This document explores the growing regulatory pressures on financial services organizations, particularly with the introduction of frameworks like DORA, PCI DSS 4.0, and NYDFS 23 NYCRR Part 500. It highlights the unique challenges of securing mainframe environments, which are often overlooked in compliance strategies. The paper provides actionable...
CISO Jadee Hanson shares how Vanta “drinks its own champagne,” running on NIST CSF with quarterly baseline reviews and using Vanta’s GRC platform to turn every release into live UAT for privacy, governance, and compliance. We rethink third-party management—why point-in-time risk scores are fading and how AI drives continuous monitoring and outcome-...
The platform enables organizations to deploy and manage sensitive workloads within a single jurisdiction, keeping data, identity management, and encryption keys under their authority to meet tightening global sovereignty regulations.
What's the biggest attack vector for breaches besides all of the human related ones (i.e. social engineering, phishing, compromised credentials, etc.)? You might think vulnerabilities, but it's actually misconfiguration. The top breach attack vectors are stolen or compromised credentials, phishing, and misconfigurations, which often work together. ...
Modern IGA programs handle employee onboarding and offboarding, as well as application access management, smoothly and automatically. But how can you handle applications that don't connect to IGA systems?
The Afterlife, AWS, ClickFix, Agentic AI Galore, Robot Lumberjacks, Robocalls, Aaran Leyland, and more on the Security Weekly News. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.