2025
Security Posture
Building a 12-Month Security Roadmap
Build a 12-month security roadmap for 2026: baseline against NIST CSF 2.0, prioritize by risk and effort, plan quarterly phases and keep the plan alive.
Security Posture
System Hardening With CIS Benchmarks
How to harden systems with CIS Benchmarks: Level 1 vs. Level 2 profiles, hardened images, automated rollout, testing, documenting exceptions and catching drift.
Security Posture
Building an Incident Response Plan That Works at 2 a.m.
Build an incident response plan people can use at 2 a.m.: contact lists, severity levels, decision rights, short runbooks and notification clocks.
Security Posture
Data Classification: Knowing What You're Protecting
A practical guide to data classification: a simple four-level scheme, data owners, labeling, handling rules, and linking it to DLP and access controls.
Security Posture
Shadow AI: Managing Employee Use of Generative AI Tools
How to manage shadow AI: discover the generative AI tools staff use, offer approved options, set data rules for prompts, and back it with DLP and training.
Security Posture
Post-Quantum Cryptography: Why You Should Start Your Crypto Inventory Now
Post-quantum cryptography migration starts with a cryptographic inventory. Here's what NIST and NSA have set out, and how to inventory and plan now.
2024
Security Posture
Secrets Management: Getting Credentials Out of Your Code
A practical guide to secrets management: move credentials into a vault, use short-lived secrets and OIDC federation, scan repos, rotate keys and handle leaks.
Security Posture
Passkeys for the Enterprise: Are You Ready to Go Passwordless?
Are passkeys ready for the enterprise? How FIDO2 works, synced vs. device-bound passkeys, attestation for admins, recovery, shared devices and a phased rollout.
Security Posture
Third-Party Risk Management Without the Spreadsheet Nightmare
A practical guide to third-party risk management: tier vendors, right-size assessments, reuse SOC 2 and ISO 27001 evidence, and tighten contracts.
Security Posture
Getting a Handle on SaaS Sprawl
How to get SaaS sprawl under control: discover apps from SSO, expense and OAuth data, add SSO and SCIM, set consent policies, fix offboarding and assign owners.
Security Posture
Hardening Your Identity Provider Against Account Takeover
How to harden your identity provider against account takeover: strong admin MFA, conditional access, token lifetimes, fewer admin roles, logging, safe resets.
Security Posture
Reporting Security Posture to the Board
How to report security posture to the board: frame it as business risk, track a few metrics over time, tie spend to risk reduction and fit it on one page.
2023
Security Posture
Google and Yahoo's Bulk Sender Rules: Getting DMARC Right
Google and Yahoo's bulk sender rules start in February 2024. Here's what they require and a practical DMARC rollout plan from p=none to p=reject.
Security Posture
Least Privilege and Just-in-Time Access in Practice
How to put least privilege and just-in-time access into practice: role design, access reviews, removing standing admin rights, cloud IAM and service accounts.
Security Posture
Logging and Monitoring: Building Visibility You Can Actually Use
A practical guide to security logging and monitoring: what to log first, time sync, retention, high-value detections, alert tuning and keeping SIEM costs down.
Security Posture
Security Awareness Training That Actually Changes Behavior
Security awareness training that changes behavior: build a blame-free reporting culture, tailor content by role, use short formats and measure real habits.
Security Posture
API Security: Protecting the Connections Between Your Systems
An API security guide for IT teams: the OWASP API Security Top 10 2023, API inventory, object-level authorization, rate limiting, gateways, schemas and testing.
Security Posture
Zero Trust in Practice: First Steps for Mid-Sized Companies
Practical zero trust first steps for mid-sized companies: MFA everywhere, device checks, per-app access, segmentation and logging, mapped to CISA's ZTMM v2.0.
Security Posture
Network Segmentation Beyond Compliance
Network segmentation beyond compliance: macro vs. microsegmentation, east-west controls, management networks and cloud VPC design, starting from mapped flows.
Security Posture
How to Run a Tabletop Exercise That Isn't a Waste of Time
How to run a tabletop exercise that finds real gaps: set objectives, pick participants, design scenarios and injects, facilitate well and follow up.
2022
Security Posture
EDR vs. MDR vs. XDR: Which Does Your Organization Need?
EDR vs. MDR vs. XDR: what each one does, how they compare, and how to choose based on staff, 24/7 coverage, existing tools, budget and response authority.
Security Posture
Attack Surface Management: Seeing Your Organization Like an Attacker
Attack surface management finds the domains, IPs, cloud assets and exposed services attackers see first. Here's how to discover, prioritize and own them.
Security Posture
Cloud Security Posture Management (CSPM) Explained
Cloud security posture management (CSPM) continuously checks cloud configurations against benchmarks. Learn what it does, its limits, and how to roll it out.
Security Posture
How to Run a Security Posture Assessment in 30 Days
A week-by-week plan to run a security posture assessment in 30 days: scope, inventory, framework control review, technical validation and a roadmap.
Security Posture
Privileged Access Management: Locking Down Your Most Powerful Accounts
Privileged access management explained: vaulting, session recording, admin tiering, separate admin accounts, PAWs, service and break-glass accounts, monitoring.