DSE security knowledge hub

Cybersecurity
Knowledge

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

127 articles
DSE visual briefCyber defense

CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefIdentity & cloud

Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefManaged IT operations

Govern every sensitive information exchange through its full lifecycle

Information remains exposed before, during, and after an exchange—regardless of whether it moves through an API, portal, file transfer, email, shared database, or manual process. Put protection duties and exit conditions in an owned agreement.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Rank critical components by mission consequence, not replacement cost

The most expensive asset is not always the component whose loss matters most. Trace organizational goals through programs, systems, functions, and components so protection, acquisition, maintenance, and recovery follow operational consequence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Use TLP 2.0 to preserve the sharing boundary of incident information

Threat and incident information loses value when recipients cannot tell who may receive it. Use the four TLP 2.0 labels consistently, keep the source’s marking intact, and add separate handling instructions when TLP does not answer the need.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Design cloud forensic readiness before evidence is needed

Cloud investigators depend on provider capabilities, customer configuration, jurisdiction, interfaces, time, and retention that cannot be improvised after an incident. Map evidence needs to cloud capabilities and mitigate gaps before collection becomes urgent.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Make identity proofing recoverable, equitable, and evidence-based

Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide