Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Dawn of Enterprise IT: Part 1 of the Enterprise OIT Series

There was a time when “Information Technology” wasn’t a department, an industry, or even a common business term. In the 1970s and 1980s, computing and telecommunications were largely separate disciplines. Computers processed information. Telecommunications moved information. Most systems operated independently, often serving specific departments or business functions. Then those worlds began to converge. Organizations started connecting computers through networks.

Sophisticated Attacks No Longer Require Sophisticated Attackers

For years, the sophistication of a cyberattack was closely connected to the sophistication of the attacker behind it. Advanced campaigns required experienced threat actors with the knowledge, resources, and time needed to research targets, understand environments, create convincing interactions, adapt when something failed, and coordinate complex operations. Artificial Intelligence is beginning to change that relationship.

OpenStack Backup And Recovery Frequently Asked Questions

My name is Kevin Jackson. I have been working with OpenStack since the first releases in various capacities — as an operator, author, architect, and currently at Trilio, where I assist organisations with cloud backup and recovery strategies. Over the years, I have watched OpenStack mature from an early-stage project into the core infrastructure underpinning demanding private and public clouds across telecoms, financial services, and the public sector.

The dark figure of supply chain detection

During World War II, Abraham Wald was asked where to add armor to bomber planes. The military's instinct was to study the planes that came back and reinforce wherever the bullet holes were clustered. Wald said to do the opposite. The planes in front of him had already survived hits to those spots. That's exactly why he could study them. The planes that took hits to the engine or the cockpit never made it back to be studied at all.

How Keeper Privileged Cloud Delivers Zero Standing Privilege

Keeper Privileged Cloud delivers Zero Standing Privilege (ZSP) by extending KeeperPAM’s Just-In-Time (JIT) access framework to cloud identity platforms. A user gets elevated permissions only after a request is approved; those permissions last for a set time window, and Keeper removes them automatically once the window ends. No permanent privilege is left in place.

Common Zero Standing Privilege Challenges and How To Solve Them

One of the most exploitable parts of modern attack surfaces is standing privileges: the persistent access rights that linger on accounts long after they’re needed. With standing privilege, static credentials are easier to steal, and overprovisioned accounts give attackers far more reach than they should have. Zero Standing Privilege (ZSP) solves these issues by granting access only when necessary and revoking it as soon as the task is finished, leaving behind no lingering access.

A Practical Guide to Attack Surface Management

Attack surface management (ASM) is the discipline of continuously discovering, inventorying, assessing, and prioritizing every asset, control, and exposure across your environment. It gives you an always-on picture of what you actually have, rather than a point-in-time scan. Done right, it answers the three questions every security leader is really asking: What do I have? Where am I exposed? What do I fix first?

A Risk Number Does Not Decay on a Smooth Curve

An annual quantification gets produced in March and quoted as fact in November. Everyone involved knows the figure has aged and nobody knows by how much, so it keeps being presented with the same confidence it had on the day it was signed off. ‍ The usual framing is that a number decays gradually and needs refreshing more often. The framing is half right and it misleads on the part that matters, because most of the decay does not happen gradually at all. ‍

Single-Agent Monitoring Records Nodes, Not Edges

Monitoring an agent tells you what that agent did. Every useful question about a multi-agent deployment concerns what happened between agents, and those are properties of the connections rather than of the participants. A per-agent view records nodes and the problems live on the edges. ‍ The shortfall is not a tooling problem waiting on a product.