Fail Closed on the Server, Fail Open at the Client
Two commits a day apart set opposite failure defaults in the same backend, and what decided each one was not the sensitivity of the asset but who gets refused when the control is wrong.
IAM, privileged access, and identity as the control plane attackers reach for first.
11 articles
Two commits a day apart set opposite failure defaults in the same backend, and what decided each one was not the sensitivity of the asset but who gets refused when the control is wrong.
Device attestation is a control where a correct implementation and a botched rollout produce the same 403, so the rollout mechanics matter more than the cryptography.
Two AWS systems went dark seventeen days apart. Deciding how to stop them took more security work than building them did, and the artifacts I preserved were deleted eighteen days later by someone doing a legitimate job.
Adding Android to a backend built for iOS forced a choice between relaxing JWT audience validation and issuing a second client identity, and the cheaper-looking option was the one that destroyed information.
A GenAI security review that spends its budget on whether the model can be talked into saying something forbidden has assessed the half of the system that does not act. The half that acts is the tool list.
An agent's permissions are whatever its tools can reach, not whatever its role description says, so the policy has to be written at the tool boundary and tested like a control.
At enterprise scale, identity telemetry is often the fastest signal for active compromise. Operations need to be built around that reality.
Cloud IAM debt accumulates quietly until attackers exploit it. Here is a practical model for reducing permission sprawl safely.
ITDR has moved from emerging category to operational necessity as attackers increasingly target identity systems, session tokens, and MFA weaknesses.
Remote work made one thing clear: perimeter controls are no longer enough. Identity has become the control plane for enterprise security.
Most Zero Trust programs fail because they start with tools instead of outcomes. Here's a practical roadmap that works in real enterprises.