Blogs and News
Find valuable insights, knowledge, and inspiration for your business in our selected articles. Explore practical tips from our team of experts and fuel your company’s growth.
Filter:Show allai-securityassuranceautomationawsblue-teamci-cdcloudcompliancecontainersdeliverydevopsflux-cdgenerative-aigitopsgovernanceidentityincident-responseinfrastructurekubernetesmonitoringnetworkingopen-sourceopenbaopentestingplatform-engineeringpurple-teamred-teamsecrets-managementsecurityspiffe-spiresupply-chainthreat-modelingtrainingzero-trust
The Post Quantum Radar
Keeping track of PQC availability
By Fabian Kammel·Tue, May 26, 2026
Tampered Tokenizers: An AI Supply Chain Meltdown
The tokenizer attack that existing scanners can’t catch, and the supply chain tooling that can.
By Sam Holmes·Fri, May 22, 2026
securitygenerative-aisupply-chain
Validating Zero Trust: Network Policy Testing with Flux CD and Netassert
GitOps revolutionised how we deliver applications, enabling faster deployments and managing infrastructure with targeted declarative precision. However, this precision doesn’t extend to securing dynamic environments and remains incredibly difficult. Consider a historical three-tier application architecture: a frontend web service, backend API, and data store. The engineer’s accountability ended when the application code was pushed to version control, and automation carried it to production (that developers may not be permitted to access).
By Giovanni Baggio·Fri, May 15, 2026
securitynetworkingkubernetesci-cdblue-teamflux-cdgitopszero-trust
The End of Safe Software? No, It's Not.
In the wake of Anthropic’s announcement of Mythos and Project Glasswing, and with the still-emerging blast radius of Aqua Security’s Trivy compromise, many security professionals are predicting the end of safe software. We do not agree. Instead, they simply highlight and reinforce: Security standards are rising, and proactivity breeds assurance Security basics are more important than ever Open source is resilient The Attack Chains that Matter What does this mythical LLM and an open source project’s compromise have to do with each other?
By John Kjell·Tue, May 5, 2026
securityopen-sourcesupply-chaingenerative-ai
Defusing CanisterWorm: How Bun and Deno Secure the JavaScript Supply Chain
TeamPCP’s CanisterWorm is exploiting npm’s postinstall hooks. Learn how modern JavaScript runtimes like Bun and Deno neutralise this threat by default.
By Fabian Kammel·Thu, Apr 30, 2026
supply-chainsecurityopen-sourcethreat-modeling
How LLMs Are Ending The Attacker-Defender Stalemate (And What to Do About It)
Frontier Large Language Models (LLMs) are reshaping how software is built, attacked, and secured. Their impact is most visible in code generation and vulnerability discovery, where they reduce the time and expertise required to produce outputs that previously demanded specialist knowledge. As organisations rush to adopt AI tools into development and operations, a practical question arises: in a world where AI can autonomously write exploits and generate patches, what is the role of human-driven security?
By Sam Holmes & James Callaghan·Tue, Apr 28, 2026
securitygenerative-aired-teamgovernanceassuranceblue-team
The Vercel Breach: When Roblox Cheats, AI Tools, and Poor Secrets Management Collide
The recent breach at Vercel is a textbook example of how modern supply-chain compromises unfold, starting with a Roblox cheat script.
By Aiman Alsari·Tue, Apr 21, 2026
openbaosupply-chainai-securitysecrets-management
ControlPlane Enterprise for OpenBao - Meet the Team
Meet the team behind the new ControlPlane Enterprise for OpenBao
By Rob Kenefeck·Tue, Apr 7, 2026
openbaosecuritysecrets-managementopen-sourceinfrastructure
sandbox-probe: Putting AI sandboxing to the test
Announcing ControlPlane’s sandbox-probe: testing the limits of AI Agent Sandboxes
By Alberto Rodriguez & Jack Kelly·Mon, Mar 23, 2026
generative-aicontainerspentestingsecurity
Why We Are Throwing Our Weight Behind OpenBao
We are expanding our open source commitment to include OpenBao. Here is why we believe in true digital sovereignty, meeting market demand, and providing sustainable support for the maintainers of critical security projects.
By Andrew Martin·Fri, Mar 20, 2026
securitygovernancecloudopen-source
ControlPlane Launches Enterprise Support For OpenBao To Strengthen Secrets Security
Announcing the launch of a new offering designed to help organizations securely adopt and operate the OpenBao secrets management platform.
By Pam Oldfield·Thu, Mar 12, 2026
assurancecloudcomplianceidentityinfrastructureopenbaoplatform-engineeringsupply-chainzero-trust
Out on the GenAI Wild West: Part II - The Long Arm of the Law
As AI agents execute workflows and access sensitive systems, organizations must shift from model safety to architectural controls, continuous testing, and framework-aligned governance.
By Torin van den Bulk·Tue, Mar 3, 2026
securitygenerative-aicompliancegovernance
Check Point and ControlPlane Partner to Help Enterprises Securely Scale AI and Accelerate Agentic Innovation
The partnership delivers a comprehensive, regulator-ready security framework to enable organizations to move confidently from AI experimentation to production deployment.
By Pam Oldfield·Tue, Feb 24, 2026
ai-securitycloudcompliancegenerative-aigovernancesecurity
Open Source Security Risks: Countering the Threat
Open source supply chain attacks are on the rise. What can businesses do to protect themselves?
By Pam Oldfield·Thu, Feb 19, 2026
generative-aicloudcompliancegovernancesecurity
FluxCon Atlanta Was Just the Start
Reflecting on eight years of Flux deployment, two years of Enterprise and a watershed moment.
By Andrew Martin·Tue, Feb 17, 2026
gitopssecurityflux-cdci-cdkubernetes
Making TDD Work for You, Part 2: crossing TDD's tribal lines
Second and final part of a series about how to make TDD work for you.
By Houssem El Fekih·Tue, Aug 26, 2025
devopsautomationdeliverycontainers
Out on the GenAI Wild West: Part I - Red Team Redemption
Multi-turn agentic adversarial testing uncovers vulnerabilities in foundational models, highlighting the need for adaptive defenses, model-specific strategies, and continuous evaluation to secure GenAI
By Torin van den Bulk·Fri, Aug 15, 2025
securitygenerative-aipentesting
Penetration Testing and Purple Teaming: Essential for Financial Services Security
The financial services sector is increasingly targeted by cybercriminals, with cyberattacks leading to significant financial losses and reputational damage. Penetration testing and purple teaming are two security testing methodologies essential in enhancing cybersecurity posture and readiness. In this article, we will explore the importance of penetration testing and purple teaming in protecting financial services institutions against ever-evolving threats. The Impact of Cybercrime on Financial Services Financial institutions are enticing targets for cybercriminals due to the potential for direct financial gain and access to vast amounts of valuable data.
By Gabriela Georgieva·Tue, Aug 5, 2025
securitypentestingpurple-teamblue-team
Trust Issues: Navigating Open Source and Software Supply Chain Risk
A two-part journey through the lens of large banks, regulated industries, and security consultancies
By Francesco Beltramini·Thu, Jul 24, 2025
securitysupply-chaincompliancegovernanceopen-source
The Quantum Leap: Navigating PQC Adoption in Today's Digital Infrastructure
Key insights on PQC adoption in today’s digital infrastructure
By Fabian Kammel·Fri, Jul 18, 2025
securityinfrastructurecompliancekubernetesopen-source
DevSecOps is the New DevOps
A look at transforming to DevSecOps from a technical and cultural perspective, including a deeper look some supply-chain considerations.
By Eugene Davis·Fri, Jul 4, 2025
securitydevopssupply-chainci-cdcontainers
Making TDD Work for You, Part 1: When to Invest and Essential Practices
First part of a series about how to make TDD work for you.
By Houssem El Fekih·Tue, Jun 10, 2025
devopsautomationdeliverycontainers
Improve your OPA policies user-based with Gatekeeper
For Open Policy Agent (OPA), most of the policies that are written are based on Kubernetes resources. For example, the deployment of Pods should be avoided with the tag latest. But sometimes it is necessary to write more fine-grained OPA policies based on Kubernetes users, groups or service accounts. Let me give you an example so that the code and explanations can be better understood. Example of a use case Imagine you have a Jenkins job that creates Namespaces for tenants.
By Jose A. Berchez - ControlPlane·Wed, May 28, 2025
kubernetessecuritycompliancecontainersidentity
Beyond Compliance: Strategic Cyber Resilience in Financial Services Under the EU’s CRA
The EU’s Cyber Resilience Act (CRA) isn’t just another regulatory hurdle; it’s a fundamental shift in how we approach digital security.
By Andrew Crawford·Thu, May 8, 2025
compliancesecuritysupply-chainthreat-modelinginfrastructure
Back to the Future: Next-Generation Cloud Native Security - A talk by Andrew Martin & Matt Jarvis
In this talk, Andrew Martin and Matt Jarvis explored the history of cloud-native computing, examined the current security landscape, and shared their predictions for the decade ahead.
By Niamh O'Loughlin·Thu, May 1, 2025
securitykubernetescloudthreat-modelingsupply-chain
Kubernetes and the UK
Kubernetes marked its 10th anniversary last year, and the CNCF commemorates a decade of remarkable success this year.
By Niamh O'Loughlin·Fri, Apr 11, 2025
kubernetessecuritycontainerscloudtraining
ControlPlane at KubeCon EU London ‘25 - Recap
A recap of ControlPlane’s activities at KubeCon EU in London
By Ashley Ward·Thu, Apr 10, 2025
kubernetessecuritytrainingpentestingcloud
Flux D2 Reference Architecture – Gitless GitOps for Secure Multi-Tenancy
Introducing Gitless GitOps and the Flux Operator for secure, scalable multi-tenant Kubernetes environments.
By Niamh O'Loughlin·Thu, Apr 3, 2025
flux-cdgitopskubernetesinfrastructuresecurity
ControlPlane is Heading to KubeCon EU '25 London
ControlPlane’s events and CTF at KubeCon EU in London
By Niamh O'Loughlin·Tue, Mar 25, 2025
kubernetessecuritytrainingcontainerscloud
Ephemeral Environments for GitLab Merge Requests with Flux Operator
Flux Operator creates ephemeral environments for GitLab MRs. Each MR gets an automatic, dedicated preview instance for faster validation and iteration.
By Francesco Beltramini, ControlPlane·Mon, Mar 17, 2025
flux-cdgitopsci-cdkubernetesdevops
See it, Hack It, Sort It: How Open Source Software Protects Our AI Enablers
Protecting GPU resources in cloud infrastructure: threat modeling, attack vectors, and practical security measures using open source tools.
By Marcus Tenorio·Mon, Feb 24, 2025
securitykubernetesgenerative-aithreat-modelingpentesting
What is Continuous Delivery & How Does It Work?
An exploration of what Continuous Delivery is, how it differs from related concepts, and how Flux can help.
By Jack Kelly·Wed, Feb 12, 2025
ci-cdflux-cdgitopskubernetesdevops
Securing Kubernetes Clusters: Lessons and Best Practices from the Field
Key lessons from ControlPlane’s KubeCon EU 2023 talk, covering Kubernetes threat modelling, attack techniques, and essential security measures to protect clusters.
By ControlPlane·Thu, Feb 6, 2025
kubernetessecuritypentestingthreat-modelingtraining
What is Flux CD
Flux is an open source tool used to keep Kubernetes clusters in sync with configuration artefacts, especially when that configuration needs to change regularly, like when you update your software or a dependent part of your system receives a patch. Flux has been built from the ground up to use native Kubernetes APIs and to integrate with the wider Kubernetes ecosystem tools like Prometheus. It supports multi-tenancy clusters and scales massively with support for syncing multiple Git Repositories or other sources of configuration artefacts.
By Rob Kenefeck·Fri, Jan 24, 2025
flux-cdgitopskubernetesci-cddelivery
Celebrating a Year of Commitment to CNCF Flux: Sustainability, Innovation, and Growth
ControlPlane supported CNCF Flux over the past year by enabling ongoing development, innovation, and community engagement.
By ControlPlane·Fri, Jan 24, 2025
flux-cdgitopskubernetesinfrastructuredevops
Streamlining Application Delivery with Flux and the Generic Helm Chart Pattern
Based on the excellent technical article written by Flux Core Maintainer and fellow ControlPlaner Stefan Prodan.
By Francesco Beltramini·Wed, Jan 15, 2025
flux-cdgitopskubernetesplatform-engineeringdelivery
What is GitOps
This is the first in a series of articles about Flux CD, and introduces the foundational knowledge of GitOps. GitOps is a term coined by Weaveworks in 2018. It has been referred to as the best thing since Infrastructure as Code, and has also been referred to as being versioned CI/CD on top of declarative infrastructure. Much like how DevOps broke down the silos between Developers and Operations/Infrastructure Teams, GitOps merges the concerns for application deployment with infrastructure deployment.
By Rob Kenefeck·Fri, Dec 13, 2024
gitopsci-cdkubernetesautomationdevops
Unlocking Delivery Success: Overcoming Framework Limitations in Regulated Environments
ControlPlane pioneers delivery success by blending Agile adaptability with Waterfall structure to overcome regulatory challenges and drive efficiency.
By ControlPlane Agile Team·Tue, Dec 10, 2024
devopscomplianceautomationdelivery
Automated Cloud Native Incident Response with Kubernetes and Service Mesh
ControlPlane is a proud member of and long-term contributor to the Fintech Open Source Foundation (FINOS), and almost a third of our firm’s consultants contribute to initiatives like the AI Readiness SIG, Common Cloud Controls, and Compliant Financial Infrastructure.
By Matt Turner & Francesco Beltramini·Tue, Nov 19, 2024
securitykubernetesautomationincident-responsethreat-modelingblue-teammonitoring
Open Source in Finance Forum New York 2024 Recap
By Francesco Beltramini·Tue, Nov 12, 2024
compliancecloudgenerative-aisecuritythreat-modeling
The Path to Zero CVEs: Vanquishing Cyber Threats
Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.
By Andrew Martin and Michael Lieberman·Mon, Nov 11, 2024
securitycompliancesupply-chainthreat-modelingmonitoring
Enterprise for Flux CD Now Available on AWS Marketplace
Our products and services are now available through our partnership with AWS
By ControlPlane·Wed, Nov 6, 2024
flux-cdgitopsawskubernetesplatform-engineering
ControlPlane at KubeCon NA '24 Salt Lake City
ControlPlane’s events and CTF at KubeCon NA in Salt Lake City
By Niamh O'Loughlin·Fri, Nov 1, 2024
kubernetessecuritytrainingcontainerspentesting
The Landscape Podcast: Flux with Core Maintainer Stefan Prodan
Stefan Prodan, core maintainer of Flux, discusses its role in automating Kubernetes with GitOps, enhancing security, and scaling infrastructure management
By Stefan Prodan·Tue, Oct 22, 2024
flux-cdgitopskubernetesdevopsplatform-engineering
Introducing the Flux Operator - GitOps on Autopilot Mode
Stefan Prodan, core maintainer of the CNCF Flux project, introduces the Flux Operator.
By Stefan Prodan·Mon, Oct 14, 2024
flux-cdgitopskubernetesplatform-engineeringautomation
ControlPlane Outreach: Exposing At-Risk Students to Careers in Tech
ControlPlane partnered with Spark! to empower at-risk students through workshops that introduced them to tech careers, continuous learning, and future possibilities.
By Maddie Clingan and Yannis Follias·Mon, Oct 7, 2024
compliancegenerative-aikubernetessecuritytraining
Future Open Source LLM Killchains! A Talk by Vicente Herrera
In The Security Ai Summit 2024, Principal Consultant Vicente Herrera explores how advanced adversaries could exploit vulnerabilities in the open-source AI ecosystem, particularly in large language models (LLMs), by targeting MLOps infrastructure, with a focus on mitigation strategies to prevent such attacks.
By ControlPlane Team·Fri, Oct 4, 2024
generative-aisecuritysupply-chainthreat-modelingkubernetes
FINOS AI Readiness Open Sourced
ControlPlane’s pivotal role in the FINOS AI Governance Framework highlights our commitment to advancing AI readiness in financial services.
By ControlPlane·Tue, Oct 1, 2024
generative-aicompliancesecuritygovernancethreat-modeling
Smarter Than Your Average SBOM! A Talk by Matt Jarvis & Andrew Martin
In Kubernetes Community Day UK 2023 Snyk, Director Matt Jarvis and ControlPlane CEO Andrew Martin teamed up and deeply delved into the Software Bill of Materials (SBOMs) world
By ControlPlane Team·Mon, Sep 2, 2024
securitysupply-chaincompliancekubernetescontainers
FINOS AI Governance Framework
At the Secure AI Summit earlier this year, ControlPlane’s Torin van den Bulk delivered an eye-opening talk on the ‘Invisible infiltration of AI supply chains by adversarial actors’. This talk examines the importance of securing the data, models, and pipelines involved at each step of an AI supply chain.
By Torin van den Bulk·Wed, Aug 14, 2024
generative-aisecuritycompliancethreat-modelingsupply-chaingovernance
ControlPlane at the Bleeding Edge: Ending the Pain of Periods
The ControlPlane Agile team is proudly taking steps toward breaking down awkwardness, stigma, and workplace barriers to menstrual health.
By ControlPlane Agile Team·Mon, Aug 12, 2024
trainingsecurityinfrastructurecompliance
I'll Let Myself In: Kubernetes Privilege Escalation Tactics
ControlPlane’s talk at KubeCon Europe 2024 gave attendees an overview of Cloud-Native Penetration Test and privilege escalation tactics to make cloud native systems more secure
By Iain Smart·Wed, Jul 24, 2024
kubernetessecuritypentestingred-teamtraining
The Impact of the Polyfill Supply Chain Attack
How the Polyfill supply chain attack highlights the issues with trust in open source software and what approaches can be taken to mitigate the risk.
By Kevin Ward·Mon, Jul 8, 2024
securitysupply-chainpentestinginfrastructurecompliance
Mastering the Cloud Native Wave: Security Resilience in Modern Systems
ControlPlane’s talk at InfoSec Europe 2024 gave attendees an overview of observations and techniques to make cloud native systems more resilient"
By Rob Kenefeck·Fri, Jun 28, 2024
securitycloudkuberneteszero-trust
Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 2)
How malicious VSCode extensions can steal your credentials
By Fabian Kammel & Kevin Ward·Wed, Jun 26, 2024
securitypentestingred-teamsupply-chaindevops
Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 1)
Attack paths for remotely compromising Visual Studio Code
By Kevin Ward & Fabian Kammel·Wed, Jun 26, 2024
securitypentestingred-teamsupply-chaindevops
Open Source Dynamics in the Era of Licence Innovation
This blog post explores innovative business models for open source projects, focusing on enterprise support and subscription services, and discusses the balance between community contributions and sustainable growth.
By Andrew Martin·Tue, May 28, 2024
cloudgenerative-aiinfrastructuresecurity
How to create a Table Top Exercise for Cyber Incident Responders
OpenSSF and ControlPlane created, hosted and ran a tabletop exercise for Incident Responders in the format of a panellist discussion. Let’s have a look behind the scenes and uncover tips and tricks how a security team can carry out a similar exercise.
By Ian Barbour·Wed, May 15, 2024
securitytrainingpentestingthreat-modelingsupply-chainincident-response
Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native Ecosystem
James Callaghan, principal consultant at ControlPlane, and Constanze Roedig discuss open source cloud native threat intelligence at KubeCon + CloudNativeCon Europe 2024
By James Callaghan·Wed, May 8, 2024
securitykubernetesthreat-modelingpentestinginfrastructure
Flux CD Architecture Overview
Stefan Prodan, core maintainer of the CNCF Flux project, provides a comprehensive overview of Flux CD architectures for multi-cluster continuous delivery
By Stefan Prodan·Thu, May 2, 2024
flux-cdgitopskubernetesci-cdplatform-engineeringmonitoring
Isovalent and ControlPlane's Joint Whitepaper
Engineers, product managers and consultants from both companies explore how Cilium can tackle the challenges of cloud native compliance
By Ollie Cuffley-Hur & Martyn Smith·Thu, Apr 25, 2024
compliancekubernetesnetworkingsecurityplatform-engineering
The Lowdown on Locked Namespaces
Marco De Benedictis, senior consultant at ControlPlane, discusses how Kubernetes namespaces have grown from an optional feature to a security boundary at KubeCon + CloudNativeCon Europe 2024
By Marco De Benedictis·Mon, Apr 15, 2024
kubernetessecuritycontainersnetworkingthreat-modeling
Zero Trust Training Courses with the Linux Foundation
ControlPlane has authored two Zero Trust training courses for the Linux Foundation
By ControlPlane·Wed, Apr 3, 2024
zero-trustsecuritytrainingspiffe-spireidentity
ControlPlane at KubeCon EU Paris ‘24 - Recap
A recap of ControlPlane’s activities at KubeCon EU in Paris
By Ashley Ward·Thu, Mar 28, 2024
kubernetessecurityflux-cdtraininggitops
The Envoy Gateway End User Threat Model, in collaboration with the Linux Foundation
ControlPlane has collaborated with the Linux Foundation to threat model Envoy Gateway and generate an End User guide
By ControlPlane·Wed, Mar 27, 2024
securitythreat-modelingkubernetesinfrastructurenetworking
Flux CD: D1 Reference Architecture
ControlPlane’s commitment to supporting the Flux Project continues, providing a model and a guide for multi-cluster, multi-tenant environments
By Andrea Martino·Wed, Mar 27, 2024
flux-cdgitopskubernetesplatform-engineeringinfrastructure
ControlPlane at KubeCon EU '24 Paris
ControlPlane’s talks and events schedule for KubeCon EU in Paris
By Niamh O'Loughlin·Thu, Mar 14, 2024
kubernetessecurityflux-cdtrainingcontainers
Container Security Basics at Securi-Tay 2024
ControlPlane’s principal consultant, Iain Smart, talks about Container and Kubernetes Security at Abertay Hackers’ Securi-Tay 2024
By Iain Smart·Mon, Mar 4, 2024
securitycontainerskubernetespentestingtraining
NIST Special Publication 800-204D calls for GitOps approaches
Exploring how NIST’s latest publication underscores the necessity of integrating GitOps strategies in software supply chain security within DevSecOps CI/CD pipelines
By Andrew Martin·Sun, Mar 3, 2024
gitopssecuritycomplianceci-cdsupply-chain
Bringing light to risks lurking in the black boxes of AI models
ControlPlane’s principal consultant, Vicente Herrera, talks about AI Security at OpenUK’s “State of Open Con 2024”
By Vicente Herrera·Fri, Feb 16, 2024
generative-aisecuritykubernetespentestingthreat-modeling
ControlPlane backs the CNCF Flux Project by Employing Maintainers
ControlPlane’s support for the CNCF Flux project ensures the sustainability and security of critical systems through open source maintenance and innovative enterprise solutions
By Andrew Martin·Thu, Feb 15, 2024
flux-cdgitopskubernetessecurityinfrastructure
ControlPlane and Scott Logic Collaborate on Scottish Government Identity and Payments Systems
Collaborative efforts between ControlPlane and Scott Logic on the Scottish Government identity and payment systems: security architectures, platform integrations, and project assurance
By Andrew Martin·Thu, Feb 15, 2024
securitycompliancekubernetesinfrastructureplatform-engineering
Tangible Value with ControlPlane Enterprise for Flux CD
ControlPlane Enterprise elevates Flux CD with enhanced security, support, and compliance, catering to diverse needs in Kubernetes deployments
By ControlPlane·Mon, Feb 12, 2024
flux-cdgitopskubernetessecuritycompliance
AI Software Development Lifecycle on Kubernetes
AI software’s evolution on Kubernetes: current methodologies, potential future developments, and inherent risks
By ControlPlane·Tue, Jan 30, 2024
generative-aikubernetessecuritythreat-modelingcontainers
ControlPlane at OpenSSF and Open Source Summit Japan, 2023
ControlPlane’s journey to Japan and an overview of some of the talks presented
By Jack Kelly·Fri, Jan 26, 2024
securitysupply-chainkubernetestraininginfrastructure
Navigating Cloud Security and Automation with Eficode
Talking to Eficode about Cloud Native Security Challenges
By Andrew Martin·Thu, Jan 18, 2024
securitycloudautomationdevopskubernetes
Play the 2023 CNCF CTF Scenarios with the Revamped Simulator
The public release of the 2023 CNCF CTF Scenarios is here! In this blog post, we’ll walk you through the revamped simulator and how to get started with the challenges.
By Kevin Ward·Fri, Jan 12, 2024
securitykubernetespentestingcontainerstraining
Cloud Native and Kubernetes Security Predictions 2024
A look into the tumultuous waters of cloud and Kubernetes security in 2024
By Andrew Martin·Thu, Jan 11, 2024
securitykubernetescloudgenerative-aisupply-chain
Andrew Martin on "Nerding Out With Viktor" — Security, Penetration Testing, and Threat Modelling
The inaugral “Nerding Out With Viktor” podcast with ControlPlane CEO, Andrew Martin
By Niamh O'Loughlin·Thu, Jan 4, 2024
securitypentestingthreat-modelingkubernetesred-team
Unveiling the Future of CI/CD Security: A Deep Dive into Advanced Practices
The “Advanced CI/CD Security” workshop we ran at DevOpsCon 2023 in Munich provided a deep dive into the latest practices shaping the future of cloud security
By Fabian Kammel·Mon, Dec 18, 2023
securityci-cddevopskubernetestraining
Conference Recap: ControlPlane at KubeCon NA '23 Chicago
Reflecting upon our experience at KubeCon North America 2023
By Jasmine Andine·Mon, Nov 27, 2023
ControlPlane at KubeCon NA '23 Chicago
Where to find ControlPlane talks and events at KubeCon North America 2023 in Chicago
By Jasmine Andine·Mon, Nov 6, 2023
kubernetessecuritytrainingpentestingcontainers
Take Zero Trust to the Next Level with Confidential Virtual Machines
SPIFFE and confidential computing are two security projects that minimize the level of implicit trust a user needs to place into a computing system. We will show how to combine these approaches to minimize the trust we need to place in public cloud services
By Fabian Kammel·Tue, Aug 29, 2023
spiffe-spiresecurityawszero-trustidentitycloud
The National Cybersecurity Strategy Implementation Plan
The first annual iteration of the National Cybersecurity Strategy Implementation Plan has been released, detailing how the US government plans to achieve the goals previously outlined in 2021’s National Cybersecurity Strategy
By Andrew Martin·Tue, Jul 18, 2023
securitycompliancesupply-chainthreat-modelinginfrastructure
Dark Matter Cloud Anonymous: Andrew Martin and Amanda Brock discuss open source and OpenUK's report
The event took questions from an audience of industry veterans and discussed open source security, developer understanding of Kubernetes, FinOps for cloud, and more
By Emma Ballantyne·Thu, Jul 13, 2023
securitykubernetescloudinfrastructurecompliance
Charting Zero Trust and High Assurance: ControlPlane’s Takeaways from the NIST Multi-Cloud and OSCAL Conferences
ControlPlane’s Experience at the 4th Annual OSCAL and Multi-Cloud Conferences Sponsored by NIST
By Torin van den Bulk·Fri, Jun 16, 2023
compliancezero-trustsecuritycloudtraining
Conference Recap: ControlPlane at KubeCon EU '23
ControlPlane talk & event write-ups from KubeCon EU in Amsterdam
By Ollie Cuffley-Hur·Mon, Apr 24, 2023
kubernetessecuritytrainingspiffe-spirethreat-modeling
Threat Modelling Zero Trust at KubeCon EU 2023 Amsterdam
ControlPlane show you how to threat model Zero Trust architectures at KubeCon Europe 2023 in Amsterdam
By James Callaghan·Fri, Apr 21, 2023
securitythreat-modelingzero-trustkubernetesidentity
KubeCon EU '23: Open Source Releases
ControlPlane open sources security and threat model knowledge
By Andrew Martin·Fri, Apr 21, 2023
securitykubernetesthreat-modelinginfrastructuretraining
Netassert v2: Network Security Testing
How to write, test, and secure your network configurations
By Prithak Sharma·Thu, Apr 20, 2023
securitynetworkingkubernetescontainersinfrastructure
Collie: A toolkit for securing cloud controller provisioned infrastructure
Demonstrating compliance and securing infrastructure provisioned by Kubernetes Cloud Infrastructure Controllers
By Rowan Baker & Henry Mortimer·Thu, Apr 20, 2023
securitycompliancekubernetescloudinfrastructure
ControlPlane at DevSecCon UK Meet-up
ControlPlane at DevSecCon UK Meet-up
By Joe Collins·Tue, Apr 11, 2023
securitykubernetescloudinfrastructurenetworking
ControlPlane at KubeCon EU 2023 Amsterdam
Where to find ControlPlane talks and events at KubeCon Europe 2023 in Amsterdam
By Ollie Cuffley-Hur·Thu, Mar 16, 2023
kubernetessecuritytrainingpentestingcontainers
Intro to the CloudNative SecurityCon CTF
Capture-the-Flag platform demo with The New Stack 🔐🏴☠️
By ControlPlane·Mon, Mar 6, 2023
securitykubernetescontainerspentestingtraining
The Most Excellent Learnings of CloudNative SecurityCon 2023
The Cloud Native security community is vibrant and strong 🌩🎉
By ControlPlane·Tue, Feb 7, 2023
securitykubernetestrainingcloudthreat-modeling
The Inaugural CloudNative SecurityCon, North America, and Security Zero Day
Cloud Native security bursts onto the conference circuit 🌩🎉
By ControlPlane·Mon, Jan 16, 2023
securitykubernetestrainingpentestingcontainers
SPIFFE: The Keystone Species of Cloud Native Security
Short-lived cryptographic identities are the basis upon which secure communication and access control are built 🗟🙊
By ControlPlane·Mon, Jan 16, 2023
spiffe-spiresecurityidentityzero-trustkubernetes
Cloud Native and Kubernetes Security Predictions 2023
A speculative look into the perils and opportunities that 2023 holds 🕵️🔎
By Andrew Martin·Fri, Jan 13, 2023
kubernetessecuritycloudsupply-chaingenerative-ai
KCD UK 2022
Kubernetes Community Days 2022 at CodeNode, London ☸
By Jaymie Thomas·Thu, Nov 24, 2022
kubernetessecuritynetworkingcontainerstraining
ControlPlane Accelerates International Expansion
ControlPlane expands into North America and APAC with two key executive hires 📈
By Andrew Martin·Tue, Nov 22, 2022
securitykubernetescloudinfrastructure
KubeCon NA 2022 - Techstrong TV interview
Andrew Martin joins Mitch Ashley of Techstrong TV for a chat about ControlPlane, Hacking Kubernetes, and avoiding configuration gotchas 📺
By Jaymie Thomas·Mon, Nov 21, 2022
kubernetessecuritycontainerstraining
An evening of network security
An evening of network security by Tailscale and ControlPlane 🔐
By Jaymie Thomas·Mon, Nov 14, 2022
securitynetworkingkubernetestraining
ControlPlane at KubeCon NA 2022 Detroit
Where to find ControlPlane talks and events at KubeCon North America 2022, Detroit ☸
By Jaymie Thomas·Sun, Oct 23, 2022
kubernetessecuritytrainingpentestingcontainers
The Future of Open Source Technology in Financial Services
ControlPlane’s New York City event with FINOS 🏙
By Jaymie Thomas·Wed, Oct 19, 2022
securitycompliancecloudkubernetescontainers
What's New - Kubernetes 1.25 Security Features
Overview of new security features in Kubernetes v1.25 ⚸🔐
By James Cleverley-Prance·Tue, Sep 27, 2022
kubernetessecuritycontainersidentityinfrastructure
VEXing challenges - ControlPlane at the Open Source Summit Europe 2022, Dublin
ControlPlane and OpenUK information at the Open Source Summit Europe 2022 in Dublin 🔐
By Jaymie Thomas·Tue, Sep 13, 2022
securitysupply-chainkubernetestraining
OpenUK Reports on the State of Open: The UK in 2022
ControlPlane contributes to the definitive open source report for the UK
By Andrew Martin·Sun, Jul 10, 2022
securityinfrastructuresupply-chaincompliancetraining
Walking the talks - ControlPlane at KubeCon Europe 2022
ControlPlane talks at KubeCon EU, 2022 ☸
By Jaymie Thomas·Tue, Jun 28, 2022
kubernetessecuritytrainingthreat-modelingpentesting
Shift Left: Where Cloud Native Computing Security Is Going (The New Stack)
DevSecOps leaders on the direction of CloudNative Security
By ControlPlane·Fri, Jun 3, 2022
securityclouddevopskubernetesgitops
Hacking Kubernetes Book Released
A threat-based guide to Kubernetes security 📖
By Andrew Martin·Sat, Nov 6, 2021
kubernetessecuritypentestingthreat-modelingcontainers
Securing the Kubernetes Supply Chain: Software Factory Reference Architecture
Sophisticated mechanisms and best practices to enhance defenses against supply chain threats in Kubernetes
By Andrew Martin·Wed, Oct 13, 2021
kubernetessecuritysupply-chainci-cdcontainers
Hardening Git for GitOps
ControlPlane whitepaper on securing GitOps workflows at source ✍
By Andrew Martin·Wed, May 12, 2021
gitopssecurityflux-cdci-cdkubernetes
CNCF Cloud Native Security Whitepaper
ControlPlane collaborates with authors in sig-security 📜
By Andrew Martin·Tue, Dec 1, 2020
securitykubernetescloudthreat-modelingcompliance
Hands-on Kubernetes Security
Learning Kubernetes the Secure Way 💻
By Pi Unnerup·Thu, Nov 12, 2020
kubernetessecuritytrainingpentestingcontainers
Kubernetes Predictions 2019
5 predictions and 5 wishes for Kubernetes in the year ahead 🕵️🔎
By Andrew Martin·Wed, Jan 9, 2019
kubernetessecuritycloudcontainersinfrastructure
ControlPlane Sponsors PhD of in-toto Author Santiago Torres
ControlPlane, the open source and cloud native security company, sponsors the PhD work of in-toto author Santiago Torres, furthering the advancement of software supply chain security.
By Andrew Martin·Thu, Nov 15, 2018
securitysupply-chaininfrastructuretraining
11 Ways (Not) to Get Hacked
An overview of essential security features for Kubernetes, and a glance to the future 👨🚀
By Andrew Martin·Tue, Jun 5, 2018
kubernetessecuritycontainersinfrastructureincident-response
No posts match the selected tag. Reset filter.
We value your privacy
Cookies are used to enhance your browsing experience.
Accept CookiesOpt out