DSE security knowledge hub

Cybersecurity
Knowledge

Page 6 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

164 articles
DSE visual briefContinuity & recovery

Engineer critical services to anticipate, withstand, recover, and adapt

Cyber resilience is an engineered ability to continue mission-essential outcomes through attack and compromise—not a synonym for prevention or backup. Define what must endure, then design and test for anticipation, resistance, recovery, and adaptation.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Finish the Windows Secure Boot trust-chain transition from 2011 certificates

Windows devices can keep booting after the 2011 Secure Boot certificates expire yet miss future early-boot protections. Inventory status, update OEM firmware, pilot by hardware family, and verify the 2023 trust chain with evidence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Deploy SMB over QUIC only after identity, port, and fallback testing

SMB over QUIC protects Windows file access with TLS 1.3 over UDP 443, but Windows clients can still prefer TCP and external authentication can fall back to NTLM. Prove transport, identity, certificates, and renewal before production.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefNetworks & infrastructure

Use RPKI route-origin validation without confusing Valid with safe

RPKI lets resource holders authorize which ASN may originate a prefix and lets operators validate BGP origins. It does not validate the full AS path or prove a route is benign. Build careful ROAs, redundant validators, policy, and monitoring.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Treat Terraform state as production data with locking and recovery

Terraform state binds configuration to real infrastructure and can contain sensitive data. A team needs controlled remote storage, supported locking, restricted access, serialized changes, versioned recovery, and a tested process for failed writes.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist