Insights for Secure, Compliant, and Scalable Growth
Practical guidance on cybersecurity, compliance, AI governance, and GRC—built to help your team manage risk with confidence.
Almost a year into a post-GDPR world, the question for many cloud service providers is still, “How do I evidence GDPR compliance?” With no meaningful …
Bottom Line Up Front (BLUF): By design, it is up to individual audit firms (CPA firms) to decide, based upon their understanding of the SOC 2 requirem…
Many modern forms of malware are now file-less and rely on Command & Control (C2) infrastructure to assist outsiders with gaining unauthorized acc…
One of the biggest threats facing enterprises are outsiders plugging directly into an Ethernet port and being granted instant, unauthenticated access …
Developing a cyber security baseline can be daunting. Oftentimes the burden falls on the Chief Information Officer or Chief Technology Officer. These …
Business boils down to one thing: People People are the most challenging (and rewarding) part of a successful business. And I mean the full lifecycle …
When most people think of hacking, they think of what Hollywood portrays. In a dark basement, a hooded, perhaps tattooed outcast rapidly types nonsens…
There is understandably quite a bit of confusion in the market place when it comes to offensive security engagements. Consultants use a number of term…
The EU-US Privacy Shield may soon be a thing of the past after the European Parliament passed a resolution on July 5th , calling on the European Commi…
The Data Protection Impact Assessment (DPIA) is a significant new burden on data controllers under GDPR. As many have noted, GDPR does not clearly out…
I recently finished the book "Traction" by Gino Wickman. Next to Scaling-Up by Verne Harnish, I think it is one of the most actionable business books …
Mention "Risk Committee" or "Enterprise Risk" to upper management and you will probably get an eye role. If you suggest a standing meeting about risk …
Tags
- Cyber Risk Management (59)
- IT Audit And Compliance (33)
- Penetration Testing (31)
- Cybersecurity (26)
- CISO Discussions (24)
- SOC Reporting (23)
- Security (22)
- News And Events (20)
- Christian Hyatt (19)
- ISO 27001 Compliance (19)
- Risk Management (19)
- ISO 27001 (18)
- SOC 2 (18)
- Compliance (17)
- Business (16)
- HITRUST (16)
- PCI DSS (13)
- Regulatory Compliance (12)
- Information Security (11)
- IT Audit (9)
- Webinars (9)
- CISO (8)
- Privacy (8)
- Penetration Test (7)
- Privacy Compliance (7)
- VCISO (7)
- Business Continuity (6)
- Cyber Risk (6)
- GRC Tool (6)
- ISO 42001 (6)
- Leadership (6)
- Compliance As A Service (5)
- Disaster Recovery (5)
- News (5)
- Risk Assessment (5)
- Training (5)
- BCAW (4)
- Cybersecurity Controls (4)
- GDPR (4)
- Network Security (4)
- Access Control (3)
- Artificial Intelligence (3)
- Attack Surface Management (3)
- Awareness Week (3)
- EU AI Act (3)
- Hacking (3)
- ISO (3)
- Passwords (3)
- Press Release (3)
- AWS (2)
- Attack Surface (2)
- Business Continuity Planning (2)
- Cyber Security Law (2)
- ISO 27701 (2)
- Internal Audit (2)
- NIST 800 Series (2)
- Report (2)
- SDLC (2)
- Vendor Management (2)
- Vulnerability Management (2)
- Amazon (1)
- Assessment (1)
- Attestation (1)
- Audit (1)
- BCMS (1)
- Backup And Recovery (1)
- Blackbasta (1)
- CI (1)
- CMMC (1)
- COVID (1)
- Caas (1)
- Certification (1)
- Cloud (1)
- Competitive (1)
- Engineers (1)
- Ethical Hacking (1)
- Exercises (1)
- Grit (1)
- Hashcat (1)
- ISO 22301 (1)
- ISO 27018 (1)
- ISO 42005 (1)
- IaaS (1)
- Kahoot (1)
- Management (1)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- PIA (1)
- Pentest Report (1)
- Phishing (1)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Security Advisory (1)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Vulnerability Scan (1)
- Wannacry (1)