Attack Surface Management

Articles, news, and research on attack surface management.

Attack Surface Management

Cybersecurity
Attack Surface Management

What is Zero Trust? A Model for More Effective Security

This is a complete overview of Zero Trust. Learn about Zero Trust and how to implement it with this in-depth post.
Read more
Attack Surface Management
Cybersecurity

How to Secure Rsync

Rsync is a ubiquitous data backup tool that comes bundled with many operating systems, and configuring it properly for secure use is of utmost importance.
Read more
Cybersecurity
Attack Surface Management

What is Email Spoofing?

Email spoofing is the creation of emails with a forged sender address enabled by the lack of in-built authentication in core email protocols.
Read more
Attack Surface Management
Cybersecurity

What is The Difference Between Vulnerabilities and Misconfigurations?

What are misconfigurations? Truth be told vulnerabilities are not the source of most exploits, misconfigurations are.
Read more
Cybersecurity
Attack Surface Management

What is a Network Security Assessment?

This is a complete overview of network security assessments. Learn how to run a network security assessment in this in-depth post.
Read more
Attack Surface Management
Cybersecurity
Data Breaches

Check your Amazon S3 permissions. Someone will.

Companies regularly host sensitive data on Amazon's S3. Sometimes they forget to close it off to the internet. Here's a guide to make sure you don't.
Read more
Cybersecurity
Attack Surface Management

What is Network Security?

Network security is the process of using physical and software security solutions to protect the underlying network infrastructure from unauthorized access
Read more
Attack Surface Management
Cybersecurity

How to Secure Apache Tomcat 8 in 15 Steps

A practical guide to hardening and securing your Apache Tomcat Server with best practices to ensure your server is more secure than the default.
Read more
Cybersecurity
Attack Surface Management

S3 Security Is Flawed By Design

There are two design flaws that cause most S3 data breaches. Read why we AWS should separate S3 into two products that clearly separate private and public.
Read more
Cybersecurity
Attack Surface Management

How to Secure Your Windows Environment: Top 10 Ways

Learn more about the basic elements to bolstering your Windows environment against cyber attackers.
Read more
Attack Surface Management
Cybersecurity
Data Breaches

Don’t Use Production Data In Your Test Environment: The Impact Of Leaked Test Credentials

Read about why your third-party vendors and test environments should not contain production data, and how to protect your customers by taking a few steps.
Read more
Cybersecurity
Attack Surface Management

What is HSTS (HTTP Strict Transport Security)?

This is a complete overview of the HTTP Strict Transport Security. Learn about what HSTS is and why it is important in this in-depth post.
Read more
Cybersecurity
Attack Surface Management

Carbon Black vs CrowdStrike

How does Carbon Black's endpoint security platform match up against CrowdStrike's SaaS-based solution for endpoint protection? Read more to find out.
Read more
Attack Surface Management
Cybersecurity

DNSSEC: What Is It and Why Is It Important?

The DNSSEC is a set of IETF specifications for securing certain kinds of information provided by the DNS as used on Internet Protocol (IP) networks.
Read more
Cybersecurity
Attack Surface Management
Data Breaches

What is an Incident Response Plan?

An incident response plan is a set of written instructions that outline your organization's response to data breaches, data leaks, and cyber attacks.
Read more
Attack Surface Management
Cybersecurity
Third-Party Risk Management

What are Security Ratings? Cybersecurity Risk Scoring Explained

This is a complete guide to security ratings and common use cases. Learn why security and risk management teams have adopted security ratings in this post.
Read more
Deliver icon

Sign up for our newsletter

Stay up-to-date on everything UpGuard with our monthly newsletter, full of product updates, company highlights, free cybersecurity resources, and more.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
  • Check icon
    Instant insights you can act on immediately
  • Check icon
    Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities
Website Security scan resultsWebsite Security scan rating

Ready to see
UpGuard in action?