September 2022 Summaries
7 posts from Twingate
Filter
Month:
Year:
Post Summaries
Back to Blog
Twingate is a Zero Trust Remote Access solution that allows network administrators to provide secure fine-grained access to internal or private resources. With the recent update, Twingate is now available in the AWS Marketplace, enabling organizations to obtain Twingate directly through AWS and benefit from simplified procurement and billing. This update also introduces an AWS CloudWatch Lambda integration, which enables administrators to define resources and manage access directly from the AWS Management Console using AWS Resource Tags. The new feature supports a range of AWS resources, including EC2 instances, RDS databases, and ECS services. Twingate's device posture checks, integrations with best-of-breed solutions like CrowdStrike Falcon, and Secure DNS are part of its unrivalled set of integrated components that help organizations solve Remote Access problems. The solution can be used to delegate access control management, allowing teams to self-administer remote access to certain environments, enabling more decentralized access controls for some or all environments, and using AWS as the Source of Truth for remote access.
Sep 26, 2022
1,697 words in the original blog post.
WebAuthn is an industry standard that aims to make online security easier and more straightforward for users, developers, and administrators. It eliminates the need for passwords by using public key credentials and authenticators. WebAuthn's benefits include widespread support, improved user experience, and stronger security. However, it faces challenges such as inconsistent device support, slow adoption by public and private web services, and usability issues. Despite these hurdles, WebAuthn offers significant improvements over other authentication methods like passwords and one-time passwords. It creates stronger credentials by taking human nature out of the security equation and pushes authentication to edge devices. With its simplicity, ubiquity, and security, WebAuthn is poised to revolutionize online authentication and improve online security dramatically.
Sep 23, 2022
5,867 words in the original blog post.
Opal is a modern solution for identity governance and privileged access management, trusted by forward-thinking enterprises such as Blend, Marqeta, and Databricks. It enables employees to easily use its permissions catalog to make self-service requests or generate auto-expiring credentials for cloud infrastructure. Admins can configure powerful security and governance policies on critical resources. The Opal + Twingate integration allows users to request short-lived just-in-time access to infrastructure and applications from web and Slack, delegate approvals and management to system owners and managers with the most context, and automate the escalation and revocation of privileged resource access based on on-call schedules. This integration is part of a holistic zero-trust architecture that limits an organization's attack surface by default. With Opal, employees are assumed to be unvetted, and access must be manually requested using seamless workflows via web or Slack, which is then continuously re-certified as needed.
Sep 22, 2022
1,331 words in the original blog post.
Traditional access control systems were designed for employees on managed devices, but today's blended workforces force administrators to manage a shifting mix of employees and contractors who could be anywhere in the world. Securing contractor access is a particular concern for DevOps teams due to supply chain attacks that are accelerating and making developers primary targets for credential theft. Legacy VPN technologies make this situation worse by giving contractors access to any resource and service on the network, similar to how hackers compromise an IT supply chain. A modern approach of Zero Trust Network Access (ZTNA) offers a path to better access and better security by providing granular control over resource access through the principle of least privilege. ZTNA systems decouple access control from the physical network, making managing contractors much easier, and eliminate lateral movement techniques that hackers use to expand their foothold in networks. By adopting ZTNA solutions like Twingate, companies can protect their codebase from direct attack, reduce supply chain risk, and improve contractor experience without the headaches of VPN.
Sep 15, 2022
4,559 words in the original blog post.
Twingate's secure access solution is based on the principles of Zero Trust Network Access (ZTNA) and provides a scalable, automated provisioning, and management of secure access control. It decouples secure access from traditional physical networks, making deployment and management more straightforward. Twingate creates a flexible network overlay that supports a large user base with diverse access needs, protected resources can be on-premises or across the cloud, and users can be in the office or working remotely. The solution consists of proxies between protected resources and the firewall called Connectors, which make resources invisible from any network, public or private. Twingate's Client app explicitly verifies every access request and enforces least-privileged access policies before user devices connect to protected resources. It supports blended and hybrid workforces by managing all users within a single solution, regardless of their location. The solution also lets administrators create strict, granular access control policies beyond password authentication, monitors device postures, integrates with endpoint security platforms, and provides DNS security. Twingate streamlines access administration by unifying all resources and users within a single system, allowing non-technical personnel to onboard and offboard users or change access policies using a simple console. The solution is scalable, deployable at scale through CI/CD pipelines, and can be integrated with corporate Infrastructure as Code workflows. It supports complex network architectures and provides micro-segmentation, which turns each resource into a virtual subnet with its own secure access policies.
Sep 12, 2022
4,169 words in the original blog post.
Zero Trust Network Access (ZTNA) is a modern approach to access control that makes an organization’s protected resources more secure from cyberattacks. It recognizes that a 0-day flaw or stolen password can compromise a network at any time, and hackers exploit these footholds by using lateral movement techniques. ZTNA's strength lies in its ability to prevent lateral movement and minimize an attack's blast radius. Traditional security approaches try to block lateral movement but fail; instead, ZTNA uses software-defined perimeters (SDPs) to make resources invisible from compromised networks, reducing the opportunities for breach. Micro-segmentation creates a granular network structure that enhances security by hiding each microsegment's structure, limiting exposed resources on a compromised segment, and limiting users to authorized segments. SDP systems can redraw the secure perimeter around each resource, turning it into its own microsegment, and companies no longer need vulnerable VPN gateways or DMZs. ZTNA solutions evaluate device posture and controls, such as firewall, antivirus, lock screen, encryption, and biometric security, to define least-privileged access rules. Implementing ZTNA can reduce the attack surface further by limiting users' access to authorized resources after a social engineering attack.
Sep 09, 2022
4,097 words in the original blog post.
SASE is a technology framework that guides enterprises through the converging trends in secure networking, replacing secure perimeters with a cloud-native service that enforces policies at the network's edge. It represents the convergence of five technologies: Software-Defined Wide Area Networking (SD-WAN), Firewall-as-a-Service (FWaaS), Secure Web Gateway (SWG), Cloud Security Broker (CASB), and Zero-Trust Network Access (ZTNA). Gartner's SASE future identified these five converging technologies. However, few offer a complete solution today, and none offer truly cloud-native solutions.
Sep 02, 2022
4,859 words in the original blog post.