(Day 1 of 22 in our Cybersecurity Awareness Month series. See the whole month’s schedule below.)
Every October is Cybersecurity Awareness Month in the United States. While infosec community feelings tend to be mixed, we’ve always thought the event presents a nice opportunity to talk about security in a way that isn’t purely transactional. So many of the daily conversations we have are tactical. Your organization needs to enable data-at-rest encryption, or pass an audit, or be resilient to failure, and you have questions. No problem, VMware Cloud Foundation (VCF) can do all of that, and we enjoy helping you think through it. Occasionally, though, it’s nice to step back and look at cybersecurity more strategically.
It feels like a decade has passed since last October. October 2025 is regarded as the turning point where artificial intelligence became good enough to start helping humanity with its chores. Of course, some predict that AI will exterminate humanity, and others predict a utopia where we can follow our dreams, fed and clothed from the abundance AI provides. The truth, as always, is likely somewhere in the middle, though on a personal level I’m hoping for more abundance than Terminator. Regardless, there is no doubt that AI is a force multiplier, both for good and for evil. Good people are building incredible things with it. So are bad people; in the security space we see attacks ramping up, more than ever. Frontier AI models often draw focus here, but it’s also the open-source models, running on GPUs everywhere, that are doing the attacking. As the saying goes, there’s no putting that toothpaste back in the tube.
Despite all that, there’s good news: all the same security tactics that the industry has been talking about for decades work very well in defending against evil, whether it’s human or a bot. Zero trust, when meaningfully implemented, seriously hinders attacks and lateral movement. Good identity management practices, including MFA, passkeys, conditional access, and more, not only block attackers but help expose their presence. Firewalls and isolation buy time as a part of defense-in-depth. And good organizational risk management and patching practices remove vulnerabilities that can provide access to bad actors.
Even more than that, as organizations bring security to the forefront, system administrators, architects, and engineers are learning to think with a security mindset. They think of second- and third-order effects of changes. They ask themselves how something could be misused, how systems and components will fail, and speak of concepts like blast radius, RPO, and RTO. They think about attack surfaces and ask themselves whether they really need that extra component or tool, knowing they’ll have to audit it and protect it for years.
Schedule
Over the next four weeks my colleagues and I are going to post and speak about security foundations, staying secure, trust, and resilience. The schedule right now looks like this:
Webinars
Register for the technical webinar series at:
https://go-vmware.broadcom.com/vcf-ama-cybersecurity-awareness-month
- Thursday, October 8: Starting at the Beginning with VCF Security
(Base security controls, logging, vMotion, vSphere HA, and DRS) - Thursday, October 15: VCF Protects While the Landscape Changes
(Technical and organizational strategies for patching both VCF and workloads, snapshots, vTPM, confidential computing) - Thursday, October 22: VCF Identity and Access Control
(Using tools like identity federation, isolation, and even organizational process changes to protect against stolen credentials and high-quality phishing attacks) - Thursday, October 29: VCF Helps You Survive Bad Situations
(Talking through scenarios around ransomware, bad application upgrades, natural disasters, and geopolitical turmoil)
There is also a webinar on Wednesday, November 4 as part of our VCF Adoption Series, on Designing Secure VCF. Please register for that as well: https://go-vmware.broadcom.com/vcf-inside-vcf91-series-part-2
Blog Posts
- October 1: Security is a Way of Thinking
- October 2: Security Starts in Hardware
- October 5: VCF Security Hardening Guidance
- October 6: Dependencies are a Boat Anchor
- October 7: Everything You Never Wanted to Know About Vulnerabilities
- October 8: Security Scanners and VCF
- October 9: Certificates, Trust, and Network Encryption
- October 12: Patch Easier, Not Faster
- October 13: Upgrading VCF
- October 13: The Anatomy of an AI
- October 14: AI Security Threats: Real or Movie Plot?
- October 15: Securing Your Own AI Workloads
- October 16: Snapshots Are Your Best Friend
- October 19: It’s Not About Backups, It’s About Restores
- October 20: Common Themes in Resilient System Design
- October 21: Easiest Thing Ever: VCF Storage Encryption
- October 22: Encryption Key Provider Design
- October 23: Security Features Inside the Virtual Machine
- October 26: Workloads Keeping Secrets: Confidential Computing
- October 27: Logs, Events, and Logging Inside VCF
- October 28: Zero Trust Versus Identity Providers
- October 29: Good Fences, Good Neighbors: Isolating Infrastructure Management
- October 30: Protecting Active Directory with VCF
- November 2: Regulatory Compliance and VCF
Please subscribe to the blog, and make sure to join us for the webinars.
And, as always, stay secure and safe.
Discover more from VMware Cloud Foundation (VCF) Blog
Subscribe to get the latest posts sent to your email.