DTG-IG25 · Identity Governance · 4 min

What the Attacker Knew About Your Access Model That You Didn't

The post-incident investigation produced a finding that was uncomfortable in its specificity: the attacker had navigated the environment with a precision that suggested d…

DTG-IG22 · Identity Governance · 4 min

The Conditional Access Policy That Failed Under Operational Pressure

The conditional access policy was designed to enforce authentication requirements based on user context: stronger authentication when accessing from unusual locations, ad…

DTG-IG21 · Identity Governance · 4 min

How Does Your Organization Govern Access That Was Never Formally Requested?

Identity governance programs are designed around formal access requests: a user submits a request, the request is approved by the appropriate authority, and the access is…

DTG-IG19 · Identity Governance · 4 min

The Orphaned Account Problem That Never Gets Fully Solved

An orphaned account is an account in an organizational system with no current, identifiable owner — no active employee, no active contractor, no active vendor relationshi…

DTG-IG14 · Identity Governance · 5 min

Privilege Creep Is Not a Failure of Technology. It Is a Failure of Process

Privilege creep is the gradual accumulation of access rights by users who move through roles, projects, and responsibilities over time. Each addition is individually just…

DTG-IG09 · Identity Governance · 4 min

Role Explosion in SaaS Environments and Why Nobody Is Cleaning It Up

Enterprise SaaS environments accumulate roles faster than any identity governance program was designed to manage. Every SaaS application has its own role model.

DTG-IG08 · Identity Governance · 5 min

Zero Trust Is Not a Product. It Is a Commitment to Identity Discipline

The zero trust market is worth billions of dollars. Vendors offer zero trust platforms, zero trust network access, zero trust architecture solutions.

DTG-IG05 · Identity Governance · 4 min

Identity Federation Means Your Trust Boundary Is Someone Else's Problem

Identity federation allows users to authenticate with one identity provider and access resources across multiple systems and organizations. It is one of the most signific…

DTG-137 · Identity Governance · 8 min

Identity Governance in SaaS Is Fragmented by Design

Enterprise identity governance was built on the premise that identity is centralized: a directory, an IAM platform, a set of federation standards.

DTG-132 · Identity Governance · 8 min

Privilege Escalation Happens Within Approved Access

Privilege escalation is typically framed as a security concern about attackers gaining access beyond what they were authorized to have. The more common and more difficult…

DTG-128 · Identity Governance · 10 min

Access Provisioning Is Automated. Revocation Is Not

Organizations have built excellent infrastructure for giving people access. Joining triggers automation: account creation, group assignment, license provisioning, entitle…

DTG-126 · Identity Governance · 8 min

Privileged Access Expands Faster Than It Is Governed

Every system addition is a potential privileged access expansion. Every cloud resource provisioned, every SaaS application deployed, every microservice added creates a ne…

DTG-125 · Identity Governance · 10 min

Service Accounts Are the Most Overlooked Risk Surface

Service accounts are the identity type that enterprise governance programs most consistently underaddress. Human accounts are governed by HR processes, access reviews, an…

DTG-122 · Identity Governance · 10 min

Least Privilege Is a Principle. Not an Operational Reality

Least privilege is one of the most widely adopted access control principles in enterprise security. It is documented in every security framework, required by every compli…

DTG-121 · Identity Governance · 9 min

Access Control Works. Until Privilege Accumulates Over Time

Access controls are designed to enforce defined permissions at a point in time. They do not prevent permissions from accumulating over time as users change roles, join pr…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center