When a database security incident happens, everyone turns to the security team. We look for a simple root cause analysis, and then we add a control, tighten a policy, and maybe even buy a silver bullet tool. We feel progress! But the incident didn’t start there. It started years earlier,…Read more
Database security has often been treated as a final checkpoint before release. But DevSecOps ensures security is integrated throughout the DevOps process, making compliance more efficient, reducing manual effort, and ensuring organizations stay ahead of evolving threats.Read more
The Open Web Application Security Project (OWASP) is a nonprofit foundation focused on improving the security of software. They have all sorts of projects, presentations, and educational content, but one of the things they are most known for is the OWASP Top Ten. This is an annual report on the…Read more
It seems every week there’s a new data breach to read (or tweet) about. I recently discovered this lovely visualization of the growing amount of private data about people like you and me that is being exposed. You can filter and/or sort the data by industry sector, method of leak…Read more