Boards Are Interested in Cybersecurity Too

Dateline: September 29, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. With all the media attention focused on recent cyber events, it's no wonder our Boards are getting involved.  Certainly a catastrophic event such as Equifax experienced recently shows Board leaders that a large vulnerability might exist in their company.  Making sure these … [Read more...]

Reducing Cybersecurity Threats From Ex-Employees

Dateline: August 4, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Most cybersecurity breaches are aided by insiders...either intentionally or unintentionally.  But a recent study showed that ex-employees may also be a threat, but this one is more easily managed with the right processes in place.  According to Bob Violino, a free-lance writer … [Read more...]

The Business Mindset of Cyber-Criminals

Dateline: July 21, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Cyber-criminals are organized, smart and well-funded.  If we think of cyber attacks as the 'service' of a 'well-organized business' then we can come up with strategies to 'compete' against it.  By compete, we mean become more cyber-resilient, not go into the cyber-crime business, … [Read more...]

Threat Hunting Needs Technology and People

Dateline: July 14, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Continuing on our theme of the organizational side of cybersecurity leadership, this week we look at threat hunting.  A blog titled Threat Hunting and the Pyramid of Pain (written by flOx2208, a "common human being wanting to share my knowledge and experience") suggests that … [Read more...]

Cybersecurity Basics

Dateline: July 7, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Next week I'm leading a session on building a cybersecurity culture at of the annual meeting of the Cybersecurity Consortium at MIT's Sloan School (Full disclosure: I am the Executive Director of the Consortium, you can learn more about (IC)3 activities and membership here).   In … [Read more...]

Changing Corporate Perception of Cybersecurity

Dateline: June 30, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. This past week a new ransomware cyber threat made its way through hundreds of computers.  While not surprising that another attack was launched, what was surprising is that NotPetya exploited the same vulnerability as WannaCry just a few weeks earlier.  It was successful because … [Read more...]

Strategic Cybersecurity Plans

Dateline: June 16, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Building a culture of cybersecurity is one tool available to senior leaders who want to make their organizations more secure.  In a recent article, cybersecurity expert Adam Meyer, Chief Security Strategist at SurfWatch Labs, makes a case for strategic cyber threat intelligence … [Read more...]

The Need for a Culture of Cybersecurity

Dateline: June 9, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. In the wake of the WannaCry ransomware attack, there have been many expert opinions on what, why and how this happened.  A recent article by security expert Jennifer Blatnik, published at SecurityWeek.com, titled The Impact of WannaCry on the Ransomware Conversation, … [Read more...]

IoT: Internet of Threats?

Dateline: June 2, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. For several years now, as the Internet of Things (IoT) connects many of our seemingly harmless devices to the web in order to add features and functionality, cybersecurity professionals have  pointed out how much more vulnerable to attacks we have become.  No one makes this point … [Read more...]

The Widening Cybersecurity Workforce Gap

Dateline: May 26, 2017 Welcome to our Friday WRAP – one thought-provoking idea to think about over the weekend. Cybersecurity concerns always increase when there is a widely publicized event such as the WannaCry ransomware attack a week or so ago.  But according to a recent article, published by SecurityIntellignece.com,  the cybersecurity workforce needed to help us protect our … [Read more...]