All articles

NIS2 Requirements: Why Credential Security is Non-Optional

7 min. read

AT

Akanksha Thakar

4 December, 2025

NIS2 & Passbolt

  • A clear, demonstrable access control model
  • Evidence such as permission matrices, group definitions, and access review records
  • Strong authentication beyond a single password
  • Concrete evidence such as MFA policies, enforcement screenshots, and logs of MFA-protected logins
  • A written MFA policy detailing when MFA is mandatory, exceptions, and outage handling
  • How external MFA providers (e.g., YubiCloud, Duo) fit into your risk picture
  • A cryptographic design you can reference directly in your policy
  • Independent audits and signed releases that support supplier trustworthiness
  • A cryptography policy specifying algorithms, key sizes, and rotation rules
  • How to handle long-lived secrets and rotation requirements
  • A record of who accessed which credential, before and during an incident
  • Time-stamped evidence for early warnings, 72-hour notifications, and final reports
  • Baseline data to detect suspicious behaviour (e.g., unexpected sharing, out-of-pattern access)
  • An incident classification system (to decide what is “significant” under NIS2)
  • A clear review and escalation process from Passbolt logs
  • Uptime monitoring and incident management tools and processes
  • Deployment options independent from a vendor-managed SaaS
  • Evidence such as backup configs, restore test results, and documented recovery procedures
  • Source code you can inspect
  • Signed artifacts you can verify
  • External audit reports for supplier risk records

Continue reading

Bitnami Legacy Changes: Passbolt’s Migration Plan for Open-Source, Secure Helm Deployments

4 min. read

Bitnami Legacy Changes: Passbolt’s Migration Plan for Open-Source, Secure Helm Deployments

Bitnami’s deprecation of free container images impacts the Passbolt Helm chart. This update covers new open-source alternatives, the migration plan, and user next steps.

AT

Akanksha Thakar

1 December, 2025

Passbolt with MariaDB Galera Cluster using Mutual TLS (mTLS) authentication

13 min. read

Passbolt with MariaDB Galera Cluster using Mutual TLS (mTLS) authentication

A practical guide to running passbolt with MariaDB Galera Cluster and mTLS, ensuring authenticated replication, flexible topology, and no-lag failover.

Gareth

Gareth

20 November, 2025

Flag of European UnionMade in Europe. Privacy by default.