Console Login

Security & Compliance Articles

Technical insights and best practices for Security & Compliance

Security & Compliance

Automating Security Compliance: Surviving Datatilsynet with OpenSCAP and Ansible

Manual security hardening is a liability in 2019. Learn how to automate CIS-level compliance on Norwegian infrastructure using Ansible and OpenSCAP to keep the auditors happy.

Automating Security Compliance: Surviving the GDPR Era with Ansible and OpenSCAP in Norway

Manual security audits are a liability in 2019. Learn how to automate compliance on Norwegian VPS infrastructure using Ansible and OpenSCAP to satisfy Datatilsynet and sleep better at night.

The Perimeter is Dead: Implementing Zero-Trust Security on Norwegian Infrastructure

Firewalls are no longer enough. Learn how to architect a Zero-Trust environment using mTLS, SSH CAs, and identity proxies while keeping your data compliant with Norwegian regulations.

Zero-Trust Architecture: Implementing 'Never Trust, Always Verify' on Linux in 2019

The 'castle-and-moat' security model is dead. Learn how to implement a Zero-Trust architecture using WireGuard, Nginx mTLS, and SSH CAs on your Linux infrastructure, keeping your data compliant with Norwegian standards.

Surviving the Blackout: A Pragmatic Disaster Recovery Guide for Norwegian Systems

Hope is not a strategy. We deconstruct the mechanics of Disaster Recovery in 2019, from Master-Slave replication in MySQL 5.7 to real-time filesystem syncing with lsyncd, ensuring your RTO stays low and your data stays in Norway.

Container Security in 2019: Stop Running as Root or Get Hacked

Containerization has transformed deployment, but default configurations are a security nightmare. We dive into essential hardening techniques for Docker and Kubernetes, from dropping capabilities to enforcing strict RBAC, specifically tailored for Norwegian compliance standards.

Container Security in 2019: Hardening Docker and Kubernetes for Production

Containers aren't magic security boxes. From the recent runC vulnerability to kernel isolation, we break down how to secure your stack using 2019's best practices, leveraging strict KVM boundaries and immutable infrastructure principles.

The Perimeter is a Lie: Implementing Zero-Trust Architecture on Bare Metal

VPNs are just glorified backdoors. In 2019, the only secure network is one that assumes it's already breached. Here is how to build a Zero-Trust environment on CoolVDS using Nginx mTLS and strict iptables.

Automating Security Compliance: From 'Manual Hell' to Continuous Auditing on Linux VPS

Manual security hardening is a liability in 2019. Learn how to implement CIS benchmarks using Ansible and OpenSCAP to satisfy Datatilsynet requirements while maintaining high-velocity deployments.

Container Security in 2019: Surviving the Breakout

With the recent runc vulnerability shaking the DevOps world, it is time to harden your Docker stack. We analyze kernel isolation, immutable infrastructure, and why Norwegian data sovereignty matters for your cluster.

The Perimeter is Dead: Implementing Zero Trust Architecture on Linux Infrastructure (2019 Edition)

The 'castle and moat' security strategy is obsolete. Learn how to implement Zero Trust principles using mTLS, granular iptables, and KVM isolation in a post-GDPR world.

Zero-Trust Infrastructure on Linux: Why Your Firewall Is Not Enough

The 'castle and moat' security strategy is obsolete. Learn to implement a pragmatic Zero-Trust architecture using mTLS, SSH hardening, and strict iptables on KVM infrastructure.

Automating Security Compliance: From CIS Benchmarks to GDPR-Ready Infrastructure

Manual server hardening is a liability in 2019. Learn how to automate security compliance using Ansible and OpenSCAP, and why infrastructure sovereignty in Norway is your best defense against Datatilsynet audits.

Docker is Not a Security Strategy: Hardening Containers for Production in 2019

Default Docker configurations are a security nightmare waiting to explode. We break down how to lock down your container infrastructure, navigate Norwegian GDPR requirements, and why strict kernel isolation on CoolVDS is your last line of defense.

Automating GDPR Compliance: OpenSCAP and Ansible on Norwegian Infrastructure

Manual security audits are a liability in 2019. Learn to automate CIS-level hardening on CentOS 7 using OpenSCAP and Ansible, keeping the Norwegian Datatilsynet happy and your infrastructure secure.

Automating GDPR Compliance on Linux Infrastructure: A 2019 Survival Guide

Manual security audits are a liability. Learn how to automate server hardening using Ansible and OpenSCAP on Norwegian infrastructure to satisfy Datatilsynet without sacrificing DevOps velocity.

Disaster Recovery in 2019: Why Your RAID Array Won't Save You From `rm -rf`

Hardware redundancy is not a backup strategy. In this guide, we tear down a robust Nordic DR plan using KVM, off-site replication, and GDPR-compliant architecture standard for 2019.

Disaster Recovery in a Post-GDPR World: A Norwegian CTO’s Playbook

It is December 2018. GDPR is enforced. Is your infrastructure resilient enough to handle a total site failure without violating Datatilsynet regulations? We break down the RTO/RPO math, MySQL replication strategies, and why sovereignty matters.

Disaster Recovery in the GDPR Era: Why Your Norway VPS Needs a "Plan B" (December 2018 Edition)

It's late 2018. GDPR is here. Is your Disaster Recovery plan compliant? A pragmatic CTO's guide to replication, failover, and keeping data on Norwegian soil.

The Perimeter is Dead: Implementing Zero-Trust Security on Linux Infrastructure

The 'castle and moat' security strategy failed. In a post-GDPR world, we explore building a Zero-Trust architecture using Nginx mTLS, SSH Certificates, and strict KVM isolation.

The Perimeter is Dead: Architecting Zero-Trust Infrastructure in a Post-GDPR World

Firewalls are no longer enough. Learn how to implement Mutual TLS (mTLS), hardened SSH CAs, and granular access controls to survive modern threats. A technical deep-dive for Norwegian DevOps teams.

Container Security in 2018: Stop Running as Root or Go Home

Docker containers are not virtual machines. If you are treating them as such, you are one kernel panic away from disaster. Here is the battle-hardened guide to locking down Docker and Kubernetes in a post-GDPR world.

Zero-Trust Infrastructure: Why Your VPN Is a Single Point of Failure (And How to Fix It)

Perimeter security is dead. In the wake of the Equifax breach and GDPR, relying on a single VPN gateway is professional negligence. Learn how to implement SSH Certificate Authorities, mTLS with Nginx, and true network isolation on CoolVDS.

Automating GDPR Compliance: Infrastructure as Code Strategies for Norwegian Systems

The May 25th deadline has passed, but the real work has just begun. We strip away the legal jargon and dive into the technical reality of automating server hardening with Ansible to satisfy the Norwegian Datatilsynet without slowing down your release cycles.

The Perimeter is Dead: Implementing Zero-Trust Security on Your Norwegian VPS Infrastructure

It is August 2018, and the old 'castle-and-moat' security strategy is failing. Here is how to implement a Zero-Trust architecture using Nginx mTLS, SSH hardening, and strict iptables rules on a Linux VPS.

Automating GDPR Compliance: A DevOps Guide to Hardening Linux Infrastructure (August 2018 Edition)

The GDPR grace period is over. Manual security hardening is a liability. Learn to automate compliance using Ansible and OpenSCAP, ensuring your infrastructure meets Datatilsynet standards without destroying your velocity.

Automating Security Compliance: Surviving the Post-GDPR Audit in 2018

The panic of May 25th is over, but the liability remains. Learn how to automate server hardening using Ansible and OpenSCAP on Norwegian infrastructure to satisfy Datatilsynet without burning out your DevOps team.

Automating GDPR Compliance: A DevOps Approach to Security Standards in 2018

The May 25th deadline has passed, but compliance is a continuous process. Learn how to automate security auditing using Ansible and OpenSCAP on Linux infrastructure, specifically tailored for Norwegian data privacy requirements.

Automating GDPR Compliance on Linux: A CTO’s Guide to Infrastructure Security in 2018

It is August 2018. The GDPR grace period is over. Learn how to use Ansible and OpenSCAP to automate compliance on Norwegian VPS infrastructure without breaking the bank.

Disaster Recovery in the GDPR Era: A Norwegian Survival Guide

Hope is not a strategy. In 2018, data loss isn't just an operational failure; it's a legal catastrophe. Here is how to architect a compliant, bulletproof DR plan using Norwegian infrastructure.