Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

PAM ROI: Modern privileged access management pays for itself

Privileged access management (PAM) is one of the clearest ways to reduce identity-based risk and demonstrate security value. But ROI depends on more than simply deploying a PAM tool. Organizations need a solution that can be implemented efficiently, managed without unnecessary operational burden and scaled in a way that supports long-term cost control. For organizations evaluating PAM investments, these factors matter.

'Set menu or à la carte?' Customizing the Identity Manager UI

A “set menu” or “à la carte” design? Drawing on nearly 12 years of experience using Identity Manager by One Identity, Andrew Edney, a lead consultant at iC Consult, gives a lightning-quick breakdown of useful UI customization options using Designer, including changes to overview forms and updating navigation with features like custom filtering.

10 MCP Security Best Practices

A natural-language decision can now trigger a real API call, query sensitive data, deploy code, or modify infrastructure. MCP expands the security boundary beyond the connection to the identities, privileges, tools, credentials, and downstream systems behind each action. That challenge is growing with adoption. Anthropic reported more than 10,000 active public MCP servers by December 2025, alongside 97M+ monthly downloads of its Python and TypeScript MCP SDKs.

How identity sprawl is quietly expanding your attack surface

No city is designed to become complex. It starts with a simple plan with a handful of streets and a few neighborhoods. Then it grows. New districts appear, roads extend, bridges get built and temporary solutions slowly become permanent. As cities grow, complexity compounds, perhaps because that growth was never planned for. Identity environments follow the same pattern.

EMEA compliance just made sovereign cloud mandatory

For years, sovereign cloud was basically a data center pin on a map. A vendor would point at Frankfurt or Paris and call it a day. That pitch doesn’t work anymore, and it stopped working fast. Between late 2024 and late 2025, the EU passed three separate rules that turned sovereignty from a talking point into something organizations now have to prove, on a schedule, with documentation, to a specific regulator.

Your AD is a stomping ground for lateral movement

Active Directory (AD) is the backbone many enterprises lean on for their IT environments. Yet, most organizations rarely govern the directory with the scrutiny necessary. This was the throughline of a recent webinar with Nitish Deshpande, senior analyst at KuppingerCole, and Robert Kraczek, global strategist at One Identity. The pair made a strong case for mediating admin access to AD, emphasizing just how easily compromised credentials can beget full-blown incidents.

Vulnerability Assessments in an Agentic World: Step-by-Step Guide

An old package or a misconfigured cloud storage bucket can be identified by a legacy scanner, but it does not account for the unique risk profile of autonomous systems. It cannot confirm that an AI agent with access to your production environment can chain together a CRM read, an email send and a production write using inherited credentials. Your agents are dynamic: they plan, call tools, and act across multiple environments, and some may retain context or long-term memory beyond the original request.