Category
Identity Governance
Access reviews, IGA architecture, lifecycle controls, and governance that holds up in practice.
The Evolution of Identity Governance and Administration (IGA) Over the Years
How IGA evolved across seven eras—from manual directory governance and compliance reviews to continuous governance for humans, machines, and AI agents.
The Certification That Never Was
A fictional story about a real IGA failure pattern: access reviews that create evidence of governance without governance actually happening.
Cloud Breaches Don't Start in the Cloud — They End There
Most compromises begin outside the cloud, then ripple inward through identity, federation, and trust chains.
The Guest User Blind Spot: Lessons from the Salesloft Breach
When an attacker can add a guest account without approvals or alerts, it's not a breach problem — it's an identity governance problem.
Weekend Read: What IGA Do You Use?
A roundup of practitioner takes on Okta, SailPoint, One Identity, Saviynt, Omada, midPoint, and Wren:IDM from a Reddit thread worth bookmarking.
Hacked Data, Real Projects, Fake Invoices: The Perfect Scam Recipe
A Plymouth fraud case shows how data theft plus social engineering can bypass every control you've built — by impersonating a vendor you already trust.
Unmasking a USPS Phishing Scam: A Sandbox Walkthrough
A 'delayed package' text from USPS landed in my inbox. Three checks in a sandbox were enough to confirm it was a phishing scam.
When the Phishing Email Is Real: Booking.com's Magic Link Problem
Scammers don't need to spoof Booking.com — they trigger it to send you a real login link. MFA doesn't help. Here's why.
Humans Are Still the Weakest Link — So Build for That
A LockBit ransomware attack on a bank started with one employee clicking a link. The lesson isn't 'train harder' — it's 'design assuming the click happens.'
RockYou2024: 10 Billion Passwords and Why Credential Stuffing Is the Real Threat
The leak itself isn't the danger — it's what attackers do with it next. A practical take on why MFA stopped being optional.
The Patelco Ransomware Attack: Anatomy of a Modern Breach
A credit union with $9B in assets and 400,000 members gets hit. Walking through how ransomware actually unfolds — and what the real impact looks like.
TeamViewer and Midnight Blizzard: When Password Sprays Find an Open Door
The TeamViewer breach is a textbook case of why MFA strength — not just MFA presence — is the line between an attempted attack and a successful one.
Detecting Phishing: How I Caught a Suspicious Email
Gmail's built-in filters didn't flag this one. Six small signals — none of them obvious individually — told the real story.