Category

Identity Governance

Access reviews, IGA architecture, lifecycle controls, and governance that holds up in practice.

Identity Governance Jul 12, 2026 · 3 min read

The Certification That Never Was

A fictional story about a real IGA failure pattern: access reviews that create evidence of governance without governance actually happening.

Identity Governance May 28, 2026 · 1 min read

Cloud Breaches Don't Start in the Cloud — They End There

Most compromises begin outside the cloud, then ripple inward through identity, federation, and trust chains.

Identity Governance Sep 9, 2025 · 1 min read

The Guest User Blind Spot: Lessons from the Salesloft Breach

When an attacker can add a guest account without approvals or alerts, it's not a breach problem — it's an identity governance problem.

Identity Governance Aug 30, 2025 · 1 min read

Weekend Read: What IGA Do You Use?

A roundup of practitioner takes on Okta, SailPoint, One Identity, Saviynt, Omada, midPoint, and Wren:IDM from a Reddit thread worth bookmarking.

Identity Governance Aug 31, 2024 · 2 min read

Hacked Data, Real Projects, Fake Invoices: The Perfect Scam Recipe

A Plymouth fraud case shows how data theft plus social engineering can bypass every control you've built — by impersonating a vendor you already trust.

Identity Governance Aug 19, 2024 · 2 min read

Unmasking a USPS Phishing Scam: A Sandbox Walkthrough

A 'delayed package' text from USPS landed in my inbox. Three checks in a sandbox were enough to confirm it was a phishing scam.

Identity Governance Jul 27, 2024 · 3 min read

When the Phishing Email Is Real: Booking.com's Magic Link Problem

Scammers don't need to spoof Booking.com — they trigger it to send you a real login link. MFA doesn't help. Here's why.

Identity Governance Jul 9, 2024 · 2 min read

Humans Are Still the Weakest Link — So Build for That

A LockBit ransomware attack on a bank started with one employee clicking a link. The lesson isn't 'train harder' — it's 'design assuming the click happens.'

Identity Governance Jul 5, 2024 · 2 min read

RockYou2024: 10 Billion Passwords and Why Credential Stuffing Is the Real Threat

The leak itself isn't the danger — it's what attackers do with it next. A practical take on why MFA stopped being optional.

Identity Governance Jul 3, 2024 · 2 min read

The Patelco Ransomware Attack: Anatomy of a Modern Breach

A credit union with $9B in assets and 400,000 members gets hit. Walking through how ransomware actually unfolds — and what the real impact looks like.

Identity Governance Jul 1, 2024 · 3 min read

TeamViewer and Midnight Blizzard: When Password Sprays Find an Open Door

The TeamViewer breach is a textbook case of why MFA strength — not just MFA presence — is the line between an attempted attack and a successful one.

Identity Governance Apr 30, 2024 · 3 min read

Detecting Phishing: How I Caught a Suspicious Email

Gmail's built-in filters didn't flag this one. Six small signals — none of them obvious individually — told the real story.