Pivot Point Security Inc. Sitemap
Pages
- 20 Key Questions Vendor Risk Management
- 4 Ways A Gap Assessment Template Can Help Reduce Your Business Risk
- 4 Ways a Risk Assessment Template Can Quickly Reduce Your Risk
- a Network Security Administrator – Best Practices
- A Simplified Checklist for FedRAMP
- About CBIZ Pivot Point Security
- Accelerated Risk Management (ARM)
- AI Risk Assessment
- Best Practices for Firing A Network Security Administrator
- Blog
- Business Continuity Management ISO 22301 – Implementation Roadmap
- California Consumer Privacy Act (CCPA) Compliance Roadmap
- CISO Podcast & News
- CMMC 2.0 Capabilities
- CMMC Assessment Checklist
- CMMC Certification Guide
- Custom Blog Inner
- Darknet & Dark Web Research & Monitoring Services
- Database Security Roadmap
- End User Agreement
- Expert AI Governance & Advisory Services
- Free Cybersecurity Resources
- Government Vendor Risk Management Information Security Guide
- Homepage
- Incident Response
- Inclusivity: Our Stance & Actions
- Information Security For Industries
- Information Security Services
- Accelerated Vendor Due Diligence
- Active Directory Review
- AI Red Teaming
- Application Security Code Review
- Application Source Code Scanning
- Blockchain Security Consulting
- California Consumer Privacy Act (CCPA) Compliance Services
- Center for Internet Security (CIS) Critical Security Controls (CSC) Consulting Services
- Cloud Controls Matrix
- CMMC
- Configuration / Change Management Review
- Cyber Liability Loss Control Government Risk Pools
- Cybersecurity Compliance Services
- Database Architecture Review
- Database Operational Assessment
- Database Security Code Review
- DFARS Compliance
- FedRAMP Information
- Firewall Assessment
- HIPAA – Health Insurance Portability and Accountability Act
- HITRUST Certification Made Simple
- How to Effectively Use a Vendor’s SOC 2 Report in Your VRM Program
- Industrial Control Systems
- IoT Security Consulting and Assessments
- ISO 27002
- ISO 27017 Consulting Services for CSP’s
- ISO 27018 Consulting Services for CSPs
- ISO 27701 Consulting Services
- Know Your Network is Secure & Prove it
- Network Architecture Review
- Network Architecture Review 2019
- New GLBA Security Requirements: What You Need to Know
- New York Department of Financial Services Cybersecurity Regulation
- NIST AI Risk Management Framework
- NIST Framework
- NIST Security Assessments
- NIST SP 800-218 (SSDF)
- Outsourced Information Security Internal Auditing
- PCI DSS | Payment Card Industry Data Security Standard
- Prove You Are Compliant to a Key Stakeholder
- Prove Your Government Standard Compliance
- Security Questionnaire Response Managcement (SQRM)
- Shared Assessments
- SOC 2 Consulting Services
- Standardized Control Assessment (SCA) Services
- Third-Party Risk Management Consulting
- Triumph Over Any Disaster & Prove Your Future is Secure
- Virtual CISO
- Web Application Architecture Review and Threat Assessment
- IoT Security
- IoT Security Assessments
- IoT Security Roadmap
- ISO 22301 Checklist
- ISO 27001
- ISO 27001 Checklist
- ISO 27001 Roadmap
- ISO 27001 The Recipe & Ingredients for Certification
- ISO 42001 Certification Consulting Services
- LCP
- Make An Impact
- Master Services Agreement
- MOBILE APPLICATION PENETRATION TESTING
- Network Security
- New headers and FAQs Test Page
- NIST CSF
- Optimizing Application Security Whitepaper
- OSCAR GRC Platform
- OUR BLOGS
- Penetration Testing
- API Penetration Testing
- Application Penetration Test
- Database Penetration Test
- Mobile Application Penetration Testing Whitepaper
- Network Penetration Testing
- OWASP ASVS Testing Guide
- Penetration Level Comparison Chart
- Penetration Testing Methodology
- Physical Penetration Test
- Ready for a Network Penetration Test?
- Social Engineering
- The Penetration Test Trail
- Wireless Penetration Test
- Policy Automator
- Press Releases
- Privacy Settings Page
- Protect Your Business & Invest in Your People
- Resources
- SaaS Information Security
- SaaS Information Security Advice
- SaaS Security – SOC 2 vs. ISO 27001 (Or Both)
- Search Results
- Secure Your APIs
- Security Awareness Education
- Security Event Managed & Log Monitoring Simplified
- Sitemap
- SSP for CMMC Compliance
- Standardized Control Assessment
- Tenable Managed Services
- Test Form
- Thank You – Download
- The DoD’s CMMC: Key Terms and Acronyms
- The Virtual CISO Podcast
- TISAX
- Vendor Due Diligence
- Virtual CISO
- Webinars
- Energy Information Security: Overcoming Key Challenges
- Enhancing Energy Security: Challenges and Solutions
- Financial Information Security Case Study
- Healthcare Information Security Case Study
- Innovative Approaches in Government Security Case Study
- Legal Information Security Case Study
- Proven Information Security Strategies
- Technology Information Security Case Study
- WEBINAR: Risk-Based App Secuity
Recent Posts
- CMMC Level 2 Compliance—What Should We Do Now as a DIB Org with CUI?
- CMMC Phase 2 Suspended: What Defense Contractors Need to Do
- How to Choose an AI Governance Framework (ISO 42001 vs. NIST)
- Virtual CISO Services: What’s Included?
- AI Governance Compliance: Regulations You Need to Know
- The CMMC Phase 2 Pause: What’s Most Important and What to Do Next
- The CMMC Assessment Pause Took Away Your Witness
- CMMC Pause—Will It Reduce DIB Cyber Compliance Costs?
- 9 Reasons Why Agentic AI Alarms CISOs
- 7 Reasons Why the Time for AI Governance and Compliance is Now
- What is Compliance Theater and How to Close the Curtain on It?
- When the Model Goes Dark: The Case for an AI Business Continuity Plan
- Why AI Guardrails Don’t Work
- Agentic AI Security: From Roadblock to Business Enabler
- The Rise of Agentic AI and Its Implications for Identity Security
- Is CMMC Compliance Harder than ISO 27001 or SOC 2?
- Evolving an ISO 42001 Program to Meet the EU AI Act
- Converging Physical and Cybersecurity: What are the Top Challenges and Solutions?
- How is AI Driving the Convergence of Physical Security and Cybersecurity?
- How are Attackers Using AI to Break Converged Security—and How are Defenders Fighting Back?
- AI Governance Shouldn’t Be an Adjunct to Your AI Strategy—It Should Be Integral to It
- What is Trusted Arrival and Why Should We (as an Org Protecting High-Value Assets) Care?
- The AI Governance Trap: When Your AI Guru Becomes Judge, Jury, and Executioner
- Guide to ISO 27001
- Shadow AI and the Equity Partner Problem
- Where is the Legal Vertical on the Path to AI Adoption?
- AI is Intensifying Third-Party Cyber Risk—Especially for SMBs
- Virtual CISO (vCISO) Services vs. Hiring a Full-Time CISO
- Law Firms: Leverage Your ISO 27001 Investment to Govern AI and Privacy
- 6 Ways Cybersecurity Leaders Can Prepare for an AI-Driven Future
- What is the EU Digital Omnibus and What Does It Mean for AI, Privacy, and Cybersecurity?
- ISO 27001 Cost Factors
- Is Your Business Ready to Responsibly Govern AI?
- The “AI Risk Reserve”: Every Organization Should Reinvest AI Savings into Risk Management
- Using AI in Cyber Defense—It’s About Prevention, Not Just Detection
- AI-Enhanced Cyber Threats: Same Vulnerabilities, Different Intensity!
- What is an AI Audit and Why Does My Business (Urgently) Need One?
- Does MCP Make Your AI More Secure or Less Secure?
- Natural Language Prompt Attacks Use Social Engineering against Conversational AI
- Prompt Firewalls, Content Filters, Classifiers—What and Why Are They in AI Security Stacks?
- The Jack Dorsey/Block Layoff’s Impact on AI Acceleration and AI Governance
- What is the Model Context Protocol (MCP) in AI and Why Does It Scare Cybersecurity Pros
- Got AI? Then Get an AI Incident Response Plan.
- AI Without Governance is Negligence
- Conditional CMMC Certification: What is It and How Can It Help My Business?
- CMMC Level 2 Certification—How and When to Choose a C3PAO
- What Verizon’s Outage Teaches Us about Resilience and Continuity Planning
- Before You Climb: Why Many CMMC Preparation Efforts Miss the Mark
- Latest FINRA Report Puts Brokers on Notice about AI Governance
- Threat Modeling is Step 1 to Secure Agentic AI
- AI Agents are the Weakest Link in Your Cybersecurity
- AI Security and AI Safety: How Do They Relate?
- What is NYC’s AI Bias Law and How Does It Impact Firms Using HR Automation?
- AI Tokens and How They Impact Usage Costs—Explained
- What are the NIS2 and DORA EU Cyber Laws and Why Should My US-Based Business Care?
- Can “War Games” Help with Cybersecurity Talent Issues
- Why Traditional Business Continuity Planning is No Longer Relevant for Today’s Cloud-First SMBs
- Falling Behind on CMMC Compliance? Here’s How to Catch Up Fast.
- SMBs with No vCISO: Can You Answer These 5 Business-Critical Cybersecurity Questions?
- What are Cloud War Games and How Can They Help Reduce Downtime Risk on AWS
- What is Resilience Testing and Should We Be Doing It?
- How Does the EU’s NIS2 Cybersecurity Directive Impact US-Based IT Suppliers?
- How Can DORA Impact IT Suppliers in Financial Services?
- Threat-led Penetration Testing: What is It and Who Needs It?
- DORA and NIS2 Cyber Regulations—How Do They Compare?
- 2 Little-Known AI Roles and Why They’re Important
- AI Partner, AI Provider and/or AI Producer – Which are We and Why Does It Matter?
- Is AI Tanking? Or Poised to Advance Even Faster?
- What is an AI Impact Assessment and Does My Business Need One
- What is the ISO 42001 AI Management System Standard and Who Should Consider Implementing It?
- CMMC Levels: What You Need to Know
- CMMC 2.0 Rollout Update: The Wait is Over
- CMMC Levels—Here’s What You Need to Know
- What is Advanced File-Level Encryption and How Does It Support CMMC Compliance?
- Advanced File-Level Encryption: Top 7 Use Cases
- Silent Ransom Group Phishing Attacks
- The Changing Virtual CISO Role—Is It Right for Your Business?
- Vulnerability Exploitation is Now Hackers’ Number One Attack Vector
- CMMC in Q2 2025: Your Top Questions Answered
- How Third-Party Experts Can Help with OSCAL Adoption
- Can OSCAL Help with FedRAMP and CMMC Compliance?
- Got FedRAMP – OSCAL
- OSCAL Cliff Notes for Business and Technical Leaders
- When Do We “Really” Need to Be CMMC 2.0 Certified?
- How High a Hurdle is CMMC Compliance for Today’s DoD Suppliers?
- Is CMMC Level 2 Worth it for DIB SMBs?
- CMMC 2.0 Access Control Domain: Here are the Basics
- AI-Related Roles That ISO 42001 Auditors Will Look For
- What is the DFARS 7012 Clause and Why Should DIB Orgs Care?
- What is the DFARS 7019 Clause and Why Should DIB Orgs Care?
- What is the DFARS 7021 Clause and Why Should DIB Orgs Care?
- 5 AI Stakeholder Roles for ISO 42001: Where Does Your Business Fit?
- 6 Reasons Why Every SMB Now Needs a vCISO
- Passkeys: 7 Possible Downsides for SMBs
- SMBs—Is It Time to Start Moving from Passwords to Passkeys?
- Why are Passkeys So Much Better than Passwords?
- Cloud Detection and Response: How Much Auto-Remediation is Safe?
- Is the Cybersecurity Tool Space Evolving Toward a Platform Approach?
- What is Cloud Detection and Response and How Can It Help My Business?
- Four Drivers Making Virtual CISO Engagements More Popular than Ever in 2025
- Hiring a vCISO? Make Sure They Know Your Industry
- What are “The 3 Phases of vCISO” and Which Phase is My SMB In?
- Do We Need a Virtual CISO? Or a Virtual Security Team?
- 9 Reasons vCISO Engagements Fail
- Dark Web Monitoring for SMBs—7 Features to Look For
- 10 Top Dark Web Monitoring Use Cases for Your Business
- What is the Dark Web and Why Does My Business Need to Go There?
- 3 Essential Tips for Maintaining CMMC Compliance
- CMMC 2.0 Gap Assessment: Should We Hire an External Resource?
- CMMC Final Rule: 5 Key Concerns Around the Annual Affirmation of Compliance
- CMMC Final Rule: Does My MSP or CSP Need to be CMMC Compliant?
- CMMC Final Rule: What is the Final Word on Flowdown?
- CMMC Final Rule: When Do We Need to be Ready?
- Cybersecurity Contingency Planning 101
- TX-RAMP Versus StateRAMP—Which is Right for My Business?
- The Rising Threat from Targeted “Data Ransom” Attacks—and How to Protect Your Business
- Four Major Reasons Why Up To 60% FedRAMP Efforts Fails – And How To Prevent Them.
- What is AZRAMP and Does My Business Need to Comply?
- What are the New CMMC 2.0 Flowdown Requirements to Manage Defense Supply Chain Cyber Risk?
- What is Swarm AI and How Can It Advance Cybersecurity?
- How CMMC Enhances Defense Supply Chain Security
- Is Decentralized Cybersecurity Mesh the Future of Cybersecurity?
- What is a Post-Quantum Strategy and Does Our Business Need One?
- What is Kubernetes Security Posture Management (KSPM) and Why Should We (as Cloud-Native Developers) Care?
- Registered Practitioners Versus Certified CMMC Professionals: What’s the Difference for DIB Orgs Seeking CMMC Compliance?
- What is a Cloud Native Application Protection Platform (CNAPP) and What Can It Do for My Business?
- What is Cloud Infrastructure Entitlement Management (CIEM) and Why Is It Becoming So Important?
- What is the CMMC Assessment Process (CAP) Handbook and Why Should DIB Orgs Care?
- ISO 27001 vs NIST 800-53: All You Need to Know
- ISO 27001 vs NIST Cybersecurity Framework: What’s the Difference?
- The Primary Importance of CUI Scoping for CMMC Certification
- Know the Difference between ISO 27001 vs 27002 vs 27003
- What is Content Disarm and Reconstruction and Why Should I (as a Recipient of Digital Documents) Care?
- The Role of Leadership in ISO 27001 Compliance
- Why File-Based Malware Dominates Cyberattacks
- Data Detection and Response for Privacy and Compliance
- DIB SMBs Rate Their Cybersecurity as Much Better than It Actually Is – Why?
- Top 5 Insights from Radicl’s DIB Cybersecurity Maturity Report 2024
- How Should Crisis Management Connect with Incident Response?
- CMMC Certification vs. CMMC Compliance: Which One Do You Need?
- CMMC Certification: How Long Does It Take to Get Certified?
- What Privacy Roles Does My Business Need?
- What is a Secure Web Gateway and How Does It Support Zero Trust?
- 18 US States Have Now Passed Privacy Laws – Time to Start Building Trust
- Risk Tolerance: To Avoid, Transfer, Mitigate or Accept
- 10 Most Important Steps to Build a Data Privacy Program
- What are SaaS Providers Doing with Your Data?
- The Problem with Zero Trust Network Access is Trusting the Service Provider
- Considering ISO 42001? Here are 5 Recommended Guidance Sources
- Top Ransomware Defenses You Probably Don’t Have in Place
- What is Ransomware and How Has It Morphed in the Last Decade?
- What is ISO 42001 and Why Should We (as an Org that Develops and/or Uses AI) Care?
- The Crucial Role of Cybersecurity in IPO Preparation
- ISO 42001: What are the Key Elements of an AI Management System?
- ISO 42001, ISO 27001 and ISO 27701: Is This the New “Big 3” for Provably Secure and Compliant AI?
- Local Storage Versus Cookies: Which to Use to Securely Store Session Tokens
- Does My DIB Org Need a SIEM for CMMC Compliance
- How Much Does ISO 27001 Certification Cost in 2024?
- What is Distributed Ledger Technology (DLT) and How Can It Simplify Privacy Compliance?
- CMMC Rulemaking Changes Again—What’s the Timeline Now?
- Virtual CISOs and Community Banks—Perfect Together
- What is Hedera Hashgraph and How Does It Solve Blockchain Privacy Issues?
- CMMC and ISO 27001 Audit Requirements Compared
- Data Privacy Compliance in Higher Ed: Now is the Time
- What is a TISAX Simplified Group Assessment and Who Can Use It?
- CMMC Proposed Rule Changes: What’s Changing and How to Prepare
- What is Kubescape and Why Should We (as Cloud-Native Developers) Care?
- Container and Kubernetes Security: A Nontechnical Introduction
- What is a Container and Why are They So Popular with Developers?
- What is the New Jersey Data Privacy Law, and How Can We Streamline Compliance?
- The EU AI Act: 9 Top Questions Answered
- SOC 2 Reports – Which Trust Services Criteria Do You Need?
- 6 Key Takeaways from the 2023 SOC Benchmark Study
- CMMC Proposed Rule: New Guidance on CMMC Level 3
- The New CMMC Proposed Rule—Answers to Your Top 9 Questions
- ISO 27001 Accreditation: Why It Matters for Cloud Service Providers
- CMMC Benefits
- 2 Principles to Revolutionize Security Awareness Training
- What is Cyversity and How Can It Improve Diversity on My Cybersecurity Team?
- Empowering Diversity in the Cybersecurity Industry
- What is the Digital Operational Resilience Act (DORA) and How Will It Impact My Business?
- ISO 27001 and Data Protection: The Crucial Link
- What are the 5 Key DevOps Research & Assessment (DORA) Metrics and Why Should I Care?
- Cyber Essentials Plus: What is It and How Can It Help My Business?
- Understanding the ISO 27001:2022 Update
- Getting Certified to ISO 27001:2022? Your Transition Plan is Critical for the External Audit.
- Here’s How to Make Sure Your Security Awareness Training is Working
- CMMC Gets Posted to the Federal Registry
- ISO 27001 Security Policies: What They Are and Why They’re Important
- Top 10 Benefits of ISO 27001 Compliance for Startups
- NIST AI Risk Management Framework: What You Should Know and Why You Should Care
- Human-Level AI: What Can It Do, What Are the Risks, and When Will It Be Here?
- “Failure is Not an Option”—What Does That Mean for Recovery Planning?
- The EU’s NIS2 Directive: Here’s What You Need to Know
- Understanding and Applying Risk Management Strategies for CMMC Certification
- 5 Common Mistakes When Pursuing ISO 27001 Certification
- How to Demonstrate Compliance with CMMC: An Overview
- The Difference between ISO 27001 and Other Certifications
- 3 Questions to Consider before Pursuing ISO 27001 Certification
- What is CMMC?
- The Importance of Maintaining an Up-to-Date ISO 27001 Certification
- How to Get CMMC Certified: 7 Steps to Take Before Applying
- What is CMMC Certification and What Does it Mean for Your Business?
- CMMC Rulemaking Update and Timeline
- What is ISO 27001 Certification and Why Does It Matter?
- Leaking Meta’s LLaMA AI – the Good, the Bad, and the Very Bad
- Public and/or Shared AI Models Cannot be Trusted Until an AI Bill of Materials Become the Norm
- Time and Cost Factors to Attain a FedRAMP ATO
- FedRAMP ATO: 3 Tips to Minimize Cost, Complexity, and Time to Target
- Big Pros and Cons of an “Agency” Versus “JAB” Approach to a FedRAMP ATO
- Getting Ready for Your FedRAMP Third-Party Assessment
- FedRAMP Requirements Can Change Your Solution Architecture
- To FedRAMP or Not to FedRAMP: That is the (First) Question
- Intro to FedRAMP
- A FedRAMP ATO – The Good, The Bad, and the Ugly
- What is a Microservice Architecture and How Do I Secure It?
- Security and Development Must Work Closely to Secure Microservices
- How Do Microservices Change Software Security?
- Microservices and APIs—How Do They Connect?
- What is a Microservice Architecture?
- How Poor Cyber Asset Management Enabled the Equifax Breach
- 4 Ways a Strong Cyber Asset Management Program Can Help Block Ransomware Attacks
- Active Asset Scanning in OT Environments
- Why Vulnerability Management Tools Fall Short for Cyber Asset Discovery
- 2 Biggest Challenges with Cyber Asset Management – Pivot
- How ISO 27001:2022 Attributes Might Impact Your Certification Audit (and Improve Your Security)
- ISO 27001:2022—What is the Level of Transition Effort?
- ISO 27001:2022—When Should My Org Make the Transition?
- ISO 27001:2022—Insights into What’s New
- RSA Conference 2023 Takeaway—“Shifting Security Left” is Now in Full Swing
- RSA Conference 2023 Takeaway—Privacy Will Drive Data Governance
- RSA Conference 2023 Takeaway—AI is Coming But It’s Not Here Yet
- RSA Conference 2023 Takeaway—More Than Ever, a Product-Centric Security Strategy is Dangerous
- How Long Before Software Bill of Materials (SBOM) Moves from Buzzword to Expectation
- A Software Bill of Materials (SBOM) Benefits Both Vendors and Users
- What is an SBOM and Why Are My Customers Suddenly Asking for One?
- When You’re Doing Cyber Asset Management… What’s An Asset?
- If your asset management sucks, your security sucks
- Beware the Latest Funds Transfer Fraud —Deepfake Voice Cloning
- Should We Implement DevSecOps? You May Not Have a Choice.
- DevSecOps: Recommended Guidance and Standards to Help Get You Started
- Shifting DevSecOps Left
- DevSecOps Depends on Understanding Application-Specific Risk
- Getting Started with DevSecOps
- DevSecOps Defined
- 4 Tactical Steps to Implementing DevSecOps in 2023
- 7 Reasons Why You Should Get CMMC Certified Ahead of the May 2023 Rulemaking
- Pros and Cons to a “Hybrid Approach” to Microsoft 365 Commercial and GCC/GCC High
- Why is Microsoft 365 GCC High “So Expensive”?
- The “Feature Factor” in Moving to Microsoft 365 GCC or GCC High
- How Long Does a Microsoft 365 “Government Cloud” Migration Take?
- 3 Top Considerations for Migrating to a Microsoft 365 “Government Cloud”
- Should My Org Be on a Microsoft 365 “Government Cloud”?
- Should we be in Microsoft 365 GCC, GCC High, or Commercial?
- 2 “Gotchas” to Avoid on Move to ISO 27001:2022 – Pivot
- Will Implementing the New ISO 27001:2022 Control Set Improve Your ISMS?
- 3 Things Your ISO 27001:2022 Auditor Would Love to See in Your ISMS
- Benefits of Moving to ISO 27001:2022 ASAP
- ISO 27001:2022—How Does It Impact Related Standards?
- We’re Working Towards Certification to ISO 27001:2013—How Does ISO 27001:2022 Impact Us?
- When Will Auditors Be Ready to Certify ISO 27001:2022 Compliance?
- When Should You Move to ISO 27001:2022?
- Need to Align Your Web App Security Program with NIST’s SSDF or ISO 27001? OWASP SAMM Can Help.
- Don’t Dump Application Security on Your Developers
- Web Application Security—How Mature Are Most Orgs Today?
- How (Not) Good is Your Web App Security? OWASP SAMM Can Tell You.
- Getting to “Secure by Design” with OWASP SAMM
- What is OWASP SAMM and How Can It Elevate Your Application Security?
- The TISAX Audit Process: Here’s What to Expect
- TISAX and ISO 27001: How Do They Relate?
- TISAX Assessment Objectives, Levels, and Labels
- What is TISAX and Why Should We (as an Auto Industry Supplier) Care?
- Understanding TISAX (Trusted Information Security Assessment Exchange)
- Emerging Use Cases for Cyber Threat Intelligence
- How Does Cyber Threat Intelligence Relate to Attack Surface Management or Digital Risk Management?
- Still Think Your Org Has Nothing Hackers Want?
- Cybercrime Business Models and Supply Chains
- How Financially Motivated Cybercriminals Really Operate, and Why You (as an Org with Exploitable Assets) Should Care
- Understanding How Cybercriminals Operate Can Protect Your Business
- What’s New and Exciting with AWS Security?
- Public Cloud Consumers: Is Your Management Plane Secure?
- What are the Most Important AWS Security Tools that Every Org Should Use?
- Why Do So Many Orgs Stumble on Cloud Security?
- Different Public Cloud Services Equal Different Shared Security Responsibilities with Your CSP
- 2 Top Security Problems AWS Users Cause – Pivot Point
- AWS Cybersecurity Best Practices—From Amazon’s Security Solutions Architect
- Cyber Insurance Considerations for DIB Orgs
- Export Controlled Data: What is It and Why Should We (as a US Government Contractor) Care?
- DIB Orgs: Here’s How to Avoid False Claims Act Sanction
- Should You Voluntarily Disclose a CUI Incident or Data Breach?
- CUI Basic and CUI Specified—What’s the Difference
- Understanding the Legalities around Controlled Unclassified Information (CUI)
- Security Staffing Moves for a Down Economy
- Want to Work Smarter Not Harder in a Down Economy? Embrace Security Automation.
- In a Down Economy, Ensure You’re Getting the Max from Security Investments
- Why You Should Keep Making Needed Security Investments in a Down Economy
- Why Aligning Cybersecurity with Trusted Frameworks is More Important than Ever in a Down Economy
- A Cybersecurity Strategy is More Critical Than Ever in a Slow Economy
- John Verry’s Top 10 Ideas to Advance Security and Compliance Even in a Tight Economy
- Leveraging OOTB “Policy as Code” for Cloud Security Posture Management
- Addressing False Positives and Alert Fatigue across Enterprise Security Tools
- Your Cloud Security Posture Needs Both Preventive and Detective/Corrective Components
- Governance as Code—Is It the Answer to Cloud-Native Security?
- Security, Compliance and Governance in the Cloud—How Do They Relate?
- Dynamic Relationships between Governance, Security, and Compliance
- Is Your Board Prepared for the SEC’s New Cybersecurity Regulations?
- Is Attack Surface Management Right for SMBs?
- Factoring Third-Party Risk into Attack Surface Management
- Is It Still a Data Breach if the Data was Outside Your Infrastructure?
- How Much of Your Attack Surface is Beyond Your Visibility?
- How Do Assets Relate to Attack Surface Management?
- What is Digital Business Risk Management and Why is It So Valuable to Security Leaders?
- Is Digital Business Risk Management the Future of Attack Surface Management?
- Monitoring Security of Your Deployed Public Cloud Application
- Validating Security Within Your DevOps Pipeline
- Skills to Look for in Developers to Move Your Applications to the Cloud
- Should We Containerize Our Cloud-Based Application?
- Should You Outsource Managing Your App Along with Building It?
- Are There Any Simple Templates to Help Manage a Secure Web App in the Public Cloud?
- The Complexities of Deploying a Secure Application in the Cloud
- What are a New Privacy Lead’s Biggest Challenges? (From a Fortune 500 CPO)
- Tips from a Fortune 500 CPO on Automating Your Privacy Program
- Time’s (Almost) Up for California Privacy Compliance
- Tackling the Legal Side of Privacy without Becoming a Lawyer
- How Does Physical Security Tie into Privacy?
- The New Intersection of Privacy and Security (from a Fortune 500 CPO)
- The Intersection of Privacy & Security
- What Will It Take to Survive a Third-Party CMMC Level 2 Assessment?
- DIB Orgs: Here’s What’s Up with CMMC “Flowdown” and New Pressures from Primes
- We Don’t Think We Need CMMC Level 2 but the Government Says We Do…
- Should We Pursue a Voluntary CMMC Assessment?
- House Approves Updated FedRAMP Authorization Act
- Is There a Path for Non-US Companies to be CMMC Certified?
- ISO 27001 Certified Orgs—Here’s the Latest on CMMC Reciprocity
- Can SMBs Afford CMMC Level 2 Certification?
- DIB Orgs: Here are Answers to Your Top CMMC Encryption and MFA Questions
- Your Top CMMC Questions Answered
- How Automation Can Help Operationalize a Privacy Program
- SME InfoSec Leads: Here’s How to Kickstart a Privacy Program
- How Automation Can Help with Data Privacy Impact Assessment
- SMEs: Do You Know Where All Your Customers’ Personal Data Resides?
- SMEs: Are Your Customers Pushing You Towards a Privacy Program?
- The Two Audiences For Privacy & How They Drive Data Collection
- Is Cybersecurity Certification Worth the Effort?
- Can Disaster Recovery and Business Continuity Help with Software Supply Chain Risk Assessment?
- Can Cybersecurity Frameworks Help with Software Supply Chain Risk Management?
- Supply Chain Risk Management and Third-Party Risk Management: What’s the Difference?
- What is Software Supply Chain Risk Management and Why Should We (as an Org That Uses Software) Care?
- The FTC’s Intensified Prosecution of Deceptive Cybersecurity and Privacy Practices: Here’s What You Should Know
- Unpacking Critical Elements of Supply Chain Risk Management
- PATCH Act Legislation Could Expand Medical Device Manufacturing Cybersecurity Regulations
- NIST Update on HIPAA Security Rule Can Help Your Org Reduce ePHI Risk Exposure
- OMB Mandates US Federal Agencies to Comply with NIST Guidance on Software Supply Chain Security
- DIB Orgs: Time is Almost Up for DFARS and NIST 800-171 Compliance
- OWASP SAMM’s 5 Business Functions Unpacked
- BSIMM and OWASP SAMM Compared
- Using OWASP’s Software Assurance Maturity Model (SAMM) and Application Security Verification Standard (ASVS) Together
- What is the OWASP Software Assurance Maturity Model (SAMM) and Why Should We (as an Org That Develops Software) Care?
- Applying the OWASP Software Assurance Maturity Model (SAMM) in Your Environment
- Breaking Down the Latest in Software Security Standards & the Impact on SaaS Businesses
- Top Use Cases for Continuous API Security
- What is Continuous API Scanning and Why Should We (as App Developers) Care?
- What are the Financial Benefits of API-Level Security?
- How Does an API-First Architecture Affect Your App Attack Surface?
- Application Security and API Security are Becoming Synonymous—Are You Ready?
- What You Need to Know about APIs and API Security
- Aligning Security with Business Goals to Create More Value
- The “Value Creation” Side of Return on Security Investment (ROSI) Estimates
- A Risk-Based Approach to Calculating Return on Security Investment (ROSI)
- Return on Security Investment (ROSI): What is It and How Do You Calculate It?
- How to Measure the Value of Information Security
- How Does the NIST Secure Software Development Framework (SSDF) Compare with OWASP SAMM, BSIMM, etc.?
- What’s the Effort to Align Your Dev with the NIST Secure Software Development Framework (SSDF)?
- Here’s Why Software Vendors Should Align with the SSDF Whether Mandated or Not
- Why Does the USG Think We Need the NIST Secure Software Development Framework (SSDF)?
- Making the Most of the CMMC Assessment Guidance from the CyberAB
- What is the Software Development Lifecycle and Why is It Central to Software Security?
- What is the NIST Secure Software Software Development Framework and Why Should We (as a Software Vendor) Care?
- What NIST’s Secure Software Development Framework Means to You
- US Government Threat Intelligence Programs: Where Are They Headed?
- What is the Cyberspace Solarium Commission 2.0 Project and Why Should I (as a US Citizen) Care?
- Recent White Papers from the Cyber Solarium Commission—What is Their Purpose?
- The Cyberspace Solarium Commission Report and CMMC—How Do They Connect?
- We Need Public/Private Partnership to Fight the Cyber War We’re In
- What is Continuity of the Economy Planning and Why Should I (as a US Citizen) Care?
- What is the Cyberspace Solarium Commission Report and Why Should I Care?
- US Gov. Cybersecurity Roadmap: Where it came from and Where is it Going?
- How Does DevOps Impact Your Database Security?
- Your Database Attack Surface is Bigger than You Think
- How Moving to the Cloud Impacts Your Database Security
- 3 Reasons Why Database Security is Undervalued
- 5 Top Database Risks You Didn’t Know You Had
- Confronting the Wild West of Database Security
- The Argument for More Board-Level Cybersecurity Expertise
- Why Philanthropy is Important in Cybersecurity
- What is “Secure By Default” and How Do We Get There?
- The Strategy Behind the Gula Tech Adventures Portfolio
- Looking Beyond Trusted Frameworks to Achieve Robust Cybersecurity
- How Do You Know If Your Business is Really Secure?
- Bridging the Gap Between Cybersecurity and the Business World
- What is a Breach Counselor and Why Do We (as an Org with Cyber Liability Insurance) Care?
- Do You Know Your Cyber Liability Insurance Obligations?
- Does Your Cyber Liability Insurance Fit with Your Total Insurance Coverage?
- 3 Top Reasons Why an Attorney Should Review Your Cyber Liability Insurance Policy
- Are Cyber Liability Insurance Companies (Entirely) to Blame for Today’s Onerous Premiums
- Why Cyber Liability Insurance Has Become the “Wild West”
- Legal and Infosec Strategies to Deal with Exploding Cyber Liability Insurance Premiums
- CMMC 2.0: Is Certification Worth the Cost and Risk?
- CMMC 2.0: Choose Your Registered Provider Organization Carefully
- CMMC 2.0: DoD Emphasizes “Nothing Has Changed” (So Why Aren’t You Ready?)
- CFIUS Cybersecurity Considerations: Here’s What You Need to Know
- Benefits of Categorizing NIST 800-171 Requirements as Technical Versus Nontechnical
- What Really Drives Innovation in Cybersecurity?
- Are We More or Less Secure than 20 Years Ago?
- Investors are Targeting These Emerging Cybersecurity Areas
- 3 Different Types of Private Equity Firms Explained
- 5 Top Criteria for Venture Capitalists Evaluating Tech Companies
- The Past, Present and Future of Cybersecurity From the Viewpoint of a Venture Capitalist
- What is OWASP SAMM and Why Should We (as an Org that Develops Software) Care?
- How Attack Surface Management Calculates Attack Paths
- How Does Attack Surface Management Connect with Patch Management?
- Top Scenarios for Implementing Attack Surface Management
- NopSec’s Vision for Attack Surface Management
- Attack Surface Management: Should It Cover Configuration Management?
- What is Attack Surface Management and Why Should We (as an Org with Vulnerabilities) Care?
- Understanding Attack Surface Management
- Protecting CUI Nonfederal Organizations
- Here’s What State-of-the-Art Entryway Security Looks Like
- Does My Business Need Better Entryway Security?
- Why Physical Security and Cybersecurity are Converging
- The Convergence of Physical & Cybersecurity
- CMMC 2.0 Level 3 Certification: What’s Up with That for MSPs/MSSPs?
- MSPs/MSSPs: Here’s the Latest CMMC/NIST 800-171 Compliance Timeline
- Why MSPs/MSSPs Should Develop a Shared Responsibility Matrix
- When is an MSP/MSSP a CSP for CUI Protection Purposes?
- MSPs/MSSPs: Are You Subject to “Flowdown” CUI Protection Requirements?
- CMMC Compliance for MSPs/MSSPs: Taking a “Cross-Client” Approach
- CMMC Compliance for MSPs/MSSPs: 3 Shared Responsibility Angles
- What New CMMC Guidance Means for MSPs and MSSPs
- Got Hardcopy CUI? NIST SP 800-171 Requirements Apply.
- Step #8 to Retaining Security Talent: Win-Win Communication
- Step #7 to Retaining Security Talent: Make Career Promotion Criteria Outlined & Transparent
- Step #6 to Retaining Security Talent: Roles & Responsibilities are Clearly Defined & Measured
- Step #5 to Retaining Security Talent: Consistent Management Training
- Step #4 to Retaining Security Talent: Kindness-Only Culture
- Step #3 to Retaining Security Talent: Self-Care Culture
- Step #2 to Retaining Security Talent: Positive Attitude Culture
- Step #1 to Retaining Security Talent: Emotionally Intelligent Managers
- 8 Ingredients for Baking Inclusivity into Your Culture
- How Panther Helps Get You Real-Time Access to Arbitrary Security Data
- Comparing the Cost of “SIEM”: How Much and Time-to-Value
- Get Proactive with Real-Time Streaming Security Analytics
- Big Data, Snowflake and the Reinvention of SIEM
- “The State of SIEM” and Why the Security Industry Needs to Move On
- What is “Serverless SIEM” and Why Should We (as an Org Trying to Detect Cyber Threats) Care?
- Becoming More Efficient w/ a Cloud-Native Approach to Data Security
- SEC Proposes New Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
- The NIST Cybersecurity Framework Helps Business and Technical Leaders Communicate About Security
- Understanding the Cloud Controls Matrix
- Using the CSA STAR Program for Procurement
- How the Cloud Security Alliance Addresses Privacy
- What is the CSA Cloud Controls Matrix and Why Should Everyone on the Cloud Care?
- What is the Cloud Security Alliance and Why Should I (as Someone Selling or Buying Cloud Services) Care?
- Essential Cloud Security & Compliance Tips from CSA
- CMMC 2.0 Rulemaking: What are the Implications for Government Contractors Outside the DIB?
- CMMC 2.0: What’s Ahead for the DIB?
- Dib Orgs: Here’s How to Apply the CMMC Scoping Guide to OT Assets
- Why is Management Buy-In a Challenge for CMMC Compliance?
- Dib Orgs: Why is Asset Management a Challenge?
- Dib Orgs: What to Do If You Don’t Think You Have CUI
- 3 Reasons Why It’s So Hard to Identify CUI
- CMMC 2.0 Scoping
- 3 Top Challenges with CMMC 2.0
- Ongoing Challenges with CMMC
- Fleet Device Management: Future Plans
- How Malware Spreads
- Using Fleet’s Policy Feature for Configuration Management
- Open Source Device Management—Can It Improve Your Vulnerability Management?
- Open Source Device Management—Is It Right for Your Use Cases?
- Open Source Device Management—It’s All About Transparency and Flexibility
- Is Open Source the Future of Endpoint Security
- IoT Device Security: What to Look for from Vendors
- IoT Security Guidance: What is Its Real-World Value?
- Remotely Hacking IoT Devices: Here’s How It’s Done
- “AWS for Security” — A One-Stop Shop in the Making?
- A Hardware Hacker’s Top Tips for Building Secure IoT Devices
- “AWS for Security” — Can It Also Support Compliance?
- The New NIST Secure Software Development Framework: Why It’s So Important for the USG Supply Chain
- “AWS for Security”—Can It Reduce Your Security Software Costs?
- OK, So… What’s an IoT Device?
- Are You Ready for “AWS for Security”?
- The “AWS Approach” to Provable Security
- The New ISO 27002:2022—What Does It Mean for Your ISO 27001 ISMS?
- The Value of Attributes in the New ISO 27002:2022
- The OMB’s Final Zero Trust Strategy: 8 Key Takeaways
- The New ISO 27002:2022—What’s New with the Controls?
- The New ISO 27002:2022—What are “Themes” and Why are They Cool?
- The New ISO 27002:2022 — How Was It Developed?
- What Does the New ISO 27002 Update Mean for You?
- DIB Orgs: Can You Identify CUI?