incident response strategy

Incident Response Strategy: Determining Where to Invest

It can be hard to plan for a security incident if you’ve never experienced one first hand. Incidents involve unauthorized access, denial of service, presence of malicious logic, and improper usage. As an incident responder, I’ve seen plenty of these situations play out. I was fortunate to share some of my experiences and lessons with… Read More

2018 cyber security trends

2018 Cyber Security Trends: Where are We Headed This Year?

We’re only a month into 2018 and we’ve already seen a flurry of security incidents. Meltdown and Spectre grabbed headlines early, bringing attention to a serious design flaw in Intel processor chips. Ransomware breaches that hit Allscriptsand Hancock Health were born from the SamSam variant, which has only gained strength as a major threat across all sectors.  What else is in… Read More

ransomware lawsuit

[Guest Blog] Allscripts Attack Sets the Bar: First Notable Ransomware Lawsuit Puts Providers Under the Spotlight

 About the Author Arnold Abraham is Principal Attorney and Founder of the CyberLaw Group (cyberlawgroup.net), a law firm focused on personal privacy and data protection. He previously served as a Senior Federal Cyber Security Executive in USCYBERCOM and the Department of Homeland Security. Companies hit by cyber attacks are increasingly finding themselves open to potential liability… Read More

amazon s3 misconfiguration

Cloud Security Learning Curve Remains High: Latest Amazon S3 Misconfiguration Illustrates Need for Safety Nets

We can add yet another sensitive data breach to our lessons learned catalog. This one, involving a large volume of sensitive medical records exposed to the world, goes in the fat folder related to misconfigured storage services. A U.S.-based digital records management company stored this information in a large PDF file, which was then stored in an Amazon Web Services… Read More

threat hunting best practices

Incident Response Q&A Part II: Why Incident Response Playbooks Aren’t the Answer, and Advice for New CISOs

Incident response will continue to be an important cyber security priority for many organizations in 2018. We took a moment to get some deeper insight into the incident response landscape from Delta Risk Senior Consultant Ryan Clancy. Here’s part II of our incident response discussion (you can find part I here). Dev: There have been some… Read More

incident response q&a

Incident Response Q&A Part I: Preparing Your Staff for a Cyber Security Incident (Including How to Respond to the Media)

Incident response will continue to be an important cyber security priority for many organizations in 2018. We took a moment to get some deeper insight into the incident response landscape from Delta Risk Senior Consultant Ryan Clancy. Here’s part I of our incident response discussion. Dev: It seems like the tide is shifting and we’re… Read More