top of page
Search
When "Shift Left" Isn't Quite Right
I recently had a discussion about secrets management at a CISO forum that turned into a much broader conversation about DevOps security. We spend a lot of time thinking about whether a security control can detect something, but considerably less time thinking about when in the engineering process that detection occurs. In a GitOps or DevOps workflow, timing can be at least as important as the detection itself. I use secrets management throughout this article because it provid

Jeremy Druin
Aug 2010 min read
Does This Web Application Really Need to Be Behind the VPN?
For a long time, putting a web application inside the corporate network was considered an obvious security decision. If an application was intended only for employees, the reasoning was straightforward. Do not expose it to the Internet. Put it on the internal network and require employees to connect through the corporate VPN. There are certainly applications and environments where that still makes sense; for example, applications that are not web- or mobile-based. But I am in

Jeremy Druin
Aug 136 min read
The Best Security Controls Don't Feel Like Security
Security succeeds when it changes the environment, not the developer. For years, vulnerability management has followed a familiar pattern. A security scanner identifies an issue, a security engineer reviews the finding, a ticket is created, and eventually that ticket finds its way into a developer's backlog. If the issue isn't addressed quickly enough, we often conclude that the problem is prioritization, security culture, or a lack of developer awareness. I don't think that'

Jeremy Druin
Jul 184 min read
The Five Home Security Decisions That Matter Most
One of the most common cybersecurity questions I receive has nothing to do with corporate networks, cloud security, or penetration testing. Instead, it usually sounds something like this: "What should I do to protect my family online?" Friends, family members, and neighbors often assume the answer involves expensive software, complicated network equipment, or a deep understanding of cybersecurity. The reality is much simpler. Most successful cyberattacks do not succeed becaus

Jeremy Druin
Jun 273 min read
The Security Decision Nobody Can Make Correctly
In recent years, several high-profile intrusions have reportedly begun with a remarkably simple attack path: convincing a help desk employee to reset account credentials. What appears at first glance to be a failure of identity verification is often a much more interesting problem involving trust, uncertainty, and decision-making. The resulting breaches disrupted operations across organizations and became some of the most widely discussed examples of social engineering. The i

Jeremy Druin
Jun 155 min read
What Do Phone Phreaking and AI Prompt Injection Have in Common?
Phone phreaking, command injection, SQL injection, cross-site scripting, and prompt injection are generally treated as distinct classes of security vulnerabilities. The technologies involved span more than fifty years of computing history and operate in completely different environments. At first glance, they appear unrelated. A closer examination reveals a common architectural characteristic. In each case, untrusted users are able to communicate with a system's control plane

Jeremy Druin
Jun 34 min read
Automate Your Pi-hole: Keep Your Network Secure and Hassle-Free
If you use Pi-hole to block ads and trackers on your home or business network, you already care about privacy and clean browsing. But...

Jeremy Druin
Jul 6, 20252 min read
How Often Should You Conduct Penetration Testing?
Penetration testing (pen testing) is a crucial component of any organization’s cybersecurity strategy. By simulating real-world attacks,...

Jeremy Druin
Jan 20, 20253 min read
Cloud Penetration Testing: Challenges and Best Practices
As organizations increasingly migrate to cloud environments to leverage scalability, flexibility, and cost efficiency, the security of...

Jeremy Druin
Jan 20, 20253 min read
External vs. Internal Penetration Testing: Understanding the Scope
As cyber threats continue to evolve, organizations must proactively test their defenses to identify and mitigate vulnerabilities....

Jeremy Druin
Jan 20, 20253 min read
The Different Types of Penetration Testing: Which One is Right for You?
In an age where cyber threats are growing more sophisticated, penetration testing (pen testing) has become a cornerstone of a strong...

Jeremy Druin
Jan 20, 20254 min read
Vulnerability Management for ISO 27001 Certification
ISO 27001 is one of the most widely recognized standards for information security management systems (ISMS). It provides a framework for...

Jeremy Druin
Jan 20, 20253 min read
Mapping Vulnerability Management to the NIST Cybersecurity Framework
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is a widely recognized and adopted set of...

Jeremy Druin
Jan 20, 20253 min read
How Vulnerability Management Supports Compliance with GDPR, CCPA, and HIPAA
In today’s regulatory landscape, organizations face increasing pressure to protect sensitive data and maintain compliance with stringent...

Jeremy Druin
Jan 20, 20253 min read
The Role of AI and Machine Learning in Modern Vulnerability Management
Cyber threats are growing in complexity, frequency, and sophistication, making traditional vulnerability management methods increasingly...

Jeremy Druin
Jan 20, 20253 min read
Patch Management vs. Vulnerability Management: What’s the Difference?
In the realm of cybersecurity, terms like “patch management” and “vulnerability management” are often used interchangeably. While they...

Jeremy Druin
Jan 20, 20253 min read
The ROI of Effective Vulnerability Management Programs
In the ever-evolving world of cybersecurity, organizations often grapple with the question: Is vulnerability management worth the...

Jeremy Druin
Jan 20, 20253 min read
Top 10 Common Vulnerabilities Found in Enterprise Networks
1. Unpatched Software and Systems Unpatched or outdated software remains one of the most exploited vulnerabilities in enterprise...

Jeremy Druin
Jan 20, 20252 min read
What is Vulnerability Management and Why Your Business Needs It
In today’s digital-first world, cybersecurity is a critical priority for businesses of all sizes. With cyber threats growing more...

Jeremy Druin
Jan 20, 20253 min read
Exploring the Intersection of IoT Security and Identity Management
The Internet of Things (IoT) has revolutionized industries by connecting devices, systems, and people in unprecedented ways. From smart...

Jeremy Druin
Jan 20, 20253 min read
bottom of page
