DSE security knowledge hub

Cybersecurity
Knowledge

Page 8 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

191 articles
DSE visual briefContinuity & recovery

Use TLP 2.0 to preserve the sharing boundary of incident information

Threat and incident information loses value when recipients cannot tell who may receive it. Use the four TLP 2.0 labels consistently, keep the source’s marking intact, and add separate handling instructions when TLP does not answer the need.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Design cloud forensic readiness before evidence is needed

Cloud investigators depend on provider capabilities, customer configuration, jurisdiction, interfaces, time, and retention that cannot be improvised after an incident. Map evidence needs to cloud capabilities and mitigate gaps before collection becomes urgent.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Make identity proofing recoverable, equitable, and evidence-based

Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefCyber defense
PlaybookImportantCybersecurity

Assess whether controls produce the intended outcome—not whether they exist

A policy, screenshot, or enabled setting proves only part of a control. Build assessment procedures around what must be examined, interviewed, and tested, then record whether implementation is correct, operating as intended, and producing the required outcome.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Engineer critical services to anticipate, withstand, recover, and adapt

Cyber resilience is an engineered ability to continue mission-essential outcomes through attack and compromise—not a synonym for prevention or backup. Define what must endure, then design and test for anticipation, resistance, recovery, and adaptation.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Finish the Windows Secure Boot trust-chain transition from 2011 certificates

Windows devices can keep booting after the 2011 Secure Boot certificates expire yet miss future early-boot protections. Inventory status, update OEM firmware, pilot by hardware family, and verify the 2023 trust chain with evidence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Move Exchange Online SMTP AUTH clients off Basic authentication with evidence

Microsoft now plans to disable SMTP AUTH Basic authentication by default for existing Exchange Online tenants at the end of December 2026. Find every sender, choose a supported replacement, pilot it, and prove the legacy path is quiet.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook