Tools Don’t Deliver CMMC Compliance – Documentation Does

In many organizations, CMMC readiness is approached like a familiar engineering problem: select the right tools, automate where possible, and assume the compliance outcome will follow. That assumption is costly. Tools can strengthen security. They can generate telemetry, enforce configurations, and reduce manual effort. But CMMC is not a product review, and it is not […]
Official RPO Status: What It Means for Our CMMC Clients—and What Comes Next

For organizations across the Defense Industrial Base (DIB), cybersecurity is no longer optional. It’s a prerequisite for winning and retaining contracts. At Idenhaus, we have been helping clients meet that standard for years—well before CMMC formalized those expectations. Now, we are pleased to share an important milestone in that work: Idenhaus is a Registered Provider […]
Laying the Identity Foundation: Building Your Digital House

Building a strong house requires a solid foundation and a well-thought-out design. The same principle applies to your organization’s digital identity foundation. Just as a physical house protects its inhabitants and valuables while allowing authorized comfort and access for a growing family, a robust Identity Management (IdM) system safeguards your digital assets and seamlessly controls […]
6 Best Practices for Privileged Access Management: What Experts Agree On

Privileged Access Management (PAM) is a cornerstone of modern cybersecurity, especially as organizations face increasing threats from insider misuse, credential theft, and lateral movement attacks. Most organizations use PAM as part of a broader compliance risk framework to meet regulatory expectations while supporting operational agility by automating access provisioning and revocation. As you look to […]
Strategies for RBAC Alignment: Pre-Go-Live Baselining and Automation

By Richard Hawes In a previous blog, I discussed the challenges of implementing a Role-Based Access Control (RBAC) framework that will almost surely not be perfectly aligned with all users’ real access for practical reasons. Misaligned entitlements complicate RBAC and access certification, leading to inefficiencies and potential security gaps. This second part of the series explores […]
Top 10 Reasons To Do End-to-End (E2E) Testing

By Hanno Ekdahl Frequently, testing is often shortchanged in the implementation cycle because it is often the last step in the process. Delays in design and development are often mitigated by reducing testing time to meet deadlines, or at least minimizing delays. While this strategy may alleviate leadership’s concerns in the moment, it is unlikely […]
Turning User Password Management On Its Head

Resetting passwords is a required task for end users in any organization. Yet, it often comes with a host of challenges that lead to frustration and confusion. Here’s a closer look at some of the most prevalent challenges end users face when resetting their passwords that can leave them feeling like they’re navigating a labyrinth […]
Zero Trust – Avoiding the Paranoid Posture of “Trust No One”

The approach for protecting our digital assets from cybercrime, fraud, and abuse has been coined by the cybersecurity industry as “Zero Trust” and even defined as an architecture approach by NIST 800-207. At first glance, it appears that the pendulum on managing digital threats seems to have turned towards an almost paranoid response: “Trust No […]
The Good, The Bad, The Agile

The Good, The Bad, and The Agile Agile methodologies have become increasingly popular as businesses have sought to develop software more quickly and efficiently. Agile methods are based on iterative development, where software is developed in small increments and delivered on shorter timeframes. These development cycles, called Sprints, allow greater flexibility and responsiveness to changing […]
The Importance of Multiple IT Environments

By Richard Hawes Very early in my IT career, I learned that, as a matter of general best practice, companies almost always have at least two environments for critical systems and usually three for application development and management. Some companies, depending on their complexity and needs, have more than that. This is to enable the […]