How organizations overcome cybersecurity hiring challenges

A strong security-focused culture and adherence to best practices helps companies attract and retain cybersecurity talent. (ISC)² commissioned the study to better understand how successful organizations are overcoming the shortage of skilled cybersecur… Continue reading How organizations overcome cybersecurity hiring challenges

Confidence wavers in face of evolving cybersecurity threats

Webroot found that businesses in the U.S., U.K. and Australia are taking cybersecurity seriously – with almost 100 percent of respondents conducting some form of employee cybersecurity training. However, despite these efforts, 79 percent say they aren’… Continue reading Confidence wavers in face of evolving cybersecurity threats

Cybersecurity: A core component of digital transformation

In this podcast, Kai Grunwitz, Senior VP EMEA at NTT Security, talks about the NTT Security 2018 Risk:Value Report, and the importance of cybersecurity for a successful digital transformation. Here’s a transcript of the podcast for your convenience. He… Continue reading Cybersecurity: A core component of digital transformation

The eternal struggle: Security versus users

There’s an old joke that a job in security is a safe place to be grumpy. From what I’ve seen over my career, that is often true. Security people seem to cherish their reputation for being pessimistic and untrusting. Some take it further and cast their … Continue reading The eternal struggle: Security versus users

Why developing an internal cybersecurity culture is essential for organizations

ENISA published a report providing organisations with practical tools and guidance to develop and maintain an internal cybersecurity culture. Understanding the dynamics of cybersecurity culture The Cybersecurity Culture in Organisations report is based… Continue reading Why developing an internal cybersecurity culture is essential for organizations

Know your adversary: Focus on social engineering

In this podcast recorded at Black Hat USA 2017, Tim Roberts, Senior Security Consultant at NTT Security, talks about social engineering and emphasizes the importance of security awareness and security culture. Here’s a transcript of the podcast for your convenience. Hi, my name is Tim Roberts. I work for NTT Security Threats Services Group. We provide service offerings for offensive security testing. This includes network application, wireless mobile penetration testing, as well as on-site social … More Continue reading Know your adversary: Focus on social engineering

Review: Advanced Persistent Security

About the authors Ira Winkler, CISSP is President of the Internet Security Advisors Group. He is considered one of the world’s most influential security professionals. Araceli Treu Gomes is an Intelligence and Investigations Subject Matter Expert for CrowdStrike. She serves on several cybersecurity industry boards. Inside Advanced Persistent Security As businesses are finally beginning to realize that their cyber defenses can and will occasionally fail and, therefore, must continually evolve, this book couldn’t be more … More Continue reading Review: Advanced Persistent Security

Is remote access technology leaving you vulnerable?

Insider and third-party access are growing security threats facing organizations and enterprise IT systems, according to Bomgar. Proliferation of security issues Despite rising awareness of the threats posed by users with privileged access permissions, most organizations still allow a myriad of internal and external parties to access their most valuable systems and data. Many are placing trust in both employees and third parties without a proven means of managing, controlling, and monitoring the access that … More Continue reading Is remote access technology leaving you vulnerable?

Security awareness is good, but good security culture is better

As an efficient mechanism to influence employee behavior, security culture is one of the most important, yet most overlooked, aspects of organizational security. “A common flaw in our industry is that awareness trainings will change, i.e. improve, security behavior,” says Kai Roer, co-founder of European security startup CTLRe (and Help Net Security columnist). “This idea comes from the rational economic theory, with which a hundred years ago economists tried to explain how people are influenced … More Continue reading Security awareness is good, but good security culture is better

88% of employees lack awareness to stop privacy or security incidents

The results of a new survey testing employee data privacy and cybersecurity knowledge reveal that 88 percent lack the awareness to stop preventable cyber incidents. MediaPro surveyed 1,000 employees across the U.S. to quantify the current state of privacy and security awareness, and revealed employee knowledge trends across eight risk domains, ranging from working remotely to identifying phishing attempts, and assigned three risk profiles indicating employees’ privacy and security awareness IQ. These risk profiles are … More Continue reading 88% of employees lack awareness to stop privacy or security incidents