IT Security

April 18, 2024 Your Employees Are the Target: Proofpoint’s Human-Centric Answer

Proofpoint, an innovator in the cybersecurity industry, has earned its reputation as a leader in email security and DLP. As the threat landscape evolves, Proofpoint has expanded its solutions, embracing a more holistic, human-centric approach.

April 16, 2024 Beyond IGA: SailPoint's Identity Security Cloud for the Modern Enterprise

Identity governance and administration (IGA) platforms have become essential for robust security strategies in modern enterprises. SailPoint, at the forefront of IGA solutions, has strategically expanded its capabilities to align with the growing demand for unified identity security. This note will examine the growing need for these platforms and SailPoint's transformation to address it.

April 12, 2024 Senhasegura: An Analysis of Their Cloud Entitlements CIEM Solution and How It Complements PAM

I have met with David from senhasegura several times. He explained this translates to Secure Password in Portuguese. Founded in Brazil and available in more than 60 countries, senhasegura is a leading cybersecurity firm specializing in Privileged Access Management (PAM), Certificate Lifecycle Management (CLM), and Cloud Infrastructure Entitlement Management (CIEM) solutions. Senhasegura is recognized as a global leader in PAM by top consulting firms and clients and has been consistently rated as a leader and challenger in various reports by analysts and industry experts. Senhasegura's PAM solution is known for its ease of use, good customization, unique key analysis features, and ability to meet rigorous auditing requirements.

April 04, 2024 Maximizing Security: Choosing the Best Multifactor Authentication Tool (MFA) for Your Company

"Fortresstify" your company's defenses with the right multifactor authentication (MFA) tool. This article dives deep into the world of MFA, exploring its features, key providers, and why cultivating a strong relationship with your chosen vendor is crucial. Discover how MFA can become your ultimate security ally, safeguarding your data and empowering a worry-free digital environment.

March 26, 2024 Acronis: Exploring Core Features, Differentiators, and Security Considerations

Acronis presents a compelling option for organizations seeking a comprehensive platform that merges reliable data protection with proactive cybersecurity measures.

March 21, 2024 Revolutionizing Data-Driven Decisions: The Cisco-Splunk Acquisition and Its Impact on CIOs and CTOs

Cisco consolidated its position as one of the largest software companies globally by completing the acquisition of Splunk.

March 08, 2024 The Rise of Answer Engines: Why Search Engines May Soon Be a Thing of the Past

AI-powered “answer engines” are revolutionizing the way the audiences retrieve information online. These engines respond to user queries with short, straight answers, unlike traditional search engines that show lists of links.

March 08, 2024 Zoho: Vision, Growth, and Global Expansion Themes at ZohoDay 2024

At ZohoDay24, the key themes were Zoho’s long-term growth strategy and social impact, Zoho’s financial performance and customer value proposition, Zoho’s unique approach to software development and AI, and Zoho’s global expansion and localization efforts.

February 29, 2024 Spoofing Be Gone: Abnormal Security Says Hasta la Vista, Baby, to Business and Vendor Email Compromise Scams

The conversation around security awareness training and phishing simulations has changed in the past year. The training and tools of the past simply aren’t working against today’s more sophisticated attackers. Abnormal Security can mitigate an assortment of the most common types of business and vendor email compromise.

February 23, 2024 AppViewX: Beyond PKI Automation – A Comprehensive Machine Identity Management Solution

In today's cybersecurity landscape, managing machine identities and digital certificates across complex, hybrid multi-cloud environments is a growing challenge. As the volume of digital certificates used to secure machines, applications, workloads, services, and devices continues to grow exponentially, organizations often struggle with a lack of visibility and manual processes, resulting in critical service outages and security vulnerabilities. AppViewX CERT+ is a next-generation automated certificate lifecycle management (CLM) solution that simplifies PKI and certificate management. It combines the best of automation, security, and insights to meet enterprise machine identity and digital trust requirements. AppViewX CERT+ features are purpose-built to address both the operational and security challenges of certificate management to, in turn, help organizations prevent application outages and security breaches. By enabling enterprise-wide crypto-agility, AppViewX CERT+ enhances machine identity trust, eliminates security gaps, promotes compliance, and supports post-quantum cryptography readiness.

February 23, 2024 Zscaler: Redefining Security in the Zero Trust Era

This analysis examines Zscaler's cloud-based security platform, with a focus on its Zero Trust Exchange (ZTE), Zero Trust Network Access (ZTNA), and broader suite of security solutions. It explores Zscaler's approach to overcoming the limitations of traditional VPN architectures, using artificial intelligence (AI) for threat detection, and integrating various security functionalities within a unified platform. Drawing insights from analyst demo notes, vendor information, and independent research, this analysis aims to provide a comprehensive and unbiased assessment of Zscaler's value proposition for security professionals.

February 07, 2024 Assessing Onfido: Combating Fraud With AI-Based Identity Verification

In the digital realm, trust is currency. Without robust identity verification, online interactions become a breeding ground for fraud and exploitation.

January 23, 2024 From Cloud Chaos to Controlled Confidence – Adaptive Shield’s Rise in SSPM

In the ever-evolving landscape of SaaS Security, one company has quietly forged its path, becoming a beacon of protection for large enterprises grappling with the growing complexity of SaaS applications. This is the story of Adaptive Shield, a rising star in the SaaS Security space, whose journey from a nimble startup to a recognized industry leader is as remarkable as the solutions it offers. Founded in 2019 by cybersecurity veterans Maor Bin and Jony Shlomoff, Adaptive Shield entered the scene with a bold vision: to address the growing blind spot in the SaaS ecosystem regarding enterprise security – including the dangers deriving from misconfigured security controls, lack of management regarding human and non-human identities, interconnected apps, and the detection of threats within these business-critical apps. Recognizing the exponential adoption of SaaS and the inherent risks it posed, the company set out to build a comprehensive shield, not just for individual applications, but for the entire interconnected SaaS ecosystem.

January 16, 2024 The CIAM Superhero – How LoginRadius Saves the Day

LoginRadius started as a simple social login provider but pivoted to create a comprehensive CIAM platform that now reaches over a billion consumers worldwide. My analyst demo with LoginRadius confirmed what they pride themselves on: delivering a user-friendly platform that simplifies CIAM implementation and management.

December 12, 2023 Conquering the Secrets Dilemma: A Real-World Case Study With GitGuardian

We should start by defining what a secret is. It’s really any piece of confidential information used to authenticate access to sensitive resources. This includes passwords, API keys, encryption keys, SSH keys, and other digital credentials. Many of the organizations I talk to have an application security program with some OWASP checks in the pipeline, some SAST, but rarely SCA or DAST testing. GitGuardian believes secrets detection and remediation is crucial for maintaining security and preventing unauthorized individuals from accessing sensitive information or disrupting critical systems. I agree and believe the value it can bring to an application security program is significant.

December 12, 2023 The Rise of AI in Application Security: An Analysis of Qwiet AI's Capabilities and Impact

Qwiet AI is a San Jose, California-based company that develops an AI-powered application security platform. The company's flagship product, preZero, uses machine learning to automate and accelerate application security testing, enabling developers to identify and remediate vulnerabilities early in the software development lifecycle (SDLC). Qwiet AI was founded in 2016 by a team of experienced cybersecurity professionals with a shared vision of empowering developers to build secure software. The company's mission is to "Prevent the Unpreventable" by providing a comprehensive and AI-driven solution that helps organizations of all sizes secure their applications from the very beginning.

November 28, 2023 AWS Launches Q Chatbot as It Positions Itself as the 'Steady Hand' for Enterprise AI

Q headlines a bevy of announcements at AWS re:Invent 2023 in Las Vegas that shed more light on the cloud service provider’s AI strategy and where its differentiation from other vendors lies.

November 06, 2023 Appdome: How to Shift Left Security and Build Secure Mobile Apps From the Start

It’s simply not enough today to pit your traditional application security toolkit against today’s advanced threats, especially those attacks that target APIs or mobile platforms. Bolstering your CI/CD pipeline by introducing more advanced and accurate SAST, SCA, IAST, and DAST will most certainly improve your security posture, but the journey does not end there. There are attacks and use cases that need careful consideration for how you approach security. Appdome believes it has those unknown challenges addressed and can significantly improve your application security program with very little effort from your development and security team, a welcome change from solutions that required a good bit of work to introduce problem-free into your code base four years ago.

November 06, 2023 Tips and Tricks to Setting Up and Configuring Your Kubernetes Cluster to Orchestrate Containers

This note outlines some tips and tricks that you should be aware of when embarking on the installation and configuration of a Kubernetes cluster. Such an endeavor should only be attempted if the need for an enterprise-grade container orchestration solution is required.

October 18, 2023 What Is Zoom in 2023?

This post provides a review of Zoom’s 2023 conference, Zoomtopia 2023. Core aspects covered include what major product releases and upgrades Zoom announced at Zoomtopia 2023, and what these announcements mean for Zoom’s market positioning in 2024.

October 17, 2023 Generative AI in the Enterprise Contact Center – Use Cases, ROI, and Preparation

Contact center as a service (CCaaS) enterprise providers are steamrollering ahead with embedding generative AI functionality in their platforms – whether organizations are prepared for it or not. In this post, I explore a positive outlook for how generative AI can be used to enhance organizations' customer experience capabilities while generating ROI. This includes: 1. Listing the major use cases for generative AI in the contact center. 2. Discussing how we might calculate ROI from utilizing generative AI in the contact center. 3. Considering what organizations can do to prepare for CCaaS vendors’ release of generative AI functionality.