Roger Grimes on Prioritizing Cybersecurity Advice

This is a good point:

Part of the problem is that we are constantly handed lists…list of required controls…list of things we are being asked to fix or improve…lists of new projects…lists of threats, and so on, that are not ranked for risks. For example, we are often given a cybersecurity guideline (e.g., PCI-DSS, HIPAA, SOX, NIST, etc.) with hundreds of recommendations. They are all great recommendations, which if followed, will reduce risk in your environment.

What they do not tell you is which of the recommended things will have the most impact on best reducing risk in your environment. They do not tell you that one, two or three of these things…among the hundreds that have been given to you, will reduce more risk than all the others…

Continue reading Roger Grimes on Prioritizing Cybersecurity Advice

GitHub Touts 2FA Adoption Success, Looks Ahead to Further Adoption

GitHub today revealed that its initiative to get users to enable one or more forms of two-factor authentication (2FA) by the end of 2023 has been hugely successful.
The post GitHub Touts 2FA Adoption Success, Looks Ahead to Further Adoption appeared fi… Continue reading GitHub Touts 2FA Adoption Success, Looks Ahead to Further Adoption

Microsoft Quietly Improved Authenticator Security to Thwart MFA Fatigue Attacks

Microsoft today reported that it finished rolling out a new feature for its Authenticator app in September, improving its security.
The post Microsoft Quietly Improved Authenticator Security to Thwart MFA Fatigue Attacks appeared first on Thurrott.com.
Continue reading Microsoft Quietly Improved Authenticator Security to Thwart MFA Fatigue Attacks

Online Identities, Passwords, and Passkeys, Oh My (Premium)

I’ve been using a Google Workspace account—paul@thurrott.com—as my primary online identity since before we launched Thurrott.com, and for the most part, I don’t have any major complaints. But there has long been one major downside to this account t… Continue reading Online Identities, Passwords, and Passkeys, Oh My (Premium)

Google Authenticator Gets Major Upgrade with Account Sync

Google has finally addressed one of the major issues with its Authenticator app on Android and iPhone, and it’s given the app a new icon too.
The post Google Authenticator Gets Major Upgrade with Account Sync appeared first on Thurrott.com.
Continue reading Google Authenticator Gets Major Upgrade with Account Sync