Dispatches from Mission Control

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
J1  Rapid Response: Travis CI Flaw

On Monday, September 13, Travis CI put out a security bulletin obliquely mentioning a security problem. “As a reminder from the Support Team, cycling your secrets is

Austin Kelleher
Sep 17th, 2021
Design Update: Compliance App 2.0

The team at JupiterOne was well underway building version 2.0 of our Compliance App when I joined the company this summer. The primary motivation for the work on 2.0

Patrick Morgan
Sep 15th, 2021
Boardroom Conversations on Security: Part 4

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation

Mark Miller
Sep 13th, 2021
SINET 16 Awards Winner: JupiterOne

We are honored to receive this significant industry recognition as the 2021 SINET 16 Innovators Award winner. We know that the market competition is fierce, so we

JupiterOne Team
Sep 10th, 2021
De Morgan's Law in JupiterOne

If you recently read about the breaking fix JupiterOne introduced to maintain J1QL language correctness as defined by De Morgan's Law you may have found yourself in

Tony Ramirez
Sep 8th, 2021
The Absolute Minimum Every Developer Must Know about AWS Security

The cloud is becoming increasingly popular. It is the driving force of the modern world, and engineers are starting to shift their careers accordingly. Whatever your

Nishant Thorat
Sep 7th, 2021
  • CAASM
Boardroom Conversations on Security: Part 3

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation

Mark Miller
Sep 6th, 2021
CAASM is the Future... CSPM is Dead

Beyond the classic Cloud Security Posture Management (CSPM) tools like Dome9, DivvyCloud, etc. now even infrastructure and workload scanners claim CSPM as part of the

Akash Ganapathi
Sep 1st, 2021
  • CAASM
  • CSPM
Boardroom Conversations on Security: Part 2

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation

Mark Miller
Aug 30th, 2021
JupiterOne Named Winner in WorldFestival 2021 Innovation Awards

We are excited to announce that JupiterOne has been selected as a Winner in the WorldFestival 2021 Innovation Awards in the Cloud Computing category! We are extremely

JupiterOne Team
Aug 26th, 2021
My Bucket, My Data! (or is it?)

AWS S3 has long become a standard for storing file object data. Despite the many efforts in making S3 secure, we continue to see data in private buckets exposed or ex

Erkang Zheng
Aug 24th, 2021
  • CAASM
Boardroom Conversations on Security: Part 1

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation

Mark Miller
Aug 23rd, 2021
Compliance is cumbersome, but cloud can help

Guest author Chris Hughes, CISO and Co-Founder of Aquia, offers a view of the "Shared Responsibility Model".

Chris Hughes
Aug 18th, 2021
  • CSPM
JupiterOne Launches Query Anywhere

This week JupiterOne launched Query Anywhere. As you might guess, this feature will allow J1 users to access the core 'search for anything' functionality of J1QL no

Chum Wongrassamee
Aug 11th, 2021
Podcast: CYA - Cover Your Assets with Chris Roberts

A couple weeks ago I read an article by Chris Roberts. The headline screamed, “Security Solved!” Security solved? What the hell was he talking about. Everyday

Mark Miller
Aug 9th, 2021
  • CAASM
  • SecOps
JupiterOne Named Winner of Top 10 CISOs; Finalists in 'Baby Black Unicorn' and Top 10 Cyber Security Experts Awards

We are starting to make waves in the cybersecurity universe. Turns out, people love us and we are crushing this awards season (like Bong Joon-Ho's Parasite).

JupiterOne Team
Aug 5th, 2021
  • CAASM
  • GRC
  • SecOps
Policy as Code: How We Do It

If you only read the first two sentences of this blog, this should be your takeaway: Policy as Code provides a roadmap to verify the processes in security and govern

Tony Ramirez
Aug 4th, 2021
  • GRC
  • SecOps
Automating Data Classification with JupiterOne

Anyone reading this article already understands the importance of Data Classification. Increased regulation has been a by-product of greater understanding of the dang

Akash Ganapathi
Jul 28th, 2021
  • CAASM
  • IAM
JupiterOne Founder Named Top 25 Cyber CEO of 2021

We just received the awesome news that JupiterOne Founder and Chief Executive Erkang Zheng has been selected as one of The Top 25 Cybersecurity CEOs of 2021 by

JupiterOne Team
Jul 28th, 2021
Cisco Investments and Splunk Ventures, New Strategic Investors

Today, we are proud to announce two additional strategic investors, Cisco Investments and Splunk Ventures, to the JupiterOne journey. This announcement reflects our

Erkang Zheng
Jul 27th, 2021
Azure Access Review using Optional Traversals in JupiterOne

Azure role-based access control (RBAC) allows for expressive access policies through the use of Azure role assignments. Azure role assignments are nodes that link

Nick Dowmon
Jul 21st, 2021
  • CSPM
A Modern Definition for Cyber Assets

Cloud adoption, digital transformation, and API-first architecture are fundamentally changing how we build, manage and secure the enterprise. Enterprises use speciali

Mark Miller
Jul 14th, 2021
  • CAASM
The Next Evolution of ITAM, Beyond CMDB and ITSM

I’m old. When I began my career, IT asset management (ITAM) meant going around, from computer to computer, and putting stickers with barcodes and numbers on every

Tyler Shields
Jun 23rd, 2021
  • CAASM
Podcast:  OWASP Flagship Projects - Episode 02

Today’s episode begins with Seba Deleersnyder, project lead for the Software Assurance Maturity Model, or SAMM. The mission of this OWASP Flagship Project is to

Mark Miller
Jun 16th, 2021
  • CAASM
  • SecOps
Solving for Endpoint Compliance in a Cloud-First Landscape | JupiterOne | Simplified Security Operations

Before I became a Security Engineer at JupiterOne, I was the sole security automation and cloud compliance engineer at LifeOmic. We built the JupiterOne platform to

Erich Smith
Jun 14th, 2021
JupiterOne Cares: Serving our Local Communities

"What did you do this weekend"? It's a typical question that gets asked a million times a day, around the world, every Monday. We posed the question to our team a

JupiterOne Team
Jun 9th, 2021
The Future of Cloud Security - Cybersecurity Summit Silicon Valley

In this panel originally recorded for CyberSecurity Summit 2021 in Silicon Valley, speakers from JupiterOne, axiad, Duo Security, Gigamon, Recorded Future, and

Tyler Shields
Jun 9th, 2021
  • CAASM
Podcast:  OWASP Flagship Projects - Episode 01

This is part of an ongoing podcast series, highlighting the OWASP Flagship Projects that will be featured at the OWASP 20th Anniversary Celebration in September.

Mark Miller
Jun 4th, 2021
  • CAASM
  • SecOps
5 Factors to Building a Better Security Engineering Culture and Team

"Security engineering is the process of incorporating security controls into the information system so that they become an integral part of the system's operational

Sounil Yu
Jun 2nd, 2021
  • CAASM
  • SecOps
IAM, CSPM, VM, IR, Compliance... Oh My!

In security, when you think of the term 'asset', where does your head go? Chances are, you're thinking of employee laptops and bare-metal servers on-premise or in

George Tang
May 26th, 2021
  • CAASM
  • IAM
  • CSPM
How to Measure the Cost of Risk

Caroline Wong and I recently had a call to discuss something that’s been bothering me for years… how do we assess financial risk before a data breach happens. How do

Mark Miller
May 19th, 2021
  • CAASM
  • SecOps
Identifying & Avoiding Insider Threats - Cybersecurity Summit Dallas

In this panel originally recorded for CyberSecurity Summit 2021 in Dallas, speakers from JupiterOne, Cobalt, Code42, Netenrich, Securonix, Spirion, and Venafi discuss

Tyler Shields
May 13th, 2021
  • CAASM
Identifying & Avoiding Insider Threats - Cybersecurity Summit Nashville

In this panel originally recorded for CyberSecurity Summit 2021 in Nashville, speakers from JupiterOne, Code42, Venafi, and Abnormal Security discuss the various fact

Tyler Shields
May 6th, 2021
  • CAASM
How Cyber Assets Are Like Star Trek's Tribbles Problem

When I was in middle school, my science teacher, Mr. B., introduced me to the original Star Trek series. And it had me shook. Ever since, the series has been my stand

Jennie Duong
May 5th, 2021
  • CAASM
JupiterOne Raises $30 Million Series-B Led by Sapphire Ventures

For Star Wars fans, May the 4th is a very special day. We get to make all sorts of silly puns, memes, and jokes based on our love of a series of movies.

Erkang Zheng
May 4th, 2021
Map Your Cyber Relationship Graph Before Your Adversaries Do

I was watching the movie Heat today. For those of you that don’t know anything about the movie, it’s an amazing cops and robbers story featuring an all star cast that

Tyler Shields
Apr 28th, 2021
  • CAASM
Make Compliance = Real Security in HealthCare

JupiterOne CEO Erkang Zheng has traveled the journey of a healthtech CISO with 20+ years of cybersecurity experience. In this fireside chat delivered at HealthConDX

Erkang Zheng
Apr 22nd, 2021
  • GRC
Podcast: The Cyber Defense Matrix

In 2020, Security Magazine listed Sounil Yu as one of the most Influential People in Security, in part because of his work on the Cyber Defense Matrix, a framework

Sounil Yu
Apr 21st, 2021
  • CAASM
I didn't want to be CISO - Sounil Yu joins JupiterOne

Over the past year, I thoroughly enjoyed my time at YL Ventures as their CISO-in-Residence, meeting brilliant entrepreneurs and brainstorming creative approaches for

Sounil Yu
Apr 21st, 2021
Two Truths And A Lie About Cloud Security

Cloud technology saved many businesses from catastrophe during this past year, but it's also introduced additional challenges to security, compliance, and governance

Ashleigh Lee
Apr 8th, 2021
  • CSPM
Stunt Kites and Security Tools

I rode my bicycle across the United States in 1996 (Everett, Washington to Washington DC), and up into Nova Scotia. That summer I logged over 4400 miles on my bike.

Mark Miller
Apr 5th, 2021
  • CAASM
You Can Not Secure What You Can Not See

"The future of application development and infrastructure is in public clouds — and for many organizations, it's not just the future; it's today. Securing data, apps,

Mark Miller
Apr 2nd, 2021
  • CAASM
Video: How to modify out-of-the-box dashboards

The purpose of the JupiterOne Dashboards is to have a centralized set of dashboards that can be used by your security team to view, edit, and share with all teams in

Jayson Jensen
Apr 1st, 2021
Turn 10,000 AppSec Findings into 10 Actual Risks

You’ve seen it, you’ve been a part of it. Alert fatigue sets in with warnings coming from multiple domains: cloudsec, infrasec, netsec, data security, appsec, seceng

George Tang
Mar 31st, 2021
  • SecOps
  • Vuln Mgmt
Podcast: The 2021 OWASP Top 10

The OWASP Top 10 is considered one of the most important community contributions to come out OWASP. In 2003, just two years after the organization was started, the

Mark Miller
Mar 26th, 2021
JupiterOne, DevOps Connect at RSAC 2021

DevOps Connect: DevSecOps, this year co-organized by JupiterOne and MediaOps, has been part of the RSA Conference agenda for 5 years. Each spring, we put together

Mark Miller
Mar 24th, 2021
Integrations and APIs - OH MY!

As recently as just a few years ago, products, infrastructure, and security tooling were all on-premise and designed without thought for API-based integrations.

Tyler Shields
Mar 18th, 2021
  • CAASM
How to Create Customized Dashboards

The JupiterOne Insights Application allows you to create customized dashboards in multiple ways. In this video, Jayson Jensen shows you customization strategies using

Jayson Jensen
Mar 17th, 2021
Video: Insights Application Overview

In this session, Jayson Jensen, takes a quick look at the Insights Application of JupiterOne, with a high-level overview of how to use the tool. The Insights App

Jayson Jensen
Mar 15th, 2021
Fireside Chat: Security as a Basic Right

Tyler Shields and Erkang Zheng presented at Cybersecurity 2021 on March 4, 2021. Instead of the usual slidedeck presentation, they had a little chat to talk through

Tyler Shields
Mar 12th, 2021
  • CAASM
CyberSecurity Summit 2021 - Spotlight Demo

Visibility is a problem we all have when it comes to cyber assets and security. How do we keep track of all of the cloud assets we have in AWS, GCP, and Azure? What

Akash Ganapathi
Mar 12th, 2021
Video: Workflows within the J1 Compliance App

Compliance Workflows make it possible to collaborate internally with your team members or externally with your auditors. George Tang shows how to use the pre-built

George Tang
Mar 10th, 2021
  • GRC
JupiterOne Adds Strategic Investors to Drive Expansion of Its Innovative Cyber Asset Security and Governance Platform

We announced today that several new industry leaders across SaaS and Cybersecurity organizations have joined their strategic board of investors. Frederic Kerrest, Exe

Jennie Duong
Mar 9th, 2021
Video: Update Your Vulnerable NPM Packages

In this "Bite-size Security Showcase", Erich Smith walks through a common developer security scenario, dealing with vulnerable third party dependencies.

Erich Smith
Mar 5th, 2021
We Are JupiterOne

Brand is perception, and perception is important. We all want to be seen by others as having certain values, ethics, morals, and vision. The interesting thing about

Tyler Shields
Mar 4th, 2021
Video: Evidence Collection with the Compliance App

For compliance purposes, whether going through an external audit or for an internal initiative, it will be required to demonstrate to auditors or other stakeholders

George Tang
Mar 3rd, 2021
  • GRC
Security is a Basic Right

We live in a world where security is something that you have to do, and very rarely something that you want to do. In the world of young companies and startups,

Erkang Zheng
Mar 2nd, 2021
  • CSPM
  • CAASM
  • GRC
  • SecOps
Video: How to Map GRC Policies and Procedures

George Tang continues his exploration of JupiterOne GRC capabilities with this video on how to map policies and procedures to specific controls or requirements within

George Tang
Mar 2nd, 2021
  • GRC
Video: Managing GRC with JupiterOne

George Tang has recorded a series of videos to show how JupiterOne can be used for GRC. In this session, George covers the usage of policies and procedures within J1

George Tang
Feb 24th, 2021
  • GRC
3 Steps for Continuous Improvement in Cloud Security | JupiterOne

Relationships make life rich. Together, we can do so much more than a single person alone – inspire change on micro and macro levels, recover and restore hope from

Ashleigh Lee
Feb 2nd, 2021
  • CSPM
  • GRC