Cybersecurity

A long aisle running between two rows of blue lit server cabinets in a data center.
Cloud Security
Cloud security is mostly configuration security. The large providers operate infrastructure to a standard few organizations could match, and the incidents that occur are overwhelmingly caused by how customers configured ...
A metal padlock closed on top of an illuminated computer keyboard.
Email and Collaboration Security
Email remains the most common way intruders first reach an organization, and collaboration platforms have become the place a compromise pays off. The two belong in one discussion because they are now one system: a mailbo...
An opened hard disk drive in black and white, showing the platter and the read head arm.
Backup, Recovery and Cyber Resilience
Every organization that has been through a serious ransomware event learned the same lesson, and most learned it late: having backups and being able to recover are different conditions. The first is a procurement outcome...
Two professionals review a multi-lane organizational workflow diagram on a dual-screen laptop; with a customer journey map on the lower display.
The CIS Critical Security Controls
Most security frameworks tell you what good looks like. Very few tell you what to do on Monday. The CIS Critical Security Controls are an attempt at the second problem, and that is the reason to be interested in them. Th...
Rows of white storage boxes marked archive, shelved on either side of a wooden door.
Cybersecurity Policies and Documentation
Security documentation has a reputation problem. It is associated with binders written for an audit, approved once, and never read again. That reputation is deserved for a great deal of it, and it obscures the fact that ...
Railway tracks converging beneath overhead lines and signal gantries.
Continuous Security and Compliance Monitoring
Passing an assessment and maintaining an effective security program are different achievements, and the second is considerably harder. An assessment measures a moment. A program has to hold a position while the environme...
Rolled architectural floor plans on a desk beside a pen, a scale rule and drafting tools.
The NIST Cybersecurity Framework
The NIST Cybersecurity Framework is the most widely used way of organizing a conversation about cybersecurity risk, and it is regularly misdescribed. It is not a standard, not a control catalog, and not something an orga...
A corridor running between tall library shelves filled with bound volumes.
NIST SP 800-53 Security Controls
NIST SP 800-53 is a catalog of security and privacy controls. It is thorough, it is long, and it is routinely misunderstood as a list an organization is supposed to complete. It is not, and reading it that way produces e...
Two people shaking hands over a signed document folder and pen on a desk.
ISO/IEC 27001 and Information Security Management
ISO/IEC 27001 differs from the other frameworks in this cluster in one decisive respect: an organization can be certified against it by an accredited third party. That single fact explains most of how it is used, and mos...
People meeting around a long boardroom table with laptops and papers.
Managed Cybersecurity for Regulated and Public-Sector Environments
Regulated and public sector organizations do not have a different security problem from anyone else. They have the same problem plus an obligation to demonstrate, to somebody external, that they are addressing it. That s...