How to Rotate Sessions and Secrets After a Third-Party Provider Leak
When a provider you depend on — a CDN, identity platform, CI/CD service or SaaS tool — announces that tokens or secrets may have leaked, speed matters more...
Insights
Articles in How-To & Hardening.
When a provider you depend on — a CDN, identity platform, CI/CD service or SaaS tool — announces that tokens or secrets may have leaked, speed matters more...
Amazon S3 is extremely durable, but a single region can still become unavailable. Here is how to design S3-backed workloads to keep running — or at least...
Outages are rare enough that teams forget how to handle them. A tabletop exercise — a structured discussion of a realistic scenario — is the cheapest way to...
AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is...
Use this checklist to check whether an AWS-hosted application is ready for a denial-of-service attack. Each "no" is a gap to plan for.
Turning on multi-factor authentication for every Microsoft 365 user is the single most effective identity control you can deploy. It is also the change most...
The 2016 Dyn attack proved that DNS can take a healthy application offline. Here is a practical way to design DNS and DDoS protection for workloads running...