orchestration. We help IT leaders, CISOs, and MSPs:

- Stop phishing, ransomware, and malware at the DNS layer (99.97% verified block rate).
- Cut false positives and reduce alert fatigue.
- Simplify bloated stacks with 1,000+ service-level controls.
- D

eploy in minutes — no hardware, no agents, no upsells. Trusted by companies like Pinnacle ICT, Data Net Solutions, and public venues such as Massey Hall and Roy Thomson Hall, Control D turns DNS from your weakest link into your moat.

👉 Start your 30-day risk-free trial at [https://controld.com](https://controld.com/)

08/14/2026

We need to shut down the perimeter. And that's what we did. We unplugged, literally unplugged the internet router."

Mo Balakrishnan was already late to the office when SonicWall's 2021 ransomware attack surfaced.

Encrypted file systems everywhere.

No clear picture of what happened or how far it had spread.

Their call: pull the logs, trace the movement, then pull the plug on the internet entirely.

This clip is from Full Metal Packet, hosted by Control D founders Alex Paguis and Yegor Sak.

Full episode link in bio.

07/09/2026

You built the perfect secure system. Then you handed it to your employees. 😬

First came the edge cases. Then the exceptions. Then the support tickets saying "I literally cannot do my job. Fix this right now."

So you start opening things up. One rule at a time.

And that is exactly how a secure system quietly becomes a vulnerability.

But here is the real problem Ross Young pointed out on Full Metal Packet.

Ask any developer how they get promoted. It is not by fixing 200 security vulnerabilities. It is by shipping features. Hitting milestones. Delivering version two.

So when they have to choose between 200 hours of security fixes or one feature that gets them a bonus, the answer is obvious.

The problem was never the tools. It was always the incentives.

Full episode out now. Link in bio.

07/07/2026

The CFO refused to fund the security program. Then the breach happened. And he still made the right call 🤯

Here is the math.

$2 million a year for an AI security program. Over 4 years that is $8 million.

The average breach costs $4 million.

CFO says no. Breach happens 4 years later. Company pays $4 million.

Net saving by NOT funding the security program? $4 million.

Ross Young laid this out on Full Metal Packet and it stopped the conversation cold.

Because in cybersecurity we are trained to say we stop all breaches. We protect everything. Every dollar we ask for is justified.

But the uncomfortable truth is you could spend everything the company has and still not be fully secure.

The real skill is not asking for more budget. It is knowing how to have an honest conversation about what the money actually buys.

And most security leaders have never been taught how to do that.

Full episode out now. Link in bio.

07/06/2026

"We fixed that years ago."

The most dangerous sentence in cybersecurity.

Ross Young was inside Capital One when the 2019 breach happened.

It was not a sophisticated zero-day. It was a WAF that never got fully migrated. A gap sitting at 98% complete that nobody went back to finish.

Now with AI tools scanning attack surfaces at machine speed, attackers are finding those exact gaps before you even know they exist.

Every CISO needs to watch this. Full episode out now. Link in bio.

07/03/2026

"We fixed that years ago."

The most dangerous sentence in cybersecurity.

Ross Young was inside Capital One when the 2019 breach happened.

It was not a sophisticated zero-day. It was a WAF that never got fully migrated. A gap sitting at 98% complete that nobody went back to finish.

Now with AI tools scanning attack surfaces at machine speed, attackers are finding those exact gaps before you even know they exist.

Every CISO needs to watch this. Full episode out now. Link in bio.

07/03/2026

Someone impersonated the RCMP to scam Alex Paguis (one of the co-founders of Control D) and it almost worked!

Convincing phone calls. Personal details.

They even tried to get me to walk into an RCMP office to meet an officer face to face.

Here is what Ross Young said that stopped me cold: Attackers are now putting THREE deepfake executives on a single Zoom call at the same time.

CFO. CEO. Legal. All telling you to approve something.

People do it, because nobody thinks three people can be faked at once. No training fully stops this. What stops it is process. If it is not approved inside your system of record, it does not happen. No exceptions. Not even for the CEO.

That is what a defensible organization looks like.

Full episode out now. Link in bio.

07/01/2026

What if your $3 million security tool is only giving you 40% protection and nobody in your company knows it?

That's the exact blind spot Ross Young, former Capital One CISO, author of Cybersecurity's Dirty Secret, and founder of Clear Capabilities, breaks down on this episode of Full Metal Packet.

He reveals:

◼ The "murder board" method for calculating whether a security tool is actually worth its price tag

◼ What really went wrong at Capital One in 2019 and why "we fixed this years ago" is the most dangerous sentence in security

◼ Why DLP is often security theater and how attackers bypass it in minutes

◼ How AI is changing the speed of both attack and defense, and what CISOs need to do about it

◼ Why hardware security keys might be the highest ROI purchase in your entire security stack

This is a masterclass in why "we have a tool for that" isn't the same as being secure.

Full episode out now. Link in Bio.

Address

555 Richmond Street West
Toronto, ON
M5V3B1

Alerts

Be the first to know and let us send you an email when Control D posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share