10 Most Impactful PAM Use Cases for Enhancing Organizational Security

November 21, 2024 at 08:33AM Privileged Access Management (PAM) is crucial for enhancing cybersecurity. It minimizes risks by enforcing the principle of least privilege, automating access permissions, and monitoring user activity. PAM also supports compliance, mitigates insider threats, and secures remote and cloud access. Implementing solutions like Syteca strengthens organizational security effectively. ### Meeting Takeaways … Read more

Will passkeys ever replace passwords? Can they?

November 17, 2024 at 01:43PM The text discusses the concept of passkeys, a secure alternative to passwords, defined by the WebAuthn specification. While passkeys enhance security and reduce phishing risks, implementation issues and user experience challenges hinder widespread adoption. A systematic approach to security must prioritize user-friendliness to ensure effectiveness in protecting against online threats. … Read more

The true (and surprising) cost of forgotten passwords

November 14, 2024 at 11:16AM Password resets are costly, averaging $70 per reset, impacting productivity, innovation, and security. With employees averaging two resets annually, organizations can incur significant expenses. Implementing self-service password reset solutions can save about $65,000 annually by reducing helpdesk dependency, wait times, and enhancing user experience, particularly for hybrid workforces. ### Meeting … Read more

Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms

October 24, 2024 at 07:39AM Bitwarden’s new build requirements have raised concerns about its status as free and open-source software (FOSS). A recent GitHub discussion highlighted that the SDK needed for compilation is not free, prompting comparisons to other companies that have shifted away from open-source principles. Alternatives exist but may require more user management. … Read more

NIST Drops Password Complexity, Mandatory Reset Rules

September 26, 2024 at 08:32AM NIST’s latest password guidelines (SP 800-63-4) no longer recommend using a mix of character types or regular password changes. They suggest CSPs stop mandating specific password types and periodic changes, and reduce knowledge-based authentication usage. The new guidelines stress a minimum 15-character length, allowing up to 64 characters, and incorporating … Read more

Why ‘Never Expire’ Passwords Can Be a Risky Decision

September 23, 2024 at 08:06AM The text discusses the impact of password expiry policies, exploring the reasons behind them and the potential drawbacks. It highlights concerns about weak password reuse, IT burden, and compromised password risks. It also suggests implementing a comprehensive password strategy, advocating for longer and stronger passwords alongside measures to detect compromised … Read more

The Silver Bullet of MFA Was Never Enough

August 22, 2024 at 06:53AM Recent attacks on high-profile organizations are drawing comparisons to action movies, where the hero triumphs over adversity with a magical solution. Multi-factor authentication (MFA) is seen as a silver bullet, but it’s not foolproof. Social engineering can bypass MFA, and other security measures like passkeys and device posture checks are … Read more

UK govt links 2021 Electoral Commission breach to Exchange server

July 30, 2024 at 08:06AM The U.K.’s Information Commissioner’s Office (ICO) announced that the Electoral Commission was breached in August 2021 due to unpatched Microsoft Exchange vulnerabilities. Around 40 million people’s personal information was compromised, leading to the ICO reprimanding the commission for inadequate security measures. The breach has been linked to state-backed hacking groups … Read more

For Service Accounts, Accountability Is Key to Security

April 18, 2024 at 08:42AM Over 32 years in cybersecurity, managing risks related to service accounts has been a constant challenge. Service accounts should have limited access and perform specific functions. However, managing and securing them is often overlooked. Common gaps in knowledge include lack of visibility and understanding of the necessity and ownership of … Read more

Ivanti Releases Fixes for More Than 2 Dozen Vulnerabilities

April 17, 2024 at 02:38PM Ivanti has released 27 fixes for vulnerabilities in its 2024 first-quarter release. None are actively exploited. Users are advised to download the Avalanche installer and update to version 6.4.3 to apply the fixes. The vulnerabilities have CVSS scores ranging from 4.3 to 9.8. Ivanti recommends users keep their MSSQL database … Read more