Insights — Blog

The AppliedIAM blog

Practical takes on identity security, privileged access, and what the latest breaches mean for how you protect access.

Diagram showing the KeeperPAM cloud-native architecture with the Keeper Gateway connecting users to servers, databases, and cloud workloads without a VPN
August 4, 2026

KeeperPAM Explained: What It Is and How It Works

KeeperPAM unifies privileged access, secrets, and remote connections on a cloud-native platform — no VPN, no agents, no firewall changes required.

Read more
Illustration of a locked vault representing privileged account protection in a PAM system
July 28, 2026

What Is PAM (Privileged Access Management)? A Plain-English Guide

PAM secures the accounts with the most system power. Here's what privileged access management does and why attackers go after these credentials first.

Read more
Dashboard-style diagram showing identity risk indicators across an enterprise estate
July 27, 2026

Identity Security Posture Management: What ISPM Is and Whether You Need It

Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.

Read more
Diagram showing time-bound privileged access being granted and automatically revoked
July 27, 2026

Just-in-Time Access and Zero Standing Privileges: What It Takes to Get There

Standing privilege is what turns one compromised account into a bad week. Here is how just-in-time access actually works in practice.

Read more
Diagram showing service accounts, API keys, certificates and workload identities under governance
July 27, 2026

Non-Human Identity Management: Service Accounts, Machine Identities and Secrets

Service accounts, API keys and workload identities outnumber your people — and almost nobody reviews them. Where to start.

Read more
Diagram comparing role-based, attribute-based and policy-based access control models
July 27, 2026

RBAC vs ABAC vs PBAC: Which Access Control Model Should You Actually Use?

Three access control models, three different failure modes. How RBAC, ABAC and policy-based access control actually compare in practice.

Read more
Diagram of an access certification campaign showing review, approval and revocation steps
July 27, 2026

User Access Reviews: Why Access Certification Fails and How to Fix It

Managers approve 400 entitlements in eleven minutes and the campaign passes. Here is what makes an access review genuinely work.

Read more
A split illustration showing a login shield on one side and a locked vault on the other, representing identity access management versus privileged access management
July 24, 2026

CyberArk vs Okta: Why You Probably Need Both, Not Either

"Is Okta or CyberArk the better choice?" is one of the most common questions we hear — and it's usually the wrong question. They aren't competing for the same job.

Read more
Two interlocking gears labeled with a login key and a checklist, representing how identity access management and identity governance work together
July 24, 2026

IAM vs IGA: The Difference That Shows Up at Audit Time

You deployed SSO. You turned on MFA. Then the auditor asked 'who has access to what, and should they?' — and that question lives in the gap between IAM and IGA.

Read more
Two control panels side by side, one built around a credential vault and one around a connection gateway, representing two approaches to privileged access management
July 24, 2026

KeeperPAM vs StrongDM: Choosing on Visibility and Control

Both promise privileged access done for the modern, cloud-first world — but they get there differently, and the difference matters for how you see and control access.

Read more
A network map with nodes spread across multiple locations, each secured with a lock, representing a phased privileged access rollout across a distributed workforce
July 24, 2026

How Hard Is It to Actually Roll Out CyberArk Across a Distributed Workforce?

The honest answer: not as hard as a stalled project makes it look, but only if you phase it by risk instead of trying to boil the ocean.

Read more
A checklist beside a handshake, representing the criteria for evaluating an identity and access management implementation partner
July 24, 2026

What to Look for in an IAM Implementation Partner

The platform you buy matters less than who deploys it. Here's what actually distinguishes an IAM partner that finishes the job from one that leaves it half-done.

Read more
Split diagram comparing role-based access control and attribute-based access control decision flows
July 21, 2026

RBAC vs ABAC: Which Access Control Model Is Right for Your Organisation?

Role-based or attribute-based access control? Learn the real differences and when each model fits your security environment.

Read more
Abstract visualization of a web server with exposed file directories and credential theft indicators
July 10, 2026

WP-SHELLSTORM: What an Exposed Hacker Server Teaches Us About Credential Theft at Scale

An exposed hacker server revealed a mass WordPress backdoor campaign that also harvested cloud credentials from corporate systems. Here are the identity-security lessons.

Read more
Abstract illustration of an AI chatbot interface with a broken padlock overlay, representing a compromised conversational AI platform
July 8, 2026

The Rogue Agent Vulnerability: What AI Platform Flaws Mean for Identity and Data Security

A flaw in Google's Dialogflow CX reportedly allowed silent conversation hijacking — here's what it reveals about AI platform access controls.

Read more
Abstract visualization of an identity verification workflow with a phone call icon and lock symbol
July 7, 2026

How a Help Desk Call Unlocked a Retailer's Network — and What the Scattered Spider Case Teaches Us About Identity Verification

Attackers reportedly bypassed MFA entirely by calling the help desk. The Scattered Spider case is a sharp reminder that process gaps can outweigh technical controls.

Read more
A key icon representing stolen credentials used in a large-scale password spray attack against Azure environments
July 1, 2026

81 Million Password Spray Attempts Against Azure CLI: What the MFA Gaps Tell Us

Over 81 million login attempts targeted Azure CLI in under two weeks — and MFA gaps let attackers through even where it was supposedly enabled.

Read more
Abstract visualization of credential data being extracted from developer workstations across multiple operating systems
June 30, 2026

Djinn Stealer and the SimpleHelp RMM Exploit: What Developer Credential Theft Means for Your Organization

A critical SimpleHelp authentication bypass reportedly enabled attackers to deploy credential-harvesting malware targeting developer tools, cloud tokens, and AI assistants.

Read more
Data breach prevention in 2026 — how stolen credentials fuel breaches and how Keeper stops them
June 25, 2026

Data Breach Prevention in 2026: How Stolen Credentials Fuel Breaches — and How Keeper Stops Them

The biggest breaches of 2026 didn't start with a zero-day — they started with a stolen password. Here's how credential-based attacks work, and how Keeper stops them.

Read more