Zip x Johanson Group Webinar: How the best vCISOs guide their clients through successful audits01d:01h:20m:51s

Browse Categories

Why Automated CIS Benchmark Enforcement Is Stronger Than Manual Security

Security

Why Automated CIS Benchmark Enforcement Is Stronger Than Manual Security

Learn how to enforce CIS benchmarks with automated device hardening, continuous control enforcement, and a stronger security baseline.

Josh Zweig

Josh Zweig

April 27, 2026 · 7 min read

Identity and Access Management that Blocks Unauthorized Access

Company

Identity and Access Management that Blocks Unauthorized Access

Identity issues rarely start with bad intent. They start with change. A new hire needs access right away, a contractor needs a temporary exception, or a manager forgets to remove an app assignment.

Josh Zweig

Josh Zweig

April 21, 2026 · 7 min read

Ready to Work in Minutes with Zero-Touch Security

Security

Ready to Work in Minutes with Zero-Touch Security

Deploy secure hardware in minutes. Learn how Zip's zero-touch enrollment automates onboarding and prevents security drift from day one.

Josh Zweig

Josh Zweig

April 21, 2026 · 8 min read

How Intrusion Prevention Systems End Alert Fatigue

How To Guide

How Intrusion Prevention Systems End Alert Fatigue

Alert fatigue occurs when security teams receive so many alerts that the queue becomes less useful. Too many are low priority, repetitive, or unclear, diverting time from meaningful security work to constant triage.

Chris Bond

Chris Bond

April 3, 2026 · 5 min read

Fixing the Hidden Gap in Security With Autonomous Monitoring

How To Guide

Fixing the Hidden Gap in Security With Autonomous Monitoring

Modern security gaps rarely come from a total lack of tooling. More often, they appear in the space between deployment and day-to-day reality, where an endpoint protection platform looks healthy in the console but fails to collect, report, or enforce as expected.

Josh Zweig

Josh Zweig

March 31, 2026 · 4 min read

How Automated Enforcement Saves 20+ Hours a Week

Security

How Automated Enforcement Saves 20+ Hours a Week

Manual security work quietly consumes hours weekly through device checks, policy follow-up, and audit preparation. Automated enforcement helps teams maintain approved settings without constant manual oversight.

Josh Zweig

Josh Zweig

March 27, 2026 · 4 min read

Why vCISOs Are Building Continuous Compliance For Clients with Zip

SOC2

Why vCISOs Are Building Continuous Compliance For Clients with Zip

A SOC 2 badge from Delve didn't protect LiteLLM. Here's what vCISOs need to know about continuous enforcement, and how Zip makes it scalable.

John Merklinger

John Merklinger

March 26, 2026 · 5 min read

The Automated Onboarding Process Your Growing Teams Need

Security

The Automated Onboarding Process Your Growing Teams Need

An automated onboarding process is a repeatable system that deploys a new hire's device, applies baseline security controls, provisions the right access, and provides proof that everything works—without relying on manual checklists.

Gabbi Merz

Gabbi Merz

March 23, 2026 · 6 min read

Fix Security Issues Overnight With Automated Remediation

Security

Fix Security Issues Overnight With Automated Remediation

Security drift can happen in a single day. A patch fails, encryption gets turned off, or an agent stops reporting. That does not mean your tools are broken. It means real environments keep changing, and small gaps can create security vulnerabilities if nothing pulls systems back to baseline.

Gabbi Merz

Gabbi Merz

March 12, 2026 · 8 min read

The Security Questionnaire Just Paused Your Deal. Here's How to Be Ready Next Time.

How To Guide

The Security Questionnaire Just Paused Your Deal. Here's How to Be Ready Next Time.

Security requirements are now standard in enterprise procurement. Here's what customers are asking for, why it's getting stricter, and how to stay ahead of it.

Kelli Trapnell

Kelli Trapnell

March 9, 2026 · 4 min read

IT Security Checks Without the Manual Work

Security

IT Security Checks Without the Manual Work

An IT security check should give you a fast answer to a simple question: are the basics still true? Devices stay protected, access stays controlled, and your tools keep working the way you expect.

Josh Zweig

Josh Zweig

March 3, 2026 · 5 min read

How to Answer a Security Questionnaire Without a Security Team

How To Guide

How to Answer a Security Questionnaire Without a Security Team

You don't need a dedicated security team to pass enterprise vendor reviews. You need enforced controls, current visibility, and answers you can actually back up.

Josh Zweig

Josh Zweig

March 2, 2026 · 4 min read

Operation Winter SHIELD: What You Need to Know

Security

Operation Winter SHIELD: What You Need to Know

Operation Winter SHIELD highlights the gap between security policy and enforcement. Learn how automation turns core controls into continuous protection.

Josh Zweig

Josh Zweig

February 23, 2026 · 4 min read

Compliance Requirements: How to Earn Enterprise Trust

SOC2

Compliance Requirements: How to Earn Enterprise Trust

Enterprise buyers include compliance requirements because procurement has one job: reduce risk in a consistent, defensible way.

Josh Zweig

Josh Zweig

February 19, 2026 · 8 min read

5 Questions to Ask Your MSP to Prove Your Security Is Working

How To Guide

5 Questions to Ask Your MSP to Prove Your Security Is Working

Most MSPs say they "handle security," but that doesn't automatically mean your environment is secure. The challenge is that security is hard to verify, especially when it spans dozens of tools, dashboards, and configurations.

Josh Zweig

Josh Zweig

February 16, 2026 · 6 min read

Preventing Configuration Drift With Automated Enforcement

How To Guide

Preventing Configuration Drift With Automated Enforcement

Configuration drift comes with modern IT. Devices update, people change roles, exceptions pile up, and system configurations don't always stay aligned.

JE

Jonathan Eidelman

February 10, 2026 · 7 min read

Connect Your Security Tools to Simplify Endpoint Security Management

Security

Connect Your Security Tools to Simplify Endpoint Security Management

Discover how connecting your tools makes endpoint security management visible, continuously enforced, and provable—without adding more tools or busywork.

ZS

Zip Security

February 5, 2026 · 14 min read

From Technical Debt to Baseline: 5 Ways to Automate Your Security

How To Guide

From Technical Debt to Baseline: 5 Ways to Automate Your Security

A clear, automated five-step path to move from technical debt (and security risk) to a stable, enterprise-ready baseline.

Josh Zweig

Josh Zweig

February 3, 2026 · 6 min read

Stay Audit-Ready All Year Long

How To Guide

Stay Audit-Ready All Year Long

How continuous compliance monitoring closes the gap by keeping controls enforced, evidence current, and compliance status clear all year.

Chris Bond

Chris Bond

January 30, 2026 · 7 min read

Still Managing Security Manually? Here's the Path to Automation

Security

Still Managing Security Manually? Here's the Path to Automation

Learn security configuration management and why manual approaches stop working as companies grow.

Josh Zweig

Josh Zweig

January 29, 2026 · 5 min read

How You Know You're Ready for Your First IT or Security Hire

How To Guide

How You Know You're Ready for Your First IT or Security Hire

For most growing companies, the first IT or security hire doesn't come from a big "aha" moment. Instead, it's a decision shaped by the gradual build-up of operational friction, compliance demands, and the need to manage risk as the business scales.

Josh Zweig

Josh Zweig

January 20, 2026 · 7 min read

Identity Access and Device Management: A Simple Model for Modern SMB Security

Identity Solution

Identity Access and Device Management: A Simple Model for Modern SMB Security

For most small and mid-sized businesses (SMBs), cybersecurity is more than just knowing what to do. The challenge comes when people, devices, and tools change.

Josh Zweig

Josh Zweig

January 12, 2026 · 8 min read

Jamf vs. Mosyle: Which Apple-focused MDM Solution is Best?

macOS

Jamf vs. Mosyle: Which Apple-focused MDM Solution is Best?

Apple device management presents a critical challenge for enterprises, as these devices don't come with built-in centralization capabilities. Two leading Mobile Device Management (MDM) platforms have emerged to address this need: Jamf, a veteran solution with extensive enterprise presence managing approximately 30 million devices worldwide, and Mosyle, a newer competitor offering streamlined workflows.

ZS

Zip Security

October 9, 2025 · 5 min read

Endpoint Protection vs. Data Control: Understanding the Difference

How To Guide

Endpoint Protection vs. Data Control: Understanding the Difference

Endpoint Protection secures devices from external threats through measures like malware blocking, patching, and firewalls, while Data Control safeguards sensitive information by managing access, classification, and usage across systems.

ZS

Zip Security

October 7, 2025 · 6 min read

The 3-Step Path to Security Maturity

Security

The 3-Step Path to Security Maturity

This tactical guide is designed for small and mid-sized organizations asking those exact questions about where to start with security.

Josh Zweig

Josh Zweig

October 6, 2025 · 8 min read

Navigating Compliance: 3 Tools to Secure SOC 2 Success

SOC2

Navigating Compliance: 3 Tools to Secure SOC 2 Success

To help first-time organizations navigate the SOC 2 auditing process, we sat down with Ryan Johanson, CEO of Johanson Group.

Josh Zweig

Josh Zweig

October 3, 2025 · 8 min read

SaaS Visibility: Detecting Modern Malware via Observability

Reevaluating traditional security practices

SaaS Visibility: Detecting Modern Malware via Observability

Learn how SaaS visibility and endpoint security management stop modern malware. Discover how to detect silent failures and configuration drift with Zip.

AG

Ankit Gupta

October 3, 2025 · 9 min read

The Importance of Two-Factor Authentication (2FA) for Cloud Platforms

Security

The Importance of Two-Factor Authentication (2FA) for Cloud Platforms

2FA is now a non-negotiable security standard for cloud platforms, preventing breaches caused by stolen or reused credentials.

AM

Ashley Meuser

October 1, 2025 · 3 min read

How Much Does SOC 2 Compliance Really Cost? A Clear Guide

SOC2

How Much Does SOC 2 Compliance Really Cost? A Clear Guide

A clear guide to SOC 2 compliance costs, trade-offs, and long-term benefits for growing companies.

Josh Zweig

Josh Zweig

September 22, 2025 · 32 min read

Jamf vs. Kandji: Which Apple MDM solution is best in 2025?

MDM

Jamf vs. Kandji: Which Apple MDM solution is best in 2025?

Apple devices lack centralized management by default, creating a gap for IT teams needing to enforce security policies at scale. Two leading MDM platforms serve Mac environments: Jamf, the established market leader emphasizing customization, and Kandji, the modern challenger known for simplicity.

Josh Zweig

Josh Zweig

September 19, 2025 · 27 min read

What is the Jamf Compliance Editor?

How To Guide

What is the Jamf Compliance Editor?

How Jamf Compliance Editor and Zip Security help maintain Apple device compliance beyond deployment.

Josh Zweig

Josh Zweig

September 17, 2025 · 22 min read

HIPAA and PCI

How To Guide

HIPAA and PCI

A clear guide to understanding HIPAA vs PCI DSS, their differences, and how to stay compliant with both.

Josh Zweig

Josh Zweig

September 15, 2025 · 15 min read

Small Business Cyber Security Checklist

Security

Small Business Cyber Security Checklist

Learn how to build a practical small business cyber security checklist that reduces risk, prevents security drift, and supports compliance.

Josh Zweig

Josh Zweig

September 12, 2025 · 8 min read

What Is Mobile Device Management (MDM)?

MDM

What Is Mobile Device Management (MDM)?

Mobile Device Management (MDM) is the foundational control behind modern security programs, providing visibility, enforcement, and trust at scale.

Josh Zweig

Josh Zweig

September 10, 2025 · 8 min read

Device and Endpoint Compliance

Reevaluating traditional security practices

Device and Endpoint Compliance

Why endpoint compliance is critical for scaling companies and how to build a strategy that works.

Josh Zweig

Josh Zweig

September 9, 2025 · 17 min read

MDR vs EDR Guide for Modern Endpoint Protection

Security

MDR vs EDR Guide for Modern Endpoint Protection

EDR vs MDR: key differences, use cases, and how to choose the right fit for your security team.

Josh Zweig

Josh Zweig

September 3, 2025 · 8 min read

Securing the Full Stack: Zip Security and Galvanick Announce Strategic Partnership

Company

Securing the Full Stack: Zip Security and Galvanick Announce Strategic Partnership

Zip Security and Galvanick are now partnering to provide unified cybersecurity across both Information Technology (IT) and Operational Technology (OT) environments.

Perry Rahman-Porras

Perry Rahman-Porras

June 10, 2025 · 5 min read

Intune Deployment: How to Keep Devices Healthy After Setup

How To Guide

Intune Deployment: How to Keep Devices Healthy After Setup

Explore Intune deployment with proven conditional access and compliance best practices and prevent policy drift.

Josh Zweig

Josh Zweig

February 11, 2025 · 13 min read

Case Study: Zip Security & Observa defend SaaS company against malware tied to Russia

Security

Case Study: Zip Security & Observa defend SaaS company against malware tied to Russia

An employee at a client firm was recently targeted by a malvertising campaign, unknowingly downloading malware designed for data exfiltration and credential theft. CrowdStrike swiftly neutralized the threat and a Managed Detection & Response team isolated the device, preventing any client impact.

Gabbi Merz

Gabbi Merz

October 18, 2024 · 4 min read

Mastering Mixed-Platform MDM

How To Guide

Mastering Mixed-Platform MDM

Learn about dual-solution approach using Microsoft Intune and Jamf for mixed-platform environments.

Josh Zweig

Josh Zweig

September 16, 2024 · 6 min read

An Overview of the CrowdStrike Outage & Proactive Strategies for Mitigating IT Disruption

Security

An Overview of the CrowdStrike Outage & Proactive Strategies for Mitigating IT Disruption

CrowdStrike made headlines early Friday morning as a routine content upgrade pushed bad code to an estimated 8.5 million Windows devices worldwide.

Josh Zweig

Josh Zweig

July 25, 2024 · 5 min read

Enhancing Enterprise Security: The Case for Enterprise Browsers

Security

Enhancing Enterprise Security: The Case for Enterprise Browsers

Through its integration with Chrome Enterprise Core, Zip Security enables organizations to centrally manage and secure browser configurations, extensions, and updates across all endpoints.

Josh Zweig

Josh Zweig

July 23, 2024 · 4 min read

Start-Up Banking 101: How to Protect your Business from Disruption

How To Guide

Start-Up Banking 101: How to Protect your Business from Disruption

Learn how to set up accounts and security to protect against disruption to operations.

Josh Zweig

Josh Zweig

July 18, 2024 · 5 min read

Developing a Security Awareness Program That Actually Changes Behavior

Security

Developing a Security Awareness Program That Actually Changes Behavior

Learn how developing cybersecurity awareness programs helps reduce human risk, improve consciousness, and deliver effective cyber training for employees.

AM

Ashley Meuser

June 7, 2024 · 5 min read

What Is SaaS Security? Visibility, Risks, and Control Explained

Security

What Is SaaS Security? Visibility, Risks, and Control Explained

SaaS security is the practice of protecting data, access, and workflows across cloud-based software applications that employees rely on every day.

Josh Zweig

Josh Zweig

April 26, 2024 · 5 min read

MSP vs MSSP: What's the Difference in IT Security?

Security

MSP vs MSSP: What's the Difference in IT Security?

MSPs handle day-to-day IT operations, while MSSPs focus specifically on cybersecurity, monitoring, and incident response.

Josh Zweig

Josh Zweig

April 19, 2024 · 5 min read

Announcing Our Collaboration with Ambience Healthcare on a Co-Authored Whitepaper to Help Healthcare Organizations Assess Security Risks

Company

Announcing Our Collaboration with Ambience Healthcare on a Co-Authored Whitepaper to Help Healthcare Organizations Assess Security Risks

Zip Security and Ambience Healthcare have partnered to release a co-authored white paper addressing third-party vendor cybersecurity risks in healthcare organizations.

Cindy Huang

Cindy Huang

April 3, 2024 · 8 min read

We're Excited to Unveil our New Branding!

Company

We're Excited to Unveil our New Branding!

We're excited to unveil our revamped branding, break down the design process, and explore the values and story behind Zip.

Cindy Huang

Cindy Huang

March 25, 2024 · 5 min read

The Future of Authentication Without Passwords

Security

The Future of Authentication Without Passwords

Passwords shouldn't serve as the primary way users prove who they are. In modern environments, they're too easy to steal, too hard to manage, and too costly to maintain at scale.

BZ

Brendan Zegers

March 15, 2024 · 5 min read

The Evolving Cybersecurity Landscape: Reevaluating the Role of VPNs

Security

The Evolving Cybersecurity Landscape: Reevaluating the Role of VPNs

In the ever evolving landscape of security and technology, this article explores the question: what is the role of the VPN in a modern security program?

Cindy Huang

Cindy Huang

February 29, 2024 · 5 min read

In Defense of Local Admin Rights

Security

In Defense of Local Admin Rights

Learn the risks and benefits of local admin rights. Discover how to balance user productivity with least privilege security using modern endpoint guardrails.

Josh Zweig

Josh Zweig

February 16, 2024 · 5 min read

Building a Culture of Security Consciousness: Getting a Security Program off the Ground as a 'Department of One'

Security

Building a Culture of Security Consciousness: Getting a Security Program off the Ground as a 'Department of One'

Discussion of how security leaders can effectively run programs as first hires in organizations, covering prioritization, communication, and strategic approaches to building security awareness.

Cindy Huang

Cindy Huang

February 8, 2024 · 5 min read

Endpoint Security Management: From Antivirus to Posture Management

Security

Endpoint Security Management: From Antivirus to Posture Management

Master endpoint security management with Zip Security and prevent configuration drift, enforce device trust, and harden your security baseline.

AG

Ankit Gupta

February 2, 2024 · 5 min read

How to Manage Windows MDM and Asset Inventory Without Entra ID Accounts

Windows

How to Manage Windows MDM and Asset Inventory Without Entra ID Accounts

Most security frameworks assume you have an enterprise-sized team and a perfectly uniform Microsoft environment. But for many IT admins, reality looks different.

Chris Bond

Chris Bond

January 25, 2024 · 8 mins

Unified Endpoint Management for Device Security

MDM

Unified Endpoint Management for Device Security

Discover how unified endpoint management enforces device security, prevents silent failures, and strengthens device trust across your organization.

Josh Zweig

Josh Zweig

January 16, 2024 · 5 min read

Navigating the Cybersecurity Landscape: A Deep Dive into Identity Solutions

Identity Solution

Navigating the Cybersecurity Landscape: A Deep Dive into Identity Solutions

This deep dive demystifies the complexities of Identity Solutions, offering insights into their mechanisms, selection criteria, and the impact they have on safeguarding against the theft of credentials.

Cindy Huang

Cindy Huang

January 9, 2024 · 8 mins

What Cybersecurity Tools do you Need to Build an Effective Security Strategy?

How To Guide

What Cybersecurity Tools do you Need to Build an Effective Security Strategy?

In this post, we'll cover the fundamental building blocks of an effective cybersecurity strategy and provide practical information on how best to assess different tools.

Cindy Huang

Cindy Huang

January 4, 2024 · 8 min read

Security for Hard Tech Companies

Security

Security for Hard Tech Companies

Securing your hard tech company can be a daunting task. To help you stay secure, we've compiled a list of the highest return on investment (ROI) actions you can take to protect your company data.

Gabbi Merz

Gabbi Merz

November 20, 2023 · 3 min read

Announcing Our $7.7M Funding Round to Protect Businesses from Cyber Threats

Company

Announcing Our $7.7M Funding Round to Protect Businesses from Cyber Threats

Most organizations do not have the ability to invest in cybersecurity like a Fortune 500, but the burden is increasingly on them to do so.

Josh Zweig

Josh Zweig

November 14, 2023 · 4 min read

Satisfy Compliance Frameworks in One Click with Zip

Product Update

Satisfy Compliance Frameworks in One Click with Zip

Save countless hours by automatically having your software deployed, configured, and reported against according to your desired compliance framework, with the single click of a button!

ZS

Zip Security

November 2, 2023 · 5 min read

BYOD Security Policy for SMBs: Securing Personal Mobile Phones at Work

Security

BYOD Security Policy for SMBs: Securing Personal Mobile Phones at Work

Learn how SMBs can build a practical BYOD security policy to manage personal phone risk, prevent configuration drift & enable remote wipe without full MDM.

Josh Zweig

Josh Zweig

October 26, 2023 · 5 min read

What Is an MSSP? Managed Security Explained Simply

Security

What Is an MSSP? Managed Security Explained Simply

Learn what an MSSP is, how it differs from an MSP and when a managed security service provider makes sense for your business.

Josh Zweig

Josh Zweig

October 5, 2023 · 5 min read

A Guide to Achieving SOC2 with Zip

SOC2

A Guide to Achieving SOC2 with Zip

SOC 2 is a framework for evaluating controls related to security, availability, processing integrity, confidentiality, and customer data privacy. Zip was purpose-built to solve the challenges of deploying and managing required security tools.

ZS

Zip Security

September 21, 2023 · 3 min read

A Quick Primer on DoD Cybersecurity Standards

Security

A Quick Primer on DoD Cybersecurity Standards

The US is raising cybersecurity standards for government contractors, especially those working with the Department of Defense. Many software companies unfamiliar with government contracting must now contend with these standards and associated acronyms.

Josh Zweig

Josh Zweig

September 7, 2023 · 3 min read

Which is Better for Account Security, WebAuthn or Biometric MFA?

Security

Which is Better for Account Security, WebAuthn or Biometric MFA?

MFA that is more convenient than TOTP and more secure than SMS: WebAuthn using biometrics.

CW

Chase Walters

May 26, 2023 · 15 min read

Prevent Data Breaches From Laptop Thefts

Security

Prevent Data Breaches From Laptop Thefts

Laptop theft is a growing threat. MDM with remote wiping can help protect sensitive data.

ZS

Zip Security

May 18, 2023 · 8 min read

Cybersecurity for Startups: A Practical Guide to Getting Secure on a Budget

Security

Cybersecurity for Startups: A Practical Guide to Getting Secure on a Budget

Small businesses must prioritize cybersecurity. Steps include educating employees, enforcing MFA, using strong passwords, securing Wi-Fi, and obtaining cyber insurance.

AM

Ashley Meuser

May 12, 2023 · 5 min read

Activation Lock: Friend or Foe

macOS

Activation Lock: Friend or Foe

macOS Activation Lock -- friend or foe for small businesses?

Gabbi Merz

Gabbi Merz

May 2, 2023 · 6 min read

Vulnerability Management for MacOS Fleets

macOS

Vulnerability Management for MacOS Fleets

Run macOS fleet vulnerability management with minimal disruption. Reduce Mean Time to Patch with proper CVE response, patch SLAs, and safe update workflows.

Chris Bond

Chris Bond

March 30, 2023 · 8 min read

Our Commitment to Security: Announcing SOC2 Type I

Security

Our Commitment to Security: Announcing SOC2 Type I

Zip Security is now SOC2 Type I compliant!

Gabbi Merz

Gabbi Merz

March 16, 2023 · 5 min read

3 Best Practices for Wiping and Locking macOS Devices

macOS

3 Best Practices for Wiping and Locking macOS Devices

Wiping and locking corporate devices is a regular part of managing an enterprise fleet. As employees come and go or devices get lost or stolen, employers must be ready to wipe and lock devices in different contexts.

Gabbi Merz

Gabbi Merz

March 14, 2023 · 5 min read

Jamf MDM Deployment Best Practices

MDM

Jamf MDM Deployment Best Practices

If your company runs on Macs, at some point you'll need a way to manage them, systematically and at scale. That's where Jamf comes in.

Josh Zweig

Josh Zweig

February 22, 2023 · 7 min read