Combatting the Evolving SaaS Kill Chain: How to Stay Ahead of Threat Actors

June 28, 2024 at 08:10AM Enterprises are struggling to secure their modern business infrastructure, specifically SaaS, as they continue to rely on outdated security programs. The shared responsibility model in SaaS requires customers to take ownership of components that are often targeted by threat actors, leading to growing SaaS attack activity. Implementing a true Zero … Read more

CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)

April 9, 2024 at 07:54AM CISO Conversations with Nick McKenzie at Bugcrowd and Chris Evans at HackerOne delve into the diverse paths into CISO leadership, emphasizing adaptability and self-starting drive. Ultimate CISO attributes, their roles’ changing nature, and the challenges they face are discussed, exemplifying leadership, team building, and future-focused preparation in the cybersecurity world. … Read more

Security is hard because it has to be right all the time? Yeah, like everything else

February 25, 2024 at 11:13AM The text describes the importance and complexity of integrating security into system designs, emphasizing the need to prioritize security throughout the entire process. It also discusses the challenges and unique aspects of security, emphasizing the importance of understanding requirements, assumptions, and mechanisms, and decomposing the system into elemental components to … Read more

Survey Shows a Surge in (Artificial) Intelligence

January 22, 2024 at 09:08AM Generative AI (GenAI) gained attention in 2023, with 2024 seeing a move towards practical applications. It holds promise for human augmentation, productivity, and creativity, but raises cybersecurity concerns. A survey by Omdia highlights the symbiotic relationship between GenAI and cybersecurity, showing growing interest and evolving cybersecurity strategies. Vendors face the … Read more

Outside the Comfort Zone: Why a Change in Mindset is Crucial for Better Network Security

December 11, 2023 at 07:48AM The enterprise network has traditionally relied on controlled settings and legacy security tools. The COVID-19 pandemic accelerated the shift towards remote work, leading to a more dispersed and vulnerable network. Increased malware and security threats necessitate a proactive approach, shared responsibility, risk-awareness, and preparedness for worst-case scenarios to enhance network … Read more