Dek: PAM, DNS Filtering and Endpoint Protection are three critical components that make up a strong, secure cybersecurity vendor stack.Â
In the world of cybersecurity, there are numerous core domains, key principles, and defensive layers. As a result, it can be challenging to keep up with all the different components.Â
One way to think about a typical vendor stack is to compare it to a decadent stuffed sandwich, filled with different fillings and toppings. There are the critical ingredients, the meat of the sandwich, and then the extra additions like the condiments, tomatoes and extra bits that make it robust. Each distinct tier protects a different part of the network infrastructure.Â
With this defense analogy in mind, here is a look at three of the critical components within a cybersecurity vendor stack: Privileged Access Management (PAM), DNS Filtering and Endpoint Protection.Â
Privileged Access Management (PAM)
Many cybersecurity vendors will have Privileged Access Management (PAM) solutions for MSPs and tech departments. PAM will monitor and log actions that administrators take while using their elevated privileges within a security system. Â
Because of this, PAM is a way to protect IT managers, system network administrators and employees with access to a company’s sensitive data. It can also protect cloud-based applications and service tools that leverage API or SSH keys.Â
Within the vendor stack, PAM sits inside the broader IAM category, also known as the Identity and Access Management category. This just means it’s a framework of policies and processes to control user access to certain applications and data. PAM will enforce the principle of least privilege, or only giving the minimum access to those who need it. This eliminates the possibility of someone without a need for certain data having full access to it. In addition to PAM, multi-factor authentication, single sign-on and directory services sit within the IAM category.Â
Going back to the sandwich analogy, PAM would be a speciality sauce or spread — perhaps a flavored tahini or avocado dip. PAM is highly selective and should be applied to the domain controllers or the meat of the sandwich, rather than being wasted on the extra fillings.Â
DNS FilteringÂ
While PAM grants access, DNS Filtering blocks attacks. DNS (domain name system) Filtering is a foundational protective layer in a cybersecurity vendor stack. It’s the first line of defense from hackers gaining access, blocking phishing attempts, malware downloads and more. It also helps with load reduction by blocking bad traffic at the DNS layer — reducing the overall volume of threats that firewalls and endpoint protection handle. Â
When a user clicks a link, the request goes to the source. This source is a cloud-based filtering resolver as opposed to a standard internet provider. With DNS filtering, the system will check the domain against any blocklists, allowlists and real-time threat intelligence. If the user is deemed safe, the site will load as normal. If not, the connection is stopped, and the user receives a redirect or warning page. This helps ensure employees aren’t accidentally browsing or entering sites that could potentially pose a threat to the company’s internal data and cybersecurity system as a whole.Â
Because DNS Filtering is the first line of defense, it could be seen as the paper wrapping or foil protecting the sandwich. It’s a thin, outermost layer or shield that stops unwanted contaminants from touching the sandwich. Just like a wrapper stops dirt from touching a sandwich, DNS filtering stops threats from touching the network. Â
Endpoint Protection Â
DNS Filtering is a defensive mechanism against digital attacks, and endpoint protection is a defensive mechanism for individual user devices. Laptops, smartphones and servers can be compromised by hackers without the right endpoint protection software. It works proactively by monitoring behaviors in real time and providing a continuous feedback loop between the device and a cloud-based threat dataset. Â
With endpoint protection software, businesses can help prevent company-owned devices from being breached by insecure digital threats. The cybersecurity vendor will have a single dashboard to view all connected laptops and phones, ensuring both prompt and remote responses. In today’s hybrid and work-from-home culture, endpoint protection can protect remote employees who work on their own or public Wi-Fi networks.Â
Endpoint protection can serve as the tomato slices within a sandwich. Each slice is a separate endpoint, and each needs its own layer of protection to stay firm and juicy rather than slimy — because nobody wants to bite into a soggy sandwich! In cybersecurity, an unprotected endpoint is a weak and compromised asset that can ruin the entire system, or sandwich in this metaphor.Â
Putting it All Together
There are hundreds of ways to make a delicious sandwich, and there are also plenty of ways to create a comprehensive cybersecurity vendor stack. PAM, DNS Filtering and Endpoint Protection are just three of the most critical ingredients to consider for a comprehensive security strategy. No single ingredient can do it all, so each of these components comes together to create a multi-layered offering that is strong at its core.Â
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

