DSE security knowledge hub

Cybersecurity
Knowledge

Page 5 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

164 articles
DSE visual briefIdentity & cloud

Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefManaged IT operations

Govern every sensitive information exchange through its full lifecycle

Information remains exposed before, during, and after an exchange—regardless of whether it moves through an API, portal, file transfer, email, shared database, or manual process. Put protection duties and exit conditions in an owned agreement.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Rank critical components by mission consequence, not replacement cost

The most expensive asset is not always the component whose loss matters most. Trace organizational goals through programs, systems, functions, and components so protection, acquisition, maintenance, and recovery follow operational consequence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Use TLP 2.0 to preserve the sharing boundary of incident information

Threat and incident information loses value when recipients cannot tell who may receive it. Use the four TLP 2.0 labels consistently, keep the source’s marking intact, and add separate handling instructions when TLP does not answer the need.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Design cloud forensic readiness before evidence is needed

Cloud investigators depend on provider capabilities, customer configuration, jurisdiction, interfaces, time, and retention that cannot be improvised after an incident. Map evidence needs to cloud capabilities and mitigate gaps before collection becomes urgent.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Make identity proofing recoverable, equitable, and evidence-based

Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefCyber defense
PlaybookImportantCybersecurity

Assess whether controls produce the intended outcome—not whether they exist

A policy, screenshot, or enabled setting proves only part of a control. Build assessment procedures around what must be examined, interviewed, and tested, then record whether implementation is correct, operating as intended, and producing the required outcome.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook