Category: Identity

  • The CISO Job Market Has Fundamentally Changed

    The CISO Job Market Has Fundamentally Changed

    The CISO job market of 2026 is not the CISO job market of 2018. The skills, the compensation, the reporting structure, the board relationship, the budget authority, the legal exposure, all of these have shifted in ways that are reshaping what boards are looking for and what the role actually is.

  • The Second Life of the Password Manager in 2026

    The Second Life of the Password Manager in 2026

    The password manager the enterprise has been quietly deploying has been quietly developing a second life, the life the security team has been hoping for, the life the passkey has been quietly trying to replace.

  • The Honest State of the Passwordless MFA in 2026

    The Honest State of the Passwordless MFA in 2026

    The passwordless MFA in 2026 sits in a state the industry has been promising for ten years, the state where the marketing finally matches the deployment, the deployment the enterprise can actually land.

  • The Passkey Recovery Options Compared in 2026

    The Passkey Recovery Options Compared in 2026

    Passkey recovery options in 2026 are not the options the security team has been quietly offering, the backup key, the recovery code, the help desk override. Those three are still the fallbacks. The honest version sits in the trust model, the support cost, the failure mode the user actually has to live with.

  • Hardware Tokens: The Quiet Comeback

    Hardware Tokens: The Quiet Comeback

    The hardware token in 2026 has made a quiet comeback, with the YubiKey, the Titan, the Feitian all seeing the adoption that the push notification lost, with the hardware token sitting as the authentication that cannot be phished, that cannot be bypassed, that cannot be social engineered. The 2026 guide covers why the hardware token…

  • The Passkey Rollout That Actually Worked

    The Passkey Rollout That Actually Worked

    The passkey rollouts that actually worked in 2026 share the same pattern: the platform support sits in place, the user experience runs as smooth, the help desk runs ready, the metrics run visible. The rollouts that failed share the opposite pattern. The 2026 field guide covers what the working rollout looks like, what the failed…

  • A Field Guide to Phishing Resistant MFA

    A Field Guide to Phishing Resistant MFA

    Passwords died somewhere around 2022. The funeral for SMS codes happened in 2024. The survivors in 2026 sit at three: hardware keys, passkeys, certificate based auth. The choice between them runs as the choice the enterprise has been postponing for three years, and the postponement has cost enough breaches to retire the debate.

  • SSH Key Management: The Honest Guide

    SSH Key Management: The Honest Guide

    A field guide to SSH key management in 2026, with the inventory problem, the rotation problem, the trust problem, and the right way to actually manage the SSH keys in a production environment.

  • The Quiet Death of Passwords

    The Quiet Death of Passwords

    The password is dying. Not in a flashy way. In a slow, decade-long, regulatory-driven way that most users will not notice until one day they realize they have not typed a password in a year.

  • Non-Human Identity Attestation in 2026

    Non-Human Identity Attestation in 2026

    Non-human identity attestation is the work of knowing what every service account, every API key, every bot identity, and every machine credential can do, who owns it, when it was last used, and whether it is still needed. Most enterprises in 2026 have not done this work. The attackers know. The auditors are catching up.