Category

Identity Governance

Access reviews, IGA architecture, lifecycle controls, and governance that holds up in practice.

Identity Governance Aug 1, 2026 · 11 min read

The Evolution of Identity Governance and Administration (IGA) Over the Years

How IGA evolved across seven eras—from manual directory governance and compliance reviews to continuous governance for humans, machines, and AI agents.

Identity Governance Jul 12, 2026 · 3 min read

The Certification That Never Was

A fictional story about a real IGA failure pattern: access reviews that create evidence of governance without governance actually happening.

Identity Governance May 28, 2026 · 1 min read

Cloud Breaches Don't Start in the Cloud — They End There

Most compromises begin outside the cloud, then ripple inward through identity, federation, and trust chains.

Identity Governance Sep 9, 2025 · 1 min read

The Guest User Blind Spot: Lessons from the Salesloft Breach

When an attacker can add a guest account without approvals or alerts, it's not a breach problem — it's an identity governance problem.

Identity Governance Aug 30, 2025 · 1 min read

Weekend Read: What IGA Do You Use?

A roundup of practitioner takes on Okta, SailPoint, One Identity, Saviynt, Omada, midPoint, and Wren:IDM from a Reddit thread worth bookmarking.

Identity Governance Aug 31, 2024 · 2 min read

Hacked Data, Real Projects, Fake Invoices: The Perfect Scam Recipe

A Plymouth fraud case shows how data theft plus social engineering can bypass every control you've built — by impersonating a vendor you already trust.

Identity Governance Aug 19, 2024 · 2 min read

Unmasking a USPS Phishing Scam: A Sandbox Walkthrough

A 'delayed package' text from USPS landed in my inbox. Three checks in a sandbox were enough to confirm it was a phishing scam.

Identity Governance Jul 27, 2024 · 3 min read

When the Phishing Email Is Real: Booking.com's Magic Link Problem

Scammers don't need to spoof Booking.com — they trigger it to send you a real login link. MFA doesn't help. Here's why.

Identity Governance Jul 9, 2024 · 2 min read

Humans Are Still the Weakest Link — So Build for That

A LockBit ransomware attack on a bank started with one employee clicking a link. The lesson isn't 'train harder' — it's 'design assuming the click happens.'

Identity Governance Jul 5, 2024 · 2 min read

RockYou2024: 10 Billion Passwords and Why Credential Stuffing Is the Real Threat

The leak itself isn't the danger — it's what attackers do with it next. A practical take on why MFA stopped being optional.

Identity Governance Jul 3, 2024 · 2 min read

The Patelco Ransomware Attack: Anatomy of a Modern Breach

A credit union with $9B in assets and 400,000 members gets hit. Walking through how ransomware actually unfolds — and what the real impact looks like.

Identity Governance Jul 1, 2024 · 3 min read

TeamViewer and Midnight Blizzard: When Password Sprays Find an Open Door

The TeamViewer breach is a textbook case of why MFA strength — not just MFA presence — is the line between an attempted attack and a successful one.

Identity Governance Apr 30, 2024 · 3 min read

Detecting Phishing: How I Caught a Suspicious Email

Gmail's built-in filters didn't flag this one. Six small signals — none of them obvious individually — told the real story.