Mission Control Blog

Discover how to advance your security program with the latest content from our community.
Erkang Zheng
Erkang Zheng

I founded JupiterOne because I envision a world where decisions are made on facts, not fear; teams are fulfilled, not frustrated; breaches are improbable, not inevitable. Security is a basic right.

We are building a cloud-native software platform at JupiterOne to deliver knowledge, transparency and confidence to every digital operation in every organization, large or small.

I am the Founder and CEO of JupiterOne, and also a cybersecurity practitioner  with 20+ years experience across IAM, pen testing, IR, data, app, and cloud security. An engineer by trade, entrepreneur at heart, I am passionate about technology and solving real-world challenges. Former CISO, security leader at IBM and Fidelity Investments, I hold five patents and multiple industry certifications.

12 cyber resilience questions
May 12, 2023
Blog
12 cyber resilience questions for the C-Suite and Board

Cyber resilience starts with knowing which questions the organization should answer, across all levels, from the front lines to the Board of Directors.

Erkang Zheng
JupiterOne participates in new Open Cybersecurity Schema Framework (OCSF) industry initiative
August 10, 2022
Blog
JupiterOne participates in new Open Cybersecurity Schema Framework (OCSF) industry initiative

At JupiterOne, we recognize the importance of building community — not just for the benefit of every cybersecurity professional out there, but for the organizations

  • CSPM
  • CAASM
Erkang Zheng
JupiterOne Achieves $1B+ Valuation with $70M Series C: The Next Step in Our Journey
June 2, 2022
Blog
JupiterOne Achieves $1B+ Valuation with $70M Series C: The Next Step in Our Journey

It’s a big day for us here at JupiterOne. We just closed a $70M Series C funding round, achieving a $1B+ valuation, and welcomed new investors to the JupiterOne

  • CAASM
Erkang Zheng
Empowering Security with Critical Assets & Connecting Business Context
April 14, 2022
Blog
Empowering Security with Critical Assets & Connecting Business Context

You’ve identified and collected all your cyber assets into one place. Now what? There are thousands, or even hundreds of thousands assets and potentially countless

  • CAASM
  • SecOps
Erkang Zheng
Launching Starbase: A New Open-Source Contribution from JupiterOne
February 23, 2022
Blog
Launching Starbase: A New Open-Source Contribution from JupiterOne

I started JupiterOne with two strong core beliefs that shape how to address the technical challenges I was facing and overall battles in the cybersecurity industry as

  • CSPM
  • CAASM
  • SecOps
Erkang Zheng
2022 Lunar New Year Video Greeting from Erkang Zheng
January 31, 2022
Blog
2022 Lunar New Year Video Greeting from Erkang Zheng

As we prepare to celebrate Lunar New Year, we offer you a personal story of what the new year tradition means to Erkang Zheng, CEO of JupiterOne.

Erkang Zheng
Potential CloudFront/S3 takeover risks
December 23, 2021
Blog
Potential CloudFront/S3 takeover risks

We recently helped a customer identify some potential CloudFront/S3 takeover risks. You can find the details of the risk described in the article, "Simple Route53/Clo

  • CSPM
  • CAASM
  • SecOps
Erkang Zheng
Cisco and JupiterOne Partnership Goes Beyond Traditional Cloud Security
November 15, 2021
Blog
Cisco and JupiterOne Partnership Goes Beyond Traditional Cloud Security

Fireside chat: Cisco Sr. Director of Product Management for Cloud Security Munawar Hossain, JupiterOne CEO Erkang Zheng and CMO Tyler Shields discuss the new partners

  • CSPM
  • CAASM
Erkang Zheng
Book Preview: Modern Cybersecurity, Preface
October 20, 2021
Blog
Book Preview: Modern Cybersecurity, Preface

On October 19, 2021, we published a book, "Modern Cybersecurity: Tales from the Near-Distant Future". Over the next few weeks, we'll be publishing excerpts from the

  • CSPM
  • CAASM
Erkang Zheng
My Bucket, My Data! (or is it?)
August 24, 2021
Blog
My Bucket, My Data! (or is it?)

AWS S3 has long become a standard for storing file object data. Despite the many efforts in making S3 secure, we continue to see data in private buckets exposed or ex

  • CAASM
Erkang Zheng
Cisco Investments and Splunk Ventures, New Strategic Investors
July 27, 2021
Blog
Cisco Investments and Splunk Ventures, New Strategic Investors

Today, we are proud to announce two additional strategic investors, Cisco Investments and Splunk Ventures, to the JupiterOne journey. This announcement reflects our

Erkang Zheng
JupiterOne Raises $30 Million Series-B Led by Sapphire Ventures
May 4, 2021
Blog
JupiterOne Raises $30 Million Series-B Led by Sapphire Ventures

For Star Wars fans, May the 4th is a very special day. We get to make all sorts of silly puns, memes, and jokes based on our love of a series of movies.

Erkang Zheng
Make Compliance = Real Security in HealthCare
April 22, 2021
Blog
Make Compliance = Real Security in HealthCare

JupiterOne CEO Erkang Zheng has traveled the journey of a healthtech CISO with 20+ years of cybersecurity experience. In this fireside chat delivered at HealthConDX

  • GRC
Erkang Zheng
Security is a Basic Right
March 2, 2021
Blog
Security is a Basic Right

We live in a world where security is something that you have to do, and very rarely something that you want to do. In the world of young companies and startups,

  • CSPM
  • CAASM
  • GRC
  • SecOps
Erkang Zheng
Sampling Based Security – An Outdated Approach | JupiterOne
November 11, 2020
Blog
Sampling Based Security – An Outdated Approach

If all it takes is one bad apple to spoil the entire bunch, should the owner of an apple orchard do a statistical sampling to look for the bad apple, or should they

  • CAASM
  • GRC
Erkang Zheng
JupiterOne Announces $19M A Round | JupiterOne
September 17, 2020
Blog
JupiterOne Announces $19M A Round

Three years ago, I joined LifeOmic, the latest of three companies founded by successful serial entrepreneur Donald Brown, with the crazy idea of building a startup in

Erkang Zheng
Building a Streamlined Cyber Risk Assessment Process using Jira and JupiterOne | JupiterOne | Simplified Security Operations
April 10, 2020
Blog
Building a Streamlined Cyber Risk Assessment Process using Jira and JupiterOne

Risk assessment is a foundational step to any security governance program. It is a mandatory step by regulations and compliance frameworks like HIPAA and GDPR.

  • SecOps
Erkang Zheng
Reduce Noise when Analyzing User MFA Status with Graph Queries
March 17, 2020
Blog
Reduce Noise when Analyzing User MFA Status with Graph Queries

There is no doubt multi-factor authentication (MFA) is a simple and effective way to reduce account compromise, yet only 11% of all enterprise accounts use a MFA

  • SecOps
Erkang Zheng
Capital One Breach: Is your AWS environment just as susceptible?
August 9, 2019
Blog
Capital One Breach: Is your AWS environment just as susceptible?

It's been a little over a week since the coverage of the Capital One data breach. The impact of 100 million plus records that were compromised breathed gasoline onto

  • CSPM
  • CAASM
Erkang Zheng
Simplifying Security and Compliance with Amazon Neptune
May 17, 2019
Blog
Simplifying Security and Compliance with Amazon Neptune

Most organizations take a linear, list-based approach to security operations. It's a two-dimensional process. First, identify resources. Second, manage their

  • GRC
  • SecOps
Erkang Zheng
We Turned Off AWS Config | JupiterOne
April 19, 2019
Blog
We Turned Off AWS Config

That's right. It wasn't a typo. After enabling AWS Config across five of our AWS accounts, we decided to remove all but two of our Config rules. But why?

  • CSPM
  • CAASM
Erkang Zheng
BSidesSLC 2019 | JupiterOne | Simplified Security Operations
February 22, 2019
Blog
BSides SLC 2019 - Three Dimensional Security

BSidesSLC 2019 | JupiterOne | Simplified Security Operations

Erkang Zheng
Three Dimensional Security
January 28, 2019
Blog
Three Dimensional Security

I am going to skip the small talk about the security landscape, how much it all sucks and how we are all doomed and get straight to the point.

  • CAASM
  • SecOps
Erkang Zheng
What Does Digital Transformation Mean for Security and Compliance?
November 14, 2018
Blog
What Does Digital Transformation Mean for Security and Compliance?

I recently attended the Gartner Symposium ITXpo in Orlando, with nearly 10,000 other CIOs and IT leaders. It was an exciting week with conversations concentrated

  • CAASM
  • GRC
  • SecOps
Erkang Zheng
Finding a cure to the cyber breach pandemic  - JupiterOne is here
September 5, 2018
Blog
Finding a cure to the cyber breach pandemic – JupiterOne is here

Let's be honest. This is a mess. We are losing in the battle of cybersecurity. There is no stopping the attacks.

  • SecOps
Erkang Zheng
Data-Centric, Zero-Trust Security for Security Operations
September 24, 2017
Blog
Data-Centric, Zero-Trust Security

Let me start by sharing the foundational and most important aspect of our view of cybersecurity operations and the genesis of why we created JupiterOne. Prior to

  • SecOps
Erkang Zheng
Perhaps It's Time We Stop Blaming the Users | JupiterOne | Simplified Security Operations
July 16, 2017
Blog
Perhaps It's Time We Stop Blaming the Users

For years, I’ve been hearing security people say that about uninformed users who fall victims to cyberattacks. I gotta admit, I was guilty too of saying that on a few

Erkang Zheng
The State of Cybersecurity: Are We Doomed in the Cyber-pandemic?
April 16, 2016
Blog
The State of Cybersecurity: Are We Doomed in the Cyber-pandemic?

Just a short decade ago, cybersecurity was still a fringe subject to most people. Today, while still fascinating, it has undoubtedly become part of our daily life.

  • CSPM
  • CAASM
  • GRC
Erkang Zheng
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

  • This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.