DSE security knowledge hub

Security knowledge,
without the noise.

Page 10 of the DSE Security Knowledge Hub, with source-backed guidance, checklists, explainers, and playbooks.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Guidance and analysis from DSE

254 articles
DSE visual briefContinuity & recovery
PlaybookImportantBusiness Continuity

Manage fire-protection impairments before the valve closes

Planned maintenance and unexpected failures can leave a protected area without its normal water-based fire protection. Assign an impairment coordinator, assess the increased risk, authorize safeguards, notify the right parties, tag the condition, and prove restoration.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefPhysical security

Build a workplace-violence program before behavior becomes an emergency

Workplace violence prevention is not a poster or a single security response. It needs management ownership, safe reporting, multidisciplinary assessment, lawful intervention choices, emergency escalation, employee support, records, training, and post-incident recovery.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefCyber defense

Prepare bomb-threat decisions before the call or message arrives

Bomb threats demand organized intake, prompt responder notification, credible assessment, controlled searches, and deliberate choices among monitoring, search, lockdown, or evacuation. Automatically emptying the building can move people toward danger.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefPhysical security

Route suspicious mail into isolation, distance, and coordinated reporting

Mailrooms need a practiced response for a package that appears dangerous or releases an unknown substance. Recognition matters, but the safer operating priorities are to stop handling, isolate, create distance, protect exposed people, and contact the proper responders.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefPhysical security

Commission exterior security lighting for the people who must use and maintain it

Exterior lighting should support specific human tasks without disabling glare, deep shadow, uncontrolled spill, failed controls, or an unmaintainable layout. Define the task, design to maintained performance, then measure and walk the installed result at night.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Finish the Windows Secure Boot trust-chain transition from 2011 certificates

Windows devices can keep booting after the 2011 Secure Boot certificates expire yet miss future early-boot protections. Inventory status, update OEM firmware, pilot by hardware family, and verify the 2023 trust chain with evidence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Deploy SMB over QUIC only after identity, port, and fallback testing

SMB over QUIC protects Windows file access with TLS 1.3 over UDP 443, but Windows clients can still prefer TCP and external authentication can fall back to NTLM. Prove transport, identity, certificates, and renewal before production.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefNetworks & infrastructure

Use RPKI route-origin validation without confusing Valid with safe

RPKI lets resource holders authorize which ASN may originate a prefix and lets operators validate BGP origins. It does not validate the full AS path or prove a route is benign. Build careful ROAs, redundant validators, policy, and monitoring.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook