Sectigo Blog

Phishing Is Getting Harder to Spot: How Organizations Can Help Customers Know What to Trust

By Sectigo Team
September 23, 20265 min read

Phishing remains a growing threat. The Anti-Phishing Working Group (APWG) identified 3.8 million unique attacks in 2025, showing just how widespread these schemes have become. Cybersecurity Awareness Month emphasizes the importance of recognizing and reporting phishing, while organizations also have an important role to play in making legitimate communications easier to authenticate and recognize.

Phishing has become more convincing, making traditional warning signs harder to rely on. Training and awareness still matter, but technical safeguards and trust signals can give recipients additional ways to distinguish legitimate brand communications from impersonation attempts.

Email remains a top form of outreach and a great way to connect brands and consumers. By combining authentication with visible brand signals, organizations can help protect recipients, make legitimate messages easier to recognize, and build brand trust.

200-day certificates are starting to expire. Is your organization ready?

The 200-day certificate era stopped being theoretical. On March 15, 2026, the CA/Browser Forum's Ballot SC-081v3 cut public SSL/TLS certificate validity from 398 days to 200 days. That was the warning. Now comes the test: certificates issued on and around that date are reaching the end of their validity window, and the first real wave of 200-day renewals is landing on IT and security teams right now.

For organizations that treated March 15 as a distant compliance deadline rather than an operational one, this is the moment the gap becomes visible.

Sectigo Team

Sectigo Quantum Ready™: Moving from quantum awareness to quantum action

For years, conversations about post-quantum cryptography (PQC) have focused on a future threat. Security teams have been warned about "harvest now, decrypt later" attacks, emerging standards, and the eventual need to replace quantum-vulnerable cryptography. But for many organizations, one fundamental question remains unanswered:

Ian Hassard

Flexible tenancy, same leadership: the next evolution of the Sectigo Partner Platform

When Sectigo launched the industry-first Sectigo Partner Platform (SPP) earlier this year, we set out to solve a problem that many managed service providers (MSPs), resellers, and distributors were struggling with: how to securely and efficiently manage certificate lifecycle operations across an entire customer portfolio. Our answer: the industry’s first multi-tenant partner operations platform purpose-built to enable MSPs, MSSPs, VARs and distributors to scale and monetize certificate management operations.  

Sectigo Team

Sectigo's F5 partnership expands to F5 Distributed Cloud Services: What this means for you

When Sectigo and F5 announced their partnership earlier this year, the goal was straightforward: bring automated certificate lifecycle management directly into F5 environments, so teams could stop chasing renewals manually and start trusting their infrastructure to stay current. That partnership began with support for the F5 Application Delivery and Security Platform (ADSP), giving organizations a way to automatically issue, deploy, and renew certificates across on-premises, hybrid, cloud, and edge deployments.

Now that partnership is expanding. With the launch of Sectigo Orchestration Gateway (SOG), Sectigo Certificate Manager (SCM) customers can extend the same automation to F5 Distributed Cloud, F5's SaaS-native solution for securing and delivering applications and APIs across multi-cloud and edge environments.

Henry Lam

How to sign a PDF: Electronic and Digital Signature methods explained

A PDF file is a go-to digital resource for official documentation: contracts, business agreements, legal documents, and even HR forms. Short for Portable Document Format, this file format was developed by Adobe and is now standardized under ISO (International

Organization for Standardization). It’s favored for its versatility and ease of use. 
PDFs often need to be signed to verify identities or indicate approval, whether they’re used by businesses, teams, or independent professionals. These situations call for electronic signatures, which can be added to files through specialized tools or PDF editors.

Not all signature methods provide the same level of tamper evidence, and solutions vary in terms of both security and ease of use. Common strategies range from basic electronic signatures to certificate-based digital signatures.

For documents that require strong protection, certificate-based digital signatures offer the most secure option. They use a document signing certificate to help verify the signer’s identity and show whether the PDF has changed after it was signed.

Keep reading to learn how trust is added to PDFs through digital signatures and how cryptographic protection helps safeguard sensitive documents. 

Sectigo Team

Scaling certificate lifecycle management (CLM) with Sectigo Orchestration Gateway (SOG)

As certificate volumes grow and lifecycles shrink, traditional automation methods fail to scale. Sectigo Orchestration Gateway (SOG) replaces fragmented scripts and connectors with a unified orchestration layer, enabling end-to-end automation, centralized control, and secure, policy-driven certificate lifecycle management across hybrid and multi-cloud environments.

Sectigo Team

The website didn't go down. Your customers just stopped trusting It.

Many small and midsize businesses think outages only happen when a server crashes or a website stops loading. In reality, your site can be online and still feel unavailable to customers. This is what happens when an SSL/TLS certificate expires. Visitors likely see a browser warning telling them the site cannot be trusted:

"Your connection is not private."

"This site is not secure."

"Your information may be at risk."

This means the customer experience failed before it even began. A browser warning turns your digital storefront from a place to buy, book, or engage… into a reason to leave. For SMBs, that means an expired certificate is not just a technical outage. It is a trust, brand, and revenue hit.

The business impact can add up quickly. For SMBs, downtime can cost anywhere from $140 to $1.7K per minute through lost revenue, lost productivity, and recovery time.

SSL (Secure Sockets Layer), more accurately known today as TLS (Transport Layer Security), is the technology that encrypts data exchanged between a website and its visitors while also verifying the website's identity. As small organizations grow, SSL/TLS certificates often accumulate faster than teams realize. Most of the time, they do their job quietly in the background—until one expires, breaks trust, and turns a routine visit into a warning sign.

Maggie White

Behind-the-Scenes Technologies That Keep the World Wide Web Secure

World Wide Web Day on August 1 is a reminder that the secure, reliable Web depends on technologies most people never see. Every HTTPS connection, authenticated software download, and protected digital identity relies on infrastructure working behind the scenes.

Online convenience and security do not happen by chance. They depend on interconnected technologies that verify identities, protect sensitive information, and help people use websites, applications, and devices with confidence.

Without this trust infrastructure, users and organizations would face greater risks of interception, impersonation, software tampering, untrusted connections, and certificate-related outages.

PKI and digital certificates help protect activities such as browsing, online shopping, authenticated software downloads, and secure email. As the Web becomes more complex, World Wide Web Day offers a timely opportunity to recognize these unseen technologies and the role they will continue to play in keeping digital interactions trusted and secure.

Sectigo Team

How Automation Protects Trust and Uptime Across the Modern Web

Observed on August 1, World Wide Web Day recognizes how deeply the web has transformed the way people communicate, work, shop, and access information. This day encourages us to reflect on just how far we've come since those early years of the World Wide Web and consider the technologies operating behind the scenes to keep those digital interactions trusted and available.

Many of these technologies are invisible to everyday users. Digital certificates authenticate websites, applications, devices, and other digital identities while helping encrypt sensitive communications. Certificate automation supports this trust infrastructure by discovering certificates, streamlining issuance, monitoring their status, and renewing them before they expire.

As digital environments grow and certificate lifespans shrink, this behind-the-scenes automation is becoming increasingly important for preventing outages and keeping the modern web trusted, available, and secure.

Sectigo Team

What are the differences between RSA, DSA, and ECC encryption algorithms?

Public key cryptography relies on mathematical algorithms to generate pairs of keys: a public key for encrypting messages and a private key for decrypting them, ensuring only the intended recipient can read the message. RSA, DSA, and ECC are the most common algorithms used today, each offering unique benefits in terms of performance, speed, and security.

RSA, the oldest, is widely used and known for its robustness, while ECC provides greater cryptographic strength with shorter key lengths, making it ideal for devices with limited computing power. DSA, endorsed by the U.S. Federal Government, is efficient for both signing and verification processes. The strength of these cryptographic methods underpins digital certificates used in secure web browsing (TLS/SSL) and various digital identity applications.

With rapid advancements in quantum computing, researchers are now developing new post-quantum encryption methods to address future threats that will eventually make current cryptographic algorithms obsolete.

Sectigo Team