top of page



How to Prepare Defensible SaaS Compliance Evidence for Your Next SOC 2 Audit
Auditors have grown more sophisticated about SaaS and identity controls. This guide describes how to assemble a defensible evidence package that survives the new questions.
May 133 min read


How to Build a SaaS Offboarding Checklist That Actually Closes Every Access Path
Most offboarding processes terminate at the IdP. The access that remains active afterward is the access that produces post-employment incidents. This guide closes the loop.
May 133 min read


How to Build the Business Case for a SaaS Discovery Initiative
Funding for SaaS discovery is often blocked because the value is preventive rather than visible. This guide describes how to articulate the value persuasively.
May 133 min read


A Brief History of OAuth: From Twitter Frustration to Enterprise Authorization Standard
OAuth is now the dominant authorization protocol for cloud applications. Its history explains both its strengths and the security properties that make it difficult to govern.
May 133 min read


How to Audit OAuth Permissions in Google Workspace and Microsoft 365 Without Installing an Agent
OAuth grants are the silent privilege expansion of modern SaaS. This guide describes how to audit them in both major workspaces using only built-in administrator tooling.
May 133 min read


Defense in Depth Means Something Different in 2026 Than It Did in 2006
Defense in depth was a network concept. It still applies in 2026 — but the layers are no longer about the network. Here is how the model translates to the identity perimeter.
May 133 min read


"Identity Is the New Perimeter": Where the Phrase Came From and Why It Finally Matters
"Identity is the new perimeter" became security cliché around 2015. It became operational reality only recently. The gap between the two is the subject of this piece.
May 133 min read


How to Detect AI Features Quietly Enabled Inside the SaaS Applications You Already Use
AI capabilities are being added to SaaS products at unprecedented pace, often by default. This guide describes how to detect them without depending on vendor notifications.
May 133 min read


Five Compliance Frameworks Every Security Team Will Hear About in 2026
Compliance frameworks proliferate, but a small number dominate practitioner conversations in any given year. Here is the 2026 short list and what each one actually requires.
May 133 min read


A Field Guide to the Cloud and SaaS Security Acronym Soup: CSPM, CWPP, CNAPP, CIEM, SSPM, DSPM, ASPM
The acronym population in cloud and SaaS security has grown faster than most teams can track. This guide explains what each category actually addresses, in plain terms.
May 133 min read


How to Conduct a 48-Hour Pre-Audit SaaS and AI Risk Assessment
Pre-audit assessments often run for weeks and surface issues too late to remediate. A focused 48-hour approach can recover the schedule and protect the audit outcome.
May 133 min read


How to Locate Unauthorized AWS, Azure, and GCP Accounts Across Your Organization
Cloud accounts created outside the corporate organization are common, persistent, and rarely visible to CSPM. This guide outlines a structured way to find them.
May 133 min read


The SolarWinds Breach: What Most Retrospectives Got Right, and What They Quietly Missed
The SolarWinds story is widely told as a supply-chain incident. The post-implant identity activity, less widely covered, contains the deeper lesson for 2026.
May 133 min read


What Security Engineers Actually Do All Day in 2026
If you imagine security engineers as dramatic incident responders, the reality is going to surprise you. The work that produces most of the value looks much quieter.
May 133 min read


How to Discover Every AI Tool Your Employees Are Using in Under an Hour
Most organizations underestimate their AI footprint by an order of magnitude. This guide walks through a 60-minute exercise to surface what's really in use.
May 133 min read


The Anatomy of a Modern SaaS Breach: A Composite Walk-Through
Modern SaaS breaches rarely involve dramatic intrusions. Most follow a quiet, predictable arc through identity, OAuth, and SaaS-to-SaaS access. Here is the composite arc.
May 133 min read
bottom of page