Kamin Associates, Inc.

Kamin Associates, Inc. We are a business focused on providing an IT support structure to small and mid-sized companies that

Over time, it’s easy to forget which apps you’ve connected to your email, cloud storage, or social media accounts. Every...
08/14/2026

Over time, it’s easy to forget which apps you’ve connected to your email, cloud storage, or social media accounts. Every connected app is another potential access point to your data.

Take a few minutes to review your connected applications and remove anything you no longer use or don’t recognize. It’s a simple step that helps reduce security risks and keeps your accounts better protected.

Want to strengthen your organization’s cybersecurity? Visit our website to learn how we help businesses stay secure.

www.kamin.us

Technology decisions have a lasting impact on how your business operates. Choosing the right tools, reducing friction wh...
08/13/2026

Technology decisions have a lasting impact on how your business operates. Choosing the right tools, reducing friction where information moves between teams, making sure every IT investment supports a business goal, simplifying routine changes, and planning for future growth all help create a stronger foundation for success.

If you’re ready to build an IT strategy that grows with your business, visit our website and see how our team can help.

www.kamin.us

Your business can’t protect what it doesn’t know it has. Without an accurate IT asset inventory, outdated devices, unaut...
08/12/2026

Your business can’t protect what it doesn’t know it has. Without an accurate IT asset inventory, outdated devices, unauthorized software, and forgotten systems can create security gaps, increase costs, and make IT management far more difficult. A complete inventory gives your business the visibility needed to improve cybersecurity, simplify planning, and make smarter technology decisions.

Our latest blog explains why every business needs an IT asset inventory, what should be included, and how maintaining one helps reduce risk while supporting long-term growth.

Read the full blog here: https://loom.ly/vvswtf8

Know what you're protecting. Learn how an IT asset inventory strengthens cybersecurity, improves compliance, reduces risk, and supports smarter IT management. %

Least privilege is not a new security concept.  For decades we have applied it to desktops and data. Users receive stand...
08/11/2026

Least privilege is not a new security concept.
For decades we have applied it to desktops and data. Users receive standard accounts instead of administrator rights. Group Policy, security groups, and file permissions limit access to what people actually need for their jobs. We often call this “need to know.”

Zero Trust architecture extends that thinking across the entire environment. Trust is no longer granted simply because a user or system sits inside the network. Access must be explicitly authorized based on identity, device, resource, purpose, and context.

At the network layer, microsegmentation limits systems to the specific communications their functions require. A workstation that needs an application server does not automatically need access to every other workstation—or even every service on that server.

Just-in-time privileged access (JIT) takes least privilege one important step further. Instead of maintaining large numbers of standing privileged accounts—domain admins and similar highly privileged users whose day-to-day actions are often poorly auditable—privilege can be granted:

- To a specific person
- For a specific task
- To a specific resource
- For a limited period
- With approval and an auditable record

When the task ends, the privilege expires automatically. By eliminating persistent elevated rights, JIT significantly reduces the attack surface.

A mature JIT process can also enforce separation of duties. The person requesting privileged access is not the same person authorized to approve it. For especially sensitive actions, organizations can require two-person approval—the digital equivalent of the two-person rule that protects critical physical operations.

This approach delivers something traditional standing privilege often lacks: visibility. The organization can see who requested access, who approved it, why it was needed, what resource was affected, when the privilege became active, and when it expired. Combined with session and activity logging, it can also show exactly what the administrator did while elevated.

The question shifts from:
“Who should have administrative access?”

To:
“Who needs this privilege, for what purpose, to which resource, who should authorize it, and for how long?”

Least privilege limits unnecessary access.
Microsegmentation applies it to network communication.
JIT applies it to time and shrinks the attack surface.
Separation of duties applies it to authority.
Logging makes the use of that privilege visible and accountable.

The principle has not changed. Our ability to enforce—and prove—it has.

The best technology strategies aren’t always the most noticeable. Reviewing outdated reports, improving recovery times, ...
08/10/2026

The best technology strategies aren’t always the most noticeable. Reviewing outdated reports, improving recovery times, challenging inefficient processes, staying ahead of your IT budget, and making behind-the-scenes improvements all contribute to a more resilient and efficient business.

Looking for an IT partner that helps you plan ahead instead of simply reacting to problems? Visit our website to learn how we can help your business get more from its technology.

www.kamin.us

Cybercriminals don’t always choose their victims one by one.Many attacks begin with automated tools that continuously se...
08/07/2026

Cybercriminals don’t always choose their victims one by one.

Many attacks begin with automated tools that continuously search for exposed systems, outdated software, weak passwords, and other vulnerabilities. If a weakness is found, your business could become a target without anyone specifically seeking you out.

The best defense is reducing your exposure before automated threats have the chance to find it.

Ready to strengthen your security? Visit our website to learn how proactive monitoring and layered protection can help keep your business secure.

www.kamin.us

Technology isn’t a one-time purchase. Every device, application, and system has a lifecycle, and without a plan to manag...
08/06/2026

Technology isn’t a one-time purchase. Every device, application, and system has a lifecycle, and without a plan to manage it, businesses can face higher costs, security risks, and unexpected downtime. A proactive technology lifecycle management strategy helps maximize the value of your IT investments while keeping your business secure and productive.

Our latest blog explains why every business should take a strategic approach to technology lifecycle management and how planning ahead can improve performance, reduce risk, and support long-term growth.

Read the full blog here: https://loom.ly/MciI39E

Plan ahead with a technology lifecycle management strategy to reduce downtime, improve cybersecurity, extend hardware life, and simplify IT budgeting.

One lesson that 30 years of running an IT company and 10 years of teaching cybersecurity has reinforced is this: impleme...
08/05/2026

One lesson that 30 years of running an IT company and 10 years of teaching cybersecurity has reinforced is this: implementing a control is easy compared to proving it's still working.

**Security controls are not the objective.**

**Control assurance is.**

Organizations invest enormous amounts of time and money implementing administrative, technical, and physical controls. Firewalls. MFA. Endpoint protection. Backups. Encryption. Privileged access management. SIEMs.

But after implementation, a more important question emerges:

**How do you know the control is still there?**

Even more importantly...

**How do you know it's still working?**

One of the concepts I emphasize to my students is this:

**There are controls that watch other controls.**

Every meaningful security control should produce evidence.

Sometimes that's obvious. A firewall logs connections. An EDR agent generates telemetry. An identity system records authentication events.

But what about the controls that remain quiet for long periods of time?

How do you know the backup job is still running if it hasn't failed?

How do you know an endpoint agent hasn't silently stopped reporting?

How do you know a vulnerability scanner is still executing against every intended asset?

How do you know a security control hasn't simply... disappeared?

In distributed systems, we often solve this problem with **heartbeat** or **health** messages—regular signals that prove a component is alive and functioning even when nothing interesting is happening.

Cybersecurity should increasingly think about controls the same way.

A SIEM doesn't usually stop an attack. It watches the controls that generate telemetry.

Endpoint management systems verify that EDR agents are installed, healthy, and reporting.

Configuration management systems verify that security baselines remain intact.

Vulnerability scanners verify that systems continue to meet security expectations.

Even security analysts spend much of their time validating that the controls designed to protect the organization are still functioning as intended.

This raises an important question:

**Who watches the watchers?**

The answer is: more controls.

Cybersecurity isn't a flat collection of independent safeguards. It's a layered architecture of controls validating other controls, producing evidence that risk is actually being managed.

As AI becomes integrated into SOC platforms and SIEMs, I believe one of its greatest strengths will be reasoning across this web of evidence. Not just identifying attacks, but recognizing when the absence of expected telemetry suggests a control has failed, become misconfigured, or quietly disappeared.

Ultimately, trust in cybersecurity doesn't come from implementing controls.

It comes from continuously proving that those controls are still working.

After running an IT services company for more than 30 years and teaching ISC2 cybersecurity certification classes for th...
08/04/2026

After running an IT services company for more than 30 years and teaching ISC2 cybersecurity certification classes for the past decade, one lesson has been reinforced time and time again.

Many professionals think governance is primarily about writing policies, standards, procedures, and guidelines.

We don't.

Those documents are necessary—but they're only the beginning.

The difficult part of governance isn't defining what people **should** do.

It's proving what they **actually** do.

Every policy implies one or more security controls. Every control should produce evidence. Without evidence, compliance is little more than trust.

That is why auditing is so fundamental to cybersecurity.

In modern environments, periodic audits are rarely sufficient. Many of today's critical controls must be continuously monitored, producing evidence in near real time that they remain effective.

A password policy isn't governance.

Knowing every account complies with that policy is.

A vulnerability management policy isn't governance.

Knowing critical systems are actually being scanned, remediated, and verified is.

An access control policy isn't governance.

Knowing privileged access is appropriate today—not just when the audit occurred is.

I've found that this is where many organizations struggle. Writing governance documents is relatively straightforward. Building the technical and operational capability to continuously demonstrate that those documents are being followed is considerably harder.

Ultimately, governance exists to manage risk—and evidence is how we demonstrate that risk is actually being managed.

What are your thoughts? Is governance primarily about defining expectations, or proving they're being met?

One of the challenges of studying for cybersecurity certifications is the sheer volume of material. CISSP, CCSP, CSSLP, ...
07/31/2026

One of the challenges of studying for cybersecurity certifications is the sheer volume of material. CISSP, CCSP, CSSLP, Security+, CISM... each covers a vast body of knowledge that can seem overwhelming.

After teaching ISC2 CISSP for the past 10 years, we've become convinced that the students who succeed are the ones who recognize that all of those topics are built on a few timeless principles. Technology changes rapidly—especially with AI—but the fundamentals have remained remarkably constant.

To me, nearly everything in cybersecurity comes back to two foundational concepts.

1. Risk
Cybersecurity exists to manage risk. We identify threats and vulnerabilities, assess the likelihood and impact, and implement administrative, technical, and physical controls to reduce risk to an acceptable level. Whether you're discussing governance, cloud security, software development, cryptography, or incident response, you're really discussing different ways of managing risk.

2. State
Information systems are constantly changing state. Users authenticate. Processes execute. Files are created, modified, transmitted, encrypted, archived, and eventually destroyed. Privileges are granted and revoked. Network connections are established and terminated.

Security controls exist to ensure those state transitions occur only in authorized ways—and to prevent, detect, or correct unauthorized changes. In many ways, cybersecurity is the discipline of governing the allowable state transitions of systems while continuously managing the risk associated with them.

Whenever we introduce a new CISSP domain, we mentally ask two questions:
• What risk are we trying to manage?
• What state are we trying to control?

Those two questions have served us well as an instructor, a practitioner, and an architect. More importantly, they help transform cybersecurity from a collection of disconnected technologies into a coherent discipline.

We'd be interested to hear from other security professionals. What foundational principle has remained constant throughout your career, regardless of how much the technology has changed?

Address

121 Interpark Boulevard, Suite 219
San Antonio, TX
78209

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+12102017800

Alerts

Be the first to know and let us send you an email when Kamin Associates, Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Kamin Associates, Inc.:

Shortcuts

Share