Taking Notice of AWS IAM Roles Anywhere
August 30, 2022IAM Roles Anywhere may be a pivotal moment for security — the new service lets you enrich the arsenal of tools at your disposal to improve your AWS security posture.
DevSecOps: An Organizational Fix for Improving Cloud Security – Friction-free
August 24, 2022By implementing the DevSecOps culture, tools and training, you’ll be on your way to more shift-left security and less organizational friction. Here’s how.
Facing the Shift-Left Security Conundrum. A True Story
August 17, 2022Shift left security is hot — until it's not. Dynamic business requirements and cloud complexity pose major least privilege challenges.
3 Ways to Reduce the Risk from Misused AWS IAM User Access Keys
August 10, 2022Used incorrectly, AWS IAM user access keys can pose high risk; the good news is that great alternatives, explored here, exist.
3 Types of Cyber Attackers: Which Organizations Do They Target?
July 28, 2022Is an attacker interested in your organization? Probably. Deconstructing the PoV of cyberattackers is key to defending your turf.
Cloud and Data Security for Financial Services
July 5, 2022Financial service organizations are adopting the cloud at a rapid pace. A robust solution for compliance and cloud security will ensure they enjoy all the benefits.
AWS, Azure and GCP: The Ultimate IAM Comparison
June 8, 2022AWS vs. Azure vs. GCP — how do these cloud providers compare when it comes to IAM? Read on to find out.
6 Tips for Successfully Securing Your AWS Environment
May 25, 2022Top six actions and practices you can take to protect your AWS environment today.
Securing Your Cloud with Zero Trust and Least Privilege
May 18, 2022Zero trust could be the solution for your modern security perils. Read on to discover what zero trust and least privilege are – and how to get started.
Hidden Risk in the Default Roles of Google-Managed Service Accounts
May 17, 2022Some Google-managed service accounts are binded by default to a role granting access to storage.objects.read. This hidden risk is yet another great reason to use customer-managed KMS keys to encrypt your sensitive data stored in buckets.
The Advanced Risk of Basic Roles In GCP IAM
May 17, 2022Basic roles in GCP allow data-level actions, even though at first glance it might seem like they don’t. Avoid using basic roles, and if you must use them, make a special effort to protect any sensitive data you store in your GCP projects.
Identity Access Management in Google Cloud Platform (GCP IAM): What Security Pros Need to Know
May 17, 2022An introduction to GCP’s RBAC mechanism for permission assignments — and how to apply the principles of least privilege to keep your organization secure.