<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Malavika Rajesh</title>
    <description>The latest articles on DEV Community by Malavika Rajesh (@malavika__).</description>
    <link>https://dev.to/malavika__</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061917%2F1f67dab1-b833-4bec-a358-d27c709ceea1.png</url>
      <title>DEV Community: Malavika Rajesh</title>
      <link>https://dev.to/malavika__</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/malavika__"/>
    <language>en</language>
    <item>
      <title>Strengthening Remote Work Security with CASB and DNS Filtering</title>
      <dc:creator>Malavika Rajesh</dc:creator>
      <pubDate>Thu, 13 Aug 2026 08:55:19 +0000</pubDate>
      <link>https://dev.to/malavika__/strengthening-remote-work-security-with-casb-and-dns-filtering-3e8l</link>
      <guid>https://dev.to/malavika__/strengthening-remote-work-security-with-casb-and-dns-filtering-3e8l</guid>
      <description>&lt;p&gt;Remote work has changed how organizations manage security. Employees now access cloud applications, websites, and company resources from different locations and devices. This makes it important for organizations to have security controls that provide visibility and help manage access across distributed environments.&lt;/p&gt;

&lt;p&gt;One useful approach is combining Zero Trust access with additional layers of security such as Cloud Access Security Broker (CASB) capabilities and DNS filtering.&lt;/p&gt;

&lt;p&gt;Why CASB Matters&lt;/p&gt;

&lt;p&gt;Cloud applications are now an important part of everyday business operations. Employees may use multiple cloud services to communicate, store files, collaborate, and manage projects. This can create security challenges when organizations do not have enough visibility into cloud usage.&lt;/p&gt;

&lt;p&gt;A &lt;a href="https://www.quickztna.com/guide/admin/casb/" rel="noopener noreferrer"&gt;CASB&lt;/a&gt; capability can help organizations gain better visibility and control over cloud application activity. It provides an additional security layer between users and cloud services, helping organizations manage cloud access while supporting their broader security policies.&lt;/p&gt;

&lt;p&gt;For distributed teams, this type of visibility can make it easier for administrators to understand how cloud resources are being accessed and identify areas that may require additional security controls.&lt;/p&gt;

&lt;p&gt;The Role of DNS Filtering&lt;/p&gt;

&lt;p&gt;DNS is another important part of internet access. When users visit a website or connect to an online service, DNS helps translate domain names into network addresses. Because DNS requests occur frequently, controlling DNS traffic can provide another opportunity to improve security.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.quickztna.com/guide/admin/dns-filtering/" rel="noopener noreferrer"&gt;DNS Filtering&lt;/a&gt; can help organizations control access to domains according to defined security policies. This can reduce exposure to unwanted or potentially risky destinations and give administrators greater control over internet access.&lt;/p&gt;

&lt;p&gt;A Layered Security Approach&lt;/p&gt;

&lt;p&gt;CASB and DNS filtering work well as complementary security controls. CASB focuses on cloud application visibility and access, while DNS filtering provides control at the domain level. When combined with Zero Trust principles, identity-based policies, and device security, these capabilities can contribute to a stronger remote-work security strategy.&lt;/p&gt;

&lt;p&gt;Modern organizations need more than a traditional VPN to protect distributed teams. A layered approach helps security teams manage access, improve visibility, and apply consistent policies across users and devices.&lt;/p&gt;

&lt;p&gt;To explore more &lt;a href="https://www.quickztna.com/" rel="noopener noreferrer"&gt;QuickZTNA capabilities&lt;/a&gt;, visit the QuickZTNA platform and&lt;a href="https://www.quickztna.com/features/" rel="noopener noreferrer"&gt; QuickZTNA Features&lt;/a&gt;.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>What Modern Remote Access Should Consider Beyond the VPN</title>
      <dc:creator>Malavika Rajesh</dc:creator>
      <pubDate>Wed, 12 Aug 2026 05:47:12 +0000</pubDate>
      <link>https://dev.to/malavika__/what-modern-remote-access-should-consider-beyond-the-vpn-274a</link>
      <guid>https://dev.to/malavika__/what-modern-remote-access-should-consider-beyond-the-vpn-274a</guid>
      <description>&lt;p&gt;Remote access is no longer just a question of connecting a laptop to a private network. As organizations adopt distributed teams, cloud infrastructure, and device-based security controls, the underlying architecture of remote connectivity has become more important.&lt;/p&gt;

&lt;p&gt;A traditional VPN can still provide encrypted communication, but it does not automatically answer questions such as: Who should access a particular resource? Is the connecting device trustworthy? How should access policies change over time? And what happens when the organization needs to meet newer security or compliance expectations?&lt;/p&gt;

&lt;p&gt;One area receiving increasing attention is post-quantum security. Organizations evaluating VPN or ZTNA solutions should look beyond general claims of “quantum readiness.” Questions around the cryptographic algorithms being used, whether post-quantum mechanisms are actually deployed, and how keys are managed can provide a much clearer picture. A practical checklist for evaluating these claims is discussed in Post-&lt;a href="https://www.quickztna.com/blog/post-quantum-vpn-vendor-questions/" rel="noopener noreferrer"&gt;Quantum VPN: 6 Questions to Ask Your Current Vendor&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Another architectural decision involves the coordination layer behind encrypted device-to-device networks. WireGuard provides the encrypted data plane, but managing device discovery, authentication, policies, and connectivity across multiple machines can become complicated as a network grows. Teams may choose between operating their own coordination infrastructure or using a managed service. The trade-offs include operational effort, control, maintenance responsibilities, and cost. The comparison in &lt;a href="https://www.quickztna.com/blog/headscale-vs-managed-coordination/" rel="noopener noreferrer"&gt;Self-Hosting Headscale vs a Managed Coordination Server &lt;/a&gt;explores these differences.&lt;/p&gt;

&lt;p&gt;Compliance is another factor that increasingly influences remote-access architecture. For organizations affected by NIS2, security teams need to consider how remote access fits into broader requirements for risk management, access control, authentication, monitoring, and security measures. Rather than treating compliance as a separate layer added after deployment, these requirements can influence the architecture from the beginning. A practical breakdown is available in &lt;a href="https://www.quickztna.com/blog/nis2-remote-access-requirements/" rel="noopener noreferrer"&gt;NIS2 Directive Remote Access Requirements: A Builder's Checklist.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The larger lesson is that remote access should be evaluated as an architecture, rather than simply as a VPN product. Encryption is important, but identity, device posture, authorization, coordination, monitoring, and regulatory requirements all affect how securely employees and systems can connect.&lt;/p&gt;

&lt;p&gt;For organizations reviewing their current setup, a useful starting point is to document how users authenticate, how devices are verified, which resources they can reach, how access decisions are enforced, and what evidence is retained for security reviews.&lt;/p&gt;

&lt;p&gt;That approach makes it easier to identify gaps before they become operational or compliance problems.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Managing Remote Access, Observability, and Billing in a Modern Security Platform</title>
      <dc:creator>Malavika Rajesh</dc:creator>
      <pubDate>Tue, 11 Aug 2026 09:29:23 +0000</pubDate>
      <link>https://dev.to/malavika__/managing-remote-access-observability-and-billing-in-a-modern-security-platform-1jen</link>
      <guid>https://dev.to/malavika__/managing-remote-access-observability-and-billing-in-a-modern-security-platform-1jen</guid>
      <description>&lt;p&gt;Managing Remote Access, Observability, and Billing in a Modern Security Platform&lt;/p&gt;

&lt;p&gt;With increasing trends of distributed working, managing security infrastructure becomes much more complicated than just securing an office network. The modern workplace has employees connecting to it from various places, cloud workloads, remote servers, and internal applications. In addition to that, administrators need to keep control of their infrastructure and be aware of all the resources they use.&lt;/p&gt;

&lt;p&gt;It is supposed that a modern security platform will simplify these administrative activities, rather than complicate them even further.&lt;br&gt;
**&lt;br&gt;
Remote Access Needs to Be Controlled&lt;br&gt;
**&lt;br&gt;
One of the areas which require attention of any organization dealing with distributed team is remote access. It is often the case when employees and administrators need to gain access to their internal systems, not making these systems directly available on the Internet.&lt;/p&gt;

&lt;p&gt;There are many ways of implementing remote access besides traditional username and password. For example, access can be assessed based on identity, device, permissions, and other contexts, thus enabling only necessary access to the resource and minimizing network exposure.&lt;/p&gt;

&lt;p&gt;For administrators interested in remote access in Zero Trust architecture, there is an additional &lt;a href="https://www.quickztna.com/guide/admin/remote-access/" rel="noopener noreferrer"&gt;remote access guide &lt;/a&gt;available in QuickZTNA project.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Visibility Gained Through Observability&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Security controls are only helpful when the administrator knows what is going on within the environment. Without enough visibility, any anomalies, configuration issues, or access problems could be challenging to detect.&lt;/p&gt;

&lt;p&gt;The observability process could allow the team to gather important security and infrastructure information from one centralized place. Logs, events, connection details, and other operational information could be valuable during problem solving and investigations of any anomalies.&lt;/p&gt;

&lt;p&gt;Without having to make any assumptions, the administrator could get information about how the system is accessed and which area should be taken into consideration.&lt;/p&gt;

&lt;p&gt;For further information on observability, see the&lt;a href="https://www.quickztna.com/guide/admin/observability/" rel="noopener noreferrer"&gt; QuickZTNA observability documentation.&lt;/a&gt;&lt;br&gt;
**&lt;br&gt;
Billing and Resource Usage Transparency**&lt;/p&gt;

&lt;p&gt;Another operational aspect that is often neglected with security solutions is billing and resource usage. The team must know the account structure and usage in case they add more users, devices, or capabilities.&lt;/p&gt;

&lt;p&gt;Having transparency regarding the billing information will help the organization to budget, track usage, and decide when scaling the security infrastructure is necessary. It will also help the administrator to differentiate essential capabilities from unnecessary ones.&lt;br&gt;
The &lt;a href="https://www.quickztna.com/guide/admin/billing/" rel="noopener noreferrer"&gt;QuickZTNA billing guide&lt;/a&gt; can help administrators understand the billing-related aspects of managing the platform.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bringing Administration into the Mix&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Remote access, observability, and billing may seem like different administrative activities, but they all share one key thing – visibility and control.&lt;/p&gt;

&lt;p&gt;A growing company needs to know who accesses their resources, what is going on in their environment, and how the security infrastructure is used. Aligning those activities within a proper administrative process can help make security operations easier as the company grows.&lt;/p&gt;

&lt;p&gt;Zero Trust security is not just about implementing more secure authentication or limited network access. Zero Trust is also about building an environment that allows admins to make the right decisions.&lt;/p&gt;

&lt;p&gt;By aligning remote access, observability, and account management within controlled environments, companies can build their security environment in such a way that it will be easier to operate, while still allowing proper access controls for remote teams.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Stop Exposing SSH to the Internet: A Better Way to Access Private Servers</title>
      <dc:creator>Malavika Rajesh</dc:creator>
      <pubDate>Tue, 04 Aug 2026 09:20:01 +0000</pubDate>
      <link>https://dev.to/malavika__/stop-exposing-ssh-to-the-internet-a-better-way-to-access-private-servers-2bfm</link>
      <guid>https://dev.to/malavika__/stop-exposing-ssh-to-the-internet-a-better-way-to-access-private-servers-2bfm</guid>
      <description>&lt;p&gt;SSH is one of those tools that are used automatically by the developers.&lt;/p&gt;

&lt;p&gt;Want to see what's going on with the server?&lt;/p&gt;

&lt;p&gt;ssh user@server&lt;/p&gt;

&lt;p&gt;Easy.&lt;/p&gt;

&lt;p&gt;However, public SSH access usually requires exposing port 22 to the web, setting up firewalls, limiting IP addresses, or adding a bastion host before the internal network.&lt;/p&gt;

&lt;p&gt;It will work, but as you add more infrastructure, it will become harder to manage your remote access.&lt;/p&gt;

&lt;p&gt;There is an alternative, however – to keep the servers private and limit their access with a Zero Trust network.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why Public SSH Access May Be an Issue&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Publicly accessible SSH server is always exposed to the internet.&lt;/p&gt;

&lt;p&gt;Although authentication is done properly, there is always a need to think about firewalls, credentials, authorized users, IP address restrictions, and monitoring.&lt;/p&gt;

&lt;p&gt;One of the solutions to reduce the exposure is to allow SSH access from a specific set of IP addresses.&lt;/p&gt;

&lt;p&gt;However, it will not be convenient for remote developers.&lt;br&gt;
Bastion Host could also be considered another popular choice:&lt;/p&gt;

&lt;p&gt;Developer&lt;br&gt;
    ↓&lt;br&gt;
Bastion Host&lt;br&gt;
    ↓&lt;br&gt;
Private Server&lt;/p&gt;

&lt;p&gt;Here we decrease exposure of the internal servers, however, the bastion becomes another infrastructure component that needs to be protected and maintained.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;But What If There Was No Need for SSH on the Server from the Outside?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Instead of exposing SSH externally, let us picture the developer and the server communicating via a private encrypted channel.&lt;/p&gt;

&lt;p&gt;Developer Laptop&lt;br&gt;
       ↓&lt;br&gt;
Private Encrypted Channel&lt;br&gt;
       ↓&lt;br&gt;
Production Server&lt;/p&gt;

&lt;p&gt;We have no need to expose SSH while the server remains behind its firewall, and devices access the server via a private encrypted channel.&lt;/p&gt;

&lt;p&gt;It is at this point when solutions like Zero Trust Network Access start getting interesting.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.quickztna.com/" rel="noopener noreferrer"&gt;QuickZTNA&lt;/a&gt; works by connecting devices and infrastructure via WireGuard-based private mesh while applying Zero Trust security controls to access.&lt;/p&gt;

&lt;p&gt;And the whole point is not to provide yet another tunnel but to control what and who accesses what.&lt;br&gt;
**&lt;br&gt;
Being Connected Does Not Necessarily Mean Having Access to Everything**&lt;/p&gt;

&lt;p&gt;If five developers are connected to the company's internal infrastructure.&lt;/p&gt;

&lt;p&gt;It does not necessarily mean that all of them are automatically granted SSH access to every single server.&lt;/p&gt;

&lt;p&gt;First developer requires access to the staging environment.&lt;/p&gt;

&lt;p&gt;Second developer requires access to the production environment.&lt;/p&gt;

&lt;p&gt;Contractor requires a dev environment only.&lt;/p&gt;

&lt;p&gt;Zero Trust approach may provide more accurate permissions.&lt;/p&gt;

&lt;p&gt;For instance:&lt;/p&gt;

&lt;p&gt;Developer + Approved Device + SSH + Production = Allow&lt;/p&gt;

&lt;p&gt;Contractor + SSH + Production = Deny&lt;/p&gt;

&lt;p&gt;Access policies implemented by &lt;a href="https://www.quickztna.com/guide/admin/access-policies/" rel="noopener noreferrer"&gt;QuickZTNA Zero Trust&lt;/a&gt; follow the principle of least privileges: users are granted the access they really need instead of the access to the entire network.&lt;/p&gt;

&lt;p&gt;*&lt;em&gt;What About the Setup?&lt;br&gt;
*&lt;/em&gt;&lt;br&gt;
Security upgrades are quite useless if their implementation requires one person full-time job.&lt;br&gt;
For small teams of engineers, maintaining such things as VPN gateways, bastion hosts, firewall configurations, and networking could lead to unnecessary complexity.&lt;/p&gt;

&lt;p&gt;One way to simplify is by connecting authorized devices directly to the managed private network.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.quickztna.com/guide/quickstart/" rel="noopener noreferrer"&gt;QuickZTNA Quickstart &lt;/a&gt;demonstrates how the administrator can generate an authentication key, install the client and connect the device without manually exchanging WireGuard keys or configuring inbound firewall ports.&lt;/p&gt;

&lt;p&gt;It would be especially helpful for small DevOps teams that need to have access to their private infrastructure without maintaining any additional gateway infrastructure.&lt;br&gt;
**&lt;br&gt;
Conclusion**&lt;/p&gt;

&lt;p&gt;SSH isn’t the problem itself.&lt;/p&gt;

&lt;p&gt;The real question here is how to make SSH reachable.&lt;/p&gt;

&lt;p&gt;Ports, IP allowlists, and bastions could help to solve certain aspects of remote access problems.&lt;/p&gt;

&lt;p&gt;Zero Trust networking provides an alternative approach: keep your infrastructure private, identify who and what is asking for access, and provide access to required resources only.&lt;/p&gt;

&lt;p&gt;From the point of view of developers, this changes the question:&lt;/p&gt;

&lt;p&gt;“How do I expose this server safely?”&lt;/p&gt;

&lt;p&gt;to&lt;/p&gt;

&lt;p&gt;“Do I really need to expose this server?”&lt;/p&gt;

</description>
      <category>infrastructure</category>
      <category>networking</category>
      <category>security</category>
    </item>
  </channel>
</rss>
