📣 Integrity Security Services (ISS) is now OmniTrust.
Read our CEO’s Letter ->

Search Blog

JadePuffer Isn’t Just Another Ransomware Story. It’s a Glimpse Into the Future of Cybersecurity.

AI has crossed a new line. JadePuffer demonstrates how autonomous AI can execute sophisticated cyberattacks with minimal human involvement – adapting, escalating, and making decisions in real time. Discover why this changes the cybersecurity landscape forever, and why modernizing identity, cryptography, and AI governance is rapidly becoming a business imperative.

EU CRA Tales From The Trenches #3 – Why Security Maturity is Not Enough for CRA Readiness

You can have mature cybersecurity, proven engineering practices, and recognized certifications—and still not be CRA-ready. The biggest challenge isn’t building secure products; it’s proving cybersecurity has been governed, documented, and maintained throughout the product lifecycle. In our latest EU CRA Tales From The Trenches blog, we explore why security maturity alone is no longer enough.

Why We Open-Sourced ILM

Why would a commercial cybersecurity company open-source one of its core platforms? Roman Cinkais explains why OmniTrust believes the future of trust automation will be built through open collaboration.

🇺🇸 Fireworks, Freedom & Future-Proof Trust – Your Fourth of July Weekend Reading List for the Post-Quantum Era

Washington lit the fuse. Are you ready for what’s next? Celebrate the Fourth with two practical white papers that cut through the hype and show how to operationalize post-quantum cryptography, modernize trust infrastructure, and prepare your organization for the coming era of cryptographic agility and continuous trust.

EU CRA Tales From The Trenches #2 – The First Problem Isn’t Security. It’s Scope

Most companies assume CRA compliance starts with vulnerability management, SBOMs, secure development, and incident response. In reality, the hardest first step is often figuring out which products are actually in scope, how they should be classified, and what security obligations apply to each one. Companies are discovering hidden products, legacy versions, cloud services, OEM components, and acquisitions that can multiply their CRA scope by 5x or more. The article argues that successful CRA programs begin with product inventory, classification, governance, and lifecycle ownership – not security controls – and that getting classification wrong can create compliance risk for years.

Introducing the ILM Community: Help Build the Future of Trust Automation

The old approach to trust infrastructure isn’t scaling. As AI, machine identities, and post-quantum cryptography reshape cybersecurity, the open-source ILM Community is bringing builders together to create the future of trust automation. Discover why the community matters—and how you can help build what’s next.

EU CRA Tales From The Trenches #1 – A New Blog Series from OmniTrust

Companies selling connected products into Europe are racing to prepare for the Cyber Resilience Act – but many are discovering that their biggest compliance challenges have little to do with cybersecurity controls. Why are mature security programs still struggling? Why are product inventories, SBOMs, and support commitments becoming board-level concerns? And why do some organizations move quickly while others stall? Learn the real lessons emerging from the front lines of CRA implementation in this new blog series from OmniTrust.

ILM Operator: Cryptographic Asset Management, Simplified

Certificates, keys, and secrets need lifecycle governance — but the platform providing it has always carried its own operational cost. The updated open-source ILM operator collapses that cost into two declared Kubernetes resources: one for the whole platform, one per connector. Tested upgrade bundles, continuous reconciliation, and declarative coverage of every place your cryptographic assets live.

Security Certificate Expiration: Still a Thing in 2026? 🤔

AI is taking over the world… so why are expired certificates still taking down companies in 2026?  In a world of AI agents and quantum computing, organizations are still being brought down by expired certificates. How is that possible?  OmniTrust’s Sam Delsing unpacks one of cybersecurity’s most embarrassing secrets: why certificate expiration is still causing outages in 2026.

The AI Spending Reckoning Is Coming — And CISOs May Be the Adults in the Room

AI is spreading across enterprises faster than governance, finance, and cybersecurity teams can control it. Shadow AI, runaway token spend, and autonomous agents are forcing CIOs and CISOs into a new role: not AI blockers, but the adults in the room helping businesses discover, control, optimize, and safely scale AI before operational chaos arrives.

Building a Comprehensive Cryptographic Asset Inventory

You cannot migrate to post-quantum cryptography without knowing what cryptographic assets you have. This post walks through the three-step process for building a comprehensive inventory — discovery, metadata collection, and structured cataloging — and explains how the Cryptography Bill of Materials (CBOM) standard from OWASP CycloneDX provides a standardized format for the result. Includes a comparison of open-source CBOM tooling.

PKI Maturity Model: From Ad-Hoc to Governed Operations

Most PKI environments grow organically without structured governance. The PKI Maturity Model (PKIMM), developed by the PKI Consortium, provides a CMMI-based assessment across 15 categories in four modules — Governance, Management, Operations, and Resources. It gives PKI architects a measurable way to identify gaps and build a concrete improvement roadmap.

Why Trust Lifecycle Management Must Include Secrets

Certificates get lifecycle governance — renewal dates, revocation policies, audit trails. API tokens, service credentials, and signing keys rarely get the same treatment, even though they carry equivalent trust. This post explains why trust lifecycle management must cover every artifact that confers trust, not just X.509. The answer is not replacing Vault or AWS Secrets Manager, but adding a unified governance plane above them: one inventory, one policy, one audit stream.

Ready to Secure Your Trust Lifecycle?

Let's secure your entire trust lifecycle from the physical edge to the cloud, the sea, and beyond.

Consulting & Expert Services

Work with our experts to design, implement and optimize your trust infrastructure.