Cybersecurity Training Challenges: What to Know Before Training Your Employees
We talked about why it’s important that you train your company to recognize cyber threats and also how to respond to those cyber threats. Together, these make part of a greater company-wide posture against attacks that keep you prepared. We also want to make sure you’re aware of the cybersecurity training challenges that you will […]
What is Role Based Access Control? Benefits and RBAC Examples
Role Based Access Control (RBAC) is defined as “Access control based on user roles (i.e., a collection of access authorizations that a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within […]
Increasing Security with Logging and Auditing
Logging and auditing of your user and device activity provides important evidence of the events occurring on your network. It is important to collect and understand these events so you can normalize or baseline the activities of your organization’s compute environment. This is critical so that you can detect actions that are outside the normal […]
Credential Management: Protecting User Credentials
Credential management is a crucial piece in IT and OT security. Protecting user credentials against attacks should be a top priority. Compromised accounts are one of the most common methods of attack. When an organization’s password security is low, their user access practices tend to lack as well. Once a bad actor establishes a foot […]
What are CIS Critical Security Controls and How to Meet Them
The Center for Internet Security’s (CIS) Critical Security Controls was established by cybersecurity practitioners in coordination with governments, companies, and institutions such as SANS. This effort was done in order to establish a common framework to help organizations tackle the implementation of good cyber security hygiene and controls. So, what are the CIS Critical Security […]
ICS Cybersecurity Advisory: NSA and CISA’s Steps to Better Defense
The NSA and CISA released new cybersecurity guidance to stop malicious activity and reduce OT exposure. This new NSA/CISA ICS cybersecurity advisory outlines the tactics, techniques and procedures (TTPs) that malicious actors use to compromise OT/ICS assets and the steps you should be taking against them. The underlying theme in this new cybersecurity guidance is […]
IT/OT Integration Best Practices and Strategies
IT and OT teams are converging. While that brings a great opportunity to enhance security and impart best practices learned from each team, there are inherent challenges to IT/OT integration as each works together to achieve its goals. We discussed this convergence and challenges associated with it in a previous post. As the worlds of […]
IT vs OT Cybersecurity and IT/OT Convergence
As the world of OT collides with IT, this convergence has brought a refreshed need to understand each other and how this IT/OT convergence affects businesses and their security. While in simple terms, IT deals with information and OT deals with machines, understanding the nuances beyond this and how IT vs OT cybersecurity needs are […]
Multi-factor Authentication (MFA) Best Practices
Compromised passwords are one of your biggest liabilities. For many companies with low password management maturity, a compromised password can have devastating outcomes. Our multi-factor authentication best practices are helping you increase security against your password vulnerabilities. It’s important to attach more security to your credentials. It’s not uncommon for password sharing and using the […]
Common Privileged Access Management Mistakes
Privileged access management makes you more secure by permitting least-privileged access to your most important information and endpoints at the right time and only when it is needed. It is a fundamental element in the Zero Trust architecture. To maximize your security and investment in PAM, we are reviewing common privileged access management mistakes that […]