Risk Management
Disaster Recovery: RTO, RPO and Recovery Planning
Almost every organization has a recovery plan. Rather fewer can state, per system, how long recovery would take and how much data would be lost, and fewer still have measured either. Those two numbers are the whole desig...
Disaster Recovery and Business Continuity
Disaster recovery restores technology. Business continuity keeps the organization functioning while the technology is unavailable. Organizations often build the first, call it the second, and discover the gap during an i...
Cloud Security and Shared Responsibility
Cloud security failures are rarely failures of the platform. They are usually a misunderstanding about where the provider's obligation ends, acted on for long enough that nobody rechecks it.
This page sets out the model,...
The Managed Cybersecurity Lifecycle
Almost every organization we assess has already bought good security controls. Rather fewer are still operating them as designed a year later. The gap between those two sentences is what managed cybersecurity exists to c...
What Are Managed Cybersecurity Services?
Managed cybersecurity services are the continuing operation of an organization's security controls by somebody whose job that is. Not the purchase of the controls, and not a one off review of them. The operation: the pat...
Cybersecurity Risk Assessments
A cybersecurity risk assessment answers one question: what could go wrong here that would matter, and which of those things is worth spending money on first. Everything else in the method exists to make that answer defen...
Vulnerability Management
Vulnerability management is the discipline of finding weaknesses in your environment and closing them before somebody else uses them. Almost every organization does the finding. Rather fewer do the closing at a rate that...
Security Monitoring and Incident Detection
Security monitoring is the practice of collecting enough evidence about what is happening in an environment to notice when something is wrong, and having somebody act on it. Both halves are load bearing. Organizations th...
Incident Response and Cybersecurity Recovery
Incident response is the set of activities that begin when something has gone wrong and end when the organization is back to a state it understands. It is the part of a security program that is dormant until it is the on...
The CIS Critical Security Controls
Most security frameworks tell you what good looks like. Very few tell you what to do on Monday. The CIS Critical Security Controls are an attempt at the second problem, and that is the reason to be interested in them.
Th...