Tailscale
Simplify your Kubernetes networking story with our new operator. Try Tailscale for Kubernetes now.
« October 2023 | Main | December 2023 »
Simplify your Kubernetes networking story with our new operator. Try Tailscale for Kubernetes now.
Shortcut compliance — without shortchanging security.
Vanta brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business, all without the need for additional staffing.
And because Vanta automates up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance.
From the most in-demand frameworks to third-party risk management and security questionnaires, Vanta gives SaaS businesses of all sizes one place to manage risk and prove security in real time.
Try Vanta free for 7 days. No costs or obligations.
Getting OS updates installed on end user devices should be easy. After all, it's one of the simplest yet most impactful ways that every employee can practice good security.
On top of that, every MDM solution promises that it will automate the process and install updates with no user interaction needed.
Yet in the real world, it doesn't play out like that. Users don't install updates and IT admins won't force installs via forced restart.
Let's talk about the second problem first. Sure, you could simply schedule updates for all your users, and have them restart during non-work hours. But this inevitably leads to disruptions and lost work. This, in turn, leads to users (especially executives) who simply demand to be left out of your update policy. The bottom line is: any forced restarts without user approval will lead to data loss events, and that makes them so unpopular that they are functionally unusable.
There is another class of tools that claim to get users to install updates themselves, through "nudges." These reminders pop up with increasing frequency until users relent or the timer runs out. This is an improvement, since it involves users in the process, but users still tend to delay updating as long as possible (which for some tools can be indefinitely).
At Kolide, OS updates are the single most common issue customers want us to solve. They come to us because we have a unique (and uniquely effective) approach to device compliance.
With Kolide, when a user's device -- be it Mac, Windows, Linux, or mobile -- is out of compliance, we reach out to them with instructions on how to fix it.
The user chooses when to restart, but if they don't fix the problem by a predetermined deadline, they're unable to authenticate with Okta. (At present, Kolide is exclusive to Okta customers, but we plan to integrate with more SSO providers soon.)
If your fleet is littered with devices that stubbornly refuse to update, then consider these two principles:
Installing OS updates is a top priority for both security and IT, and when you make it part of conditional access, you can finally get it done without massive lists of exemptions or massive piles of support tickets.
To learn more about how Kolide enforces device compliance for companies with Okta, click here to watch an on-demand demo.
It seems like every company is scrambling to stake their claim in the AI goldrush -- check out the CEO of Kroger promising to bring LLMs into the dairy aisle. And front line workers are following suit–experimenting with AI so they can work faster and do more.
In the few short months since ChatGPT debuted, hundreds of AI-powered tools have come on the market. But while AI-based tools have genuinely helpful applications, they also pose profound security risks. Unfortunately, most companies still haven't come up with policies to manage those risks. In the absence of clear guidance around responsible AI use, employees are blithely handing over sensitive data to untrustworthy tools.
AI-based browser extensions offer the clearest illustration of this phenomenon. The Chrome store is overflowing with extensions that (claim to) harness ChatGPT to do all manner of tasks: punching up emails, designing graphics, transcribing meetings, and writing code. But these tools are prone to at least three types of risk.
Up until now, most companies have been caught flat-footed by AI, but these risks are too serious to ignore.
At Kolide, we're taking a two-part approach to governing AI use.
Every company will have to craft policies based on their unique needs and concerns, but the important thing is to start now. There's still time to seize the reins of AI, before it gallops away with your company's data.
To learn more about how Kolide enforces device compliance for companies with Okta, click here to watch an on-demand demo.
This page contains all entries posted to Feed Sponsorship Ads in November 2023. They are listed from oldest to newest.
October 2023 is the previous archive.
December 2023 is the next archive.
Many more can be found on the main index page or by looking through the archives.