categories
cybersecurity
Browse Pomerium articles in the cybersecurity category.
Topic archive
Resources Categorized: cybersecurity
Key Insights and Lessons from the KELA 2024 Report
Cybercrime is evolving rapidly, and the KELA 2024 State of Cybercrime Report sheds light on the latest trends, attack tactics, and defensive strategies . If you don’t have time to read the full report, don’t worry—we did it for you. Here’s what you need to know.

Twingate Vs. Tailscale Vs. Pomerium: 6 Key Differences
Twingate is best suited for backend infrastructure security, Tailscale excels in simplifying device and network connections, and Pomerium provides robust zero-trust, application-layer security with advanced logging.
Elevating Remote Access: Understanding NextGen VPN Flaws
Virtual Private Networks (VPNs) have been around for decades, providing secure connections between remote locations and enabling remote workers to access company resources. NextGen VPNs, such as StrongDM , Tailscale , and Twingate offer streamlined experiences and advanced features that organizations not only use but also adore.
Signed Headers: A Safety Net for Application Security
Cryptographically signed headers are a failsafe authentication mechanism for protecting your applications when Mutual Transport Layer Security (mTLS, also known as mutual authentication ) fails. Utilizing signed headers provides defense in depth to the protected application when:

What is Zero Trust Architecture and Security?
The term "Zero Trust" has been co-opted by many marketing branches of products, but it has a defined meaning with real industry impact.

Zero Trust Maturity Rubric and Tool Matrix
Version 2 of CISA's Zero Trust Maturity Model expands on content and guidance compared to the first version, but a very specific change should be addressed:

IAM Trends and Future Outlook
Earlier this year, CISA (Cybersecurity and Infrastructure Security Agency) released their Enduring Security Framework Guidance on IAM (Identity Access Management). While we highly recommend practitioners read the document itself for its best practices and list of immediate actions, we want to discuss some of CISA’s best practices as well as their current and future trends.

What Is SASE? — A Buyer’s Guide
Update: Gartner is now supporting the service chained products they once warned about.

A Case Against Layer 4 Security Tools
We often talk about how Layer 4 tooling such as VPNs are bad for security , so this post is going to dig into why. If you just want the conclusion, it's simple: Layer 4 tooling is fundamentally blind to its own traffic and Layer 7 tooling is not, which leads to different results for auditing, logging, and continuous verification.

VPNs Are Killing Productivity
VPNs have long been the standard for secure remote access, but they come with significant drawbacks like poor security, performance issues, and increased IT workloads. As remote work continues to evolve, organizations must rethink their approach to access control.

Benefits of Zero Trust Architecture as Defined by NIST
NIST has released a draft of SP 1800-35 , Implementing a Zero Trust Architecture. The lengthy documents lay out their definition of Zero Trust Architecture (ZTA) , the benefits, why it’s important, a few examples of how an organization can implement them, expected results associated with their example builds, and a mapping of ZTA security characteristics to current cybersecurity standards and compliance.

A Close Read at NIST’s Definition of Zero Trust Architecture
This is written based on the second draft of SP 1800-35.

Your Portal is Showing
Something’s happening in the realm of cybersecurity: breaches and data leaks are happening everywhere . Here’s a shortlist of the last few months:

Prevent Insider Attacks With Context-Aware Access
Employees are a constant insider risk — they can expose, leak, or steal data from the organization at any moment with their existing access. Because of this, IT professionals have a common mandate to mitigate insider risk.

Highlights from IBM’s Cost of a Data Breach 2022
IBM’s yearly Cost of a Data Breach 2022 report is out. The 59 page report by IBM and the Ponemon Institute contains findings based on over 3,600 interviews studying 550 organizations impacted by data breaches that occurred between March 2021 and March 2022. The breaches occurred across 17 countries and regions and in 17 different industries.

How Context Drives Full Access Decision-making
Access is an interesting topic. Fundamentally, it means “ permission, liberty, or ability to enter, approach, or pass to and from a place or to approach or communicate with a person or thing ." In the context of security, the layman might phrase access as: ”Who can do that?”

How Breaches Affect Companies
Cybersecurity professionals have a fundamental problem: you’re protecting a company that doesn’t understand or appreciate what you do. Upper management is loathe to give security any more resources than what they deem “enough” and your work is seen as a necessary evil. No one considers the effort necessary to minimize risk when no breaches have happened — and when a breach does occur (one you probably warned about), the blame falls onto you.

Security Posture: When and How to Reevaluate
Security posture isn't a concern for organizations unless they're trying to make compliance audits. After all, the perception has been that security is just a cost center and a hindrance to more productivity.

Q&A with Zero Trust Architecture Writers from NIST
We interviewed Scott Rose and Oliver Borchert from the National Institute of Standards and Technology (NIST) about their publication on Zero Trust Architecture (ZTA) discussing zero trust principles and how it affects organizations.

Insulation from Third-Party Breaches
The world’s #1 identity platform Okta has suffered a potential breach , and thousands of their corporate customers find themselves wondering if they may need to take corrective measures. Though Okta’s Chief Security Officer David Bradbury officially claims “There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers”, companies like Cloudflare have taken preventative measures to protect their internal and external accounts against hackers that may exploit Okta’s potential security breach.

The Far Reach of the White House’s Zero Trust Memo
The new White House memo on zero trust is a strong signal that the US federal government is taking an active stance regarding cybersecurity. Not only does this have far-reaching ramifications for the public and private sectors, it also serves to cut through the noise about zero trust with an impartial source. Let’s look at what the White House has to say and what this means for the cybersecurity sector going forward.

The Move to Passwordless Authentication
There's been a big move to passwordless authentication in recent years. After all, large scale data breaches are occurring on a weekly basis — and data breaches are just one way security breaches manifest themselves . Compromised credentials are, by and large, the hardest problem to identify and fix. Take a look at this chart from IBM's Cost of a Data Breach Report 2021 :

Elevate Productivity with Frictionless Security
It's not uncommon for organizations to deprioritize security as it's a cost center and is typically associated with negative effects on productivity. Many organizations equate security measures with increasing friction and frustrating work-arounds — resulting in Sisyphean uphill battles to introduce or change security measures. Just as no one likes TSA lines, no business wants to put operations at the mercy of security to the point of impacting productivity.

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.
Once again, we find ourselves combining the Cybersecurity & Infrastructure Security Agency's (CISA) Week 3 theme of Explore. Experience. Share. with Week 4's theme of Cybersecurity First. Ultimately, people and organizations can better prepare for an increasingly virtual world by sharing cybersecurity knowledge and making it top-of-mind.
CyberSecurity Awareness Month: Be Cyber Smart to Phight the Phish
October is CyberSecurity Awareness Month , and the first week's theme is Be Cyber Smart. We'll combine it with the second week's theme of Phight the Phish because the two are necessarily interlinked for organizations that want to prevent breaches.
