GAO report confirms major gaps in government cybersecurity

The September GAO cybersecurity report stated that there are about 1,000 outstanding recommendations for automotive, military, and IoT security, among others. The original version of this post was published in Forbes. The U.S. government has gotten pre… Continue reading GAO report confirms major gaps in government cybersecurity

Click2Gov breaches show the power of zero-days

Patching issues fast is a step toward software security. But as the Click2Gov breaches show, zero-day vulnerabilities resist even the most persistent patchers. The original version of this post was published on Forbes. Just about every organization, in… Continue reading Click2Gov breaches show the power of zero-days

It’s past time to pay much more attention to API security

Organizations manage 363 APIs, on average. But vulnerable APIs can expose your data to anyone who knows how to ask for it. API security starts with the basics. The original version of this post was published in Forbes. It’s obvious that just abou… Continue reading It’s past time to pay much more attention to API security

SEC getting more aggressive on financial cyber lapses

SEC security measures, or cyber enforcement actions, are powerful incentives for financial institutions to protect investments and data from theft and fraud. If there oughta be a law but there isn’t, there can still be a regulation. Which so far … Continue reading SEC getting more aggressive on financial cyber lapses

President’s ‘cybersecurity moonshot’: Transformational or pie in the sky?

Making the internet safe and secure in 10 years isn’t going to be easy, if it’s even possible. And that’s why NSTAC’s new proposal is a cyber security moonshot. Stop me if you’ve heard this before: A presidential commissio… Continue reading President’s ‘cybersecurity moonshot’: Transformational or pie in the sky?