Security Awareness training has been a challenge for decades. Annual training programs have never been highly effective in training users on how to avoid or report security incidents, including phishing. More frequent training creates too much friction with productivity. We’ve seen lots of new training solutions come into the market, yet we have not seen […]
The news is flooded with updates regarding the COVID-19 vaccine. Cyberattacks are targeting the vaccine supply chain. Phishing attacks are exploiting sign-ups for the vaccine. There are even attacks to get access to vaccine data. Sounds a lot like our enterprises every day! We’re all learning about human immunology from the headlines, but what are […]
The growth of application development, DevOps, containers, and cloud has fueled the growth of application security tools. We now have static analysis, software composition analysis, interactive analysis, dynamic analysis, container scanning, infrastructure as code scanning, and a number of runtime application security products. That’s a lot of testing data, but how do we integrate it […]
The terms machine learning (ML) and artificial intelligence (AI) are way overused terms in our industry. Every vendor seems to have the latest and greatest ML/AI solution to solve your security problem. But when you really dig into the math, there are mathematical models that can actually help us. So why don’t we focus on […]
There are a lot of endpoint security solutions on the market. How do you pick and choose which solution is right for you? The answer may depend on which endpoints you want to protect. Windows? MacOS? Linux? All of the above? What about containers and cloud infrastructure? When we think of traditional endpoints, we immediately […]
When we talk about legacy security challenges and solutions, we can’t forget about our old friends email and phishing. Phishing has been around for over 20 years and is still one of the most effect attack paths to steal credential, exploit endpoints, and deploy malware. After 20 years, you’d think we could find effective solutions […]
Paul and I have talked a lot about his enchanted quadrants on the podcasts, but for those who haven’t watched, here’s a quick summary… An effective security program requires the integration of four key data sources: Logs (firewall, network, application, etc.) Endpoint (files, processes, logs, etc.) Network (flow and packets) Threat Intelligence Most organizations build […]
The endpoint market has been hot for years. At one point, there were over 80 new endpoint vendors trying to displace the traditional anti-virus vendors. The endpoint security market was transitioning from endpoint protection to endpoint detection and response (EDR). EDR is all the rage, but do you really need one? While the endpoint market […]
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.