How to Respond When Your Identity or Cloud Provider Is Allegedly Breached
When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...
Insights
Articles in How-To & Hardening.
When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...
The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...
Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.
API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.
Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....
Use this checklist to start an exposure management program with Microsoft Defender tools.
AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your...
Use this checklist to lock down the AWS root user across your organization.
Microsoft's mandatory MFA for Azure breaks automation that signs in as a user with a password. Here is how to find and migrate those service accounts.
Use this checklist to confirm your organization is ready for Azure's mandatory MFA.
Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.
Use this checklist to remediate oversharing before and during Copilot rollout.
Exposed .env files led to an AWS extortion campaign in 2024. Here is how to keep secrets out of web-accessible locations and move them into AWS Secrets Manager.
The CrowdStrike outage showed how hard recovery is when thousands of BitLocker-encrypted devices won't boot. Here is how to prepare for recovering Azure VMs...
Security agents and other kernel-level software can take down entire fleets. Use this checklist to manage the risk of endpoint agent updates.
The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA...
Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.
Use this checklist to roll out passkeys across your organization.
Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify...
Use this checklist to review each major cloud provider's security each year.
When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan...
Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.
Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in...
Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with...