Tag: Identity

  • Hardware Tokens: The Quiet Comeback

    Hardware Tokens: The Quiet Comeback

    The hardware token in 2026 has made a quiet comeback, with the YubiKey, the Titan, the Feitian all seeing the adoption that the push notification lost, with the hardware token sitting as the authentication that cannot be phished, that cannot be bypassed, that cannot be social engineered. The 2026 guide covers why the hardware token…

  • 2026: The Mid Year Cybersecurity Review

    2026: The Mid Year Cybersecurity Review

    Halfway through 2026, the threat landscape has done the usual thing of mutating faster than the people defending it expected. The first half gave us three patterns worth noticing: supply chain attacks still lead, identity attacks crossed a threshold, and AI became both a weapon and a target.

  • The Passkey Rollout That Actually Worked

    The Passkey Rollout That Actually Worked

    The passkey rollouts that actually worked in 2026 share the same pattern: the platform support sits in place, the user experience runs as smooth, the help desk runs ready, the metrics run visible. The rollouts that failed share the opposite pattern. The 2026 field guide covers what the working rollout looks like, what the failed…

  • SSH Key Management: The Honest Guide

    SSH Key Management: The Honest Guide

    A field guide to SSH key management in 2026, with the inventory problem, the rotation problem, the trust problem, and the right way to actually manage the SSH keys in a production environment.

  • The Quiet Death of Passwords

    The Quiet Death of Passwords

    The password is dying. Not in a flashy way. In a slow, decade-long, regulatory-driven way that most users will not notice until one day they realize they have not typed a password in a year.

  • The State of IAM in Q2 2026

    The State of IAM in Q2 2026

    The state of IAM in Q2 2026 amounts to the state of an industry that has been promising identity first security for a decade and that has finally started to deliver on the promise. The delivery runs in the maturity of the cloud identity providers, the federation standards, the privileged access management market, the non…

  • Non-Human Identity Attestation in 2026

    Non-Human Identity Attestation in 2026

    Non-human identity attestation is the work of knowing what every service account, every API key, every bot identity, and every machine credential can do, who owns it, when it was last used, and whether it is still needed. Most enterprises in 2026 have not done this work. The attackers know. The auditors are catching up.

  • The Service Account Attestation Problem

    The Service Account Attestation Problem

    The service account attestation problem is the largest unknown risk in the typical enterprise. The defender who solves the attestation problem has solved a category of breach the defender did not know existed. Here is the approach.

  • The Machine Identity Attestation Problem

    The Machine Identity Attestation Problem

    Machine identity attestation in 2026 amounts to the work of knowing what every workload, every container, every service mesh identity, every machine credential, every certificate, every API token can do, who owns it, when it was last rotated, whether it sits still needed. Most enterprises in 2026 have not done this work. The 2026 guide…

  • A Field Guide to the IAM Policy

    A Field Guide to the IAM Policy

    Most IAM policies in 2026 are written the way the IAM team learned to write them, which is to say they are written to satisfy the auditor and not the attacker. The result is a sprawl of over privileged roles, a stack of unused permissions, and a service account inventory that has not been touched…