Skip to main content

Insights for Secure, Compliant, and Scalable Growth

Practical guidance on cybersecurity, compliance, AI governance, and GRC—built to help your team manage risk with confidence.

Cloud Companies Can Conquer GDPR with ISO 27018 Certification

Almost a year into a post-GDPR world, the question for many cloud service providers is still, “How do I evidence GDPR compliance?” With no meaningful …

Read more

Are Pen Test and Vulnerability Scans Required for a SOC 2 Report?

Bottom Line Up Front (BLUF): By design, it is up to individual audit firms (CPA firms) to decide, based upon their understanding of the SOC 2 requirem…

Read more

Beyond Vulnerability Scans: Mitigating and Monitoring for Malware Leveraging C2 Systems

Many modern forms of malware are now file-less and rely on Command & Control (C2) infrastructure to assist outsiders with gaining unauthorized acc…

Read more

Securing Enterprise Networks with Port-Based Network Access Control

One of the biggest threats facing enterprises are outsiders plugging directly into an Ethernet port and being granted instant, unauthenticated access …

Read more

Simplified Guidance on Developing a Cyber Security Baseline for the CIO and CTO

Developing a cyber security baseline can be daunting. Oftentimes the burden falls on the Chief Information Officer or Chief Technology Officer. These …

Read more

How We Measure Candidates at risk3sixty

Business boils down to one thing: People People are the most challenging (and rewarding) part of a successful business. And I mean the full lifecycle …

Read more

Analyzing Your Attack Surface Like A Hacker

When most people think of hacking, they think of what Hollywood portrays. In a dark basement, a hooded, perhaps tattooed outcast rapidly types nonsens…

Read more

Understanding Different Types of Penetration Testing Engagements

There is understandably quite a bit of confusion in the market place when it comes to offensive security engagements. Consultants use a number of term…

Read more

European Parliament Votes Against Privacy Shield

The EU-US Privacy Shield may soon be a thing of the past after the European Parliament passed a resolution on July 5th , calling on the European Commi…

Read more
ris-blog-fallback-featured-image

New Guidance Clarifies GDPR's Data Protection Impact Assessment (DPIA) Requirements

The Data Protection Impact Assessment (DPIA) is a significant new burden on data controllers under GDPR. As many have noted, GDPR does not clearly out…

Read more

Build a Security Program and Run It Like a Business

I recently finished the book "Traction" by Gino Wickman. Next to Scaling-Up by Verne Harnish, I think it is one of the most actionable business books …

Read more

How to Turn the Risk Committee Meeting into the Most Valuable Meeting on Your Calendar

Mention "Risk Committee" or "Enterprise Risk" to upper management and you will probably get an eye role. If you suggest a standing meeting about risk …

Read more

Tags

See all