Blog · 60 posts
Notes from
inside the audit.
Certification, audit practice, AI governance, and the working life of a security leader — written by the people doing the engagements.
Apr 5, 2021 · 3 min read
Ransomware...will it ever end?
Typically, Ransomware attacks are launched by a hacker using phishing attacks or via drive by browsing or downloading. Ransomware attacks have become so lucrative for hackers that the temptation to launch the attack is well worth the risk. From the attacker's point…
Read the post
Feb 1, 2021 · 1 min read
How hackers exploit ransomware attacks within school systems amid COVID-19
As COVID-19 explodes within the United States, hackers are using the pandemic to attack school systems on an alarmingly expansive scale. Because COVID continues to spread, many school districts across the nation plan to continue online classes into the spring. This pattern…
Read the post
Jan 18, 2021 · 3 min read
Security & Compliance – Best Friends Forever
On many occasions, I found myself face-to-face with senior managers, arguing for extra funds to acquire and implement needed security programs, only to realize that it was not my security acumen that won the show, but it was my compliance arguments that…
Read the post
Dec 23, 2020 · 2 min read
Do You Choose Security vs. Productivity Regarding the Cloud Environment?
Within the cloud environment, there is a double-edged sword that many organizations face today. As companies race toward digital transformations to increase their productivity, it is becoming more popular to adopt cloud technology. However, the endeavor of the digital transformation does have…
Read the post
Dec 3, 2020 · 2 min read
Beware of Creative Ways Hackers Exploit Phishing Attacks
With people spending an unprecedented amount of time at home given COVID-19, Netflix and other home-based entertainment usage is at an all-time high. Consequently, hackers are finding new ways to target their victims using phishing attacks and Office 365.
Read the post
Nov 3, 2020 · 2 min read
Guarding Your Business and Personal Information on Facebook
If you value your business, play it safe on Facebook. Here’s how to do it, pros and cons, dos and don’ts:
Read the post
Oct 6, 2020 · 4 min read
Compassionate, Involved Leadership is Essential While Weathering COVID-19
“Leaders who don’t listen will eventually be surrounded by people who have nothing to say” (Andy Stanley)
Read the post
Sep 3, 2020 · 3 min read
Vendor / Supplier Risk Assessment and the Vulnerabilities They Can Introduce to Your Network
The cybersecurity environment is constantly changing and ever evolving. As a result, cybersecurity threats become more complex in nature. Subsequently, organizations may not understand how rapidly the cybersecurity dynamic can essentially affect their organization.
Read the post
Jul 23, 2020 · 2 min read
To Certify or Not Certify...That is the Question!
Much emphasis has been put on IT Professionals and, in particular, Information Security Professionals, to obtain certifications or compliance opinions such as ISO, SOC, PCI, NIST etc. In fact, it is quite common in my day to day life as a CISO,…
Read the post
Jun 25, 2020 · 3 min read
How to Communicate Information Security Effectively with the Business – Learn to Speak Two Languages
Information security professionals use words like threat, malware, virus, and attack vector to describe the dangers to an information system. None of those words resonate with the business executive. Business executives understand and speak risk and profit. So, when an information security…
Read the post
Jun 24, 2020 · 3 min read
Internal Audits are Crucial; The Stricter the Better
COVID-19 has taught the business community that it is essential to know your company’s vulnerabilities; this way you can mitigate your risk. An invaluable asset in this endeavor is the Internal Audit. And the best Internal Audit is your toughest critic. Since…
Read the post
Jun 1, 2020 · 2 min read
COVID-19 Pandemic and Business Continuity Planning: Be Proactive, not Reactive
If COVID-19 has taught the business community anything, it is that Business Continuity Planning must anticipate ALL disruptions, including pandemics. Businesses plan for hurricanes, tornadoes, and other natural disasters, but not for human-related national or global catastrophes, such as the COVID-19 global…
Read the post