
Ambassador
Tomas Honzak
VP, CISO at Vendavo
Czech RepublicVerified Community AmbassadorIdentified Expertise
Content Tomas is Following
Do you trust the data & reports from the big analysts?
Yes
No
Sometimes
111.8k views123 Upvotes58 Comments
Performance
High cost
Rate of Data Growth
Other (none of the above)
We are looking for a WAF for our new SaaS system which uses GraphQL API. The concern is that AWS WAF might not be suitable; the "free" OWASP ruleset would not suffice and custom rules means manpower investment and ongoing costs. Any experience or recommendation would be appreciated!
123 views
Nowadays, many SaaS tools offer SSO integration as a premium feature, sometimes effectively doubling the price-per-user. What is the right way to find balance between when to invest and leverage SSO and when to keep the costs lower and handle the provisioning and de-provisioning manually?

Tomas HonzakVP, CISO at Vendavo in Software6 years ago
It depends on what the original authentication method is. We require multi factor PIV authentication and can only use FedRAMP approved cloud providers which have been vetted to meet NIST requirements so I wouldn’t have an ...read more745 views1 Comment
How do you enhance network security?
Tomas HonzakVP, CISO at Vendavo in Software2 years ago
Hard to give a specific answer without having context, but let me try anyways:- Create network diagram and review the flow of data through it. Pay attention to understand their sensitivity.
- Review the segmentation ...read more
2k views1 Comment