Why do we, in 2021, far too often still see security not being baked into all aspects of the software development lifecycle and instead added as some kind of tack-on component way down the line?
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Two of the biggest topics in Cloud today are DevOps and DevSecOps. What makes them so important now and how organizations can leverage them are key questions. For the answers, we must jump back to look at their origins and how these methodologies developed.
Privileged Access Management (PAM) is a structured approach that governs privileged credentials and their usage.
More than ten years later, DevSecOps is still more of an idea than an effective practice. There is a better way to defend your cloud environment, and you can do it in three steps.
DevSecOps Overwhelmed by Backlogs, Significant Time and Money Being Lost to Vulnerability Management
The State of Vulnerability Management in DevSecOps" study included over 16,500 IT leaders and experts. 66% of these firms say they have a backlog of more than 100,000 vulnerabilities.
The Department of Homeland Security (DHS) has issued a bulletin to law enforcement agencies warning that Russian cyber attacks in the US are possible if Ukraine is invaded.
The CSRB found that the security breach was preventable, and that a "a corporate culture that deprioritized enterprise security investments and rigorous risk management" ended up leaving open doors for the Chinese hackers.
Ransomware is the current king of the cybersecurity threat landscape, in part because of willingness to escalate to real-world damage to infrastructure. The DHS Secretary thinks that things are poised to go a step further in that direction in the very near future.
Though Microsoft is hardly alone in terms of cloud services experiencing serious security breaches, a string of Redmond mishaps appears to have prompted new security reviews by the Cyber Safety Review Board (CSRB).
NSA and CISA issues joint report warning of cyber threats from state-sponsored actors targeting critical infrastructure, directing owners and operators to take immediate actions.










