Blog · 60 posts
Notes from
inside the audit.
Certification, audit practice, AI governance, and the working life of a security leader — written by the people doing the engagements.
Jul 3, 2024 · 3 min read
Phishing fatigue in cybersecurity: a rapidly growing problem
It’s undebatable that phishing fatigue is rapidly growing across all businesses no matter the size, and it’s beginning to cause mass paranoia with employees. Based on recent studies, organizations receive roughly 17,000 malware alerts weekly, but only 19 are deemed reliable. This…
Read the post
May 29, 2024 · 2 min read
Aging security infrastructure – what to do with it
If you’ve been in cybersecurity for any real amount of time, you’re more than likely aware that consolidating security tools is growing more popular. Most organizations view IT as just a call center, and security is considered only a small part. Typically,…
Read the post
May 5, 2024 · 4 min read
Audit and compliance awareness – the C3PAO in CMMC Certification
The Cybersecurity Maturity Model Certification (CMMC) program is aligned with the Department of Defense (DoD) Information Security requirements and is designed to enforce the protection of sensitive unclassified information shared by the department with its contractors and any subcontractors. This program provides…
Read the post
Apr 9, 2024 · 2 min read
Artificial Intelligence (AI) – addressing the impact of cyber misinformation / disinformation
The rise of AI continues to be a major game-changer in many positive ways. However, AI also creates significant dark and untapped areas for misinformation. These range from fabricating fake cyber-attacks, to disrupting incident response plans, to manipulating massive quantities of data…
Read the post
Feb 26, 2024 · 2 min read
The impact of Artificial Intelligence (AI) on social engineering and cyber attacks
Social engineering attacks continue to be a major business threat worldwide. Roughly 98% of cyber-attacks relating to this are successful, according to Splunk. The average business faces more than 700 different types of attacks annually.
Read the post
Jan 30, 2024 · 3 min read
Artificial Intelligence (AI) – a look ahead to what 2024 holds
During 2023, the AI landscape absolutely exploded. AI is currently poised for significant use that promises to accelerate its integration into society and the cyber security world in 2024.
Read the post
Jan 30, 2024 · 3 min read
TISAX Compliance: the guide to certification
The automotive industry is in the middle of a massive shift. Because of this, a standard approach to Information Security is required to meet the ever-expanding changes of securing vast networks of international suppliers while safeguarding large, extensive data streams. Given these…
Read the post
Jan 22, 2024 · 1 min read
The Department of Defense’s CMMC 2.0
The Department of Defense’s CMMC 2.0 program rule was published on December 26th, 2023 in the [Federal Register](https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program). This kicked off a 60-day comment period on the Title 32 Rule. The Title 48 Rule should be published in March 2024, and we…
Read the post
Dec 13, 2023 · 2 min read
The Cost of Cybersecurity in 2024 and How To Budget for It
Cybersecurity incidents can absolutely paralyze a business and destroy customer trust. Recovering from these attacks is very expensive. To help prevent these devastating consequences from occurring, it’s imperative that all businesses put cybersecurity safeguards into place.
Read the post
Nov 15, 2023 · 2 min read
Essential guide to cybersecurity compliance
Many organizations have heard of cybersecurity compliance but have no idea what it really entails.
Read the post
Oct 10, 2023 · 3 min read
Five steps to ensure HIPAA compliance with the increasing use of mobile devices
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law requiring the creation of national standards to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge.
Read the post
Sep 11, 2023 · 3 min read
A changing threat landscape
Defense in Depth is needed to address the security risk with the ever-evolving threat landscape as cyber threats are growing rapidly in scale and sophistication. Defense in Depth is a comprehensive approach employing a combination of advanced security tools to protect the…
Read the post