Group 440 3

Blog

  • Take Stock of Your Progress

    Take Stock of Your Progress

    Another year is nearly closing out so now is the time to start taking stock of your progress and plan for things to come. Whatever small hops or large leaps you made in your organization’s security this past year, write it down, quantify it where possible, and give yourself a pat on the back. Maybe…

    Read more: Take Stock of Your Progress
  • SaaS Security – is your data safe?

    SaaS Security – is your data safe?

    As organizations aim to become more efficient or just take advantage of the new products in the marketplace, Software-as-a-Service (SaaS) vendors are becoming more and more a part of the organizational ecosystem. We would love to tell you that every SaaS vendor puts best practice security controls in place and that they have all done…

    Read more: SaaS Security – is your data safe?
  • HIPAA Compliance – Where do I start?

    HIPAA Compliance – Where do I start?

    Through working with many healthcare and health related companies here at CTInfoSec, we often hear the questions, “I need to be HIPAA compliant; how do I make sure I am? Where do I start?” Understanding the Health Insurance Portability and Accountability Act of 1996 (HIPAA) rule and its components is critical if your organization is…

    Read more: HIPAA Compliance – Where do I start?
  • Threat Paradigm Shift

    Threat Paradigm Shift

    As companies continue their inevitable march to the cloud, so do their vendors. With this migration, new opportunities present themselves. Sometimes this is with previously unavailable technology now within reach, or more simply, it is a chance to start fresh. While there are many new hosted services to consider in the cloud, perhaps one of…

    Read more: Threat Paradigm Shift
  • Your Security Score

    Your Security Score

    Open-source intelligence, or OSINT, is a powerful tool for gauging the security posture of an organization. Performing OSINT searches typically involves searching public repositories for information that may be useful to an attacker. At CTInfoSec, OSINT searches are part of every External Network Penetration Test that we perform and can also be requested on an…

    Read more: Your Security Score
  • The Expectations vs. The Implementation

    The Expectations vs. The Implementation

    Our team provides technical assessments to ensure the build of solution is completed as expected and security controls are implemented properly. In a way, we are a digital building inspector focused on security. We often find that expectations may not be in alignment with the implementations. This can happen for several reasons such as a…

    Read more: The Expectations vs. The Implementation
  • Ready, Set, Goal

    Ready, Set, Goal

    It is often assumed that the goal of security is simple – “be secure.” The truth is, there are many goals in security beyond just being secure. Security goals for a small financial institution may look very different than those of a hospital, where unencumbered access to patient data can mean life or death. But…

    Read more: Ready, Set, Goal
  • What does a successful TTX look like?

    What does a successful TTX look like?

    In April, we opened the discussion of Tabletop Exercises (TTX). If you haven’t read that post, go here to read it .  As mentioned last month, there are several key components to executing a tabletop exercise. In addition to basic planning and day-of logistics, there are several other considerations to take into account to maximize the…

    Read more: What does a successful TTX look like?
  • TTX, A Critical Component to Your Cybersecurity Strategy

    TTX, A Critical Component to Your Cybersecurity Strategy

    Tabletop Exercises (TTX) have officially earned their position as a critical tool in the CISO’s toolbox. The use of TTX’s for internal security readiness has grown steadily over the past several years. TTX’s were once considered a nice-to-do activity; now they are required by many regulatory bodies. And while the requirement is often an annual…

    Read more: TTX, A Critical Component to Your Cybersecurity Strategy
  • Al Chat: Friend or Foe?

    Al Chat: Friend or Foe?

    Recently there has been a lot of chatter around ChatGPT and the Bing Chat platform. These AI engines are being used in a number of creative ways like composing jokes or writing essays in the ‘tone’ of specific individuals. Aside from these recreational uses, the platforms have considerations for cybersecurity as well. A simple example…

    Read more: Al Chat: Friend or Foe?
  • DDOS Attack: 5 Ways to Prepare

    DDOS Attack: 5 Ways to Prepare

    With a recent wave of attacks performed by Killnet, organizations should be on high alert and be prepared for potential DDoS attacks. A distributed denial of service attack or DDoS typically consists of many remote sources or proxies attacking an organization to render the organization’s services unusable. Because the number of sources can be significant,…

    Read more: DDOS Attack: 5 Ways to Prepare
  • Closing out the Year

    Closing out the Year

    Here in the Northeast, the seasons are changing. The leaves have fallen, and the mornings are crisp, which means it’s that time of year when CISOs must focus on the cycles of the business: budgeting, regulatory audits, risk mitigation, year-end reviews. Taking stock of the good, the bad and the ugly of the past 12…

    Read more: Closing out the Year