How to Retire On-Premises Exchange or Harden the Hybrid Server You Must Keep
On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...
Insights
Articles in How-To & Hardening.
On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...
Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...
Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.
The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...
Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.
A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.
Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.
Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...
Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...
Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.
Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin...
Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.
SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...
Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.
Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.
Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...
A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.
You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and...
A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...
IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to...
External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.
Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that...
Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.
Insider risk monitoring touches employee privacy. This checklist helps make sure policies have the right sign-off before you enable them.