Insights from our experts.
Perspectives on infrastructure security, autonomous systems, and what it means to eliminate exposure instead of manage it.

Featured blog posts
)
How Xiid's MCP server satisfies SOC 2, ISO 27001, and NIST audit controls
AI agents are taking real infrastructure actions now. Most enterprise logging can't prove what happened. Xiid's MCP server can.
)
TCP Setup Time is the VPN Metric Nobody's Measuring
VPN setup time benchmark: SealedTunnel™ vs WireGuard, IPsec
)
Autonomous Attack Paths: The Security Problem AI Is Creating
As organizations deploy AI agents, autonomous workflows, copilots, and machine-driven orchestration platforms, the actions that matter are no longer primarily human-initiated.
All blog posts
)
The Security Blind Spot in Long Lifecycle Assets
There’s a whole category of IoT/OT/CPS assets with long lifecycles like EV chargers, wind turbines, aircraft, ships, industrial machinery, and medical devices whose systems last a long time and are vulnerable to dangers that change quickly.
)
MCP servers in the enterprise: Bounded access, tamper-evident logs, and why both matter
MCP is in enterprise production. The question now is whether your implementation is actually bounded or just assumed to be.
)
How Xiid's MCP server satisfies SOC 2, ISO 27001, and NIST audit controls
AI agents are taking real infrastructure actions now. Most enterprise logging can't prove what happened. Xiid's MCP server can.
)
TCP Setup Time is the VPN Metric Nobody's Measuring
VPN setup time benchmark: SealedTunnel™ vs WireGuard, IPsec
)
Autonomous Attack Paths: The Security Problem AI Is Creating
As organizations deploy AI agents, autonomous workflows, copilots, and machine-driven orchestration platforms, the actions that matter are no longer primarily human-initiated.
)
CI/CD pipeline security: Human error is inevitable. Lateral movement isn't.
The incident report always reads "human error" - a misconfigured runner, a committed token, or an overpermissioned service account attached to a build job that didn't need it.
)
World Backup Day isn’t enough
This blog argues that World Backup Day-era thinking is dangerously outdated because reachable backups keep organizations exposed, and only Terniion’s preemptive, non-routable architecture truly protects them.
)
Beyond the Patching Treadmill: Why Industrial Security Requires Architectural Invisibility
Siemens appears in CISA advisories constantly — not due to poor engineering, but massive market share. Learn why patching fails in OT environments and how architectural invisibility eliminates the attack surface entirely.
)
Compliance Isn’t Security (PQC Edition)
This blog explains why simply upgrading your OpenSSL does not achieve post-quantum resilience or protection.
Want to stay up-to-date with Xiid?
Get the latest insights right to your inbox from our monthly Black Box Brief newsletter.