What Is PKI? A Plain-English Guide for Security Leaders

Public Key Infrastructure (PKI) is the system of keys, digital certificates, and policies that let people, devices, and software prove who they are and communicate securely. It matters because almost every trusted interaction in your organization, from a login to a banking site, to one machine quietly authenticating to another, depends on PKI working correctly […]
Certighost: How to Determine Whether Your Enterprise CA Was Exploited

Microsoft’s patch closes the Certighost vulnerability — but it cannot tell you whether an attacker previously used it. Here is how to assess your exposure and hunt for evidence with PKI Spotlight®. Certighost is the kind of vulnerability that keeps PKI teams awake at night. Tracked as CVE-2026-54121, it affects Active Directory Certificate Services and […]
PKI Insights Recap – Strengthening Security in Banking & Finance with PKI

Financial institutions rely on trust, security, and compliance to protect transactions, customer data, and business operations. However, a growing number of organizations are unaware of how new regulations will impact them. During our February PKI Insights webinar, we conducted a poll and found that 75% of attendees had never heard of DORA (Digital Operational Resilience […]
Don’t Believe the FUD – Microsoft PKI is Your Key to Crypto Agility

It’s that time again—the point in the tech cycle where vendors exploit uncertainty to spread Fear, Uncertainty, and Doubt (FUD) in cybersecurity. What’s the latest FUD in PKI? The same old misinformation: that Microsoft Active Directory Certificate Services (ADCS) is going away. If you’ve encountered a PKI vendor claiming, “Microsoft is discontinuing ADCS, so you […]
When you know, you Know – Catching HSM failures before they cost your organization!

One of the most extraordinary things about working in a new Cybersecurity space like PKI Spotlight is seeing your technology stack solve real-world problems. From our decades of experience designing, deploying, and supporting complex enterprise PKIs, we have seen that many minor issues have a significant impact on organizations. Often, these minor issues would […]
Microsoft ADCS Vulnerability – CVE-2024-49019 Escalation of Privilege

Microsoft just announced another Active Directory Certificate Services (ADCS) related vulnerability CVE-2024-49019. This vulnerability has a base score of 7.8 and is related to weak authentication that can lead to an escalation of privilege within Active Directory environments. This is yet another example of poorly configured and monitored PKI environments leading to vulnerabilities that undermine […]
PKI Insights Recap – Is Your PKI Healthy? The Essential Guide to Comprehensive Assessments

In October’s PKI Insights webinar, we delved deep into the crucial topic of PKI assessments, a subject that has evolved significantly over the last two decades. We highlighted why assessments are more vital than ever, especially as organizations become increasingly reliant on PKI to secure their data, systems, and communications. Over my 20 years in […]
Preventing ServiceNow-style Root Certificate Outages with PKI Posture Management

In September 2024, ServiceNow suffered a significant outage caused by the failure to renew a root certificate. Unlike a typical certificate expiration issue, this was a deeper problem that affected the core of the Public Key Infrastructure (PKI). The expired root certificate, which identifies the root Certificate Authority (CA) in the environment, had a cascading […]