<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[To Do or Not To Do]]></title><description><![CDATA[What if there was a reason behind every security, compliance and DevOps decision?]]></description><link>https://todo.adaptive.live</link><image><url>https://substackcdn.com/image/fetch/$s_!ZPUB!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7225b39-e421-428b-b5dc-dfa2194b4ed1_1200x1200.png</url><title>To Do or Not To Do</title><link>https://todo.adaptive.live</link></image><generator>Substack</generator><lastBuildDate>Sun, 05 Apr 2026 20:17:03 GMT</lastBuildDate><atom:link href="https://todo.adaptive.live/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Adaptive Automation Technologies Inc.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[adaptivelive@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[adaptivelive@substack.com]]></itunes:email><itunes:name><![CDATA[Ronak Massand]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ronak Massand]]></itunes:author><googleplay:owner><![CDATA[adaptivelive@substack.com]]></googleplay:owner><googleplay:email><![CDATA[adaptivelive@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ronak Massand]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Good vibes, bad vibes]]></title><description><![CDATA[PS. This site is not a GPT-generated blog. This blog is written with passion, so a full read would be appreciated. All the opinions expressed here are purely the author's opinion.]]></description><link>https://todo.adaptive.live/p/good-vibes-bad-vibes</link><guid isPermaLink="false">https://todo.adaptive.live/p/good-vibes-bad-vibes</guid><dc:creator><![CDATA[Debarshi Basak]]></dc:creator><pubDate>Wed, 04 Jun 2025 18:23:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5d2f685c-0f35-45a6-b898-02876ba62b4e_2400x1260.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>The Good Vibes</strong></h3><p>In 2014, when I joined the workforce, moving from Eclipse to JetBrains' IntelliJ was world-changing for me. The key reason for moving to JetBrains' IDE was IntelliSense. For decades, JetBrains was the dominant IDE player. However, since I switched to GitHub Copilot, my productivity has improved by 40% (as measured by issue resolution).</p><p>Several people have been recommending that I try using Cursor. I was happy in my world, using Github Copilot to autocomplete all mundane boilerplate codes. Although I was reluctant, I went ahead and installed it anyway.</p><p>First prompt: Alright, it is like an GPT-embedded IDE. The second prompt has been entered, and it works excellently. In the third and fourth prompts, I noticed something intriguing in my behavior. I did not even want to explore the files it was generating. I felt both physical and mental resistance to exploring the code and editing it manually. This kind of behavior shift toward programming is something I had not experienced before. While IntelliJ's IntelliSense was productive, it did not result in a significant change in behavior. This hit differently. The change did feel like a radical shift. You can argue it is a VS Code clone with prompt executors stitched together, but the complete experience is behavior shifting. It feels powerful, full of serendipity.</p><h3><strong>The bad vibes</strong></h3><p>People seem to instinctively kick and abuse humanoids when they see them. I believe that people have a similar instinct when it comes to using AI-generated code. After using Cursor for over a week, I realized that I was not valuing the code generated by the IDE. My second instinct was that I would be hesitant to use it on our core product. My hesitation may stem from the belief that an AI IDE could generate code better than I can; consequently, this fear might act as a barrier, particularly regarding support, operations, and maintenance.</p><p>Autocomplete from GitHub Copilot is ok, as it is just boilerplate code, but with Cursor touching multiple files, you often have a tendency to click Accept All because that's the behavior it induces. After generating several projects, I realized that you end up with a project that looks like a 3rd-party product but then you own it, rather than having no ownership. Another key observation was that I was transforming deterministic codes into probabilistic codes. Although the code generated was correct almost all the time, theoretically, changing a variable name transforms a deterministic operation into a probabilistic one.</p><p>Giving a cursor to junior engineers is like giving a chainsaw or a road roller to a teenager. If you lack the necessary knowledge to use it effectively or comprehend its side effects and technicalities, you risk causing irreversible damage.</p><p>There are specific use cases for AI-native IDEs, back-office software, and internal tools; these are scenarios where the software is considered disposable, business cases are not the primary focus, and we are developing low-ROI tools that do not require architectural discussions or team alignments.</p><p>We generated a few projects using the cursor tool.</p><h4><strong>Superclass</strong></h4><p>We designed the Superclass project to classify various types of documents, including PDFs, images, and text.</p><p><a href="https://github.com/adaptive-scale/superclass">https://github.com/adaptive-scale/superclass</a></p><h4><strong>Blacklight</strong></h4><p>Scan Google Drive, S3 buckets, and local file systems for secrets, tokens, and sensitive information.</p><p><a href="https://github.com/adaptive-scale/blacklight">https://github.com/adaptive-scale/blacklight</a></p>]]></content:encoded></item><item><title><![CDATA[Complying to Compliance - SOC2, HIPAA, PCI, HITRUST, SOX and more!]]></title><description><![CDATA[Hey, y'all!]]></description><link>https://todo.adaptive.live/p/complying-to-compliance-soc2-hipaa</link><guid isPermaLink="false">https://todo.adaptive.live/p/complying-to-compliance-soc2-hipaa</guid><dc:creator><![CDATA[Ronak Massand]]></dc:creator><pubDate>Mon, 19 Dec 2022 02:25:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Wvga!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hey, y'all! The end of the year is almost here, and the holidays are coming too! This time of year is all about self-reflection and making plans for the future. When it comes to planning, it's important for organizations to think about their security and compliance goals for the coming year. There are tons of articles out there about how to implement different compliance frameworks, but not many of them explain why they're important or what they're protecting. So don't sleep on it - make sure you've got your compliance game on lock in the coming year. </em></p><h2>Understanding Compliance as a way of life!</h2><p>The formal definition of compliance is &#8216;<strong>the act of obeying an order, rule, or request.&#8217;</strong> I&#8217;m going to come out and say exactly what you&#8217;re thinking &#8220;Gee, that sounds terrible!&#8221; And this is one of the biggest problems with compliance - it has a bad PR problem! The moment someone thinks of compliance, the words that come to mind are; boring, legal, enterprise, risk-averse, costly - don&#8217;t think I need to go on.</p><p>In fact, I even had a hard time convincing myself that this would be a worthy topic to write about. So what changed? I started looking at compliance through a different lens - not some certification or audit that is necessary for your organization but a safety net that ensures the protection of consumers and employees. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wvga!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wvga!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wvga!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1052924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wvga!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Wvga!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c744c1c-016c-47d6-b84b-06936a77a7e6_2388x1668.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">"With great compliance comes great responsibility."</figcaption></figure></div><p>Let&#8217;s take a real-world example - one that many of us are familiar with - the FTX and SBF saga! FTX was&nbsp;registered with and licensed by the Commodity Futures Trading Commission <em><strong>(CFTC),</strong></em> an independent U.S. government agency that&nbsp;regulates the U.S. derivatives markets, including futures, options, and swaps. The company was operating mainly out of the Bahamas. <br><br>In spite of the CFTC license, FTX,  like much of crypto, wasn&#8217;t regulated. No compliance, no rules!  Without compliance and regulations in place, SBF started engaging in questionable practices, such as using customer funds to invest in Alameda Research, a crypto trading firm co-founded by none other than SBF himeself! This ultimately resulted in retail investors losing billions of dollars.</p><p>It is quite obvious that if FTX were operating in a regulated environment, much like any financial services firm, just the complex ownership structure shared by Alameda and FTX would have violated a bunch of compliances. In a regulated environment, there would have been checks and balances on how customer funds could be used, which could have prevented people from losing their hard-earned money.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!csE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!csE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!csE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!csE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!csE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!csE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1584600,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!csE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!csE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!csE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!csE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f7bae5-10e0-4782-ac9f-71a5d17f169b_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;Hopefully people can learn from the difference between who I was and who I could have been.&#8221; </figcaption></figure></div><p>So if I&#8217;d like readers to have one takeaway from this piece - Compliance is not just about licenses and certifications. It's about protecting people from being cheated or losing their money. If you care about your customers and their data, it's time to take compliance seriously.</p><p>Consider the following for your next compliance thought exercise: Do you have control over customer data and dollars, and do you care about ensuring that innocent people are not harmed by your mistakes or carelessness? If the answer to both of these questions is YES, it's time to take compliance seriously!</p><h2>Cost of Compliance and of non-compliance!</h2><p>If you are still not convinced about taking compliance seriously, it&#8217;s best to look at numbers objectively. The financial costs of non-compliance are steep. <a href="https://static.helpsystems.com/globalscape/pdfs/guides/gs-true-cost-of-compliance-data-protection-regulations-gd.pdf">According to a study on 53 multinational organizations by Ponemon Institute and Globalscape</a>, the findings were really interesting:</p><ul><li><p>The average cost of compliance is $5.47M, whereas the average cost of non-compliance is $14.82M.</p></li><li><p>On average, organizations lose $5.87 Million in revenue due to a single non-compliance event.</p></li><li><p>Organizations lose an average of $4 million in revenue due to a single non-compliant event.</p></li></ul><p>So clearly, it is financially a lot more lucrative for organizations to stay compliant rather than stay non-compliant. In addition to the financial costs, non-compliance can also result in damage to an organization's reputation and loss of customer trust, further compounding the negative effects. </p><p>Overall, taking compliance seriously is crucial for the long-term success and stability of any organization.</p><h2>All the right rules in all the right frameworks, so yeah, we&#8217;re going down!</h2><p>Now let&#8217;s get to the main section of this article, understanding all different compliance frameworks. It's important to examine these frameworks not just as a list of rules, but as a way to protect certain aspects of your customers, such as their privacy, financial information, and protected health information. If your organization handles any of these customer attributes, you may need to obtain compliance certification. To fully comprehend these frameworks, it's helpful to focus on the customer attributes they are designed to protect, rather than solely on implementation details.</p><p>Once you look at different compliance frameworks from this lens, you will immediately know if it&#8217;s right for your organization or not - which is always our goal at To Do or Not To Do!</p><p>We are going to cover the following frameworks:</p><ul><li><p>SOC2</p></li><li><p>HITRUST</p></li><li><p>HIPAA</p></li><li><p>SOX</p></li><li><p>PCI</p></li></ul><h3>SOC2: Keeping private information private</h3><p>SOC 2 is a set of &#8216;Standards for Organization Control (SOC) that includes the security, availability, processing integrity, confidentiality, and privacy of a company's systems. SOC 2 reports are designed to provide assurances to customers that a company is maintaining appropriate controls to protect their data and ensure the availability of its services.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y-bv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y-bv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y-bv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:718597,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y-bv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!y-bv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F34adf7c6-d39b-4e60-a0ee-3ab81f28af28_2173x1251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Customer Attributes:</strong></h4><p>The customer attributes protected by SOC 2 are those related to the integrity of the customer's data, as well as their privacy and confidentiality. This could include things like the customer's personal identifiable information (PII) - Name, Date of Birth, Social Security Number (SSN), financial information, and other sensitive data.</p><h3>HIPAA - So that sick-notes don&#8217;t end up on TikTok</h3><p>The Health Insurance Portability and Accountability Act of 1996, commonly known as HIPAA, is a set of federal laws that establishes national standards for the privacy, security, and transmission of protected health information (PHI). HIPAA compliance is regulated by the Department of Health and Human Services (HHS) and enforced by the Office for Civil Rights (OCR). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fw6h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fw6h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fw6h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:743138,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fw6h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!Fw6h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F735a3955-91dd-4c02-9d4e-f0b9733988b2_2173x1251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Customer Attributes:</strong></h4><p>HIPAA protects customer attributes related to their medical information, including their personal and demographic information, medical history, diagnostic and treatment information, and other sensitive medical data. HIPAA applies to a wide range of entities, including healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates who handle medical information on their behalf.</p><h3>PCI DSS - So that card info doesn&#8217;t end up on the Dark Web</h3><p>PCI, or Payment Card Industry (PCI) compliance, refers to the standards set by the Payment Card Industry Security Standards Council for protecting cardholder data. To become PCI compliant, companies must meet the Payment Card Industry Data Security Standard (PCI DSS) requirements for things like network architecture, access controls, encryption, and security assessments. This helps protect against security breaches and data theft and is often required for companies that accept credit card payments.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9MqB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9MqB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9MqB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:725341,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9MqB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!9MqB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44061993-d17b-4888-b744-a6d4a5bf1b0f_2173x1251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Customer Attributes:</strong></h4><p>The customer attributes protected by PCI DSS are those related to payment card information, such as the cardholder's name, account number, expiration date, and security code (CVV). PCI DSS applies to any entity that stores, processes, or transmits payment card information, including merchants, payment processors, and financial institutions</p><h3>SOX: Keeping organization accounts accountable!</h3><p>The Sarbanes-Oxley Act (SOX) is a federal law that establishes standards for public company boards, management, and public accounting firms to improve the accuracy and reliability of financial reporting. It was enacted in response to corporate accounting scandals and applied to all publicly traded companies in the US, as well as foreign companies with securities listed on a US stock exchange. It is enforced by the US Securities and Exchange Commission (SEC).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zusb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zusb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!zusb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!zusb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!zusb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zusb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:557256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zusb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!zusb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!zusb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!zusb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a03613-4c1e-4bda-80b2-18c5fe6bd24d_2173x1251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Customer Attributes:</strong></h4><p>SOX does not specifically protect customer attributes but rather aims to ensure the accuracy and reliability of a company's financial reporting. This can indirectly protect customers by providing them with confidence in the financial information provided by the company and reducing the risk of fraud or other financial misconduct.</p><h3>HITRUST really deserves some HIPRAISE! </h3><p>The Health Information Trust Alliance (HITRUST) was founded in 2007 to provide a comprehensive framework for protecting sensitive information and managing compliance. The organization's "HITRUST approach" is particularly helpful for healthcare organizations but can be applied to companies in other sectors as well.</p><p>HITRUST certification enables companies to demonstrate their compliance with HIPAA requirements using a standardized framework. By becoming HITRUST certified, vendors and covered entities can show that they have the necessary controls and processes in place to protect sensitive information.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GCwN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GCwN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GCwN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:679508,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GCwN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 424w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 848w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!GCwN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45daddec-5218-48d6-b565-6b211dbc4db8_2173x1251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Customer Attributes:</strong></h4><p>HITRUST is designed to protect any information that can be used to identify an individual or that is considered sensitive or confidential. This can include a wide range of customer attributes, depending on the type of organization and the information it collects and processes. This can include any or all of the following:</p><ul><li><p>Personal identification information, such as name, date of birth, and social security number</p></li><li><p>Health information, such as medical history, treatment plans, and test results</p></li><li><p>Financial information, such as payment information and billing records</p></li><li><p>Personal preferences, such as communication preferences and language preferences</p></li></ul><h2>What does it take to achieve compliance and truly stay compliant?</h2><p>This is a question dreaded by many organizations because focusing on compliance really does take significant time and resources. While I won&#8217;t go into the specifics of each compliance standard, let me provide a framework that can be applied to all of them when it comes to implementation.</p><p>The main goal of any compliance framework is to ensure that the business stays compliant at all times. Compliance implementation involves creating systems, processes, and documents that demonstrate the organization's commitment to protecting customers and employees and following industry laws. It's a way to minimize risk.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!52sk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!52sk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 424w, https://substackcdn.com/image/fetch/$s_!52sk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 848w, https://substackcdn.com/image/fetch/$s_!52sk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 1272w, https://substackcdn.com/image/fetch/$s_!52sk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!52sk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png" width="1456" height="608" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112653,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!52sk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 424w, https://substackcdn.com/image/fetch/$s_!52sk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 848w, https://substackcdn.com/image/fetch/$s_!52sk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 1272w, https://substackcdn.com/image/fetch/$s_!52sk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff267c6fa-d35c-44c1-8e7c-a4ec09a710ae_2388x998.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now processes and documentation are still relatively well-understood parts of compliance, and while rigorous, they can be figured out with the right resources and knowledge. However, building the right systems for compliance can be tricky for many organizations. This involves putting controls in place to measure and validate security, such as background checks for employees, role-based access control over infrastructure, audit logs, and penetration tests.</p><p>There are tools that can help organizations accelerate the compliance process. Companies like Drata, Vanta, and SysDig offer solutions for building the right processes, documentation, and systems to meet various compliance frameworks.</p><p>Adaptive's product also helps organizations with infrastructure access and IT compliance. Our privileged infrastructure access management platform audits every query, eliminates credential sprawl, and reduces threat vectors. This not only helps organizations stay secure and continuously compliant, but also reduces a lot of the overhead and work needed for evidence-gathering during audits.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!watk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!watk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 424w, https://substackcdn.com/image/fetch/$s_!watk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 848w, https://substackcdn.com/image/fetch/$s_!watk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 1272w, https://substackcdn.com/image/fetch/$s_!watk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!watk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png" width="1456" height="1497" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1497,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:583391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!watk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 424w, https://substackcdn.com/image/fetch/$s_!watk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 848w, https://substackcdn.com/image/fetch/$s_!watk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 1272w, https://substackcdn.com/image/fetch/$s_!watk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5d0c90a4-dc39-414b-89f6-4690db7611bd_2386x2454.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://todo.adaptive.live/subscribe?"><span>Subscribe now</span></a></p><h2>Compliance isn&#8217;t for me - I believe in YOLO! </h2><p>It really wouldn&#8217;t be a To Do or Not To Do piece if we don&#8217;t steel-man the other position (thanks <a href="https://twitter.com/theallinpod">@all-in-pod</a>)! </p><p>Compliance can often seem like a distraction or a nuisance to organizations. It is only natural for members of any organization to defer or even altogether ignore compliance, at least during the earlier stages. The arguments against compliance tend to sound something like this:</p><ul><li><p>Nothing&#8217;s really happened in spite of us staying non-compliant. So what&#8217;s the point?</p></li><li><p>Compliance seems like a huge investment of time and resources and is a legit distraction. Let&#8217;s worry about this later.</p></li><li><p>Would anyone ever find out if we are not compliant?</p></li><li><p>Why should I worry about compliance when the org is really small, there is no product-market fit, and there are not many employees or customers?</p></li></ul><p>Now all of the above points are valid. Fundamentally, you wouldn&#8217;t want to focus on compliance at the risk of business taking a hit - that makes no sense. </p><p>But the counterpoint is any or all of the above thoughts can often lead to a situation where the organization realizes that they need to get compliant quickly, but often it&#8217;s already too late - case in point, FTX! While it may be tempting to prioritize other aspects of your organization over compliance, the potential costs and risks of non-compliance far outweigh the time and resources invested in maintaining compliance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://adaptive.live/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5vq1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5vq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:298247,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://adaptive.live/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5vq1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5vq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F73c91ff8-c726-4a92-ac54-3c516e0eb446_1610x788.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Make SSO great again!?]]></title><description><![CDATA[Or Not ?!]]></description><link>https://todo.adaptive.live/p/make-sso-great-again</link><guid isPermaLink="false">https://todo.adaptive.live/p/make-sso-great-again</guid><dc:creator><![CDATA[Ronak Massand]]></dc:creator><pubDate>Wed, 30 Nov 2022 12:31:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/h_600,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi everyone, I&#8217;m excited to be back with our 3rd column of the &#8216;To Do or Not To Do&#8217; series. In this piece, we look at &#8216;Single Sign-on&#8217; and dissect its good, bad, and ugly.</em></p><p><em>The bad? The ugly? Wait, are we suggesting that SSO could be better and there is more to consider while implementing it? Yessir - the world isn&#8217;t perfect (nowhere close!), and there are these small minor things called tradeoffs that need to be considered while making important decisions - especially ones that involve high-stakes infrastructure security impacting every employee in the organization. But worry not; this is why we&#8217;re here!</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K3kD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K3kD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K3kD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1322329,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K3kD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!K3kD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc836854d-86ff-4df8-b150-7d4771b42c83_4776x3336.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What is SSO? How it works?</h1><p>I&#8217;ll try my best to explain the SSO concept without any jargon.</p><p>Single sign-on (SSO) is an authentication method that allows a user to securely sign in to multiple applications and services using just one set of credentials, e.g., username and password. The SSO system is made to work through an identity provider where the user&#8217;s identity and credentials are anchored. This identity provider interacts with all applications and services by exchanging trust certificates or tokens containing the identity information needed to authenticate the user. This is how it works:</p><ul><li><p>When a user tries to log in to any website, the service provider sends a token to the identity provider with some information (mainly the user&#8217;s email address) to authenticate the user.</p></li><li><p>Suppose the identity provider has already authenticated the user. In that case, a confirmation token will be sent back to the service provider, which contains the user&#8217;s identity, and they&#8217;ll be logged in.</p></li><li><p>If the user is not authenticated, they&#8217;ll have to enter their credentials once, and upon validation, the identity provider will send the confirmation token to log the user in.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gzis!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gzis!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gzis!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1023404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gzis!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!Gzis!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1691fac9-44a6-4723-8f8e-fbd928dd18ed_4776x3336.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul><p>Now, this same log-in workflow can stay consistent for the user across all different applications and services that are tethered to the identity provider.</p><h1>Evolution of SSO protocols</h1><p>There are many SSO protocols (heads up - jargons!) - there&#8217;s LDAP, there&#8217;s SAML, there&#8217;s CAS, and then there&#8217;s OAuth - I promise we aren&#8217;t making these terms up.</p><p>They all represent different authentication protocols that have been around since the early 90s! Here&#8217;s a timeline of when they were created:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XUu8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XUu8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 424w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 848w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 1272w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XUu8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png" width="1456" height="788" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:788,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1001494,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XUu8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 424w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 848w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 1272w, https://substackcdn.com/image/fetch/$s_!XUu8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fce3835c8-b1e3-4e33-965f-d8d497df9e15_4776x2584.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">They all thought they would really be the last one&#8230;</figcaption></figure></div><p>Every authentication protocol has a specific use case and, like everything else in the world, has both pros and cons. In the next section, let's look at all these different protocols and their benefits and tradeoffs:</p><p></p><h3>Lightweight Directory Access Protocol (LDAP)</h3><p>Even though LDAP is often clubbed into various authentication protocols, it really is a directory and access management protocol that defines how one should talk to a directory server. Most systems use LDAP to talk to a directory, retrieve user accounts, verify them and retrieve attributes associated with them.</p><p><strong>Pros: </strong>Works well for on-premise authentication.</p><p><strong>Cons</strong>: Extremely complex to set up and painful to maintain. Users have to set up new accounts for external services.</p><p></p><h3><strong>Security Assertion Markup Language (SAML)</strong></h3><p>SAML is an XML-based framework for describing and exchanging assertions that applications across security domain boundaries can trust. e.g., a typical assertion from an identity provider (IdP) would convey, &#8220;This user is John Doe, with the email address of john.doe@example.com, and was authenticated using a password mechanism.&#8221; Depending on its access policies, a service provider (SP) could use this information to grant John Doe web SSO access to local resources. <a href="http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html">[Spec]</a></p><p><strong>Pros: </strong>Ability to control employee access across different services and domains, including external ones.</p><p><strong>Cons: </strong>Due to the complexity, SAML has been mostly confined to enterprises and academia.</p><p></p><h3><strong>Central Authentication Service (CAS)</strong></h3><p>Central Authentication Service (CAS) is a single sign-on protocol where the authentication process can only happen on the CAS server. Applications that authenticate with CAS never see the user&#8217;s credentials.</p><p><strong>Pros: </strong>Credentials are less likely to get compromised as applications never see them.</p><p><strong>Cons</strong>: CAS leaves the authorization to the application itself <a href="https://csguide.cs.princeton.edu/publishing/cas">[ref]</a>.</p><p></p><h3>OpenID</h3><p>OpenID was created to solve SSO for non-enterprise end users. It allowed end users to specify URLs as their identifiers. e.g., An end user claiming <em>http://www.example.com </em>as their identifier would include a link to their IdP in the HEAD section of the HTML document served by <em>http://www.example.com</em>. OpenId was never widely used but led to the evolution of OIDC. <a href="https://openid.net/specs/openid-authentication-1_1.html">[spec]</a></p><p><strong>Pros: </strong>The authentication is offloaded to the OpenID provider, and their security systems can be leveraged. Anyone can become an OpenID Provider without requiring third-party registration/approval.</p><p><strong>Cons: </strong>The support for OpenID extensions is inconsistent from provider to provider. This makes it difficult and cumbersome to implement. Moreover, OpenID&#8217;s relying parties can only be web apps.</p><p></p><h3><strong>OAuth</strong></h3><p>While SAML and OpenID enabled end users (Resource Owners) to SSO for protected resources, there was still no mechanism to authorize applications to directly access users&#8217; resources without the end user's credentials. OAuth enabled this by verifying not only the end user&#8217;s authorization to access the resource but also the application's identity that makes the resource request. e.g., applications using Google&#8217;s API often rely on OAuth to act on behalf of the end user. <a href="https://www.rfc-editor.org/rfc/rfc5849">[spec]</a></p><p><strong>Pros: </strong>Uses API calls extensively, which is why mobile applications, modern web applications, game consoles, and the Internet of Things (IoT) devices find OAuth a better experience for the user</p><p><strong>Cons: </strong>OAuth leaves out the decision of several specifics to implementors, e.g., token types, vulnerabilities, and interoperability issues. OAuth was not designed as a general end-user authentication service and required proprietary add-ons.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you are enjoying this article, consider subscribing to see us in your inbox!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>SSO is flawless! No, really, not one issue with it.</h1><p>Now that we understand all the different protocols let&#8217;s look at why SSO as a system has been the best thing since sliced bread (NOT!).</p><p>There are a lot of advantages to SSO, and no one denies that, but it does come with a fair share of problems and implementation challenges.</p><p></p><h3>Onboarding so good, we feel like hiring people all the time! <br>Offboarding so good, we feel like firing people... Oops!</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1bxB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1bxB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 424w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 848w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 1272w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1bxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png" width="1456" height="878" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:823132,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1bxB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 424w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 848w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 1272w, https://substackcdn.com/image/fetch/$s_!1bxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38a9bcf9-e9d2-4473-9d2b-ccf34e0dcc5f_4776x2880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Common Narrative</strong></h4><p>SSO relieves the pressure on IT help desks while onboarding and off-boarding employees. SSO streamlines the onboarding/off-boarding process by reducing the number of individual access requests from employees. Sure! All of that seems excellent, but you should also know some of the issues that come with it.</p><h4>What they don&#8217;t tell you</h4><p>When SSO is used to provision users in downstream apps, that process becomes opaque to the organization. This sometimes results in users having residual access to downstream apps despite being removed from the SSO directory.</p><p>The SSO mechanism, especially OAuth, relies on access tokens and refresh tokens being exchanged between the identity provider and the service provider. Refresh tokens should ideally have an expiry date on them. But the problem arises when expiry is not configured correctly, and the downstream application has to set a default in that scenario. Often the default value is never set, and hence the token never expires.</p><p>Now, if the user is removed from the identity provider but NOT explicitly logged out, they might still be able to access the downstream application. If you want to gauge the scale of this problem, organizations with more than 1,000 employees use 150+ SaaS and infrastructure applications. The higher the number of apps, the more susceptible the organization is to encountering this issue.</p><p></p><h3>So secure! Is this Fort Knox or what!</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VzYV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VzYV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VzYV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2174955,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VzYV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!VzYV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F81124fb5-8663-4c08-961c-ff4c028b4a72_4776x3336.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Common Narrative</strong></h4><p>SSO reduces the number of attack surfaces because users only log in once every day and only use one set of credentials. If login for each user happens only through a single set of credentials, the organization's security posture improves.</p><h4><strong>What they don&#8217;t tell you</strong></h4><p>The irony of implementing SSO is that the very thing that makes it secure is also a huge security risk!</p><p>SSO is more concerned with providing access than with restricting it. Login credentials are a major focus for external attackers - <a href="https://www.verizon.com/about/news/verizon-2021-data-breach-investigations-report">61% of data breaches involve credential data</a>.</p><p>If a user&#8217;s SSO credentials get compromised, the hacker or intruder can access all applications, environments, and services. SSO is usually associated with critical resources so the resulting damage will be pretty bad for an organization.</p><p></p><h3>IT teams are just loving resource management through SSO!</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DWkk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DWkk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 424w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 848w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 1272w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DWkk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png" width="1456" height="1254" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2947213,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DWkk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 424w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 848w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 1272w, https://substackcdn.com/image/fetch/$s_!DWkk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0072276b-59f1-4372-83c1-c6709f9b8eb3_4776x4114.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Common Narrative</strong></h4><p>SSO provides a unified way to manage all your apps and services through one dashboard. It provides IT teams with an easy way to keep track of all different employees and the apps and services they have access to.</p><h4><strong>What they don&#8217;t tell you</strong></h4><p>SSO introduces a single point of failure in the organization. If, for some reason, the SSO service goes down due to the identity provider going offline, users lose access to all apps, app servers, and services. It goes without saying that this situation will be highly disruptive to any organization.</p><p>The roadmap for implementing SSO is long. The process to configure each app with an identity provider consists of many-many steps and can take weeks, if not months, per application.</p><p>Moreover, SSO cannot be applied everywhere &#8211; it is mainly used with web, mobile, and desktop applications. However, SSO does not support infrastructure resources like VMs, Kubernetes clusters, and databases.</p><p></p><h3>SSO is brilliant for access management!</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JRug!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JRug!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!JRug!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!JRug!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!JRug!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JRug!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1261336,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JRug!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 424w, https://substackcdn.com/image/fetch/$s_!JRug!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 848w, https://substackcdn.com/image/fetch/$s_!JRug!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 1272w, https://substackcdn.com/image/fetch/$s_!JRug!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8f51e21b-8ef7-476e-9820-d16f7020095d_4776x3336.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Common Narrative</strong></h4><p>With the move to the cloud, employees are using more and more apps in the workplace. Requiring separate usernames and passwords for each app is a huge burden for employees and, frankly, is unrealistic. Signing in once saves time, thus improving employee productivity. Since 68% of employees switch between ten apps every hour, eliminating multiple logins can save a company significant time and money. Single sign-on reduces that cognitive burden, not just for employees but also for IT teams.</p><h4><strong>What they don&#8217;t tell you</strong></h4><p>The principle of least privilege required for various compliance measures commands users to have minimum access to data, applications, and systems required to do their job. If they need elevated access, it should be done through separate credentials. Both these things cannot be achieved easily in SSO as the setup entails giving access with a single authentication.</p><p>Moreover, SSO might be good for authentication but doesn&#8217;t work for authorization. Enterprise systems like SAML leave the authorization to the individual apps and services. So much of the groundwork is needed to assign the correct privileges to each employee, which still happens in the downstream resource.</p><h1>Make SSO great again!</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!534f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!534f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 424w, https://substackcdn.com/image/fetch/$s_!534f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 848w, https://substackcdn.com/image/fetch/$s_!534f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 1272w, https://substackcdn.com/image/fetch/$s_!534f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!534f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png" width="1456" height="833" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:833,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1711460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!534f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 424w, https://substackcdn.com/image/fetch/$s_!534f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 848w, https://substackcdn.com/image/fetch/$s_!534f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 1272w, https://substackcdn.com/image/fetch/$s_!534f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab2956da-35f6-451d-9189-9b981c3026b3_4776x2732.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The ideal way to set up SSO is to use it with an access control plane, especially for critical resources. This setup solves some of the significant shortcomings that are mentioned above. Let&#8217;s look at them one by one:</p><h4><strong>Wider reach</strong></h4><p>An access control plane can help enable SSO for infrastructure resources that wouldn&#8217;t be possible otherwise, e.g., databases, VMs, and Kubernetes clusters.</p><h4><strong>Security &amp; Auditability</strong></h4><p>An access plane can help improve the security posture. Since the access plan contains multiple access proxies in a federated setup, no single-point attack vector can bring down the resources.</p><p>Additionally, an access plane enables auditability into the resources. This helps organizations detect any attacks from internal or external sources.</p><h4><strong>Authorization &amp; Permissioning</strong></h4><p>An access plane can help automate authorization and assigning roles while onboarding and offboarding people. Moreover, the access plan keeps checking for residual access and ensures users are correctly deprovisioned from downstream apps and services.</p><h4><strong>Efficient Implementation</strong></h4><p>Lastly, having an access plane streamlines the SSO implementation. Since the access control abstracts the downstream resources, the service configuration has a minimal footprint.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zKTQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zKTQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 424w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 848w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 1272w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zKTQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png" width="1456" height="737" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:737,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1019250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zKTQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 424w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 848w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 1272w, https://substackcdn.com/image/fetch/$s_!zKTQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7541be9f-1e42-434d-ada0-bae5c3ab1fa1_3298x1670.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s no denying that SSO is a critical technology and is here to stay. Every organization, at some point in its journey, would need to implement SSO. However, what&#8217;s important is to understand all the different challenges and nuances while implementing SSO so that you can solve all its limitations.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://adaptive.live" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iKq_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 424w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 848w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 1272w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iKq_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131263,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://adaptive.live&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iKq_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 424w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 848w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 1272w, https://substackcdn.com/image/fetch/$s_!iKq_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F05e73e9e-5931-43fd-a191-01d97a195a75_1610x788.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[Do we trust Zero-Trust?]]></title><description><![CDATA[or NOT ?!]]></description><link>https://todo.adaptive.live/p/do-we-trust-zero-trust</link><guid isPermaLink="false">https://todo.adaptive.live/p/do-we-trust-zero-trust</guid><dc:creator><![CDATA[Ronak Massand]]></dc:creator><pubDate>Wed, 16 Nov 2022 12:48:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/h_600,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi everyone, &#128075;</em></p><p><em>In our next column of the &#8216;To Do or Not To Do&#8217; series, we look to understand whether organizations should implement and trust Zero Trust architecture? Zero Trust is one of the most widely used security concepts, yet ironically, one of the least understood ones. Hopefully, through this column, you will have a good understanding of the Zero Trust concept, why it was created, what it takes to implement Zero Trust, and whether it&#8217;s right for you.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!puGA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!puGA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!puGA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!puGA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!puGA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!puGA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:892568,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!puGA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!puGA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!puGA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!puGA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd157a6af-fb73-42b7-ad61-2bbad9ab5427_2388x1668.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Who knew that Johnny Johnny is the OG Zero Trust model! </figcaption></figure></div><h2>The current state of cyber attack</h2><p>Cloud adoption has lowered the barrier to building new software. On the flip side, it has given rise to new attack vectors that hackers can use to exploit infrastructure vulnerabilities. This is a story best told in numbers:</p><ul><li><p>Globally,&nbsp;<strong>30,000 websites</strong>&nbsp;are hacked daily</p></li><li><p><strong>64% of companies</strong>&nbsp;worldwide have experienced at least one form of a cyber attack</p></li><li><p>There were&nbsp;<a href="http://(https://www.securitymagazine.com/articles/97046-over-22-billion-records-exposed-in-2021#:~:text=There were 4%2C145 publicly disclosed,5%25 fewer than in 2020.)">22 billion</a>&nbsp;breached records in 2021</p></li><li><p>In 2021, ransomware cases grew by&nbsp;<a href="https://www.securitymagazine.com/articles/97166-ransomware-attacks-nearly-doubled-in-2021#:~:text=Ransomware%20attacks%20rose%20by%2092.7,2020%20and%202%2C690%20in%202021.).**">92.7%</a></p></li><li><p><strong>Every 39 seconds,</strong>&nbsp;there is a new attack somewhere on the web.</p></li></ul><p>Traditional security practices aren&#8217;t sufficient anymore, and the world is realizing we need more sophisticated mechanisms to prevent cyber attacks.</p><h2>Enter Zero-Trust</h2><p>Coming from the world of traditional security, we're all too familiar with the concept of perimeter-based security. You can access specific resources when connected to a corporate LAN, and you've been verified as trusted. The problem is that this type of security model relies on trust&#8212;and while it's great for keeping people in, it's not so great for keeping them out.</p><p>But what if the default security posture of an organization was NOT to trust anyone? Enter zero trust architecture (ZTA). The main concept behind zero trust is "never trust, always verify.&#8221; This means that no device and no user is trusted by default, even if they are connected to a permissions network such as a corporate LAN or even if they were previously verified. </p><p>The Zero Trust model revolves around three core principles:</p><h4><strong>Never Trust, Always Verify</strong></h4><p>Always authenticate and authorize based on all available data points, including user identity, location, device health, service, and anomalies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pEf3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pEf3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pEf3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:387343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pEf3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!pEf3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F889c70f8-5edb-4576-8115-51547372bee2_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Principle of least privileged access</strong></h4><p>Limit user access with just-in-time and just-enough-access (JIT/JEA).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bkW3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bkW3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bkW3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:903592,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bkW3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!bkW3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95f033fd-9279-4e99-abb0-faa1a69fc15a_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Always assume breach</strong></h4><p>Verify end-to-end encryption and use analytics to get visibility, drive threat detection, segment access and improve defenses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!phlc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!phlc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!phlc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!phlc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!phlc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!phlc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:767877,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!phlc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!phlc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!phlc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!phlc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d847fb3-9fdf-4b99-8386-67434cc41a47_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Great, so how do I implement Zero-Trust?</h2><p>I wanted to do a little research on Zero Trust implementation to see the existing literature out there, and I started questioning if the whole thing is just an SEO term being pushed by big tech. On searching &#8216;Zero Trust&#8217; on the ever-reliable Google, over 30% of results on page 1 and over 40% of results on page 2 were sponsored websites by large security companies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n_5P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n_5P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 424w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 848w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 1272w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n_5P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png" width="1456" height="776" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1689415,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n_5P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 424w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 848w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 1272w, https://substackcdn.com/image/fetch/$s_!n_5P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F60d624bd-6279-43ab-916a-c405619ac8d5_2880x1534.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Google search results for &#8216;Zero Trust&#8217;</figcaption></figure></div><p>The strange thing about Zero Trust is that every company has a different interpretation and implementation of it. So we thought it&#8217;s best to look at Zero-Trust from first principles and understand why it was created in the first place.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://todo.adaptive.live/subscribe?"><span>Subscribe now</span></a></p><h2>The right question: Why was Zero Trust created?</h2><p>In the early 90s, the internet started gaining adoption, and that unlocked new modes of sharing information across the world. But this came with a new level of risk that couldn&#8217;t be eliminated by cryptographic methods, the foundation of our security stack. As more and more information was being shared through the internet, we were forced to rethink our approach to <strong>trust</strong>.</p><p>That's what Stephen Paul Marsh did in his doctoral thesis at the University of Stirling in April 1994, and he coined the word &#8216;Zero Trust&#8217; to rethink computer security. Marsh's work studied trust as something finite that can be described mathematically&#8212;that it transcends human factors such as morality, ethics, lawfulness, justice, and judgment. Marsh proposed a security model where all users, devices, and networks are treated as untrusted and treated with the same level of scrutiny. The core idea of Marsh&#8217;s thesis was to &#8220;never trust - always verify.&#8221;</p><p>In 2009,&nbsp;Google&nbsp;implemented a zero-trust architecture referred to as&nbsp;<a href="https://en.wikipedia.org/wiki/BeyondCorp">BeyondCorp</a>. It started as an internal Google initiative to enable every employee to work from untrusted networks without the use of a VPN. BeyondCorp shifts access decisions from the network perimeter to individual users and devices, thereby enabling employees to work securely from any location.</p><p>In recent years, the rise of cloud computing, remote work adoption, and the increase in mobile devices have made it difficult to maintain a perimeter-based security model. Zero Trust is seen as a response to this new reality, as the traditional security perimeter has become more and more porous. This has been the reason for zero trust gaining popularity in recent years.</p><h2>Understanding Zero Trust implementation at Bird-App through the lens of Rahul Ligma</h2><p>Now that we have established why Zero Trust is becoming more and more important for organizations let&#8217;s actually try to understand the &#8216;how&#8217; of it more deeply. Let&#8217;s first take a look at all the components that are included in a Zero Trust architecture:</p><h4>Zero Trust Components</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mdkn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mdkn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 424w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 848w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 1272w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mdkn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png" width="1456" height="1150" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1150,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1143965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mdkn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 424w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 848w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 1272w, https://substackcdn.com/image/fetch/$s_!mdkn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F530eba61-d713-4bdd-88e5-19796e0b2f98_2547x2012.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We think the best way to understand Zero Trust implementation is to see how the above components fit into an organization&#8217;s infrastructure set-up and how they impact the employees. We chose Bird-App and its most real (NOT!) employee Rahul Ligma for this.</p><p>For readers who need a bit more context, here is a little help:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/greg16676935420/status/1586088462788206592?s=20&amp;t=GXCAE_9VQqjEWmRzSmHX4w&quot;,&quot;full_text&quot;:&quot;Turns out &#8220;Rahul Ligma&#8221; was not actually fired from Twitter, but instead was just some random dude with a box  that got CNBC with a Ligma Nuts joke &quot;,&quot;username&quot;:&quot;greg16676935420&quot;,&quot;name&quot;:&quot;greg&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Oct 28 20:12:12 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FgLrC9iX0AI_NZc.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/zVoPIf5ker&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:13891,&quot;like_count&quot;:190174,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>As a part of this section, we&#8217;ll dive into the Zero Trust components and map them to Bird-App&#8217;s set-up as well as how they impact Rahul.</p><p><em><strong>PS: The below story is a fictional representation and as true as Rahul&#8217;s employment</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vgBk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vgBk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vgBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2881550,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vgBk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!vgBk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F381b4c94-9b31-4d83-ac57-3edf1c96b250_3186x2226.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h4>Rahul&#8217;s first day at Bird-App!</h4><p>Rahul&#8217;s first day at Bird-app is going fantastic, and he sees the HR and IT Manager for onboarding!</p><p>Bird-App maintains its employee directory in Okta for SSO and uses two-factor Authentication (MFA) for access. The company also uses Certn for the background verification of each employee.</p><ul><li><p>Rahul completes his background verification on Certn, which requires him to provide <strong>proof</strong> <strong>of</strong> <strong>identity</strong> using a government-issued ID. <em><strong>User (Identity, Authentication)</strong></em></p></li><li><p>Rahul receives a managed device with certificates installed to verify device identity and compliance. <em><strong>Device (System of Record)</strong></em></p></li><li><p>After verification is successfully cleared, the IT manager adds Rahul to Okta&#8217;s user directory, and he gets a digital identity for <strong>authenticating</strong> himself inside Bird-App. <em><strong>User (Authentication)</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5XDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5XDA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5XDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2573458,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5XDA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!5XDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2e859e-9873-48d1-8ba5-0e4c837565a6_3186x2226.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> </p></li></ul><h4>Rahul needs infrastructure access to push code!</h4><p>Bird-App&#8217;s infrastructure set-up consists of Kubernetes clusters, VMs, and Databases - all hosted on the cloud. The company&#8217;s infrastructure resources are all protected by IAM and <em><strong>Microsegmentation</strong></em>.</p><blockquote><p><em><strong>Microsegmentation</strong></em> is isolating workloads in a network in order to limit the effect of malicious lateral movement. It is either <strong>Agent-based (built into the host), Network-based (SDN, VPN, switches), or Native cloud-provided (Security group, Azure firewall, Google cloud firewalls)</strong>.</p></blockquote><p>Bird-App has set up a VPN as an access proxy that requires a certificate to access the microsegmentation, and IAM resides in AWS.</p><p>The star that Rahul is, he puts on some LoFi music and starts writing code. Now he needs access to staging RDS to test his application before he can create a pull request on GitHub. This is what Rahul&#8217;s infrastructure access journey looks like:</p><ul><li><p>Rahul uses the client certificates installed in his laptop to connect to the network segment via VPN as an access proxy. <em><strong>Network (Microsegmentation)</strong></em></p></li><li><p>Rahul needs to first authenticate himself either via static credentials or SSO using a two-factor authentication system from his company laptop. <em><strong>User (Authentication)</strong></em></p></li><li><p>Once Rahul&#8217;s identity are verified, the IAM checks whether Rahul&#8217;s device has read-write permissions to the staging DB or not, and accordingly grants access for testing. <em><strong>Device (System of Record), Infrastructure (Least Privilege)</strong></em></p></li><li><p>Once the testing is done, Rahul logs into GitHub via SSO, creates a pull-request and waits for the approval from his team lead for the code to be reviewed and deployed. <em><strong>Application</strong></em><strong> (</strong><em><strong>Authorization</strong></em><strong>)</strong></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mpeo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mpeo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mpeo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/fc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3272001,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mpeo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!Mpeo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc4d5060-cbd8-4ce8-830a-b1ae66502a2e_3186x2226.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h4>Rahul is a star, becomes a team lead! In charge of access and compliance now.</h4><p>Rahul has an exceptional year at Bird-app and becomes a team lead! Rahul has new responsibilities to manage infrastructure access, security and compliance processes at Bird-App.</p><p>The company uses Splunk as a Security Information and Event Management platform (SIEM) to observe user behaviour by logging all real time communication between Zero Trust components and actors. In order to ensure compliance:</p><ul><li><p>Rahul makes sure all customer data is isolated and encrypted at both transit and rest. <em><strong>Data (Encryption)</strong></em></p></li><li><p>Rahul ensures infrastructure audit logs are in place to understand exactly &#8220;Who did What&#8221; and are being sent to SIEM so that alerts can be built on them. <em><strong>Visibility &amp; Analytics (User behavior)</strong></em></p></li><li><p>Rahul creates explicit policies so that no team member can write to production DB. User needs to obtain special break-glass privileges during an incident in order to override the policy. <em><strong>Infrastructure (Authorization)</strong></em></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9AwW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9AwW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9AwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3253960,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9AwW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!9AwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1413be-27ca-4d2d-a0c4-3d189beae90b_3186x2226.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>Bird-App gets acquired, and Rahul is let go.</h4><p>Well we all knew from the beginning how this was going to end, so Rahul being let go from the Bird App is hardly a surprise for anyone (except for Rahul maybe).</p><p>HR updates their records to indicate Rahul is no longer an employee at Bird-App. Before Rahul is off-boarded, the resources owned by him are transferred to another team lead. Eventually, Rahul is removed from Okta&#8217;s user directory.</p><ul><li><p>Rahul no longer has access to Bird-App&#8217;s infrastructure resources. <em><strong>User, Infrastructure</strong></em></p></li><li><p>Rahul returns his laptop to the HR. <em><strong>Device</strong></em><br></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bjgo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bjgo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bjgo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3001192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bjgo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 424w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 848w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 1272w, https://substackcdn.com/image/fetch/$s_!bjgo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F162d4fbb-b727-451b-ab0d-c3269ca93e62_3186x2226.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Finally Rahul collects his box of things and exits the premises as seen in the iconic pic below:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/elonmusk/status/1586108809772089345?s=20&amp;t=1Xjc6gMfObdKzJjOfuJ4fg&quot;,&quot;full_text&quot;:&quot;Ligma Johnson had it coming &#127814; &#128166; &quot;,&quot;username&quot;:&quot;elonmusk&quot;,&quot;name&quot;:&quot;Elon Musk&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Oct 28 21:33:03 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FgL9jc1UcAAPyqT.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/CgjrOV5eM2&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:63581,&quot;like_count&quot;:673695,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div></li></ul><h3></h3><h2>Cost of Zero Trust, is it really worth it for your organization?</h2><p>Now that we understand that Zero Trust improves the security posture of an organization, let&#8217;s also take a more pragmatic look to understand if it&#8217;s right for you.</p><p>A zero-trust policy affects nearly everyone in an organization, so all leaders, managers, and developers need to buy into this approach. Getting an alignment like this, especially at a large organization, takes months, if not years, and that doesn&#8217;t even account for the implementation timeline. BeyondCorp, for example, took years to implement at Google.</p><p>Even today, there is no off-the-shelf tool/service that can transition you to a zero-trust architecture overnight and do it for all of your network/applications. Moreover, threats on the internet keep evolving, making security an ongoing investment. So committing to a Zero Trust philosophy is not just a one-time process, but a mindset that requires continuous investment in resources, training, implementation, and maintenance.</p><p>If your business is young and a breach will have a low impact, you probably <strong>don&#8217;t need a full-blown zero-trust implementation just as yet</strong>. You could just start with a couple of basic good practices like making sure the network's use is always verified, and no-one has more privileges than required.</p><h2>The need for Zero-Trust in the new world</h2><p>Organizations have been talking about Zero Trust since the early 2000s, so why is it suddenly getting so popular? Well, the simple answer is that we live in a new world, especially after covid-19. There are a few trends that are being unfolded in real-time:</p><ul><li><p>Sensitive Geopolitical situation</p></li><li><p>The Great Resignation 2021, followed by the market crash of 2022, creates a transient workforce</p></li><li><p>Generative AI creates a new identity impersonation problem</p></li></ul><h4>Sensitive Geopolitical situation</h4><p>The world is in an extremely delicate place right now as global tensions are at an all-time high. While physical wars are still being fought today, it is common knowledge that the war of the future is going to be through cyber attacks.</p><p>In order to tackle this, private and public companies need to improve their security posture proactively.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/erikodbeeck/status/1473074719624777737?s=20&amp;t=0OY_97kI55IMla8gLlyS-A&quot;,&quot;full_text&quot;:&quot;Future war stories. <span class=\&quot;tweet-fake-link\&quot;>#Cyber</span> the new battlefield. &quot;,&quot;username&quot;:&quot;erikodbeeck&quot;,&quot;name&quot;:&quot;Erik Op de Beeck&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Mon Dec 20 23:35:56 +0000 2021&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FHD2AH6XoAIflKp.png&quot;,&quot;link_url&quot;:&quot;https://t.co/Igj6OtbFFk&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:13,&quot;like_count&quot;:40,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><h4>The Great Resignation of 2021 followed by the great market crash of 2022 creates a transient workforce</h4><p>According to the U.S. Bureau of Labor Statistics,&nbsp;over 47 million Americans voluntarily&nbsp;quit their jobs&nbsp;in 2021 &#8212; an unprecedented mass exit from the workforce that is now widely being called the Great Resignation. This has been followed by the market crash in 2022, that led to mass layoffs in the tech industry - Twitter, Meta, Stripe, and many more!</p><p>Workforce today is more transient than ever, which can lead to ex-employees still having residual infrastructure access if keys and credentials are not actively updated.</p><h4>Generative AI creates a new identity impersonation problem</h4><p>We have all seen first hand how far generative AI has come in the last few months. There is very little doubt that the technology is going to be great for the world. However, it also brings a unique set of challenges. With generative AI, bots can finally pass the Turing Test, originally called the imitation game by Alan Turing in 1950. For folks that need a refresher, this is a test of a machine's ability to exhibit intelligent behaviour equivalent to, or indistinguishable from, that of a human. As bots get smarter, there is a risk that they can impersonate employees making organizations more susceptible to intelligent phishing attacks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XCkn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XCkn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XCkn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1215930,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XCkn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!XCkn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fab03bdd2-2541-4440-bb33-cf41af29ad11_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Trends accelerating Zero Trust adoption</figcaption></figure></div><p>This culmination of the above trends leaves no choice for organizations but not to &#8216;trust&#8217; anyone and always &#8216;verify&#8217; their identity, aka Zero Trust! The realm of network and application security is changing rapidly, and Zero trust provides a framework to adapt to this changing landscape. Our opinion is that in this new world, implementing Zero Trust is not an &#8216;if&#8217; but a &#8216;when&#8217; question. However, the Zero Trust implementation shouldn&#8217;t be blindly followed based on whitepapers and guides. Instead, every organization should objectively evaluate its stage, risk, and the vertical they operate in and implement different elements of Zero Trust that are applicable to them.    </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://adaptive.live" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ywPd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 424w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 848w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 1272w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ywPd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:129702,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://adaptive.live&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ywPd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 424w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 848w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 1272w, https://substackcdn.com/image/fetch/$s_!ywPd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7c0de9c-dbb1-42d9-becb-7dd15e0545aa_1610x788.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>                                          Thanks for reading To Do or Not To Do!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://todo.adaptive.live/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Sharing infrastructure access with developers]]></title><description><![CDATA[or NOT ?!]]></description><link>https://todo.adaptive.live/p/sharing-infrastructure-access-with</link><guid isPermaLink="false">https://todo.adaptive.live/p/sharing-infrastructure-access-with</guid><dc:creator><![CDATA[Ronak Massand]]></dc:creator><pubDate>Wed, 02 Nov 2022 16:18:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Fv5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fv5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fv5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fv5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1925577,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fv5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Fv5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F537bfaef-5f59-495b-a197-747bc82a58fd_2388x1668.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">What do we say to the Gods of incident resolution? Not Today!</figcaption></figure></div><p><em>Hi everyone, &#128075;</em></p><p><em>We are very excited to bring you the &#8216;<strong>To Do or Not To Do</strong>&#8217; series. The goal of this series is to explore various nuances and trade-offs that organizations should consider while making security, compliance, infrastructure or DevOps decisions. If you find yourself in a position where you need to take a certain infrastructure decision, it is our hope that this column will provide a framework to think through all the different variables around it.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading To Do or Not To Do! </p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><em>While there are a lot of great technical blogs out there that focus on implementation, we feel there isn&#8217;t enough content on the strategic and business reasons behind engineering decisions.</em></p><p><em>In our first newsletter, we focus on whether <strong>organizations should share infrastructure access with the team members or not.</strong> This has become quite a critical question post-covid as companies are still adapting to the remote set-up. Also, a lot of recent high-profile stories like the Twitter whistleblower incident and the Uber &amp; crypto hacks have created an urgency in organizations to really think through their infrastructure access strategies.</em></p><div><hr></div><h2>Cost of Unsupervised Access</h2><p>Before we dive deeper into the why/ how of infrastructure access management, it is important to understand what happens when you don&#8217;t have a strategy.</p><p>Unsupervised access often leads to compromised credentials, which then lead to data breaches. Data breaches in organizations have been increasing at an alarming rate of 15% every year since 2015. In the US alone, the <a href="https://www.statista.com/statistics/273550/data-breaches-recorded-in-the-united-states-by-number-of-breaches-and-records-exposed/">number of data breaches</a> has gone up from just 785 in 2015 to more than 1800 cases in 2021.</p><p>And these data breaches are extremely expensive to an organization. An average data breach costs about $4.35M and 19% of the breaches are caused due to compromised credentials - Hence, unsupervised access is extremely dangerous and expensive!</p><p>In fact, what happened at Uber recently is a perfect example of a hack caused due to compromised credentials.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/ManieshNeupane/status/1576951998876090375&quot;,&quot;full_text&quot;:&quot;Stages of Attack on Uber !\n<span class=\&quot;tweet-fake-link\&quot;>#uberbreach</span> <span class=\&quot;tweet-fake-link\&quot;>#uberhack</span> &quot;,&quot;username&quot;:&quot;ManieshNeupane&quot;,&quot;name&quot;:&quot;Looser&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Mon Oct 03 15:07:09 +0000 2022&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FeJ1fDuaAAAuImm.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/lzUZ4jvsHS&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:11,&quot;like_count&quot;:60,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><h2>Okay, great - unsupervised access is expensive. But why care about this now?</h2><p>There are a few trends in the tech industry, all gaining momentum at the same time that have forced organizations to start thinking about their infrastructure access strategy.</p><p>Trend 1: Covid-19 forces companies to go remote-first</p><p>Trend 2: Increased Cloud Adoption</p><p>Trend 3: Compliance Requirements becoming more important and moving downstream to early-stage companies</p><p>Trend 4: Crypto creates new financial incentives for hackers!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nMbL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nMbL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 424w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 848w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nMbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png" width="1456" height="767" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:767,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1025239,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nMbL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 424w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 848w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!nMbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3554121-0dfb-405f-9061-00cb923000ed_3168x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;The Great Migration&#8221;, Every tech office in March 2020</figcaption></figure></div><h3>Trend 1: Covid-19 forces companies to go remote-first</h3><p>In March 2020 Covid struck, and it completely transformed the operating paradigm of the world - not just for people, but also for organizations. Remote work went mainstream in an unnaturally rushed timeline, and the consequence was organizations not getting enough time to think through all the different dimensions and processes in order to adapt to this change sustainably.</p><p>Tech companies were the quickest to respond to covid and moved to work-from-home policies. They promoted remote collaboration, virtual setups, and the use of cloud services and quickly embraced the new normal of remote work culture. For example, by mid-2020, <a href="https://www.cnbc.com/2020/12/25/tech-ahead-of-covid-curve-at-every-stage.html">Facebook had planned</a> to employ more than 50% of its workforce to work remotely over the next 5 years.</p><p>Organizations are forced to reimagine their infrastructure access management policies and processes in this new remote-first world.</p><h3>Trend 2: Increased Cloud Adoption</h3><p>Nothing screams validation of cloud adoption like AWS revenues, which went from $3.1 Billion in 2014 to $61.5 Billion in 2021.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NNVJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NNVJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 424w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 848w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 1272w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NNVJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png" width="1456" height="1735" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1735,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6187832,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NNVJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 424w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 848w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 1272w, https://substackcdn.com/image/fetch/$s_!NNVJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a7b8ba5-6d52-4839-b125-6d100ed3be16_4000x4766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: https://medium.com/fact-of-the-day-1/76e48e0f83a3</figcaption></figure></div><p>Cloud adoption has been a major help for tech-first companies to maintain business continuity as well as growth during covid. While other sectors struggled to stay afloat during the pandemic, the tech-first companies did quite well during the same time. During covid, Amazon went on a hiring spree and onboarded close to 275,000 employees in these 6 months, which is a great validation that cloud adoption really helped maintain business continuity.</p><p>A common infrastructure setup that companies used in the pre-covid era was setting up an on-premise server and a perimeter network to restrict access. However, this onset of cloud adoption has changed how infrastructure is set up resulting in the need for new access policies.</p><h3>Trend 3: Compliance Requirements becoming more important and moving downstream to early-stage companies</h3><p>Zero Trust has changed the way companies operate and infrastructure access is one of the most critical components that ensure compliance. In the next article, we&#8217;ll dive into Zero Trust and why it is an important security measure.</p><p>These days, even Seed and Series A stage organizations are forced to adhere to compliance standards like SOC 2, ISO 27001, and HIPAA - especially if they operate in regulated industries. Most organizations scramble to gather evidence while going through compliance audits and also struggle the most with access audit logs. Anytime an employee touches an infrastructure resource such as ubuntu VM on AWS or a managed SQL Server Database on Azure (especially in production environments), there needs to be a log that captures all the queries/commands that were executed as well as the resulting outputs.</p><p>In order to stay continuously compliant with various standards, infrastructure access hygiene is crucial!</p><h3>Trend 4: Crypto creates new financial incentives for hackers!</h3><p>Crypto has gained a lot of momentum over the past few years (for better or for worse) - and that has changed the financial incentives for hackers. Crypto rails have allowed for funds to be transferred in a way where it becomes extremely challenging to track the sender or the receiver.</p><p>On May 7 2021, an oil pipeline company Colonial Pipeline which provides roughly 45% of East Coast&#8217;s fuels (gasoline, diesel, home heating oil, jet fuel, and military supplies) got hacked by ransomware. Colonial had to cease operations temporarily and decided to proactively take certain systems offline to contain the threat. Within hours of the attack, Colonial also paid 75 Bitcoin (worth roughly $4.4 million at the time) &#8212; to DarkSide, the Russia-based cybercriminal group responsible for the attack. Colonial was finally able to resume operations 6 days later but during that time, the shutdown plus the panic resulted in fuel shortages in several areas.</p><p>Historically, a hack or a compromise in an organization&#8217;s IT infrastructure would most likely result in the hacker releasing some confidential information or documents to the public. But now, hackers often blackmail organizations with the same confidential information, and in exchange ask for funds to be transferred via a chain that cannot be traced easily (Finally a use case <a href="https://twitter.com/zachweinberg">@Zach Weinberg</a>!)</p><p>Now what is worse is if the victim of a hack is itself a crypto company. In that case, the hacker can drain the tokens directly and convert them into fiat. Case in point: Crypto.com, Qubit, Bored Apes, Wormhole, Cashio, Beanstalk, Fei Protocol - should I keep going?</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/RyanSAdams/status/1580569612055629824&quot;,&quot;full_text&quot;:&quot;1/ We had $718m in hacks in crypto this quarter.\n\n$3 billion this yr.\n\n\&quot;It's early, hacks will happen\&quot;\n\nYes.\n\nBut that's no longer good enough. Not when we face nation state level attacks.\n\nAnd if we remain cavalier &amp;amp; don't defend our code, it'll cost us. \n\nThread:&quot;,&quot;username&quot;:&quot;RyanSAdams&quot;,&quot;name&quot;:&quot;RYAN S&#926;AN ADAMS &#129299;&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Thu Oct 13 14:42:15 +0000 2022&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:71,&quot;like_count&quot;:490,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p></p><h2>OK! So, how do we figure out the best access management strategy?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PBh9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PBh9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 424w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 848w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 1272w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PBh9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png" width="1456" height="747" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:747,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1453841,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PBh9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 424w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 848w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 1272w, https://substackcdn.com/image/fetch/$s_!PBh9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f4042-3267-4bb0-80e7-d125e27fe7af_2851x1462.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So now that we&#8217;ve established how important having an infrastructure access strategy really is, how do companies currently do this? Especially w.r.t. production environments, where the cost of a breach is way more expensive?</p><p>At the end of the day, any organization&#8217;s security implementation is a tradeoff between:</p><ol><li><p>Locking everything down and making it really hard to use which is expensive to implement and maintain</p></li><li><p>Moving fast with minimal restrictions, key sharing, etc. but it&#8217;s really prone to security incidents</p></li></ol><p>However, there are a few more nuances to the above philosophies that are important to consider. We will evaluate and rate different access strategies on the basis of 4 key dimensions:</p><ul><li><p>Security Posture</p></li><li><p>Auditability</p></li><li><p>Developer Productivity</p></li><li><p>Ease of Set-up &amp; Maintenance</p></li></ul><p>We understand that a lot of people might not agree with our ratings, but the main takeaway here is to be aware of all the different tradeoffs and dimensions we are evaluating. The goal of this newsletter is not about the exact ratings but about understanding all the different tradeoffs and potential risks involved in selecting your organization&#8217;s access management strategy.</p><h2>&#8220;We don&#8217;t believe in sharing access at all&#8221;</h2><p>The first and perhaps, most inefficient way organizations tackle infrastructure access is, by NOT SHARING ACCESS AT ALL. While one can argue this is a secure practice, the organization&#8217;s productivity really suffers as a result of this.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uTZz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uTZz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 424w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 848w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 1272w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uTZz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1270459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uTZz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 424w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 848w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 1272w, https://substackcdn.com/image/fetch/$s_!uTZz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc488780c-1b2d-4d2f-b7a2-0cc7e2496a35_2932x1435.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ah, the good old &#8220;Access via screen sharing&#8221;</figcaption></figure></div><p>Let&#8217;s say there is an incident, and a developer needs access to a production server. Now in order to solve this problem, the dev will first have to get in touch with someone who has access (which might be really difficult in the first place as there are very few people in the org with keys/credentials, given the company&#8217;s policy). Once that happens, the person with access might have to somehow start a TeamViewer, or do a screen share to let the developer access the resource through their machine. <a href="http://blogs.gartner.com/andrew-lerner/2014/07/16/the-cost-of-downtime/">According to Gartner</a>, the average cost of IT downtime is <strong>$5,600 per minute</strong>. Now imagine all the time being spent with someone just trying to access the resource and resolve an incident via screen share.</p><p>Thus, while this access management strategy offers good security posture and is easy to manage as well, the trade-offs are low developer productivity and lack of auditability.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1qsz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1qsz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1qsz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:250202,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1qsz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!1qsz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea0a3a78-86af-4375-8820-b1f1935972a1_5508x2420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>&#8220;We are going to create shared keys and credentials for teams!&#8221;</h2><p>This is an extremely popular access management strategy widely adopted by many organizations. While this partially gets the job done, there are a few different challenges to this approach.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ppP3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ppP3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 424w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 848w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 1272w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ppP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png" width="1456" height="1558" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1558,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:996718,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ppP3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 424w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 848w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 1272w, https://substackcdn.com/image/fetch/$s_!ppP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F93da2264-ee13-4b26-bd79-60d3fd95c9fc_2362x2528.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>1.)</strong> <strong>Keeping track of who has access</strong></h4><p>When an organization has shared accounts, the biggest issue arises due to not having a central platform to keep track of who has access to which resources. So, what do companies do to solve this problem? They use our oldest friend, Excel.</p><p>We have seen many organizations use Excel files (Google sheets for more progressive ones) to manage and keep a track of the keys and permissions. Here&#8217;s what this actually looks like!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fFAo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fFAo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 424w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 848w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 1272w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fFAo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png" width="1456" height="451" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1422872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fFAo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 424w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 848w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 1272w, https://substackcdn.com/image/fetch/$s_!fFAo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F95a5312a-b7ec-4c9e-a35e-00b558108160_5276x1636.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h4><strong>2.)</strong> <strong>Auditability</strong></h4><p>Another issue that arises from using shared keys is the lack of auditability for any change done. Since the keys are being used by multiple folks, companies cannot pinpoint exactly &#8220;<strong>Who</strong> <strong>did What</strong>&#8221; when an infrastructure resource was changed. Now imagine someone making a change in production DB (we know this is rare, but it DOES happen!), and the organization does not know who actually made that change. Well, even Twitter suffers from this lack of auditability as highlighted in their recent whistleblower story.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IXY3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IXY3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 424w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 848w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 1272w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IXY3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png" width="1456" height="679" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:679,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1719488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IXY3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 424w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 848w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 1272w, https://substackcdn.com/image/fetch/$s_!IXY3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f1155a5-c59f-4b22-ace7-cf7dbf3bdd73_4000x1866.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">An excerpt from Twitter&#8217;s whistleblower story</figcaption></figure></div><p>This strategy scores really low on security posture as well as auditability and creates a high risk factor for any organization. The setup for this strategy is easy but maintenance is deceptively cumbersome. Let&#8217;s say an employee who has access to the shared keys leaves the organization. Now the organization will have to deprecate the earlier keys, create new ones for all resources and redistribute them with team members who are supposed to have access. This can get extremely painful to manage in a large organization where attrition is common.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V6v3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V6v3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V6v3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258473,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V6v3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!V6v3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F13d26165-6d8a-4db0-aec4-23716b89f65e_5508x2420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>&#8220;No fear when VPN is here!&#8221;</h3><p>VPN is ubiquitous and almost every organization uses one. Historically, VPN was great when organizations only cared about protecting servers located on-premise.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rK4B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rK4B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rK4B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1206043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rK4B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!rK4B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a56f00-6bd3-4e30-b964-2a9325417fee_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Modern-day infrastructure, on the other hand, is on-cloud, ephemeral and collaborative - and that is where relying solely on VPN becomes complex and cumbersome. Provisioning all these resources via VPN can be a maintenance challenge.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/dnvolz/status/1400947739358384135&quot;,&quot;full_text&quot;:&quot;Mandiant confirms on the record Colonial Pipeline was hacked with compromised credentials used on a VPN w/o two-factor authentication. \n\nThis disclosure comes late on a Friday ahead of the CEO&#8217;s scheduled testimony about the hack in front of Congress next week. &#129300; https://t.co/gPvoIVQ75X&quot;,&quot;username&quot;:&quot;dnvolz&quot;,&quot;name&quot;:&quot;Dustin Volz&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Jun 04 22:49:04 +0000 2021&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:31,&quot;like_count&quot;:57,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>Second, solely relying on a VPN follows the all-or-nothing principle. This means that when someone is inside the VPN network, they can access ALL the resources. This could be extremely dangerous if a bad actor gets inside the VPN network. This also means that providing infrastructure access to a third-party vendor or a contractor can be painful and slows down the process of granting access.</p><p>From an auditability perspective, VPNs provide TCP logs but aren&#8217;t able to provide info on individual commands or queries within the resources and hence don&#8217;t provide great transparency into user activity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eq9h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eq9h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eq9h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:242353,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eq9h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!eq9h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f2d9b-87a5-460d-96a2-31fbd7e101fc_5508x2420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>&#8220;Bastion Servers are the best!&#8221;</h3><p>A Bastion Server is a specialized computer used to access an infrastructure resource and helps create a separation between the downstream resource and developers. From a security perspective, a Bastion host is the only node in the network exposed to the public.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ymeo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ymeo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ymeo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:942602,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ymeo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!Ymeo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0e557e50-36eb-40de-aad8-60cf83991058_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The fundamental challenges with Bastion nodes are the same as with shared keys/credentials - Basically, it's hard to know who has access to that server and also there is a lack of auditability.</p><p>An additional challenge is when organizations have a larger infrastructure. In that scenario, managing Bastion hosts becomes extremely challenging and you would typically need a separate team just to maintain them. Also, in a very isolated experience, we have seen instances where someone by mistake deleted the Bastion host itself. Now if a Bastion host is deleted, there is an immense amount of groundwork needed to recreate a new host and put the credentials of all the downstream resources again.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FNGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FNGQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FNGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251985,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FNGQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!FNGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0267518-98ae-4fa1-93b5-95d53bf55f6f_5508x2420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>&#8220;I&#8217;m going to use a combination of Bastion, VPN, and shared credentials!&#8221;</h3><p>Now, this is the ground reality in most organizations - they typically use a combination of VPN, Bastion, and some shared credentials. While this dramatically improves the security posture of the organization, it also increases the security budget - as this setup is extremely cumbersome to manage and maintain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zPOC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zPOC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zPOC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png" width="1456" height="1017" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1017,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1410605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zPOC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 424w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 848w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 1272w, https://substackcdn.com/image/fetch/$s_!zPOC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2783b6d-fd6d-4dc6-83a1-b1f495233090_2388x1668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a tremendous amount of friction anytime a new resource is added to the company&#8217;s infrastructure or even a new employee is to be on-boarded. Also, the lack of auditability still continues to be a challenge and infrastructure access logs are not that easy to create with this approach.</p><p>About <a href="https://kruschecompany.com/devops-statistics-and-facts/">15% of organizations</a> using DevOps have a separate team to look after providing infrastructure access, defining processes, and even responding to tickets related to infrastructure issues for the rest of the organization. This strategy clearly provides the best security posture but is also the worst when it comes to setup &amp; maintenance given the number of moving parts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fvT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fvT3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fvT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251946,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fvT3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 424w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 848w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 1272w, https://substackcdn.com/image/fetch/$s_!fvT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3cad591-e545-402b-b7a4-6686163a150d_5508x2420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>Conclusion</h2><p>Below is a summary of all the above organization philosophies and their ratings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HOp5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HOp5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 424w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 848w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HOp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png" width="1456" height="771" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:771,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:506769,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HOp5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 424w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 848w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!HOp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F276b4078-b5cc-4083-b54b-3b437439eb17_2388x1264.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Different strategies work better at different stages of an organization. If you are a fast-moving early-stage company looking for a product-market fit, focus on developer productivity and ease of setup &amp; maintenance. Post product-market fit, improve your security posture, and auditability as the increased visibility will make you more susceptible to hacks and data breaches.</p><p>Also, the vertical in which an organization operates plays a huge part in figuring out the access strategy. If you are operating in a highly regulated vertical with sensitive customer information (for eg. FinTech, Healthcare, insurance), ensure a high-security posture and auditability at all times - even when it lowers the dev productivity and/or complicates the setup &amp; maintenance</p><p>Every organization is unique, and there are many factors at play. The most critical aspect while selecting a specific access strategy (or not) is to be intentional about the decision. It is extremely risky if an organization keeps granting access randomly on an on-needed basis. When the organization eventually matures and plans to put some structure to the access strategy, a lot of time and resources would be needed to recycle and deactivate old keys &amp; credentials.</p><p>The takeaway of this article is for organizations to be deliberate about access even at early stages and be aware of the business reasons, tradeoffs and risks involved in different strategies.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/p/sharing-infrastructure-access-with?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Show some love and help us spread the word&#8230; or NOT!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/p/sharing-infrastructure-access-with?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://todo.adaptive.live/p/sharing-infrastructure-access-with?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://adaptive.live" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F8uc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 424w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 848w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 1272w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F8uc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png" width="1456" height="617" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:617,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:104236,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://adaptive.live&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F8uc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 424w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 848w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 1272w, https://substackcdn.com/image/fetch/$s_!F8uc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3306b5b9-5955-442a-a012-24640fbcb5d6_1610x682.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://todo.adaptive.live/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading To Do or Not To Do!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>