Tag: Identity
-

The Post-Vibe Engineering Org
Vibe coding was the 2025 trend where developers let AI generate the code without understanding it. The 2026 trend amounts to the post vibe engineering org, where the teams that survived vibe coding are rebuilding around the lessons. The post vibe org runs smaller, more senior, more focused on architecture and review, and a lot…
-

Multi-Cloud Is Not the Answer (But You Will Do It Anyway)
Multi-cloud sits as the strategy the consulting firm sold the board in 2019 and the operations team has been trying to make work since. The pitch was vendor lock in avoidance, the cost optimisation, the resilience. The reality sits as the second cloud account nobody can fully account for, the second identity system nobody wants…
-

The Cloud Misconfiguration Tax You Are Paying
The cloud misconfiguration tax shows up in three places. Most organisations do not see all three. Here is what you are actually paying, and what the fix costs.
-

Session Token Theft Has Replaced Password Theft (And You Are Not Ready)
Infostealer logs have made session token theft the dominant credential attack. The password is no longer the thing the attacker wants. The session is. Here is what to do about it.
-

The Non-Human Identity Problem You Have Not Mapped Yet
Service accounts, API keys, OAuth tokens, machine certificates. The non-human identity surface in 2026 is larger than the human one, and almost nobody has mapped it.
-

Why SSO Isn’t Magic and Your Service Account Problem Is Worse
Single sign on solved the human password problem. It did not solve the service account problem. The service account problem is now larger than the human password problem was in 2015.
-

The Most Important Cybersecurity Story of 2025
Picking one story is unfair. Picking one story is also the only way to focus the lesson. Here is the 2025 story that mattered most, and the three it would have been if you asked me tomorrow.
-

Passwordless Is a Five Year Project, Not a Five Month Project
The companies that are treating passwordless like a five month project are the ones whose roadmaps have slipped twice and will slip a third time. The reason it is a five year project is that passwordless is a migration you manage.