Control D

Control D Security teams waste entire days debugging systems instead of using the full capabilities of DNS — the first mile of security. Most security stacks are bloated.

Trusted by companies like Pinnacle ICT, Data Net Solutions, and public venues such as Massey Hall and Roy Thomson Hall. Control D is DNS Security Orchestration. We help IT leaders, CISOs, and MSPs:

- Stop phishing, ransomware, and malware at the DNS layer (99.97% verified block rate).
- Cut false positives and reduce alert fatigue.
- Simplify bloated stacks with 1,000+ service-level controls.
- D

eploy in minutes — no hardware, no agents, no upsells. Trusted by companies like Pinnacle ICT, Data Net Solutions, and public venues such as Massey Hall and Roy Thomson Hall, Control D turns DNS from your weakest link into your moat.

👉 Start your 30-day risk-free trial at [https://controld.com](https://controld.com/)

06/19/2026

40,000 CVEs in 2023. 60,000+ predicted this year.

What happens when that number hits 300,000?

Ben Lipchinski, former Royal Navy submarine officer turned enterprise security leader, joins Full Metal Packet to talk about why the entire patching model may be heading toward collapse and what serious defenders should do instead.

Ben Lipchinski is Director of Security & Regulatory Services at Origina, with over a decade of experience in high-consequence operational environments before moving into enterprise cybersecurity.

In this clip, Alex Paguis, Co-Founder of Control D, and Ben break down:

- Why the volume of CVEs is growing faster than any team can realistically respond to, and why that trend is only accelerating with AI
- How AI tools are shifting from assistants to primary generators of vulnerability data, potentially producing hundreds of thousands of CVEs
- Why chasing the full list is no longer a strategy and is becoming a liability for security teams
- The case for a focused approach: identify the most critical parts of your business, run your tooling against those specifically, and tune out the rest
- Why ignoring noise isn't negligence, it's the only way to actually protect what matters before the next wave hits

Full episode out now. Link in bio.

06/16/2026

Most security teams are patching the wrong things, ignoring the right systems, and flying blind. A former Royal Navy submarine officer explains exactly why.

Ben Lipchinski, Director of Security & Regulatory Services at Origina, spent 12 years operating in some of the highest-consequence environments imaginable before bringing those lessons into enterprise cybersecurity.

In this episode, he breaks down the gap between military operational discipline and how corporate security teams actually function, and what CISOs can do about it.

In this episode, Ben explains:

- Why siloed organizations are the #1 security failure. Security teams that don't talk to engineers don't actually know what they're protecting or how critical it is to the business.
- Why patching is not a silver bullet. Patches only cover core code, sometimes introduce new vulnerabilities, and can create a dangerous false sense of security. One client had 700 flagged CVEs, but only 20 actually required action.
- How legacy systems coming online are redefining the attack surface, from SCADA systems controlled by iPads to wind farms managed by devices kids use to watch YouTube.
- Why "newest version = most secure" is one of enterprise security's most expensive myths, and how blind upgrades often trade one set of vulnerabilities for another.
- How the submarine mindset applies to incident response. Slow down, know your systems, understand what failure actually means for the mission, and build for resilience, not just recovery.

Full episode out now. Link in bio.

06/05/2026

She asked AI to clean up her inbox. It deleted everything.

A real story from cybersecurity expert John Verry: an employee gave an AI tool access to her Gmail, told it she was getting too many emails, and asked it to help her prioritize. The AI's solution was to delete everything it thought was not urgent.

Gone. All of it.

And she worked in IT.

This is shadow AI in the wild. Not some rogue hacker. Just a regular employee trying to be more productive with tools that are already available to them.

63% of SaaS apps are now AI-enabled. Most companies have no idea what data is being fed into them or what those tools can actually do.

Full episode is live now. Tap the link in bio.

The CEO said use AI. The marketing guy listened a little too well.No technical skills. No IT sign-off. Just Claude Code,...
06/03/2026

The CEO said use AI. The marketing guy listened a little too well.

No technical skills. No IT sign-off. Just Claude Code, a Salesforce API key, his company Gmail, and a big idea.

Then some bad stuff happened.

And then there was the woman in IT who asked AI to reorganize her inbox. It deleted everything it thought was not urgent. She had to ask her own IT department to restore her mailbox.

Two real stories. Two regular employees. Zero bad intentions.

This is what shadow AI actually looks like. The tools are already there. All it takes is a credential and a key.

Full episode live now. Link in bio.

AI is now coding AI. And some experts think humans could be out of the loop entirely by the end of this year.That is not...
06/02/2026

AI is now coding AI.

And some experts think humans could be out of the loop entirely by the end of this year.

That is not science fiction. That is the conversation happening right now at the frontier.

It is called the hard takeoff. Once AI starts recursively improving itself, the acceleration stops following a human timeline.

John Verry's reaction when he first heard this: "that just clicked something in my head that said, ooh."

The one thing that might slow it down? Model collapse.

When AI trains on AI-generated data, bad inputs compound fast. 1% bad data leads to 10% bad predictions. Scale that up and the whole thing starts to break.

Basically, AI can collapse the same way a person does when they spend too long in an echo chamber.

Full episode out now. Link in bio.

06/01/2026

Getting SOC2 certified doesn't mean your company is secure, it means you're good at compliance theater.

John Verry, Managing Director at CBIZ Cybersecurity and ISO 27001 certified lead auditor since 2006, joins the Full Metal Packet podcast to give CISOs a reality check on what compliance actually means in the age of AI.

He explains:

◼ Why even the best-intentioned compliance programs slip into theater, and the one mindset shift that fixes it

◼ How to operationalize security controls inside tools your team already lives in (JIRA, ServiceNow, SharePoint) so nothing falls through the cracks

◼ What shadow AI actually looks like on the ground, and the single control you can implement tomorrow to contain it

◼ Why the EU AI Act (Aug 2026) and ISO 42001 are no longer theoretical, and what a provable AI compliance program looks like right now

◼ Why agentic AI is the risk that should be keeping every CISO up at night: autonomous decisions, no human in the loop, business impact at scale

05/31/2026

You will get breached.

Every security expert already knows this.

The real question is how much damage happens before you contain it.

Devon Ackerman, former FBI agent and head of DFIR at LevelBlue, explains why the shift from breach prevention to blast radius control is the most important conversation in security right now.

Full episode, link in bio.

05/27/2026

Most of the conversation around MFA is about convenience.

Easiest to deploy. Least friction. Highest adoption rate.

Almost nobody asks the more useful question: where does the kill chain actually stop?

Devon Ackerman has worked over a thousand breach investigations. He's seen phishing kits defeat SMS codes without breaking a sweat. Authenticator apps too, if the kit is good enough. The entire software authentication handshake was designed without assuming someone is sitting in the middle, watching in real time.

Hardware keys change that.

When the device has to be physically present to authenticate, there is nothing to intercept. No token crossing the wire. That is typically where the kill chain ends.

One exception: if the certificate is a software file sitting on the machine, it can be stripped and replayed from another device. Rare. Technically demanding. But Devon has seen it.

The practical takeaway has not changed in years:

Hardware key on anything that matters. Not because it is perfect. Because it makes you a harder target than whoever is next on the list.

That is usually enough.

05/26/2026

Most of the conversation around MFA is about convenience.

Easiest to deploy. Least friction. Highest adoption rate.

Almost nobody asks the more useful question: where does the kill chain actually stop?

Devon Ackerman has worked over a thousand breach investigations. He's seen phishing kits defeat SMS codes without breaking a sweat. Authenticator apps too, if the kit is good enough. The entire software authentication handshake was designed without assuming someone is sitting in the middle, watching in real time.

Hardware keys change that.

When the device has to be physically present to authenticate, there is nothing to intercept. No token crossing the wire. That is typically where the kill chain ends.

One exception: if the certificate is a software file sitting on the machine, it can be stripped and replayed from another device. Rare. Technically demanding. But Devon has seen it.

The practical takeaway has not changed in years:

Hardware key on anything that matters. Not because it is perfect. Because it makes you a harder target than whoever is next on the list.

That is usually enough.

05/22/2026

They didn't hack the system.

They called the help desk.

One phone call. A fake IT employee. Some leaked personal info.

The attacker deliberately triggered failed login attempts — so the call center could "confirm" them.

Then asked for a password reset. Then asked to disable MFA temporarily.

"Of course. That's completely normal."

They were in. No malware. No alerts. No anomaly flagged. Just a help desk agent trying to do their job.

Devon Ackerman has investigated over 1,000 breaches. This is what he says the most dangerous ones look like.

Not zero-days. A phone call.

🎧 Full breakdown…link in bio.

Address

555 Richmond Street West
Toronto, ON
M5V3B1

Alerts

Be the first to know and let us send you an email when Control D posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share