-

Take Stock of Your Progress
Read more: Take Stock of Your ProgressAnother year is nearly closing out so now is the time to start taking stock of your progress and plan for things to come. Whatever small hops or large leaps you made in your organization’s security this past year, write it down, quantify it where possible, and give yourself a pat on the back. Maybe…
-

SaaS Security – is your data safe?
Read more: SaaS Security – is your data safe?As organizations aim to become more efficient or just take advantage of the new products in the marketplace, Software-as-a-Service (SaaS) vendors are becoming more and more a part of the organizational ecosystem. We would love to tell you that every SaaS vendor puts best practice security controls in place and that they have all done…
-

HIPAA Compliance – Where do I start?
Read more: HIPAA Compliance – Where do I start?Through working with many healthcare and health related companies here at CTInfoSec, we often hear the questions, “I need to be HIPAA compliant; how do I make sure I am? Where do I start?” Understanding the Health Insurance Portability and Accountability Act of 1996 (HIPAA) rule and its components is critical if your organization is…
-

Threat Paradigm Shift
Read more: Threat Paradigm ShiftAs companies continue their inevitable march to the cloud, so do their vendors. With this migration, new opportunities present themselves. Sometimes this is with previously unavailable technology now within reach, or more simply, it is a chance to start fresh. While there are many new hosted services to consider in the cloud, perhaps one of…
-

Your Security Score
Read more: Your Security ScoreOpen-source intelligence, or OSINT, is a powerful tool for gauging the security posture of an organization. Performing OSINT searches typically involves searching public repositories for information that may be useful to an attacker. At CTInfoSec, OSINT searches are part of every External Network Penetration Test that we perform and can also be requested on an…
-

The Expectations vs. The Implementation
Read more: The Expectations vs. The ImplementationOur team provides technical assessments to ensure the build of solution is completed as expected and security controls are implemented properly. In a way, we are a digital building inspector focused on security. We often find that expectations may not be in alignment with the implementations. This can happen for several reasons such as a…
-

Ready, Set, Goal
Read more: Ready, Set, GoalIt is often assumed that the goal of security is simple – “be secure.” The truth is, there are many goals in security beyond just being secure. Security goals for a small financial institution may look very different than those of a hospital, where unencumbered access to patient data can mean life or death. But…
-

What does a successful TTX look like?
Read more: What does a successful TTX look like?In April, we opened the discussion of Tabletop Exercises (TTX). If you haven’t read that post, go here to read it . As mentioned last month, there are several key components to executing a tabletop exercise. In addition to basic planning and day-of logistics, there are several other considerations to take into account to maximize the…
-

TTX, A Critical Component to Your Cybersecurity Strategy
Read more: TTX, A Critical Component to Your Cybersecurity StrategyTabletop Exercises (TTX) have officially earned their position as a critical tool in the CISO’s toolbox. The use of TTX’s for internal security readiness has grown steadily over the past several years. TTX’s were once considered a nice-to-do activity; now they are required by many regulatory bodies. And while the requirement is often an annual…
-

Al Chat: Friend or Foe?
Read more: Al Chat: Friend or Foe?Recently there has been a lot of chatter around ChatGPT and the Bing Chat platform. These AI engines are being used in a number of creative ways like composing jokes or writing essays in the ‘tone’ of specific individuals. Aside from these recreational uses, the platforms have considerations for cybersecurity as well. A simple example…
-

DDOS Attack: 5 Ways to Prepare
Read more: DDOS Attack: 5 Ways to PrepareWith a recent wave of attacks performed by Killnet, organizations should be on high alert and be prepared for potential DDoS attacks. A distributed denial of service attack or DDoS typically consists of many remote sources or proxies attacking an organization to render the organization’s services unusable. Because the number of sources can be significant,…
-

Closing out the Year
Read more: Closing out the YearHere in the Northeast, the seasons are changing. The leaves have fallen, and the mornings are crisp, which means it’s that time of year when CISOs must focus on the cycles of the business: budgeting, regulatory audits, risk mitigation, year-end reviews. Taking stock of the good, the bad and the ugly of the past 12…
