DSE security knowledge hub

Cybersecurity
Knowledge

Page 13 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

230 articles
DSE visual briefNetworks & infrastructure

Use RPKI route-origin validation without confusing Valid with safe

RPKI lets resource holders authorize which ASN may originate a prefix and lets operators validate BGP origins. It does not validate the full AS path or prove a route is benign. Build careful ROAs, redundant validators, policy, and monitoring.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Treat Terraform state as production data with locking and recovery

Terraform state binds configuration to real infrastructure and can contain sensitive data. A team needs controlled remote storage, supported locking, restricted access, serialized changes, versioned recovery, and a tested process for failed writes.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefContinuity & recovery

Treat the domain registrar as a business-critical control plane

Control of a domain registration can redirect websites and email, disrupt public services, or remove an organization’s online identity. Registrar access deserves named ownership, strong authentication, locks, monitored changes, and an exercised recovery plan.

Published Reviewed 4 min readBy Gavin Stewart
Read the checklist
DSE visual briefNetworks & infrastructure

Govern IPv6 even when the network is called IPv4-only

IPv6 may be active on endpoints, servers, and network equipment before an organization intentionally deploys it. Unmanaged IPv6 creates a parallel path around inventories, filtering, monitoring, segmentation, and incident procedures designed only for IPv4.

Published Reviewed 4 min readBy Gavin Stewart
Read the checklist