Skip to main content

categories

cybersecurity

Browse Pomerium articles in the cybersecurity category.

Topic archive

Resources Categorized: cybersecurity

Signed Headers: A Safety Net for Application Security
blog posts

Signed Headers: A Safety Net for Application Security

Cryptographically signed headers are a failsafe authentication mechanism for protecting your applications when Mutual Transport Layer Security (mTLS, also known as mutual authentication ) fails. Utilizing signed headers provides defense in depth to the protected application when:

IAM Trends and Future Outlook
blog posts

IAM Trends and Future Outlook

Earlier this year, CISA (Cybersecurity and Infrastructure Security Agency) released their Enduring Security Framework Guidance on IAM (Identity Access Management). While we highly recommend practitioners read the document itself for its best practices and list of immediate actions, we want to discuss some of CISA’s best practices as well as their current and future trends.

A Case Against Layer 4 Security Tools
blog posts

A Case Against Layer 4 Security Tools

We often talk about how Layer 4 tooling such as VPNs are bad for security , so this post is going to dig into why. If you just want the conclusion, it's simple: Layer 4 tooling is fundamentally blind to its own traffic and Layer 7 tooling is not, which leads to different results for auditing, logging, and continuous verification.

Benefits of Zero Trust Architecture as Defined by NIST
blog posts

Benefits of Zero Trust Architecture as Defined by NIST

NIST has released a draft of SP 1800-35 , Implementing a Zero Trust Architecture. The lengthy documents lay out their definition of Zero Trust Architecture (ZTA) , the benefits, why it’s important, a few examples of how an organization can implement them, expected results associated with their example builds, and a mapping of ZTA security characteristics to current cybersecurity standards and compliance.

Highlights from IBM’s Cost of a Data Breach 2022
blog posts

Highlights from IBM’s Cost of a Data Breach 2022

IBM’s yearly Cost of a Data Breach 2022 report is out. The 59 page report by IBM and the Ponemon Institute contains findings based on over 3,600 interviews studying 550 organizations impacted by data breaches that occurred between March 2021 and March 2022. The breaches occurred across 17 countries and regions and in 17 different industries.

How Breaches Affect Companies
blog posts

How Breaches Affect Companies

Cybersecurity professionals have a fundamental problem: you’re protecting a company that doesn’t understand or appreciate what you do. Upper management is loathe to give security any more resources than what they deem “enough” and your work is seen as a necessary evil. No one considers the effort necessary to minimize risk when no breaches have happened — and when a breach does occur (one you probably warned about), the blame falls onto you.

Insulation from Third-Party Breaches
blog posts

Insulation from Third-Party Breaches

The world’s #1 identity platform Okta has suffered a potential breach , and thousands of their corporate customers find themselves wondering if they may need to take corrective measures. Though Okta’s Chief Security Officer David Bradbury officially claims “There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers”, companies like Cloudflare have taken preventative measures to protect their internal and external accounts against hackers that may exploit Okta’s potential security breach.

The Far Reach of the White House’s Zero Trust Memo
blog posts

The Far Reach of the White House’s Zero Trust Memo

The new White House memo on zero trust is a strong signal that the US federal government is taking an active stance regarding cybersecurity. Not only does this have far-reaching ramifications for the public and private sectors, it also serves to cut through the noise about zero trust with an impartial source. Let’s look at what the White House has to say and what this means for the cybersecurity sector going forward.

The Move to Passwordless Authentication
blog posts

The Move to Passwordless Authentication

There's been a big move to passwordless authentication in recent years. After all, large scale data breaches are occurring on a weekly basis — and data breaches are just one way security breaches manifest themselves . Compromised credentials are, by and large, the hardest problem to identify and fix. Take a look at this chart from IBM's Cost of a Data Breach Report 2021 :

Elevate Productivity with Frictionless Security
blog posts

Elevate Productivity with Frictionless Security

It's not uncommon for organizations to deprioritize security as it's a cost center and is typically associated with negative effects on productivity. Many organizations equate security measures with increasing friction and frustrating work-arounds — resulting in Sisyphean uphill battles to introduce or change security measures. Just as no one likes TSA lines, no business wants to put operations at the mercy of security to the point of impacting productivity.

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.
blog posts

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.

Once again, we find ourselves combining the Cybersecurity & Infrastructure Security Agency's (CISA) Week 3 theme of Explore. Experience. Share. with Week 4's theme of Cybersecurity First. Ultimately, people and organizations can better prepare for an increasingly virtual world by sharing cybersecurity knowledge and making it top-of-mind.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo