Looking Ahead: Five Cybersecurity Predictions That Will Shape 2027

The cybersecurity landscape continues to evolve at a rapid pace, driven by emerging technologies, shifting attacker tactics, and changing business priorities. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores five key cybersecurity predictions that are expected to significantly influence how organizations manage risk and defend against threats as 2027 approaches. Attendees will gain insight into anticipated developments across areas such as AI-driven attacks and defenses, ransomware evolution, regulatory pressures, workforce challenges, and security architecture trends. The session will focus on what these predictions mean in practical terms and how security leaders can begin preparing today to stay ahead of tomorrow’s threats and build more resilient, future-ready cybersecurity strategies.

2026/11/4
阅读更多

Ransomware Readiness: Preparing Your Security Team Before an Attack Hits

Ransomware remains one of the most disruptive and costly threats facing enterprises today, and preparation is critical to minimizing its impact. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he discusses how security teams can build ransomware readiness before an attack occurs, rather than reacting under pressure once systems are locked and operations are disrupted. Attendees will learn how to assess ransomware preparedness, close common gaps in visibility and response, and ensure backup, recovery, and communication plans are tested and trusted. The session will also explore how security, IT, legal, public relations, and executive teams can align ahead of time to reduce downtime, contain damage, and maintain control during a high-pressure ransomware event.

2026/10/7
阅读更多

Systems Security Certified Practitioner (SSCP) Info Session

Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today! CPE Credit: 1 Group B CPE Credit

2026/9/23
阅读更多

The AI Arms Race: Attackers, Defenders, and the Future of Cybersecurity

Artificial intelligence is rapidly reshaping the cybersecurity landscape, giving attackers new ways to automate, scale, and personalize cyberattacks while providing defenders powerful tools to detect and respond faster than ever. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores how AI is being used on both sides of the threat equation and what this escalating arms race means for organizations. Attendees will learn how AI-driven threats such as advanced phishing, deepfakes, and automated malware are changing attacker tactics, as well as how security teams can leverage AI for threat detection, response, and risk reduction. The session will highlight practical considerations for preparing defenses as AI continues to transform the future of cybersecurity.

2026/9/16
阅读更多

Your Sneak Peek Into Three New Session Formats at ISC2 Security Congress (#3)

ISC2 Security Congress 2026 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! This year, Security Congress is introducing several exciting new interactive session formats, including ACTion Rooms: Advancing Cybersecurity Together, AI Incident Rooms, and Tabletops and Gamified Exercises. Hear from three of our esteemed conference speakers as they preview these formats and share highlights from their presentations. By joining this webinar, you’ll get a snapshot of content from the following sessions: Tabletop/Gamified: From Alert to Action: An Interactive SOC Triage Simulation for Security Analysts AI Incident Room: AI-Driven Data Classification Failure and Impact ACTion Room’s “Sharing the Cybersecurity Profession” series, including Session 4: Connecting the Cyber Dots: How the Profession Learns, Evolves and Advances Join us live September 10, 2026 at 1:00 pm Eastern/10:00 a.m. Pacific to be among the first to gain valuable insights into these formats sessions, plus have an opportunity to ask your questions. Like what you see? Register for ISC2 Security Congress 2026 to unlock access to even more great content this October. Link: https://web.cvent.com/event/0bba3198-226e-4607-aad5-dbf9a382ef2e/websitePage%3Ae3e1427f-5c48-423a-a0e5-60dcec1c4363 You won’t want to miss this enlightening webinar that's the third in a series of three 2026 Security Congress Sneak Peek webinars!

2026/9/10
阅读更多

Certified Secure Software Lifecycle Professional (CSSLP) Info Session

Join us for a deep dive into Certified Secure Software Lifecycle Professional (CSSLP), the software security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where CSSLP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The CSSLP is ideal for software development and security professionals responsible for applying best practices to each phase of the Software Development Lifecycle (SDLC). It shows your expertise and ability to incorporate security practices - authentication, authorization and auditing - into each phase of Software Development Lifecycle. In this 60-minute live virtual session, you’ll learn: - If CSSLP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CSSLP questions during the Q&A section. Register now and begin your CSSLP certification journey today! CPE Credit: 1 Group B CPE Credit

2026/8/26
阅读更多

ISC2 2026 Security Congress: Your Sneak Peek into Pre-Conference Workshops

Ready to maximize your ISC2 Security Congress experience? Get a first look at the hands-on workshops that will jump start your journey with expert guidance into specialized topics. Join two of our esteemed facilitators for an exclusive preview of some the workshops being hosted in Denver leading up to ISC2 Security Congress. By joining this webinar you’ll get a snapshot of workshop content, which includes: Security Findings That Actually Get Fixed — Map threats to business impact, prioritize what executives care about, and use AI personas to craft findings that get funded and acted on. AI Security Leader: Organizational Management — Build a deployable AI management program covering risk, policy, vendors, monitoring and incident response. Join us live August 20, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific to be among the first to gain insights into these add-on experiences, plus have an opportunity to ask your questions. Want to Learn more, visit the Congress website: https://web.cvent.com/event/0bba3198-226e-4607-aad5-dbf9a382ef2e/websitePage%3Ae3e1427f-5c48-423a-a0e5-60dcec1c4363 1 Group A CPE

2026/8/20
阅读更多

Security Industry 101: A Crash Course for New and Aspiring Security Professionals

Cybersecurity is one of the fastest-growing and most in-demand fields—but breaking in can feel overwhelming. This crash course is designed for aspiring and early-career security professionals who want a clear, practical introduction to the cybersecurity industry. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he covers important topics that every cybersecurity newcomer ought to know, including: • Size and growth of the security industry • Useful vocabulary terms and buzz words • Five types of cyberthreat actors • Modern cyberthreats and tactics • Categories of security defenses • Common security job roles • Security industry ecosystem CPE Credit 1 Group A CPE Credit

2026/8/19
阅读更多

Shift Left Isn't Enough: Validating Web Application Risk in Production

Your answer: Web applications have become attackers' preferred entry point, yet most organizations still test them the way they did a decade ago: an annual pentest here, a DAST scan there, with long gaps in between where risk goes unmanaged. In this 30 minute conversation, sponsored by Horizon3 and hosted by ISC2, we will unpack why shift-left, while valuable, never solved the core problem: attackers don't care how many flaws were caught before release, they only need one working path in the live, running application. We'll dig into what it actually takes to validate production web apps safely and continuously, why 'vulnerable' and 'exploitable' are two very different things, and how security teams can move from counting findings to proving real business risk. .5 Group A CPE

2026/8/18
阅读更多

Your Sneak Peek into "Lessons from The Field" at ISC2 Security Congress (#2)

ISC2 Security Congress 2026 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! This year, Security Congress is debuting a new session format: Lessons from the Field. These sessions will feature detailed accounts or case studies of individuals or organizations that overcome a significant challenge or cyber incident. Join three of our esteemed conference speakers as they share highlights from their “Lessons from the Field” sessions. By joining this webinar, you’ll get a snapshot of session content, which includes the following presentations: Detecting and Responding to an Insider Attack at a Fortune 500 Company From "That's Weird" to "I'm a Target": A Real-World Lesson in Operational Security (OPSEC) Lessons Learned from Real-World Zero Trust Deployments Join us live August 11, 2026 at 1:00 pm Eastern/10:00 a.m. Pacific to be among the first to gain valuable insights into these sessions, plus have an opportunity to ask your questions. Like what you see? Register for ISC2 Security Congress 2026 to unlock access to even more great content this October. Link: https://web.cvent.com/event/0bba3198-226e-4607-aad5-dbf9a382ef2e/websitePage%3Ae3e1427f-5c48-423a-a0e5-60dcec1c4363 You won’t want to miss this enlightening webinar that's the second in a series of three, 2026 Security Congress Sneak Peek webinars.

2026/8/11
阅读更多

Rebuilding Identity Assurance: Defending Against Help Desk and Account Recovery Attacks

Attackers have learned that the fastest way past strong authentication is a phone call to the help desk. Threat actor groups running the Scattered Spider playbook now target the account recovery and MFA reset flows that sit at the soft center of workforce and consumer identity, generating seven-figure extortion demands across nearly every industry. On July 30, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, this session hosted by Proof will break down how these attacks unfold in the wild, why standard IT and IAM setups leave recovery moments exposed, and what a verification-based approach to those moments looks like. We will share how a team applies these principles internally, including passwordless workflows and identity-verified account recovery, as a practical model attendees can adapt to harden their own help desk processes. .5 Group A CPE

2026/7/30
阅读更多

Securing SaaS at Scale: Protecting Data in a Cloud-First World

As organizations continue to rely on hundreds of SaaS applications, traditional security models are struggling to keep up. In this session, Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, shares insights into why SaaS has become a prime target for attackers and where security teams are most likely to lose visibility and control. The discussion focuses on proven approaches for managing SaaS risk, protecting sensitive data, and improving governance without disrupting users. Attendees will learn how to prioritize SaaS security initiatives, align controls with business needs, and build a scalable approach to protecting cloud-based applications in today’s dynamic IT environments. CPE Credit 1 Group A CPE Credit

2026/7/22
阅读更多

Your Sneak Peek into Agentic AI at ISC2 Security Congress 2026 (#1)

ISC2 Security Congress 2026 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! Join three of our esteemed conference speakers as they provide highlights into their session content – all focused around agentic AI. By joining this session you’ll get a snapshot of session content, which includes the following presentations: -73 Fraud Cases Later: Building Agentic AI Defense from Real Attack Data -The Agentic Accountability Gap: Governing Autonomous Artificial Intelligence in Compliance -The Special Ops Edge: Applying Military-Grade Decision-Making to Battle-Ready Cyber AI, Agentic and Autonomous Systems Join us live to be among the first to gain valuable insights into these sessions, plus have an opportunity to as your questions. Like what you see? Register for ISC2 Security Congress 2026 to unlock access to even more great content this October. You won’t want to miss this enlightening webinar that's the first in a series of three, 2026 Security Congress Sneak Peek webinars! Link; https://web.cvent.com/event/0bba3198-226e-4607-aad5-dbf9a382ef2e/websitePage%3Ae3e1427f-5c48-423a-a0e5-60dcec1c4363 1Group A CPE

2026/7/21
阅读更多

From Prompts to Permissions: Securing AI That Thinks and Acts

The AI landscape is shifting rapidly from passive chatbots that answer prompts to autonomous agents capable of independent execution, tool manipulation, and decision-making. While this unlocks incredible enterprise efficiency, it introduces entirely new security paradigms like untrusted tool execution and autonomous privilege escalation, untamed Agent Sprawl in enterprise. On June 25, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Sponsor Google Cloud and Host ISC2 break down the transition from prompt engineering to permission management, exploring the critical guardrails needed to secure agentic workflows. We will take a practical look at how to achieve this architecture on Google Cloud, by establishing cryptographic Agent Identities, enforce runtime defense measures.

2026/6/25
阅读更多

The 2026 Security Stack: Tools Defining the Future of Cyber Defense

As cyber threats grow more sophisticated, choosing the right security tools is critical for reducing risk and staying resilient. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he examines the technologies every organization should consider as part of a modern cyber defense strategy. Learn which tools are most effective at protecting endpoints, identities, cloud environments, and data—based on current threat trends and real-world adoption. Steve will discuss how to evaluate tools, avoid stack sprawl, and align investments with business priorities. Attendees will leave with practical guidance for building a streamlined, future-ready security toolkit. CPE Credit 1 Group A CPE Credit

2026/6/17
阅读更多

Certified in Cybersecurity (CC) Info Session

Join us for a deep dive into Certified in Cybersecurity (CC), the entry-level cybersecurity credential from ISC2, creator of the CISSP. Cyberthreats continue to escalate worldwide, and the need for cybersecurity experts is critical. But talent is scarce. Research shows the workforce needs an influx of 3.4 million cybersecurity professionals to meet global demand. ISC2 seeks to help close the skills gap with CC by opening opportunities in the industry to a new pool of professionals. With no experience required, it creates a clear pathway and breaks down traditional barriers to entry, enabling candidates to build confidence and enter their first cybersecurity role ready for what’s next. In this 60-minute live virtual session, you’ll learn: - If CC is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to maintain your certification Plus! Get answers to your CC questions during the Q&A section. Register now and begin your CC certification journey today! CPE Credit: 1 Group B CPE Credit

2026/6/10
阅读更多

Enterprise Readiness for Post-Quantum Cryptography: A Practical Guide

This webinar will cover why enterprises need to start planning their transition to Post-Quantum Cryptography (PQC) to safeguard their sensitive information against future adversaries. We will delve into the latest NIST PQC standards, discuss key considerations for cryptographic inventory and agility, and outline actionable steps for assessing risk, prioritizing systems and implementing hybrid approaches. Attendees will gain insights and an understanding of how to approach building a PQC readiness program for their organization. Join Sponsor Google Cloud Security and Host ISC2 on May 21, 2026 at 1:00 p.m. Eastern/10:00 am Pacific to learn more! <b>CPE Credit</b> 1 Group A CPE Credit

2026/5/21
阅读更多

Certified Cloud Security Professional (CCSP) Info Session

Join us for a deep dive into Certified Cloud Security Professional (CCSP), the cloud security credential from ISC2, creator of the CISSP. As cyber threats make daily headlines, the need for cloud security experts is at an all-time high. Yet talent is scarce. The cyber workforce needs an influx of 3.4 million more professionals to meet global demand. As a result, the career opportunities for CCSP-certified professionals are near limitless. CCSP, a vendor-neutral credential, not only provides a strong foundational understanding of key concepts, it shows you’re able to quickly learn and adapt to different scenarios, including working with platforms from different vendors. As more organizations worldwide move to multi-cloud operations, the versatile skills from vendor-neutral certification are highly desirable for cloud security teams. In this 60-minute live virtual session, you’ll learn: - If CCSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CCSP questions during the Q&A section. Register now and begin your CCSP certification journey today! CPE Credit: 1 Group B CPE Credit

2026/5/20
阅读更多

Key Insights from CyberEdge’s 2026 Cyberthreat Defense Report

CyberEdge’s annual Cyberthreat Defense Report (CDR) has become a staple for assessing organizations’ security postures, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. It incorporates dozens of insights from 1,200 security professionals from 17 countries and 19 industries. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he reviews key findings from CyberEdge’s 2026 CDR. Steve will break down trends in cyberattacks, ransomware, AI-driven threats, security spending, and security team challenges. Attendees will gain a clear, benchmark-driven view of how organizations are responding to today’s evolving threat landscape and learn how to apply these insights to strengthen security strategies, prioritize investments, and reduce cyber risk in the year ahead. CPE Credit 1 Group A CPE Credit

2026/5/13
阅读更多

Certified Information Systems Security Professional (CISSP) Info Session

Join us for a deep dive into Certified Information Systems Security Professional (CISSP), the cybersecurity leadership credential from ISC2. Earning the CISSP is an investment in your future and an important next step in your career. Consistently recognized globally as the gold standard cybersecurity certification, it distinguishes you as a leader committed to excellence. CISSP certification demonstrates that you have the advanced knowledge and technical skills to design, develop and manage an organization’s overall security posture. If you’re vendor-certified, it expands the depth and breadth of your knowledge and positions your skills as more versatile. In this 60-minute live virtual session, you’ll learn: - If CISSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CISSP questions during the Q&A section. Register now and begin your CISSP certification journey today! CPE Credit: 1 Group B CPE Credit

2026/4/22
阅读更多

2026 Supply Chain Attacks: Axios NPM and TeamPCP Compromises

In early 2026, we witnessed an escalation in software supply chain attacks. Threat actors are increasingly targeting widely used open-source tools and repositories to maximize their downstream impact. Notably, the North Korean threat actor UNC1069 compromised the widely used Axios NPM package, introducing a malicious dependency into a platform that sees over 100 million weekly downloads. Simultaneously, the threat group TeamPCP orchestrated a cascading supply chain compromise targeting CI/CD pipelines via popular tools like the Trivy vulnerability scanner, Checkmarx GitHub Actions and the LiteLLM PyPI package. These compromised pipelines were weaponized to harvest cloud credentials for later data theft and extortion, and to pave the way for potential ransomware deployment. On April 16, 2026 at 1:00 pm Eastern/10:00 a.m. Pacific, sponsor Google and host ISC2 will provide a look at the rapid evolution, impact and response to these dual supply chain campaigns. This session will cover: -An overview of the North Korea-nexus UNC1069 campaign targeting Axios NPM releases, detailing how the plain-crypto-js malicious dependency was used to deploy the WAVESHAPER.V2 backdoor across Windows, macOS and Linux environments. -The tactics, techniques and procedures (TTPs) of TeamPCP, including their deployment of the SANDCLOCK credential stealer via poisoned GitHub Actions to extract cloud credentials, local environment variables and cryptocurrency wallets. -How TeamPCP and collaborating actors stole highly privileged cloud tokens to facilitate data extortion and planned deployments of VECTORLOCK ransomware. -Actionable guidance and rapid response strategies alongside critical remediation steps like dependency pinning, auditing lockfiles and rotating exposed secrets. <b>CPE Credit</b> 1 Group A CPE Credit

2026/4/16
阅读更多

Securing Remote & Hybrid Workforces Without Killing Productivity

Remote and hybrid work are now permanent realities, but they have dramatically expanded the attack surface and introduced new security challenges. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores how organizations can protect users, devices, and data—without slowing down the business or frustrating employees. This webinar will cover practical strategies for securing access, managing endpoints, and protecting sensitive information across distributed environments. Steve will discuss how modern identity controls, cloud security, and user-focused policies can reduce risk while supporting flexibility and performance. Attendees will leave with actionable guidance to balance strong security with a seamless employee experience.

2026/4/15
阅读更多

Stop Chasing Alerts: Automating Email Security with Behavioral AI Roundtable

Phishing, business email compromise (BEC), and account takeover (ATO) remain some of the most disruptive and resource-draining security challenges for modern organizations. AI-generated attacks now convincingly mimic trusted colleagues, vendors, and partners, bypassing traditional defenses and landing directly in user inboxes. On April 9, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, sponsor Abnormal AI and host ISC2 discuss how security teams can shift from reactive alert triage to automated, behavior-based defense. They'll cover: - Why modern phishing, BEC, and ATO attacks evade traditional email security controls - The operational strain on SOC and IT teams, including alert fatigue and investigation backlogs - Practical ways behavioral AI can automate detection, investigation, and remediation Join us to learn how to create a smarter, automated defense against modern email threats.

2026/4/9
阅读更多

The Human-Centric Email Exfiltration Crisis and How to Stop it Cold

Most data exfiltration doesn’t start with sophisticated malware, it starts with a person and a simple email action. Whether intentional or accidental, employees forwarding sensitive information to personal accounts, partners, or competitors continues to expose organizations to regulatory, financial, and reputational risk. On March 19, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific, sponsor Proofpoint and host ISC2 examine how human-driven email data loss unfolds inside real organizations, what current Data Loss Assessments (DLAs) reveal about everyday user behavior, and why traditional, rule-based DLP controls often fail to detect subtle but high-risk activity. We’ll also discuss how behavioral AI and machine learning are enabling security teams to move from reactive detection to proactive prevention. You’ll learn: -Why user-driven email exfiltration remains a persistent, overlooked risk -Key insights from recent cross-industry Data Loss Assessments, including: - Engineers sending proprietary designs externally - Legal staff exporting sensitive client data before departure - Healthcare employees emailing credentials and unencrypted patient records - Finance teams sharing confidential revenue data outside the organization -How behavioral analysis detects personal emails and high-risk destinations -How anomaly detection flags spikes in sensitive attachments and unusual recipient activity that static DLP misses

2026/3/19
阅读更多

People-Powered Security: How to Build a Cyber-Savvy Workforce

Cybersecurity is no longer just a technology challenge—it’s a people challenge. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores how organizations can reduce risk by empowering employees to recognize, prevent, and respond to cyber threats. This webinar will cover practical strategies for creating engaging security awareness programs, reinforcing secure behaviors, and embedding security into everyday work routines. Learn how phishing simulations, role-based training, and measurable outcomes can transform employees from the weakest link into a critical line of defense. Attendees will leave with actionable insights to strengthen security culture and reduce human-driven cyber risk.

2026/3/11
阅读更多

Staying Sober Under Pressure: Recovery, Resources and Community in High-Stress Careers

Sponsored by the Center for Cyber Safety and Education. <br>In high-pressure fields like cybersecurity, long hours and constant demands can make it challenging to maintain balance—especially for professionals exploring a sober or sober-curious path while navigating intense work environments. The Center hosted a candid conversation with Jen VanAntwerp, founder of Sober in Cyber, and Tom Eston, Sr. Director of Professional Services at Snyk, who shared practical strategies for managing stress in healthier ways and building supportive peer networks within the industry. View the recording below to gain actionable insights for creating a more sustainable, balanced approach to your professional and personal well-being.

2026/3/11
阅读更多

Why Your PTaaS is Failing the Speed Test

In 2026, software is deployed multiple times a day, often automatically with every code commit, but many security teams are still operating on “on-demand” testing cycles that can’t keep up. While PTaaS (penetration testing as a service) modernized how findings are delivered, it often fails to close the exposure gaps created by daily deployments and shifting cloud infrastructure. Join sponsor Sprocket Security and host ISC2 March 5,2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific to explore why traditional PTaaS is breaking under the pressure of modern engineering and how moving to a Continuous Penetration Testing (CPT) model allows your offensive strategy to match the velocity of your development team.

2026/3/5
阅读更多

Certified in Governance, Risk and Compliance (CGRC) Info Session

Join us for a deep dive into Certified in Governance, Risk and Compliance (CGRC), the governance, risk and compliance credential from ISC2, creator of the CISSP. The CGRC is an information security practitioner who champions system security commensurate with an organization’s mission and risk tolerance, while meeting legal and regulatory requirements. CGRC, a vendor-neutral cybersecurity credential, recognizes your knowledge, skills and abilities to authorize and maintain information systems within the RMF. It proves you know how to formalize processes to assess risk and establish security documentation. CGRC is particularly well-suited for IT, information security and cybersecurity practitioners who manage risk in information systems. It is also recommended for any practitioner involved in authorizing and maintaining information systems. In this 60-minute live virtual session, you’ll learn: - If CGRC is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CGRC questions during the Q&A section. Register now and begin your CGRC certification journey today!

2026/3/4
阅读更多

Agentic Security in the SOC: Concept vs. Reality

Agentic security is no longer a future concept – it’s already reshaping how today’s SOCs operate. But with the hype accelerating, security leaders need clarity on what “agentic” actually looks like in production, which capabilities are real today, and what’s still on the roadmap. Join this session on February 26th, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn: - What “agentic security” actually means in the context of the SOC - Which agentic capabilities are realistic and deployable today with concrete examples from security teams seeing value today - How agentic systems complement human analysts in detection and response - Metrics CISOs and security leaders are using to prove measurable outcomes - What’s coming next – and how to prepare for the future SOC We’ll separate practical reality from future promise, explore how agents work alongside human analysts, and outline what the next evolution of the SOC will require. You’ll leave with a clear understanding of what’s deployable today, what’s coming next, and how to prepare your SOC for an agent-driven future.

2026/2/26
阅读更多

Building an AI Security Champions Program

Security champions programs are a proven way to scale security across large development teams, but the rise of AI-assisted development introduces new challenges, risks, and opportunities that traditional programs were not designed to handle. As AI coding assistants and autonomous agents accelerate how software is built, security champions play a critical role in embedding secure-by-design practices earlier and at greater scale. Join sponsor Snyk and host ISC2 on February 19, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn how to build an AI-ready Security Champions Program from the ground up, empowering developers to advocate for security across both human-written and AI-generated code. Attend this session to: - Understand how the role of security champions evolves in AI-accelerated development environments - Learn how to identify, train, and enable champions to address AI-specific risks alongside traditional AppSec concerns - Discover how to define success, establish KPIs, and integrate security tooling into modern workflows - Gain practical guidance on fostering collaboration, recognizing champions, and creating feedback loops that scale security as AI adoption grows

2026/2/19
阅读更多

Winning the Cyber Talent War: How to Attract and Keep Top Security Professionals

The competition for skilled cybersecurity professionals has never been more intense. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores proven, practical strategies organizations can use to attract top-tier security talent—and keep them engaged for the long term. Learn how leading teams are modernizing recruiting practices, expanding talent pipelines, and differentiating themselves in a crowded market. Steve will also examine retention drivers such as career development, work hours and location flexibility, employee recognitions, and leadership support. Attendees will leave with actionable insights to reduce turnover, combat burnout, and build resilient, high-performing security teams that can keep pace with today’s evolving threat landscape.

2026/2/18
阅读更多

AI and Quantum Attacks Exposed: Your Survival Guide for the Next-Gen Threat Era

Two technological forces are converging to reshape cybersecurity forever: AI and quantum computing. Most organizations are dangerously unprepared for what's coming next. These aren't just buzzwords—they're fundamentally changing how attacks happen, who can launch them, and which defenses will fail under pressure. While most security guidance offers surface-level awareness, attackers are already weaponizing these technologies against specific vulnerabilities in YOUR environment—from social engineering to ransomware to password cracking. Join Sponsor KnowBe4 and Host ISC2 February 12, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a no-nonsense deep dive into the specific threats you're facing and the exact defenses you need now. KnowBe4 CISO Advisor Roger Grimes cuts through the hype to deliver actionable intelligence on how AI and quantum will impact each attack vector in your organization. Discover: -What AI actually is (and isn't) and why that distinction matters for your security strategy -The real quantum threats emerging now and which defenses become obsolete overnight -Exactly how AI and quantum amplify social engineering, password cracking, ransomware and vulnerability exploitation against your systems -How to protect against threats coming from AI and quantum while securing the AI and quantum tools you’re already deploying -Specific changes to implement in your security program to counter these advanced threats effectively Stop preparing for yesterday's threats. Arm yourself with the precise intelligence and practical defenses that will actually protect your organization in the AI and quantum era.

2026/2/12
阅读更多

Cybersecurity: From Cost Center to Competitive Advantage

Security professionals often focus solely on defense. But what if we viewed cybersecurity as a strategic asset that drives sales and builds customer trust? This session on January 27, 2026 at 1:00 p.m. Eastern/10:00 a.m. Pacific will explore the untapped potential of cybersecurity to become a key enabler for revenue generation and enhanced customer relationships. We will delve into practical strategies for proactively integrating security considerations into the sales cycle, leveraging security as competitive differentiators, and effectively communicating your security posture to build unwavering customer confidence. This session will demonstrate how a shift in mindset can position cybersecurity as a vital contributor to business growth while upholding ethical responsibilities in data protection, offering actionable insights for security professionals across all levels.

2026/1/27
阅读更多

Modernizing PKI for the Post-Quantum Transition

Preparing for the post-quantum era isn’t as simple as swapping algorithms. Organizations face growing complexity across certificates, identities and encrypted data — all while standards, timelines and risks continue to evolve. On January 15, 2026, at 1:00 p.m. Eastern/10:00 a.m. Pacific, sponsor Entrust and host ISC2 will explore why PKI (public key infrastructure) plays a central role in post-quantum readiness, the practical trade-offs between pure post-quantum and hybrid approaches, and how building crypto agility today helps reduce future disruption, risk and operational strain.

2026/1/15
阅读更多

Darwinian Offense: Generative Curricula for Autonomous Red Teaming- a Security Congress Encore

AI has historically struggled to assist in offensive security due to a critical shortage of real-world training data. This session takes a deep dive into the methodology behind recently published research designed to overcome this limitation through adversarial self-learning. Following up on her popular Security Congress 2025 keynote, researcher Alissa Knight will dissect a novel architecture where an AI teaches itself to hack not by studying past attacks, but by engaging in a continuous, high-stakes war game against itself. Attendees will learn the mechanics of this "survival of the fittest" loop, where two competing agents—one constructing defensive puzzles and the other evolving breaking strategies—force the emergence of increasingly sophisticated API attacks without human intervention. The session will move from research theory to validation with a live demonstration against a banking API using Ares, a prototype implementation of this autonomous framework.

2025/12/16
阅读更多

5 Key Learnings from the Frontlines: Enterprise Passkey Deployment Realities in 2026

In the first half of 2025, over 16 billion passwords were leaked—highlighting the urgent need for stronger, phishing-resistant authentication methods. Despite growing awareness, many organizations still hesitate to adopt passkeys due to perceived complexity, cost concerns, and a lack of clear guidance, as noted in recent research by the FIDO Alliance and HID. On December 11, 2025 at 1:00 p.m. Eastern/10:00 a.m Pacific, Sponsor HID Global and Host ISC2 share practical, field-tested insights into accelerating enterprise passkey adoption. Learn how to: * Navigate common deployment challenges * Align authentication strategies with evolving security goals * Drive user adoption and organizational buy-in Join us to stay ahead of the passwordless curve and prepare your enterprise for a more secure, streamlined authentication future in 2026.

2025/12/11
阅读更多

The Invisible Threat: How Polymorphic Malware is Outsmarting Your Email Security

Approximately $350 million in preventable losses stem from polymorphic malware, malicious software that constantly changes its code to evade detection. With 18% of new malware using adaptive techniques that challenge traditional defenses, now is the time to enhance your organization's security posture. Join us December 9, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar where Sponsor, KnowBe4 and Host, ISC2 share valuable insights and proactive strategies to strengthen your security framework against sophisticated attacks. In this session, you'll discover: - Enhanced detection strategies that go beyond traditional signature-based approaches to identify polymorphic threats before they impact your systems - Proactive defense frameworks specifically designed to counter the most sophisticated shape-shifting malware - Success stories from organizations that effectively neutralized advanced threats through strategic security improvements - Communication templates for building stakeholder support for security enhancements - Practical implementation roadmaps to strengthen your security posture against adaptive threats drawing from real-world scenarios and emerging threat intelligence, You'll leave with a practical toolkit of strategies you can be implemented immediately to enhance your organization's resilience.

2025/12/9
阅读更多

Building a Post-Quantum Tech Stack: From Readiness to Implementation

Preparing for the post-quantum era requires more than awareness - it demands a modern cryptographic foundation built for agility, visibility, and compliance. Organizations must be able to discover and manage their cryptographic assets, modernize and consolidate their infrastructure, and confidently test and implement post-quantum cryptography (PQC). On December 2, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Sponsor Entrust and host ISC2 explore practical steps for aligning your PQC readiness journey with execution - including cryptographic asset management, PKI, and HSMs. We’ll discuss how crypto discovery, agility, and modernization strategies - supported by automation, compliance management, and integrated visibility - can help organizations strengthen security now and through migration. Join us to learn how you can move from planning to deploying PQC, building a tech stack ready to secure your organization against quantum threats today and tomorrow.

2025/12/2
阅读更多

AI-Powered SOCs: Automate Smarter, Defend Better

AI-driven SOCs promise efficiency gains, but how much automation is too much? While AI-powered security tools enhance SIEM, SOAR, and threat detection, adversaries are exploiting automation blind spots, manipulating AI models, and evading AI-driven defenses. This session dissects real-world adversarial AI attacks, including a case study on Microsoft Copilot’s AI vulnerabilities—where attackers exploited indirect prompt injection and adversarial inputs to manipulate security workflows. Attendees will learn how AI can be both a force multiplier and a security risk, gaining: - An understanding of how attackers bypass AI-powered security automation - A breakdown of adversarial AI tactics and AI-specific SOC vulnerabilities - A hybrid AI-human SOC model that reduces false positives while maintaining resilience This session offers a practical roadmap to securely integrate AI in SOC operations without increasing attack surfaces.

2025/12/2
阅读更多

The Road Ahead: Top Five Cybersecurity Predictions for 2026

The cybersecurity landscape is evolving rapidly. As cyberthreats grow in complexity, organizations must stay ahead of the curve by anticipating what’s next. So, what’s in store for our industry in the coming year? Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he recaps the good, the bad, and the ugly cybersecurity events of 2025 and shares his top five cybersecurity predictions for 2026. This webinar provides a forward-looking perspective, equipping attendees with the insights and strategies needed to stay ahead of emerging threats and capitalize on new opportunities.

2025/11/12
阅读更多

How to Modernize Threat Protection in the Age of AI

The surge in generative AI and increasingly sophisticated social engineering tactics has given cybercriminals powerful new tools to exploit human vulnerabilities—especially through email. These attacks are no longer just technical; they’re psychological, targeting your employees to gain access, steal data, and inflict financial and reputational damage. Join sponsor, Proofpoint and host, ISC2 on October 21, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a live 60-minute webinar. During this session we’ll explore actionable approaches for strengthening your human firewall. Discover how to empower your workforce, reduce risk, and build a resilient defense against today’s AI-enhanced threats. Don’t miss it!

2025/10/21
阅读更多

From Technicians to Professionals: The Duty of Care in Cybersecurity (#2)

What does it mean to treat cybersecurity as a true profession—not just a discipline? This session challenges practitioners, leaders, and hiring managers to rethink professional standards in cyber, highlighting the role of credentialing, clear career pathways, and people-centric leadership in retaining and growing talent. Speakers will explore how human factors such as stress and burnout can impact performance, and why self-awareness, empathy, and communication are essential leadership skills in today’s environment. Drawing from workforce insights and neuroscience, this session helps attendees understand how to position themselves for advancement—by building a foundation of professional efficacy, emotional insight, and resilience.

2025/10/21
阅读更多

Security Industry 101: What Every Newcomer Needs to Know

New to the security industry? Or thinking about transitioning into an information security role? If so, this webinar is for you. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he provides a one-hour ‘crash course’ on the entire security industry, including: - Size and growth of the security industry - Useful vocabulary terms and buzz words - Five types of cyberthreat actors - Modern cyberthreats and tactics - Categories of security defenses - Common security job roles - Security industry ecosystem

2025/10/15
阅读更多

Level Up Your Strategies in Cybersecurity Awareness Month and Beyond!

We’re already into Cybersecurity Awareness Month and that may have you asking: How do you turn mandatory security awareness into a fun and engaging campaign that actually reduces human risk and keeps momentum going for months to come? On Tuesday, October 14, 2025 at 1:00 p.m., Eastern/10:00 a.m. Pacific join sponsor KnowBe4 and host ISC2 to discover how to leverage engaging campaign ideas. This webinar will include KnowBe4's free ready-to-use kit, to run a complete themed campaign all year long. We've done the heavy lifting so you can focus on what matters most: building a stronger security culture that lasts. In this fun and practical session, you'll learn: -How to explain cyber threats to users in ways they can relate to and understand in their daily work -Real examples and creative campaign ideas showing how admins have created wildly successful cybersecurity awareness campaigns -Simple gamification techniques that transform passive learning into competitive fun -How to select the right training modules that entertain while they educate and why it matters -How to maintain momentum and engagement long after Cybersecurity Awareness Month ends Join us to get practical tools and creative ideas that will make your Cybersecurity Awareness Month campaign the talk of the organization while dramatically reducing your human risk.

2025/10/14
阅读更多

Ready to Launch Your Cybersecurity Career After Military or Government Service?

Making the move from military or government roles to the civilian cybersecurity workforce can feel like a big shift. The good news: your discipline, leadership, and technical expertise are in high demand — if you know how to showcase them. That’s where ISC2 comes in. Join us for an exclusive webinar featuring two of our own accomplished veterans: · Timothy Campo – Former Navy Information Warfare Naval Officer, now leading Security and Technical Operations at ISC2. · William Orr – USMC veteran and current ISC2 Standards Development Manager. Together, they’ll share first-hand insights on: · Translating your military experience into language that resonates with employers. · Leveraging your transferable skills to stand out in the corporate world. · Unlocking the career growth, flexibility, and opportunities unique to civilian cybersecurity. Don’t miss this chance to gain practical tools, resources, and insider advice to position yourself for success — and land your next role with confidence.

2025/9/30
阅读更多

The Workforce Under Pressure: Burnout, Skills Gaps and Organizational Risk (#1)

Cybersecurity professionals are under more pressure than ever—with 90% of teams reporting skills gaps, 67% facing staffing shortages, and burnout rising across roles. In this opening session, we reveal the latest workforce data from ISC2, CyberSN and Cybermindz to unpack the human and operational impacts of today’s talent crisis. Speakers will explore how stress, role ambiguity, and unsustainable workloads are accelerating risk—both personal and organizational—and introduce the concept of mental resilience as an essential component of operational readiness. Attendees will gain insights into identifying burnout risks in themselves and their teams, along with practical guidance for setting healthier boundaries at work.

2025/9/30
阅读更多

Securing the Future: AI, Resilience, and Evolving Cyber Roles (#3)

As AI reshapes job functions and workflows across cybersecurity, professionals face new questions: Which roles will grow or disappear? What skills will matter most? And how can we stay resilient amid constant change? In this forward-looking session, we explore ISC2 data on AI’s workforce impact alongside real-world insights from hiring trends and resilience research. Speakers will discuss how to prepare for the evolving landscape—from emerging AI-related security roles to the enduring value of human skills like judgment, adaptability, and emotional regulation. Attendees will leave with a clearer view of how to future-proof their careers—and their well-being—in an AI-driven world.

2025/9/18
阅读更多

From Shield to Spear: How AI is Reshaping Cyber Defense and Offense

The rise of artificial intelligence in cybersecurity is both a blessing and a curse. AI is redefining the cybersecurity battlefield, offering unprecedented advantages for security teams and threat actors. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores AI’s transformative impact on the IT security industry. On the defense side, AI is revolutionizing threat detection, automating incident response, and predicting vulnerabilities before they’re exploited. However, threat actors are also leveraging AI to enhance phishing attacks, create evasive malware, and orchestrate sophisticated social engineering campaigns. This webinar provides a balanced view of AI’s dual role in cybersecurity, showcasing both the opportunities and challenges it presents. Gain insights into how IT security teams can adopt AI to stay ahead, while understanding how adversaries may use it to their advantage. With expert commentary and real-world examples, this session equips attendees with the knowledge to navigate AI’s impact on the evolving threat landscape.

2025/9/17
阅读更多

Navigating Malware-Free Attacks

We started with a simple question: what do modern attackers do? After analyzing over 700,000 security incidents, one technique was almost universally present: a staggering 84% of major attacks incorporated Living Off The Land (LOTL) tactics, using the same native tools and utilities your administrators use every day. If the tools are the same, how do you tell an attacker from a user? To find out, we turned our focus to legitimate usage data. By comparing this legitimate activity side-by-side with the malicious activity, we found quite a lot of interesting patterns. Join the Bitdefender team and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific on September 16, 2025 to get actionable insights from real-world attacks to better detect threats hiding in plain sight.

2025/9/16
阅读更多

Your Sneak Peek into Cybersecurity and Business Alignment at ISC2 Security Congress 2025- #3

ISC2 Security Congress 2025 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! Join three of our esteemed conference speakers as they preview their upcoming presentations, all of which relate to aligning cybersecurity strategy with business needs. By joining this webinar you’ll get a snapshot of session content, which includes the following presentations: · Building Robust Enterprise-wide Business Information Security Officer (BISO) Programs: Key Elements for Success · Cybersecurity: From Cost Center to Competitive Advantage · Drop-Shipping a New Security Department into a Multibillion-Dollar Company Join us live Sept. 11, 2025 at 1:00 p.m. Eastern/10:00 a.m.Pacific to be among the first to gain valuable insights into these sessions, plus have an opportunity to as your questions. Like what you see? Register for ISC2 Security Congress 2025 to unlock access to even more great content this October: https://web.cvent.com/event/00885cdc-a7ef-4682-81d1-77950c2f3d07/websitePage:e3e1427f-5c48-423a-a0e5-60dcec1c4363?RefId=Attend&utm_campaign=GBL-SecurityCongress&utm_content=congress&utm_medium=bannerep&utm_source=isc2web&utm_term=eventpage

2025/9/11
阅读更多

The Do's and Don'ts of Device Control Beyond USB Storage

Modern Device Control needs to support multiple data transfer channels, adapt to emerging business and compliance requirements, and provide detailed, context-aware protections without compromising productivity. Today, data leaves organizations not only through USB sticks, but also through wireless methods such as Bluetooth, local and network printers, peer-to-peer sharing tools like AirDrop, mobile devices, and specialized ports, such as FireWire. Managing these risks is further compounded by mixed OS environments that include Windows, macOS, and Linux. During this webinar on September 3, 2025, at 1:00 p.m. Eastern/10:00 a.m. Pacific, attendees will learn how to overcome challenges related to: - Device Control: Data loss via USB, Bluetooth, printers, mobile devices, and more - Ransomware Protection: Blocking unauthorized devices completely and eliminating risk at the hardware level - Enforcing Encryption: Encrypting files and devices to accommodate authorized data transfers while controlling access to decryption keys - DLP for Mixed OS Environments: Overcoming the unique device control and DLP challenges associated with environments that include Windows, macOS and Linux.

2025/9/3
阅读更多

Eat Well, Work Well: Nutrition for Cybersecurity and High-Stress Careers

Burnout is a growing concern in cybersecurity, but nutrition can be a powerful tool to combat it. The Center hosted a webinar with Melissa Majumdar, MS, RD, CSOWM, LDN, who shared science-backed strategies for sustaining energy, improving focus, and building healthy habits under pressure.

2025/9/3
阅读更多

Managing Human Risk in an AI-Driven Threat Landscape: Are Your Defenses Evolving Fast Enough

Cybercriminals have moved beyond spray-and-pray phishing campaigns into the age of AI-powered precision attacks. Using generative AI, they're now creating hyper-personalized scams that mimic your colleagues' writing styles, clone your CEO's voice for vishing attacks, and craft multi-channel campaigns designed to slip past both technical controls and human intuition. In this eye-opening webinar at 1:00 p.m. Eastern/10:00 a.m. Pacific on September 2, 2025 KnowBe4 and ISC2 strip away the AI hype and exposes the stark reality of how artificial intelligence is transforming social engineering, making your people simultaneously your greatest vulnerability and your most critical defense. Join us and discover: • AI Threat Evolution: How attackers are using generative AI to scale sophisticated attacks that previously required weeks of research into automated campaigns launched in minutes • Deepfake Danger Zone: Real-world case studies of voice cloning, video manipulation and other AI-powered tactics that have successfully compromised organizations • Psychological Warfare 2.0: How AI allows attackers to exploit cognitive biases and emotional triggers with unprecedented precision • Human Risk Quantification: Practical frameworks for measuring your organization's human attack surface and tracking improvements over time • Next-Gen Defense Strategies: Actionable techniques to transform your security awareness program to counter AI-enhanced social engineering Whether you're securing a small business or a global enterprise, you'll walk away with concrete strategies to prepare your workforce for the AI threat revolution already underway.

2025/9/2
阅读更多

Security Report Trends - Without the Reading

So many security reports, so little time! Join our experts as we cut through the noise to highlight the trends that truly matter. In this session, we’ll explore: - SIEM Re-evaluation: Why 75% of CISOs are rethinking their strategies - The Rise of AI: How artificial intelligence is reshaping security practices (because we can't have a conversation without AI in 2025) - Emerging Threats and Vital Capabilities: What security leaders must prioritize to stay ahead From practitioner to CISO, you’ll leave with a more clear understanding of the market shifts and actionable insights from the latest security reports.

2025/8/28
阅读更多

ISC2 Security Congress 2025 | Sneak Peek Into Pre-Conference Workshops

Ready to maximize your ISC2 Security Congress 2025 experience? Get a first look at the hands-on workshops that will jump start your journey with expert guidance into specialized topics. Join three of our esteemed facilitators for an exclusive preview of some the workshops being hosted in Nashville leading up to ISC2 Security Congress. By joining this webinar you’ll get a snapshot of workshop content, which includes: - Transforming Cyber Leadership: Build strategies to lead teams, drive innovation, and strengthen organizational impact. - Vendor Contract Reviews: Managing Privacy, Cybersecurity and AI Risks: Learn practical techniques to address privacy, cybersecurity, and AI risks in contracts. - Threat Modeling AI Systems: Hands-on approach to identifying and mitigating risks in Agentic AI systems. Join us live August 21, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific to be among the first to gain insights into these add-on experiences, plus have an opportunity to ask your questions. Interesting in learning more? Visit the <a href="https://www.isc2.org/Congress">ISC2 Security Congress website</a> and <a href="https://web.cvent.com/event/00885cdc-a7ef-4682-81d1-77950c2f3d07/websitePage:322284a9-ca0d-4674-b9a0-291acfc91d60?RefId=Attend">Pre-Conference Workshop page</a> for more great information on the event.

2025/8/21
阅读更多

The Future is Here: Top IT Security Technologies Shaping 2025

Today’s cyberthreat landscape is marked by sophisticated attacks, including ransomware, deepfakes, and advanced persistent threats. The rise of AI-powered malware, supply chain vulnerabilities, and insider risks compounds challenges. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he explores the cutting-edge advancements driving the evolution of IT security, such as continuous threat exposure management (CTEM), identity threat detection and response (ITDR), passwordless authentication, and more. This session offers practical advice on implementing these innovations to protect your organization against complex and emerging risks. Whether you’re planning for growth or looking to bolster your current defenses, this webinar delivers the insights you need.

2025/8/20
阅读更多

Global Insights: New Research on Early-Career Hiring Trends

Cybersecurity has traditionally been a high-demand field, but today’s economic and geopolitical pressures are weighing on teams like never before. Hiring managers now face budget pressures and fiercer competition for talent, especially at the entry and junior levels. To better understand how organizations are navigating this environment, ISC2 surveyed 929 hiring managers across six countries with growing or established cybersecurity staffing needs. All had recently hired for early-career roles, offering a timely snapshot of current trends in candidate sourcing, the hiring process, the role of certifications, top skill requirements, and expectations for entry- and junior-level cybersecurity professionals. Join us August 14, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we dive deep into these insights!

2025/8/14
阅读更多

Crypto-Agility: How It’s Both a Critical Component and a Complex Challenge

Crypto-agility is critical to digital security. The need to encrypt everything that we see in best practices, like Zero Trust, requires crypto-agility, as does preparing for the transition of tomorrow’s post-quantum reality. This webinar with Entrust and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific on August 12, 2025 will help organizations achieve a mature crypto-agile security practice and learn to overcome the challenges to get there—from people and processes to technology.  Attendees will learn: -Why crypto-agility is essential -How to assess your organization’s crypto readiness -Key steps to building a strong cryptographic infrastructure -How crypto-agility reduces risk and boosts innovation

2025/8/12
阅读更多

Your Sneak Peek into Quantum at ISC2 Security Congress 2025 (#2)

ISC2 Security Congress 2025 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! Join three of our esteemed conference speakers as they provide highlights into their session content – all focused around post-quantum encryption. By joining this session you’ll get a snapshot of session content, which includes the following presentations: • Applied Quantum Cybersecurity Research for All: Go Beyond the Hype with the Rensselaer Cybersecurity Collaboratory and the Students Doing the Real Work • Leading Security into a Post-Quantum Future • Quantum Preparedness: Operationalizing NIST, ISO, and CISA Frameworks for Post-Quantum Cryptography Migration Join us live August 7, 2025 at 1:00 p.m. Eastern/10:00 a.m.Pacific to be among the first to gain valuable insights into these sessions, plus have an opportunity to ask your questions. Like what you see? Register for ISC2 Security Congress 2025 to unlock access to even more great content this October: https://web.cvent.com/event/00885cdc-a7ef-4682-81d1-77950c2f3d07/websitePage:e3e1427f-5c48-423a-a0e5-60dcec1c4363?RefId=Attend&utm_campaign=GBL-SecurityCongress&utm_content=congress&utm_medium=bannerep&utm_source=isc2web&utm_term=eventpage

2025/8/7
阅读更多

Beyond the SBOM: What Real Software Supply Chain Security Looks Like

SBOMs are just the beginning. Security teams need deeper visibility, tighter control, and faster response across the entire software delivery pipeline. On July 31, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific, JFrog and ISC2 will break down what lies beyond Software Bill of Materials (SBOMs), from runtime integrity to compliance mapping, and shares actionable ways to protect your pipeline from emerging threats. If you're struggling to connect the dots across your tools and teams, this session will help you build a truly resilient supply chain.

2025/7/31
阅读更多

5 Types of Penetration Testing and Why Continuous Testing Wins

Penetration testing remains a core pillar of cybersecurity, but not all tests are created equal. This webinar with Sprocket Security and ISC2 on July 24, 2025 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific explores 5 types of penetration testing: 1. Point-in-time pentest 2. PTaaS 3. Bug Bounty 4. Automated security testing 5. Continuous penetration testing Attendees will gain insight into the strengths and limitations each type brings. We’ll then examine why continuous penetration testing (CPT) offers superior protection in dynamic environments, helping security teams identify and mitigate threats in real-time.

2025/7/24
阅读更多

Surviving Ransomware: Strategies to Defend, Respond, and Recover

Ransomware attacks have reached unprecedented levels of sophistication, targeting organizations across all industries and sectors. As these threats evolve, so too must the strategies to combat them. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he provides a deep dive into strategies that can help organizations effectively navigate the ransomware threat lifecycle. From advanced prevention techniques and risk mitigation to streamlined recovery processes, this session covers every critical aspect of ransomware readiness. Don’t let ransomware catch you off guard—join us to build your defenses, improve your response capabilities, and recover faster when faced with a ransomware event.

2025/7/23
阅读更多

Your Sneak Peek into AI at ISC2 Security Congress 2025 (#1)

ISC2 Security Congress 2025 is right around the corner, and we’re so excited about this year’s speaker line-up that we decided to bring a sample of this year’s content to you early! Join three of our esteemed conference speakers as they provide highlights into their session content – all focused around AI. By joining this session you’ll get a snapshot of session content, which includes the following presentations: Agentic AI: Navigating the Uncharted Waters of Non-Human Identity and Liability How AI Will Shape the Shift-Left approach in AppSec Threat Modeling AI: STRIDE Was a Good Start, But This Is Weirder Join us live to be among the first to gain valuable insights into these sessions, plus have an opportunity to as your questions. Like what you see? Register for ISC2 Security Congress 2025to unlock access to even more great content this October. You won’t want to miss this enlightening webinar that's the first in a series of three, 2025 Security Congress Sneak Peek webinars!

2025/7/22
阅读更多

AI vs. AI: Transforming Cybersecurity Through Proactive Technologies

Cybercriminals are using AI to outsmart traditional defenses, making the world more dangerous for the rest of us. They're deploying AI-generated deepfake videos to impersonate executives and using AI-powered chatbots to mimic trusted colleagues in sophisticated social engineering attacks. But as an IT professional, you have the power to turn the tables. Now is the time to leverage the power of AI to protect your organization and gain a critical edge in cybersecurity. On July 17, 2025 join KnowBe4 and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a session where we will discuss how your organization can harness AI-powered agents for real-time threat detection, predictive analytics and automated training. You'll learn: - Jaw-dropping examples of hyper-personalized phishing and shape-shifting malware attacks - New strategies to deploy AI and autonomous agents as your 24/7 cyber guardians - How to harness predictive analytics to stay two steps ahead of evolving threats - About the ethical minefield of AI in cybersecurity and how to navigate it safely - Practical, actionable steps to leverage AI in your human risk management strategy. Attend this webinar to arm yourself with the knowledge and strategies you need!

2025/7/17
阅读更多

Certified Cloud Security Professional (CCSP) Info Session

Join us for a deep dive into Certified Cloud Security Professional (CCSP), the cloud security credential from ISC2, creator of the CISSP. As cyber threats make daily headlines, the need for cloud security experts is at an all-time high. Yet talent is scarce. The cyber workforce needs an influx of 3.4 million more professionals to meet global demand. As a result, the career opportunities for CCSP-certified professionals are near limitless. In this 60-minute live virtual session, you’ll learn: - If CCSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CCSP questions during the Q&A section. Register now and begin your CCSP certification journey today!

2025/7/16
阅读更多

Hacked, Hijacked, Exposed: The Email Threats Powering Global Attacks

Despite an expanding ecosystem of security tools and vendors, attackers continue to breach critical systems, exploit vulnerabilities, and siphon millions from organizations around the globe. Email remains their most reliable entry point. In this Proofpoint and ISC2 webinar on July 15, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific, we will unpack the latest intelligence on nation-state actors, cybercriminal campaigns, and shifting TTPs—drawing from real-world data and observed activity sets across our global telemetry.  We’ll begin with a high-level discussion of the evolving threat landscape, then dive into recent research findings, including the transformation of financially motivated groups into national security threats. Finally, we will demonstrate how these insights shape our product capabilities—showing how detection engineering and threat hunting drive real-time defense in your environment.  Join us to learn more!

2025/7/15
阅读更多

Closing the Gaps: Strengthen Endpoint Security with Proactive Remediation

As cyber threats grow more advanced, many organizations are still relying on fragmented tools and manual processes to identify and remediate vulnerabilities—leaving critical gaps in their security posture. In this webinar, join NinjaOne and ISC2 July 10, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a forward-looking discussion on how IT and security teams can modernize their approach to vulnerability management. We’ll explore strategies for reducing complexity, closing exposure windows faster, and building a more proactive security framework across your entire endpoint environment. Key takeaways will include: -How to automate and prioritize vulnerability data using risk-based intelligence (e.g., CVE, CVSS) -Tactics for accelerating patch deployment to minimize risk and reduce response times -The role of AI and sentiment analysis in evaluating patch relevance and risk Best practices for tracking remediation outcomes to ensure vulnerabilities are fully addressed Whether you’re looking to strengthen your current security operations or rethink your patching strategy, this session will offer practical insights you can apply immediately.

2025/7/10
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2025/6/27
阅读更多

Zero Trust, Unfiltered: Field-Tested Insights for Leaders Navigating Change

Zero Trust is widely discussed but often misunderstood — and even more rarely implemented effectively. This session offers a practical, experience-driven perspective on how organizations can move beyond Zero Trust theory and begin executing with purpose. Through the lens of the Zero Trust Maturity Model (ZTMM), we will explore the stages of Zero Trust adoption, the common barriers that impede progress, and the critical role of leadership, visibility, and automation in achieving lasting security outcomes. Akamai and ISC2 host this session on June 26, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific. Join us to gain an informed view of how to prioritize initiatives, align stakeholders, and advance toward a more resilient and adaptive security posture. Key Takeaways include: • A clear, operational definition of Zero Trust — and why urgency has accelerated • A breakdown of the ZTMM stages, with insights into common failure points • Practical guidance on where to start for maximum security and business impact • Lessons learned from the field: what works, what doesn’t, and why • The evolving role of AI and automation in scaling Zero Trust architectures

2025/6/26
阅读更多

Best Practices for Cloud Detection and Response: Real-World Lessons from Multi-Cloud Attacks

As cloud adoption surges, so does the speed and sophistication of attacks. Traditional static detection and response can’t keep up in today’s fast-moving, multi-cloud environments. Join Palo Alto Networks and ISC2 June 24, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific to explore actionable best practices for modern cloud detection, investigation, and response (CDR). We’ll cover how security teams are leveraging CDR to keep up with the speed and diversity of cloud-native attacks. In this session, you'll learn: - Lessons from real-world multi-cloud incidents - Why cloud security must start with prevention, not just detection - How to cut through the noise and focus on what really matters - Key capabilities to demand in a CDR solution — and red flags to avoid - How to ready your SecOps team for cloud-native response

2025/6/24
阅读更多

The Rise of Deepfakes: How Smart Security Teams Stay Ahead

Deepfakes are no longer a distant concern—they’re an active threat to businesses, governments, and individuals. As deepfake technology grows more sophisticated, security teams face mounting challenges in combating its misuse. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he discusses the evolution of deepfakes, methods for their detection, and strategies for mitigating risks. From leveraging AI to enhance defenses to improving security awareness amongst your workforce, attendees will gain actionable guidance to stay ahead of this growing challenge.

2025/6/18
阅读更多

Certified in Cybersecurity (CC) Info Session

Join us for a deep dive into Certified in Cybersecurity (CC), the entry-level cybersecurity credential from ISC2, creator of the CISSP. Cyberthreats continue to escalate worldwide, and the need for cybersecurity experts is critical. But talent is scarce. Research shows the workforce needs an influx of 3.4 million cybersecurity professionals to meet global demand. ISC2 seeks to help close the skills gap with CC by opening opportunities in the industry to a new pool of professionals. With no experience required, it creates a clear pathway and breaks down traditional barriers to entry, enabling candidates to build confidence and enter their first cybersecurity role ready for what’s next. In this 60-minute live virtual session, you’ll learn: - If CC is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to maintain your certification Plus! Get answers to your CC questions during the Q&A section. Register now and begin your CC certification journey today!

2025/6/11
阅读更多

A Day in the Life of a Penetration Tester

Ever wonder what it is like to be a in the role of a Cybersecurity Penetration Tester? Constantly on the lookout for vulnerabilities, always playing on the offensive and looking for bugs in new security code? It’s time you found out! Join us May 27,2025 at 1:00 pm BST/8:00 a.m. Eastern for a new ISC2 live webinar series where we explore A Day in the Life of… a featured cybersecurity role. In this first episode, we talk to professionals who are working as penetration testers. Join us to learn: -How did our esteemed panelists land their current roles? -What kind of skills are needed in the role of a penetration tester? -What do penetration testers really do in their day-to-day jobs? -What are some common difficulties faced while on the job? What are the biggest benefits? -Do you need some kind of specific certification/s, degree or background to do this type of work? -What kind of advice do these professionals have for those looking to land these kinds of roles?

2025/5/27
阅读更多

How to Ensure Your SOC is Built for Tomorrow’s Threats

The cybersecurity landscape is evolving at an unprecedented pace, and organizations must ensure their Security Information and Event Management (SIEM) solutions don’t merely keep up with emerging threats and compliance requirements but also provide room to adapt and grow. In this exclusive webinar, Sumo Logic will share insights on navigating SIEM implementation and optimization in a growing, cloud-first world. Learn why a modern SIEM is the cornerstone of an effective security practice, how to log critical data efficiently, and what’s the horizon for security operations. Key Takeaways: - Essential SIEM capabilities to secure your organization from evolving cyber threats. - Strategies to increase fidelity, scale security operations, and improve resilience. - How to streamline security monitoring and compliance reporting.

2025/5/23
阅读更多

From Legacy to Leading-Edge: How to Maximize Your Vulnerability Management Investment

Legacy vulnerability management approaches often struggle to keep pace with today’s dynamic threat landscape. Maximizing the value of your vulnerability management program requires moving beyond outdated practices to adopt a proactive and risk-based approach. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he shares strategies for transforming legacy vulnerability management systems into efficient, leading-edge cyber exposure programs that prioritize high-risk vulnerabilities, streamline workflows, and reduce attack surfaces. Gain insights into leveraging automation, integrating threat intelligence, and driving measurable improvements in your organization’s security posture.

2025/5/21
阅读更多

A Primer on Quantum: What Makes It "Revolutionary?"

In this webinar, we will explore a range of topics centered on the world of quantum computing and why it is relevant to cybersecurity professionals. The session will cover: Basic concepts: What is quantum, what it is used for and why is it “revolutionary”? The current state of quantum computing in the development cycle, plus a speculative look at how long it may take for a quantum-relevant computer to be developed The challenges within quantum computer development and why they are important for scale How quantum will change what we have to do in cryptography, and why The coming problem: What actions are being taken and should be taken to prepare for and be resilient to the quantum threat The webinar is aimed at those wishing to gain some general knowledge around the subject and its impact to security professionals. It is not a deep exploration of quantum mechanics and math!

2025/5/20
阅读更多

Certificated in Governance, Risk and Compliance (CGRC) Info Session

Join us for a deep dive into Certified in Governance, Risk and Compliance (CGRC), the governance, risk and compliance credential from ISC2, creator of the CISSP. The CGRC is an information security practitioner who champions system security commensurate with an organization’s mission and risk tolerance, while meeting legal and regulatory requirements. CGRC, a vendor-neutral cybersecurity credential, recognizes your knowledge, skills and abilities to authorize and maintain information systems within the RMF. It proves you know how to formalize processes to assess risk and establish security documentation. CGRC is particularly well-suited for IT, information security and cybersecurity practitioners who manage risk in information systems. It is also recommended for any practitioner involved in authorizing and maintaining information systems. In this 60-minute live virtual session, you’ll learn: - If CGRC is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CGRC questions during the Q&A section. Register now and begin your CGRC certification journey today!

2025/5/14
阅读更多

Agentic AI Ransomware: What You Need to Know

Brace yourself for agentic AI ransomware – a terrifying fusion of cutting-edge tech and malicious intent that's set to redefine cyber threats as we know them. Unlike traditional ransomware, which follows pre-programmed rules, agentic AI ransomware can adapt its behavior in real-time based on its environment and the defenses it encounters. Is your organization prepared? Join KnowBe4 and ISC2 on May 8, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this mind-blowing webinar where Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist, pulls back the curtain on the looming threat of AI-powered ransomware. Don't let your organization become a case study in what NOT to do when faced with this new breed of ransomware! In this webinar you’ll discover: - Agentic AI and why it's keeping cybersecurity experts up at night. - A glimpse into the future: what Agentic AI malware looks like and how it operates - The terrifying mechanics behind Agentic AI Ransomware Battle-tested strategies to fortify your defenses against this AI-driven attack - How to stay one step ahead with next-generation defense tactics against evolving AI threats Don't be caught with your defenses down. Join us and arm yourself with strategies you need to protect your organization in this new era of AI-powered cyber warfare.

2025/5/8
阅读更多

Key Insights from CyberEdge’s 2025 Cyberthreat Defense Report

CyberEdge’s annual Cyberthreat Defense Report (CDR) has become a staple for assessing organizations’ security postures, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. It incorporates dozens of insights from 1,200 security professionals from 17 countries and 19 industries. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he reviews key findings from CyberEdge’s 2025 CDR, including: - The percentage of organizations victimized by cyber attacks - The percentage of organizations victimized by ransomware attacks - The health of IT security budgets - The hottest security technologies planned for acquisition - Adoption of best practices for securing modern networks

2025/4/16
阅读更多

Certified Information Systems Security Professional (CISSP) Info Session

Join us for a deep dive into Certified Information Systems Security Professional (CISSP), the cybersecurity leadership credential from ISC2. Earning the CISSP is an investment in your future and an important next step in your career. Consistently recognized globally as the gold standard cybersecurity certification, it distinguishes you as a leader committed to excellence. CISSP certification demonstrates that you have the advanced knowledge and technical skills to design, develop and manage an organization’s overall security posture. If you’re vendor-certified, it expands the depth and breadth of your knowledge and positions your skills as more versatile. In this 60-minute live virtual session, you’ll learn: - If CISSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your CISSP questions during the Q&A section. Register now and begin your CISSP certification journey today!

2025/4/9
阅读更多

Navigating Work-Life Balance in the Cybersecurity Field

Cybersecurity is a high-pressure industry that frequently requires extended hours and can be stressful, making it tough to achieve a healthy work-life balance. Tune into this webinar to learn how to manage a healthy work-life balance, create solutions and thrive both professionally and personally in the cybersecurity industry!

2025/3/27
阅读更多

Beyond the Buzzword: Achieving Real Value with Zero Trust Security

Zero Trust Security has moved from a trending buzzword to a cornerstone of modern cybersecurity strategy. But how can organizations move beyond theory to achieve measurable value? Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he discusses the key principles of Zero Trust, practical steps to reduce attack surfaces, and methods for improving resilience against emerging threats. He’ll delve into the operationalization of Zero Trust, exploring how organizations can transcend theoretical discussions to achieve meaningful outcomes. Whether you're starting your Zero Trust journey or seeking to refine your existing approach, this session provides actionable insights to elevate your security framework from concept to impactful execution.

2025/3/19
阅读更多

Augmenting Microsoft to Defeat the Email Hacker Playbook

In today’s evolving cyber landscape, email threats are becoming increasingly sophisticated, often bypassing Microsoft’s built-in email defenses. Cybercriminals are leveraging advanced social engineering and generative AI to craft highly evasive attacks. These threats are growing in volume and complexity, making traditional email security methods insufficient. Today’s organizations need a comprehensive, adaptive, and effective approach to protect their greatest asserts and biggest risks: people. On March 11, 2025, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Proofpoint and ISC2 as we explore how these attacks unfold and the strategies you can implement to stay protected. By attending this webinar, you will gain insights into: - The latest trends in the threat landscape - The anatomy of these attacks and real-world threat examples - Best practice prevention and AI techniques

2025/3/11
阅读更多

Bridging the Gap: Strategies to Overcome the Cybersecurity Skills Shortage

The cybersecurity talent crisis poses significant risks to organizations worldwide. It’s leaving businesses vulnerable to escalating threats as they struggle to find qualified professionals to secure their systems. This talent gap hampers incident response, delays security improvements, and increases the risk of breaches. Organizations face higher costs, operational disruptions, and reputational damage as they compete for scarce expertise. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he describes how smart IT leaders can respond with effective recruiting, training, and retention strategies. He’ll also highlight creative approaches, such as leveraging untapped talent pools, implementing mentorship programs, and embracing flexible career pathways. Gain practical tools to attract skilled professionals, support team development, and reduce turnover, ensuring your security team remains strong in the face of emerging threats. Don’t miss this opportunity to turn workforce challenges into strategic advantages.

2025/2/26
阅读更多

North Korea’s Secret IT Army: Has Your Workforce Been Infiltrated?

Organizations around the world are unknowingly recruiting and hiring fake employees and contractors from North Korea. These sophisticated operatives aim to earn high salaries while potentially stealing money and confidential information - a chilling fact that KnowBe4 recently learned firsthand when we discovered and stopped one of these operatives at our own organization. Since sharing our experience, we've discovered that many others have faced similar situations, too. On February 6, 2025 at 1:00 p.m. Eastern/10 a.m. Pacific, join KnowBe4 and ISC2 for this webinar where we will talk about what KnowBe4 learned and discuss how you can stay one step ahead. During the webinar we will cover: - Stories of fake North Korean employees and contractors hired by unsuspecting organizations - Red flags to watch out for to spot a fake employee job submission or resume - How to tell if you've got a fake North Korean employee or contractor already on the payroll - What updates and best practices you can start using today to keep bad actors out of your organization, and what to do if you suspect you may have already hired one Don't miss this critical webinar that could be the difference between safeguarding your organization's assets and unknowingly inviting a potential security breach right in.

2025/2/6
阅读更多

Do CISOs Need Their Own Legal Counsel? Some Lessons from SolarWinds and Uber

In October 2023, the U.S. Securities and Exchange Commission (SEC) filed a civil complaint against SolarWinds and its CISO, Timothy Brown. The charges stemmed from the September 2019 intrusion by threat actors into SolarWinds, which affected some 18,000 customers. This action by the SEC is likely the first time the agency targeted a CISO for alleged cybersecurity failures. It comes on the heels of the October 2022 criminal conviction of Uber CSO Joe Sullivan for withholding information about a 2016 breach at Uber from federal investigators. All of this raises an important issue for CISOs: Should they have their own legal counsel to guide them on legal compliance and working with regulatory agencies? And if so, who should pay – them, or their employers? In this presentation by cybersecurity attorneys, we’ll take a deep dive into the hard choices that modern CISOs face and some possible ways forward. Takeaways include: · Evaluating the SolarWinds and Uber cases and the claims against the CISOs · Understanding at what point a CISO needs to hire independent legal counsel · Exploring the various types of insurance and why your policy may be the wrong one

2025/1/9
阅读更多

AI-Enabled Compliance: Your Secret Weapon for Smarter Security

Today, artificial intelligence presents both unprecedented opportunities and unique challenges for security teams. Grab your coffee and join our webinar to explore the intersection of AI, compliance, and security. On December 19th at 1:00 p.m. Eastern/10:00 a.m. Pacific, RegScale and ISC2 demonstrate how AI-enabled compliance can serve as a powerful tool to strengthen your organization’s security posture. You’ll learn: -The symbiotic relationship between good security practices and effective compliance measures - Strategies for securing AI systems while meeting stringent compliance requirements - How Continuous Controls Monitoring (CCM) automates compliance processes - Implementing AI compliance as guardrails to enhance overall security, including the security of AI applications Join us for this 30 minute session to learn how to gain an AI edge and make compliance your secret weapon for smarter, more robust security in the age of artificial intelligence.

2024/12/19
阅读更多

Top Five Cybersecurity Predictions for 2025

Embark on a foresight journey into the future of cybersecurity, highlighting key trends and innovations that are set to redefine the digital defense landscape in the year ahead. Discover how advancements in artificial intelligence will revolutionize the way security teams reduce cybersecurity risks and improve their abilities to defend against modern threats. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2025.

2024/12/4
阅读更多

All the Ways the Internet is Surveilling You

Your personal information is continuously harvested and analyzed by countless data brokers eager to sell to the highest bidder. From your name to your online activities, to your employment details and even your real-time location – all are on the market for anyone interested. On November 14, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific, KnowBe4 and ISC2 discuss the extensive surveillance enabled by the internet, the risks of your personal data falling into the hands of malicious entities, and methods to protect yourself. In this session, you will learn: -The various ways you are being surveilled, including through "free" GPS-enabled apps you've downloaded - How your digital footprint is commodified and utilized by social engineers - Techniques to detect signs of surveillance - Effective strategies to protect yourself from malicious tracking and defend against the tactics of social engineering Learn ways to keep your online information safe and protect yourself against malicious scams.

2024/11/14
阅读更多

Passwordless Authentication: A New Reality or a Pipe Dream?

Has your organization jumped on the passwordless authentication bandwagon yet? If not, it should. Passwordless authentication embraces possession factors, such as certificates and hardware tokens, and inherence factors, such as fingerprints and face scans, to replace legacy password and single sign-on (SSO) authentication methods. It also strengthens your organization’s security posture while improving the user experience for accessing company applications and data. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews modern passwordless authentication technologies and the benefits organizations have achieved by implementing them.

2024/11/13
阅读更多

The Invisible Workplace: Governing Data Access in a Hybrid, AI-Driven World

With companies adopting hybrid models—some employees working from home, others in multiple offices—managing data access has become increasingly complex. As AI tools generate large volumes of sensitive content, and the traditional security perimeter blurs, balancing security, compliance, and productivity is more challenging than ever. In this webinar on November 5, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific Netwrix and ISC2 discuss: • Creating governance policies for sensitive data to overcome challenges of hybrid teams and AI tools. • Reducing security risks across hybrid work environments without sacrificing productivity. • Practical steps to ensure compliance while managing data access in a workplace without clear boundaries.

2024/11/5
阅读更多

Security Industry 101: A ‘Crash Course’ For Security Newbies

New to the security industry? Or thinking about transitioning into an information security role? If so, this webinar is for you. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he provides a one-hour ‘crash course’ on the entire security industry, including: - Size and growth of the security industry - Useful vocabulary terms and buzz words - Five types of cyberthreat actors - Modern cyberthreats and tactics - Categories of security defenses - Common security job roles - Security industry ecosystem

2024/10/23
阅读更多

Managing Your Mental Health in the Cybersecurity Field

No CPE is provided for this webinar* Join Clinical Health Psychologist, Robyn Pashby, PhD, for an insightful webinar about managing your mental health in anxiety or stress inducing environments!

2024/10/3
阅读更多

Ransomware and Third-Party Global Supply Chains: Understanding & Mitigating Risks

CDK. Colonial Pipeline. UnitedHealth Group. What do all these companies have in common? They have all been subject to recent headline-making cyberattacks impacting the global product supply chain. Cyber incidents such as these can wreak havoc – preventing orders/payments, interrupting service, and in some cases cause detriment to human health and safety. There is no way to ignore that the vast majority of businesses rely on third-party partnerships to maintain their day-to-day operations. From a business perspective, third-party partnerships are seen as ways of reducing costs, creating efficiencies and enhancing access to goods and service. From a cyber perspective, they must be viewed as another threat surface. If your third-party partner is attacked – your data and business may be impacted as well. Join this panel of experts as they discuss and debate: · The underlying causes of most supply chain cybersecurity failures. · How to assess how secure your partners are against cyberattacks. · The value of strong business continuity procedures. · Success stories/case studies in reducing third party cyber risk exposure.

2024/9/26
阅读更多

Impact of AI on the Cybersecurity Industry: Who's Got the Upper Hand?

Artificial intelligence (AI) has bolstered cybersecurity solutions across the board. Security teams have more ways to detect advanced threats than ever before, and organizations are much better equipped to measure and reduce their attack surfaces. However, AI also benefits cyber adversaries with improved phishing and spear phishing techniques and new methods for tricking unsuspecting victims using deepfake content spawned by generative AI. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he provides a comprehensive analysis of AI's dual role in both fortifying and challenging modern cyber defenses. Discover who's winning the AI arms race in cybersecurity.

2024/9/25
阅读更多

New! AI-Driven Adaptive Learning for Systems Security Certified Practitioner

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced Systems Security Certified Practitioner (SSCP) Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder and go into the SSCP exam with confidence. You’ll learn: • Why it makes training more efficient busy professionals • What makes it a more efficient route to exam readiness • How artificial intelligence tailors learning to your needs • And much more! Wednesday, September 12 at 3pm ET Save your spot now.

2024/9/12
阅读更多

A Strategic Approach to Meeting the Newest PCI Requirements in a Cloud-Driven World

The accelerated shift to the cloud as well as new PCI DSS 4.0 requirements coming into effect by March 2025, present several challenges for financial institutions, ecommerce merchants, and others subject to its regulations. As IT teams have lost control of their digital environments due to an increased reliance on cloud computing and remote work, the process of solving challenges to meet compliance requirements has become more complex. As a result, it is more essential than ever for organizations to find a way to streamline compliance. Join this conversation to learn about: - What’s new and what’s driving PCI DSS 4.0 - Challenges of PCI compliance for today's digital world - Strategies and tools for organizations to address PCI requirements in a scalable and programmable way

2024/9/5
阅读更多

Risks of Identity and Credential-Based Cyber Attacks: A Real-World Cybersecurity Incident Walkthrough

Explore the digital footprints of a malicious hacker and uncover their attack path, as we take you for a journey inside the mind of a threat analyst responding to a cybersecurity incident that brought a business to a complete halt. Discover the evidence left behind, uncover the attack path, and understand the techniques used by the attackers. This session will delve into a real-world incident response, showcasing the methods employed by attackers to compromise identities and credentials. Join ISC2 and Delinea as we guide you through the steps taken by cybercriminals during a damaging identity compromise attack, including: • Access Gaining and Patient Zero Identification: Learn how attackers initially infiltrated systems and identified the first compromised system. • Establishing Staging, Footholds and Persistence: Understand how attackers set up their presence within the network and maintained access over time. • Tools and Commands Used: Discover the specific tools and commands utilized by the attackers, including RDP Brute Force, Mimikatz and Responder. • Credential Harvesting and Misuse: See how attackers harvested credentials and used them to escalate privileges and move laterally within the network. • Active Directory (AD) Elevation: Learn how attackers achieved AD elevation to gain further access and control over the infrastructure. Gain a comprehensive understanding of the tactics, techniques and procedures (TTPs) used by cyber criminals to compromise identities and credentials. This knowledge will empower you to better defend your organization against such cyberattacks.

2024/8/29
阅读更多

Five Smart Ways to Invest in Your Human Firewalls

Compromising end user computing devices through spear phishing attacks is frequently cited as the initial step of advanced persistent threats, often leading to data breaches. Year after year, IT security professionals cite “low security awareness among employees” as a top inhibitor to IT security’s success in CyberEdge’s annual Cyberthreat Defense Report. So, why aren’t more security teams adequately addressing this challenge? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he details five ways to invest in your company’s human firewalls.

2024/8/28
阅读更多

The ‘Hottest’ IT Security Technologies in 2024

Want to know which IT security technologies are hot and which ones are not? Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP), as he reviews key purchase insights from the 2024 Cyberthreat Defense Report. Specifically, Steve will examine which security technologies are most widely deployed and most planned for acquisition in 2024 so you can benchmark your company’s current and planned investments against your peers. Steve will review purchase intent across five key security technology categories, including: - Network security - Endpoint security - Application and data security - Security management and operations - Emerging security technologies

2024/7/24
阅读更多

Beyond DMARC: Best Practices for Impersonation Protection

Google and Yahoo announced a new set of requirements for email delivery last October, resulting in a rapid increase of DMARC (Domain-based Message Authentication, Reporting and Conformance) authentication adoption. However, meeting DMARC requirements is just the beginning. Impersonation risk remains — in the form of spoofed emails, brand abuse and threats from fake or compromised suppliers. Hijacked business communications often lead to significant financial losses and reputation damage. So how can your organization further mitigate impersonation risk even after you achieve DMARC compliance? Join Proofpoint and ISC2 on July 18, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we discuss: -Common impersonation tactics and real-world attack examples -Challenges and benefits of enforcing email authentication -Risks posed by impersonated suppliers -How AI is affecting threats like business email compromise (BEC) -Critical controls that help reduce impersonation risk

2024/7/18
阅读更多

Escalating Threats: Unveiling the Rise of DDoS Attacks in a Tense Global Climate

Denial of service (DoS) attacks more than doubled in 2023 compared with previous years. Attack size, frequency, and sophistication, have all increased which suggests that DDoS is far from being a solved problem.  Gobal geopolitical tensions rose dramatically during 2023 and, by no coincidence, so too did the quantity and ferocity of DDoS attacks. After a small but steady decline in denial-of-service attacks during 2022 and prior, 2023 saw an explosion of incidents many of which can be directly linked to political events and growing hacktivism. While many DDoS attacks are short lived inconveniences, many organizations and countries face persistent bombardment and increasingly sophisticated attacks. It begs the question: do organizations accurately evaluate the risk posed by DDoS attacks? Join F5 and ISC2 July 11, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we discuss the findings from F5 Labs' annual DDoS report. Join this threat research driven webinar to ...  -Understand how and why DDoS attacks have grown, and the tools and techniques used by threat actors -Explore the differences between regions and industries to understand how and why some are more targeted that others -Learn about effective mitigation strategies and the questions you should be asking of your DDoS protection solution

2024/7/11
阅读更多

New AI-Driven Adaptive Learning for Certified in Governance, Risk and Compliance

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced Certified in Governance, Risk and Compliance (CGRC) Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder and go into the CGRC exam with confidence. You’ll learn: - Why it makes training more efficient busy professionals - What makes it a more efficient route to exam readiness - How artificial intelligence tailors learning to your needs - And much more Wednesday July 10 at 1pm ET Save your spot now!

2024/7/10
阅读更多

Why Digital Transformation Requires Security Transformation with SSE

Digital transformation is not just about adopting new technologies but also about re-evaluating traditional security strategies for your modern business. As organizations pivot towards cloud-based environments and remote and hybrid work models, the traditional security perimeter has dissolved, necessitating a shift to Secure Service Edge (SSE) models. Join HPE and ISC2 for this session to learn: -How digital transformation has led organizations towards security transformation -Why security transformation is best achieved with a Security Service Edge (SSE) approach. -How SSE works for the modern business -How you can get started today

2024/7/2
阅读更多

Ransomware Deep Dive: To Pay or Not to Pay?

Colonial Pipeline, CNA Financial, JBS Foods, Garmin, and Travelex. All victimized by high-profile ransomware attacks. All paid ransoms. Did these companies do the right thing by paying ransoms to accelerate data and system recovery? Or are they merely funding the ransomware industry and prompting even more attacks? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews key findings from CyberEdge’s 2024 Cyberthreat Defense Report. In this webinar, Steve will: - Examine disturbing ransomware trends, by country and by industry - Evaluate key factors that go into deciding whether to pay ransoms - Outline ways to be prepared for a successful ransomware attack - Review technologies to help give security teams the upper hand

2024/6/26
阅读更多

Certified in Governance, Risk and Compliance (CGRC) Info Session

Join us for a deep dive into Certified in Governance, Risk and Compliance (CGRC), the governance, risk and compliance credential from ISC2, creator of the CISSP. The CGRC is an information security practitioner who champions system security commensurate with an organization’s mission and risk tolerance, while meeting legal and regulatory requirements. CGRC, a vendor-neutral cybersecurity credential, recognizes your knowledge, skills and abilities to authorize and maintain information systems within the RMF. It proves you know how to formalize processes to assess risk and establish security documentation. CGRC is particularly well-suited for IT, information security and cybersecurity practitioners who manage risk in information systems. It is also recommended for any practitioner involved in authorizing and maintaining information systems. In this 60-minute live virtual session, you’ll learn: - If CGRC is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your CGRC questions during the Q&A section. Register now and begin your CGRC certification journey today!

2024/6/12
阅读更多

Securing the Edge: Using SSE to Empower Zero Trust Access

Discover the integrated approach to network security and efficiency in our upcoming webinar, where we unravel the synergy between Security Service Edge (SSE), Software-Defined Wide Area Network (SD-WAN), and Secure Access Service Edge (SASE). This session will illuminate how the convergence of these technologies creates a robust, scalable, and agile framework for businesses navigating the complexities of digital transformation. Join HPE and ISC2 as we discuss practical insights on leveraging SSE and SD-WAN as foundational blocks to transition towards a comprehensive SASE model, ensuring end-to-end security and optimal network performance. This webinar will provide actionable strategies to enhance your business’s security posture and network management in the cloud era.

2024/5/23
阅读更多

Key Insights From the 2024 Cyberthreat Defense Report

CyberEdge’s annual Cyberthreat Defense Report (CDR) has become a staple for assessing organizations’ security postures, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. It incorporates dozens of insights from 1,200 security professionals from 17 countries and 19 industries. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews key findings from CyberEdge’s tenth-annual 2024 CDR, including: - The percentage of organizations victimized by cyber attacks - The percentage of organizations victimized by ransomware attacks - How AI helps both cybersecurity teams and cyber adversaries - Factors that improve overall job satisfaction among security professionals - The health of IT security budgets - The hottest security technologies planned for acquisition

2024/5/22
阅读更多

Unify How You Manage Risk

As attack surfaces continue to expand, managing cyber risk is becoming too complex: Security teams are slowed down by too much data, too many siloed tools, and too much manual effort to enforce protections across people and applications.   Discover unified risk posture – a simpler approach to mitigate risk more effectively with automated and dynamic controls. Exchanging risk indicators between the two platforms can help businesses adapt with agility to evolving dangers across their environments.   Join Cloudflare, CrowdStrike and ISC2 on May 16, 2024 at 1:00 pm Eastern/10:00 a.m. Pacific as we discuss strategies and practical guidance on how to manage risk across more of your expanding attack surface.

2024/5/16
阅读更多

Systems Security Certified Practitioner (SSCP) Info Session

Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today!

2024/5/8
阅读更多

Refreshed! ISC2 Online Self-Paced CISSP Training for Updated Exam

Join us for our live webinar where we’ll tell you all about refreshed training for the Certified Information Systems Security Professional (CISSP) exam update that launched on April 15, 2024. We’ll start with a look at what was updated in the exam and why. Then we’ll go into the details about AI-driven adaptive online training and how it helps you study smarter with a personalized experience. Agenda • CISSP Exam Update • Refreshed ISC2 Online Instructor-Led CISSP Training • Refreshed ISC2 Online Self-Paced CISSP Training • Benefits of AI-Driven Platform • Response: What the Data Shows • Q&A Save your spot now.

2024/5/2
阅读更多

Exploring Five Emerging Cybersecurity Defenses

In the world of cybersecurity defenses, the only constant is change. More than 3,500 cybersecurity vendors are continuously innovating, finding new ways to mitigate risks and secure modern computing environments. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews five emerging cybersecurity defenses, including: - SaaS security posture management (SSPM) - Cloud-native application protection platform (CNAPP) - Cloud infrastructure entitlement management (CIEM) - Identity threat detection and response (ITDR) - Passwordless authentication

2024/5/1
阅读更多

New! AI-Driven Adaptive Learning for Certified in Cybersecurity (CC)

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced Certified in Cybersecurity (CC) Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder and go into the CC exam with confidence. You’ll learn: - Why it makes training more efficient busy professionals - What makes it a more efficient route to exam readiness - How artificial intelligence tailors learning to your needs - And much more Wednesday April 24, 2024 at 1pm ET Save your spot now.

2024/4/24
阅读更多

API Security - 10 Best Practices for Strategically Applying AI

It is difficult to go anywhere in the security profession these days without the topics of artificial intelligence (AI) and API Security coming up.  Like many popular topics, there is quite a bit of buzz and hype which creates quite a bit of fog around the topics. In particular, it can be difficult to understand when AI can add value.  How can we know when AI is being leveraged in a useful way to creatively solve problems? AI works best when applied to specific problems and needs to be carefully, strategically, and methodically leveraged in order to tackle certain problems that suit it.  While there are many such problems, API security is one such problem that I’ve experienced AI producing good results for. Join F5 and ISC2 April 11, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a session on applying AI to API Security. We'll also share 10 best practices around API Security that you won’t want to miss!

2024/4/11
阅读更多

Certified Information Systems Security Professional (CISSP) Info Session

Join us for a deep dive into Certified Information Systems Security Professional (CISSP), the cybersecurity leadership credential from ISC2. Earning the CISSP is an investment in your future and an important next step in your career. Consistently recognized globally as the gold standard cybersecurity certification, it distinguishes you as a leader committed to excellence. CISSP certification demonstrates that you have the advanced knowledge and technical skills to design, develop and manage an organization’s overall security posture. If you’re vendor-certified, it expands the depth and breadth of your knowledge and positions your skills as more versatile. In this 60-minute live virtual session, you’ll learn: - If CISSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your CISSP questions during the Q&A section. Register now and begin your CISSP certification journey today!

2024/4/10
阅读更多

Trends from Hyperproof's 2024 IT Risk and Compliance Benchmark Report

Is your IT risk and compliance program ready for 2024 and beyond? For the last five years, Hyperproof has asked over 1,000 GRC professionals about their pain points, IT risk and compliance budgets, staffing, risk management best practices, and much more. We then compare results from the previous year, and provide an in-depth view of the market’s current state in our annual benchmark report. The 2024’s IT Risk and Compliance Benchmark report highlights a fascinating change in the overarching narrative of cybersecurity: respondents and key stakeholders from other departments are thinking about cybersecurity compliance as a key competitive differentiator rather than just a cost center. Join Hyperproof and ISC2 April 9, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn: -How unifying risk and compliance data affected survey respondents’ ability to mitigate risk, improve cybersecurity, and avoid breaches -Key trends for cybersecurity in 2024 -How the market has responded to AI risks in 2023 and how cybersecurity professionals plan on leveraging AI in 2024 -Why cybersecurity decision-making is becoming more collaborative with an integrated view of risk and compliance data.

2024/4/9
阅读更多

Your Digital Identity: How Cybercriminals Can Get Around Authentication Methods

Inadequate authentication measures leave your digital identity vulnerable to cybercriminals. Tools like multi-factor authentication, biometrics, passwords, PINs, and tokens are all more vulnerable to attacks and social engineering than you realize. And one wrong move leaves you and your organization powerless in the face of cyber threats. On April 2, 2024 at 1:00 pm Eastern/10:00 a.m. Pacific KnowBe4 and ISC2 take you through the ins and outs of authentication. We will also: - Take a deep dive into the authentication process and why strong authentication is vital to your organization’s security - Provide detailed explanations of authentication vulnerabilities for biometrics, MFA, passwords, and more - Show real-world examples of man-in-the-middle attacks, MFA bypasses, rogue recoveries and others - Share how to empower your end users to become your best last line of defense Your digital identity is the gateway to your organization's most valuable assets. Watch this webinar now to learn how to keep your fortress secure!

2024/4/2
阅读更多

Embracing a Passwordless Tomorrow: Unveiling the Future of Passwords

Are passwords on the brink of extinction, and what does a password-free era hold in store? In this enlightening session, delve into the comprehensive report by Delinea on the present and future trajectory of passwords. Gain invaluable insights from Delinea's survey of IT and cybersecurity leaders, along with practical strategies to contextualize the findings, including dispelling common password myths. Discover the dynamic evolution of passwords, bolstered by robust, user-friendly authentication methods such as Multi-Factor Authentication, biometrics, and Artificial Intelligence. Explore how Privileged Access Management (PAM) is evolving to address evolving needs, navigating the intricacies of workflow, technical nuances, and compliance imperatives to craft a forward-looking strategy. Witness how PAM streamlines password management, alleviates operational burdens, and empowers granular control over critical secrets.

2024/3/26
阅读更多

From Vulnerability Management to Exposure Management: Evolution or Revolution?

Vulnerability management has been a staple of security teams for decades. But if you haven’t noticed, this space has evolved considerably in recent years. Long gone are the days of lengthy, hard-to-digest vulnerability scanning reports often created to check the PCI compliance checkbox. These days, smart IT security teams are investing in exposure management platforms and embracing best practices to help prioritize which vulnerabilities to remediate first based on a variety of internal and external factors. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps the evolution from VA, to VM, to RBVM, to exposure management - Defines key elements of modern-day exposure management platforms - Reviews internal and external factors to help prioritize vulnerability remediation - Summarizes the extraordinary benefits derived from exposure management deployments - Describes what to look for when evaluating best-of-breed exposure management offerings

2024/3/20
阅读更多

Certified Cloud Security Professional (CCSP) Info Session

Join us for a deep dive into Certified Cloud Security Professional (CCSP), the cloud security credential from ISC2, creator of the CISSP. As cyber threats make daily headlines, the need for cloud security experts is at an all-time high. Yet talent is scarce. The cyber workforce needs an influx of 3.4 million more professionals to meet global demand. As a result, the career opportunities for CCSP-certified professionals are near limitless. CCSP, a vendor-neutral credential, not only provides a strong foundational understanding of key concepts, it shows you’re able to quickly learn and adapt to different scenarios, including working with platforms from different vendors. As more organizations worldwide move to multi-cloud operations, the versatile skills from vendor-neutral certification are highly desirable for cloud security teams. In this 60-minute live virtual session, you’ll learn: - If CCSP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your CCSP questions during the Q&A section. Register now and begin your CCSP certification journey today!

2024/3/13
阅读更多

New! AI-Driven Adaptive Learning for CSSLP

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced CSSLP Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder, and go into the CSSLP exam with confidence. You’ll learn: • Why it makes training more efficient busy professionals • What makes it a more efficient route to exam readiness • How artificial intelligence tailors learning to your needs • And much more Friday, March 8, 2024 at 1pm ET Save your spot now.

2024/3/8
阅读更多

ENHANCED! ISSAP Official ISC2 Online Self-Paced Training

Join us for this live webinar where we’ll tell you all about newly enhanced Official ISC2 Online Self-Paced Training for ISSAP. Find out how it provides a clear-cut and comprehensive review of the domains for a more structured and intuitive learning experience. We’ll also share details about the new second path to earning the ISSAP.

2024/3/6
阅读更多

Five Ways AI Improves Cybersecurity Defenses Today

Artificial intelligence (AI) is transforming the way cybersecurity vendors and service providers empower their customers to mitigate the risks of today’s evolving threat landscape. Security teams have more ways than ever to work smarter, rather than harder, to detect and block advanced threats, automate response and remediation, and reduce modern attack surfaces. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he describes five ways that AI is already improving today’s cybersecurity defenses. This webinar is ideal for cybersecurity professionals keen to leverage AI's transformative power in safeguarding digital assets.

2024/2/21
阅读更多

Everything You Need to Know about CGRC

Governance, risk and compliance (GRC) professionals play a vital role in organizations, aligning IT goals with objectives as they manage cyber risks and achieve regulatory needs. Learn how CGRC certification demonstrates that you have the knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within an organization. Join us to learn more about: - What is GRC? - Why is GRC important for cybersecurity? - What are the core global frameworks? - How is GRC relevant in every industry? - What is the pathway to CGRC? Save your spot today! Moderator: Brandon Dunlap Panelists: AJ Yawn, Partner in Charge, Product and Innovation Mohamed Malki, Director, Enterprise Security Architecture Chris Stanley, Exam Content Developer

2024/2/9
阅读更多

ISC2 Security Congress 2023: Using ChatGPT for Defensive Security Operations

Learn how ChatGPT, a large language model developed by OpenAI, can be used in defensive security operations. Natural Language Processing (NLP) has proven to be a valuable tool in enhancing the effectiveness and efficiency of security operations. We’ll look at the potential use cases of ChatGPT in threat intelligence, security incident response and vulnerability management. You’ll learn about the integration of ChatGPT with existing security tools and workflows, as well as the benefits and challenges of utilizing NLP in security operations.

2024/2/9
阅读更多

Prepare for the E-pocalypse: New Email Authentication Rules

To protect users from email fraud, Google, Yahoo and Apple are implementing new rules that could block all unauthenticated customer emails from the inbox or send them directly to the SPAM folder. The requirements will take effect as early as February 2024. Are you ready? Join Proofpoint and ISC2 on February 8, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn how to meet the new email authentication requirements, ensure the deliverability of your critical emails, and safeguard your brand and your business from email fraud.

2024/2/8
阅读更多

ENHANCED! ISSEP Official ISC2 Online Self-Paced Training

Join us for this live webinar where we’ll tell you all about newly enhanced Official ISC2 Online Self-Paced Training for ISSEP. Find out how it provides a clear-cut and comprehensive review of the domains for a more structured and intuitive learning experience. We’ll also share details about the new second path to earning the ISSEP. We’ll cover: • New Path to ISSEP Certification • Enhanced ISSEP training benefits • New study tools • Education Guarantee • And more! Save your spot now.

2024/2/7
阅读更多

Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them

Navigating the cloud security landscape is no walk in the park. It requires professionals like you to not only tackle traditional security threats, such as managing data access and mitigating vendor risks, but also confront virtualization risks and tackle issues unique to the cloud. With more and more programs and information relying on the cloud, maintaining robust security can feel like an uphill battle. Unsure where to start? We've got you covered! Join KnowBe4 and ISC2 on February 1 at 1:00 p.m. Eastern / 10:00 a.m. Pacific as we walk you through the ins and outs of cloud security. In this webinar we will share: - How to approach your organization’s cloud security and threat landscape - Real-world examples of cloud security breaches and their ripple effects - The risks of vendor-stored user data and strategies to prepare your organization for such threats - How to best protect yourself against today's top hacks and vulnerabilities both on and off the cloud Don’t miss this webinar to learn about the most popular and successful threats against cloud environments and what you can do to best protect yourself against them.

2024/2/1
阅读更多

De-Mystifying Generative AI

Hey, LLM, How Much Trouble ?Are We In? Is Generative AI simply the most modern of modern apps? Are we prepared as an industry to safely unlock its potential? Explore the promises and perils of GenAI, including key considerations for visibility and security across highly-connected ecosystems. Dive into real-world examples of how GenAI can go awry through analysis of recent vulnerabilities and attacks on AI-based applications. On January 25, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific, join F5 and ISC2 to hear more about: • The business and societal impacts of GenAI • Important considerations for protecting the conduit to AI workloads: app and API interfaces • Top security and safety risks including The OWASP Top 10 for Large Language Model Applications (Disclaimer: this webinar is not generated by AI (but it could be)!)

2024/1/25
阅读更多

Strategies for Recruiting and Retaining Top IT Security Talent

Recruiting and retaining qualified IT security talent is a never-ending challenge. Seven in eight organizations are experiencing a shortfall, according to CyberEdge’s annual Cyberthreat Defense Report. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can smart security organizations do to mitigate the effects of this talent shortage? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Examines the shortage of IT security personnel by job role - Proposes creative ways for recruiting new security talent - Suggests clever ways for retaining the talent you already have - Identifies technologies and services that enable security teams to do more with less

2024/1/24
阅读更多

Forensics or Fauxrensics:Understanding Capabilities for Cloud Forensics and IR

The speed and scale at which new cloud resources can be spun up has resulted in uncontrolled deployments, misconfigurations, and increased security risks. Worse, it had security teams racing to secure the business’ rapid cloud migration. While many organizations have successfully extended their prevention and detection capabilities to the cloud, they are now experiencing another major gap - understanding the wider scope and impact of an incident. Cloud forensics and its benefits are now in the spotlight. But what exactly does cloud forensics entail? On January 23, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific join Cado Security and ISC2 to learn: - How cloud forensics differs from traditional on-premises forensics - The five core capabilities that could be to considered when evaluating a cloud forensics solution - How to ensure your cloud forensics and incident response program is proactive vs reactive

2024/1/23
阅读更多

ENHANCED! ISSMP Official ISC2 Online Self-Paced Training

Join us for this live webinar where we’ll tell you all about newly enhanced Official ISC2 Online Self-Paced Training for ISSMP. Find out how it provides a clear-cut and comprehensive review of the domains for a more structured and intuitive learning experience. We’ll also share details about the new second path to earning the ISSMP. We’ll cover: • New Path to ISSMP Certification • Enhanced ISSMP training benefits • New study tools • Education Guarantee • And more! Save your spot now.

2024/1/17
阅读更多

Enhanced! SSCP Official ISC2 Online Training

Join us for this live webinar where we’ll tell you all about two newly enhanced Official ISC2 Online Training options for SSCP — self-paced and instructor-led exam prep. Find out how both options provide a clear-cut and comprehensive review of the SSCP domains for a structured and intuitive learning experience. You’ll learn about: • Enhanced ISC2 Online Instructor-Led SSCP Training • Enhanced ISC2 Online Self-Paced SSCP Training • New study tools • Education Guarantee Save your spot now.

2023/12/13
阅读更多

The Future of Generative AI: Uses and Abuse

Generative AI has been in the news since early this year and many organizations are concerned about its use by adversaries in attacks against them. In this session, we’ll look at hype versus reality of the use of GAI by threat actors and where we are likely to see its use in attacks. We will also look at how the security industry is utilizing this technology to improve detection and response against attacks. Join us to hear the discussion with Trend Micro and ISC2!

2023/12/7
阅读更多

Top Five Cybersecurity Predictions for 2024

The cybersecurity industry continues to face many challenges, including shortages of skilled security personnel, record-level ransomware attacks, and increased risks associated with modern attack surfaces. However, investments in security products and services continue to remain strong, including AI-fueled threat prevention, zero trust security, managed detection and response (MDR), and more. So, what does next year have in store for the cybersecurity industry? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2024.

2023/12/6
阅读更多

Generative AI: Top Use Cases for Security Practitioners

With generative AI now ever-present in most organizations, the next frontier for security practitioners is understanding where AI capabilities like machine learning, deep learning and natural language processing can best increase cybersecurity efficiency and effectiveness in their organizations. How can generative AI help your team respond to incidents, discover and patch vulnerabilities, or assist with programming? Or all the above? And what do teams need to consider in order to identify, review, assess risk and develop the use cases before putting them into production? Join IANS and ISC2 November 30, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear about strategy toward using generative AI within their security programs. Walk away with insights and tangible recommendations for how to: - Identify the use cases where AI can bring value to your security organization - Understand the limitations and risks of AI capabilities and where you should proceed with caution - Determine the skills, tools and domain experts needed for use case evaluation - Develop your AI use case risk assessment framework - Recognize where and how AI can enable your security teams, but not replace them

2023/11/30
阅读更多

Automate your API Security, Resilience and Compliance

APIs make the world go round. 58% of dynamic HTTP traffic on the Cloudflare network is API-related. Security and IT leaders have to balance securing their APIs and their customers’ sensitive data, without slowing down innovation while maintaining customer trust. On November 28, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join us as Cloudflare and ISC2 discuss the best practices to automate your API security with a focus on small security teams. In this webinar, you will: * Explore today’s complex API ecosystem of new APIs, diverse users, and sophisticated attackers * Experience the problems with patchwork and DIY approaches to API security * See an example of optimal API security workflow * Observe ways an API security tool enables you to automate your API security processes * Simplify compliance with ever growing requirements: PCI, HIPAA, FHIR, Open Banking Initiative, Financial Data Exchange etc.

2023/11/28
阅读更多

Securing the Welcome: Innovations, Compliance & Data with Visitor Management

In today's ever-changing landscape, where security, compliance, and providing a seamless visitor experience are top priorities, the adoption of Visitor Management (VM) systems goes beyond being a nice to have to an absolute necessity. However, it is surprising that only 10% of companies using cloud visitor management systems rate theirs as excellent. This raises the question: what is happening with the other 90%?  A robust visitor management solution should not only serve as an interface for welcoming guests with ease but also act as a stronghold for protecting your valuable data and a driver for enhancing your company's reputation. We invite you to join us on a journey as we explore the crucial role that VM plays in ensuring a warm and secure welcome, complying with regulations, and leaving a lasting impression on your visitors. Join ACRE  in collaboration with ISC2 on November 21st, 2023, at 1:00 p.m. Eastern/10:00 a.m. Pacific to discover how technological innovations fortify security, align with regulatory requirements, and harness data for a resilient visitor management system. Do not miss this opportunity to effectively fortify your organization. During this event, you will gain insights into:  - Augmenting efficiency through the automation of the check-in process with VM systems - How a cloud VMS can be a means to enable a secure path to standardization along with new technology to embrace a positive customer experience across the organization - Leveraging the data acquired through a VM system to enhance your processes and achieve cost savings - Recognizing the importance of compliance with regulations

2023/11/21
阅读更多

Your Network Knows the Truth. Are You Listening?

When it comes to network visibility, the truth can be hard to find. Enterprise organizations face enormous obstacles when it comes to gaining 'simple' visibility into their networks, and this lack of clarity can make it easier for cyber attackers to infiltrate those networks by evading endpoint controls or hiding in encrypted traffic. In fact, malware-free activity made up 71% of all detections in 2022 (up from 62% in 2021). So, how can your organization defend against threats like these? The answer may lie in leveraging network detection and response (NDR) solutions. Enhancing your XDR workflows with NDR solutions can provide a powerful source of truth and transparency across your enterprise, from on-premises to the cloud and everywhere in between—leaving attackers with nowhere to hide. Join experts from CDW, ExtraHop, CrowdStrike andISC2 as they discuss how to enhance XDR workflows with telemetry from NDR solutions.

2023/11/14
阅读更多

Hack the Brain: Social Engineering Innovation in 2023

The human factor remains a gateway for cybercriminals as phishing and ransomware attacks continue to increase. Cases like those of Uber and Rockstar Games have also shown how cybercriminals are evolving at a rapid pace, exploiting human psychology and our emotions - and hacking our brains. But how do attackers use behavioral science specifically against us? What can we do to protect those around us? On November 2, 2023 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, So Safe and ISC2 take a look at social engineering innovations in 2023 to learn more about the latest strategies cybercriminals are using.

2023/11/2
阅读更多

The Impact of Artificial Intelligence on the Cybersecurity Industry: Part 2

Last month, CyberEdge's CEO and Chief Analyst, Steve Piper, participated in an ISC2 webinar to share his perspectives on how artificial intelligence (AI) is impacting the cybersecurity industry. As AI is such a hot topic, more participants registered for that webinar than any other in ISC2 Knowledge Vault history! As enthusiasm for this topic remains sky high, ISC2 has invited Steve back to respond to unanswered audience questions from our last webinar and to address your burning questions in this webinar.

2023/11/1
阅读更多

Findings From the 2023 Identity Threat Report, Pt 2: Phishing & MFA Bypass

Changes in how we build, run and secure information systems have also changed how we look at authentication and access control. The emerging concept of identity is transforming the ways that humans and non-human actors alike make use of data and compute power. At the same time, organizations’ focus on identity also means that it has become a focus for attackers. To assess the ways that old and new attacks are targeting digital identities, F5 Labs is presenting findings from our 2023 Identity Threat Report: The Unpatchables. In a follow-up to the September session on credential stuffing, this talk will focus on phishing and multi-factor authentication bypass techniques. As phishing has grown over the last several years, its tools and tactics have transformed. We will identify which organizations are most targeted and explore recent developments that make it harder to spot and trickier to mitigate, using a combination of Dark Web intelligence and quantitative methods. This talk on October 19, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific will cover recent developments in attacker approaches to circumvent multi-factor authentication, what these developments mean for defenders, and which forms of MFA are able to resist the new approaches.

2023/10/19
阅读更多

New and Enhanced CSSLP Official ISC2 Online Training

Join us for this live webinar where we’ll tell you all about two Official ISC2 Online Training options for Certified Secure Software Lifecycle Professional (CSSLP) — new self-paced and enhanced instructor-led exam prep. Find out how both options provide a clear-cut and comprehensive review of the CSSLP domains for a structured and intuitive learning experience. You’ll learn about: • Enhanced ISC2 Online Instructor-Led Training • New ISC2 Online Self-Paced CSSLP Training • Benefits of both training options • Education Guarantee Save your spot now!

2023/10/18
阅读更多

Using New-School Security Awareness Training to Build Your Human Defense Layer

It’s become more and more evident to organizations that new-school security awareness training is an absolute requirement for managing the ongoing problem of social engineering. But how do you develop a program that will strengthen your human defense layer without doubling your workload or costing an arm and a leg? Join KnowBe4 and ISC2 October 3, 2023 at 1:00 p.m./10:00 a.m. Eastern as we discuss key measures that will help you make an informed security awareness decision for your organization. You’ll gain insight into: • Current threat landscape and what to watch out for • Critical components and considerations to make your program successful from the start • Importance of a new-school security awareness program to better train your users • Why strengthening your human layer is your best line of defense Find out now how you can not only check the box on security awareness training, but develop sustainable, meaningful change in your organization's security posture and culture.

2023/10/3
阅读更多

Security Industry 101: A 'Crash Course' for Security Newbies

New to the security industry? Or thinking about transitioning into an information security role? If so, this webinar is for you. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he provides a one-hour ‘crash course’ on the entire security industry, including: - Size and growth of the security industry - Useful vocabulary terms and buzz words - Five types of cyberthreat actors - Modern cyberthreats and tactics - Categories of security defenses - Common security job roles - Security industry ecosystem

2023/9/27
阅读更多

Making Zero Trust Possible with a Security Service Edge (SSE) Approach

The security winds are rapidly shifting from "trust but verify" models to ones that assume that every activity is insecure until proven otherwise. In an age of high-profile security attacks, increasingly sophisticated phishing schemes, and ransomware threats run amok, organizations of all shapes and sizes are urgently seeking new ways to protect their workforce, their finances, their reputations, and their business operations. On September 26, 2023 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, hear how security and networking teams today are avoiding the latest attacks and nullify exploits by choosing the right cloud-delivered technologies that enforce zero trust for global secure access. In this session you will hear: • Why organizations around the globe are prioritizing the implementation of a SASE framework, specifically with SSE • How SSE can enforce zero trust access to help protect access to Private apps, SaaS apps, and the open internet, all in a single solution.

2023/9/26
阅读更多

How to Augment Your Microsoft 365 Security

Microsoft 365 is a mission critical tool for organizations facilitating global collaboration, remote work, and cloud computing. While Microsoft provides native email security capabilities via Exchange Online Protection (EOP) and through additional security tools like Microsoft Defender for Office 365, organizations needs to augment these defenses in order to protect against modern sophisticated email threats such as business email compromise (BEC), advanced phishing, and account takeover. With over 88% of productivity software market share, Microsoft is the primary target of choice for threat actors. In 2022, cyber criminals sent more than 30 million messages that abused the Microsoft brand and products. On September 21, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join Proofpoint and ISC2 for a live webinar with threat experts and learn how to break the attack chain and stop advanced email threats. Join the webinar to hear: • Why threat actors are targeting your Microsoft 365 environment • Why industry analysts recommend supplementing native Microsoft 365 capabilities • What key areas you need to augment in your Microsoft 365 platform • Best practices for strengthening your Microsoft 365 security.

2023/9/21
阅读更多

Everything You Need to Know about CGRC in North America

Governance, risk and compliance (GRC) professionals play a vital role in organizations, aligning IT goals with objectives as they manage cyber risks and achieve regulatory needs. This webinar talks about governance, risk and compliance globally, as well as specific core frameworks in the North American region. Get answers to these questions and more: - What is GRC? - Why is GRC important for cybersecurity? - What are the core frameworks for the North American Region? - How is GRC relevant in every industry? - What is the pathway to CGRC? Learn how CGRC certification demonstrates that you have the knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within an organization. Register today! Panelists: AJ Yawn, Partner in Charge, Product and Innovation Mohamed Malki, Director, Enterprise Security Architecture Chris Stanley, Exam Content Developer Moderator: Brandon Dunlap

2023/9/20
阅读更多

Findings From the 2023 Identity Threat Report, Pt 1: Credential Stuffing

Changes in how we design, build, run and secure information systems have also changed how we look at authentication and access control. The emerging concept of identity is transforming the ways that humans and non-human actors alike make use of data and compute power. At the same time, the emergence of identity as a focus for organizations also means that it has become a focus for attackers. To assess the ways that old and new attacks are targeting digital identities, F5 Labs is presenting findings from our 2023 Identity Threat Report: The Unpatchables. On September 19, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific this session will focus on credential stuffing. This will be the first of two sessions. We will quantify its prevalence, explore targeting trends such as attackers’ choice of industries and endpoints, and outline credential stuffing tactics, techniques and procedures (TTPs). We will also take a deeper look into some case studies, with a particular focus on the differences between basic and sophisticated attacks. This talk will also assess the stolen credentials supply chain before focusing on mitigation strategies for combating credential stuffing.

2023/9/19
阅读更多

Ransomware in the Wild: Lessons Learned

The ransomware scourge continues to plague the cybersecurity industry. To help ensure you and your company are better prepared, we will share insights and lessons learned from ransomware case studies. In this session, on September 12, 2023 at 1:00 p.m./ 10:00 a.m. Pacific IANS and (ISC)2 will lead you through: • What went right (and wrong) in these examples and how best to incorporate that experience into your defenses and program • Threat actor behavior and how to take advantage of their internal processes to thwart them • TTPs used in various ransomware operations • Alert monitoring – from investigating to remediating • The reality and best practices around backups and recovery

2023/9/12
阅读更多

Navigating the Cloud Attack Landscape

Want to know more about safeguarding your organization against an increasingly sophisticated array of threats? In this session, Lacework will dissect the most pertinent cloud security attack trends and techniques of 2023. Delve into actionable insights, real-world metrics, and the current threat landscape as we equip your team with the latest knowledge and strategies. This discussion will cover the following topics and more: - Kubernetes attacks and abuses: The rise in complexity and vulnerabilities in deployment, and the resulting increased attacks and administrative plane abuses. - Zenbleed impact: How Zenbleed affected cloud providers and how Lacework approaches this security concern. - Cloud supply chain attacks: An examination of the JumpCloud APT case and its broader implications. - CloudWizard APT: The use of OneDrive, Dropbox, and Google Drive as a C2 in the ongoing CloudWizard threat, including an analysis of its evolution.

2023/9/12
阅读更多

Talking AuthZ: Why Authorization? Why Now?

Identity and access management has been a pillar in security for decades now; it has emerged, changed, and evolved many times over as the problems it solved grew larger and more complex. Identity governance, identity providers, and authorization platforms are all required to deliver a secure identity practice. Authorization, like every piece of identity, enables the modern business, reduces risk, tightens security, and protects access to your digital assets. Join PlainID and ISC2 to hear a discussion where speakers dive into the project and business drivers they see that require centralized authorization. his talk will help you: · Distinguish how IGA (Identity Governance and Administration) and IAM (Identity Access Management) tools control access through RBAC and ABAC approaches · Learn how Policy-based Access Control (PBAC) compares with previous methods · Understand the growing importance of authorization in today's threat and compliance landscape and how it protects digital assets.

2023/8/31
阅读更多

The Impact of Artificial Intelligence on the Cybersecurity Industry

The impact of artificial intelligence (AI) on the cybersecurity industry is among the hottest topics discussed and debated amongst security professionals. From a positive perspective, AI has infused a myriad of threat detection and prevention platforms with newfound methods for uncovering sophisticated threats. It has also helped short-staffed security teams automate complex processes, such as incident validation and response. But AI also comes at a price. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he addresses the good, the bad, and the ugly outcomes of artificial intelligence.

2023/8/30
阅读更多

Policy-Based Access Control: What It Is & Why You Can’t Modernize Without It

Ever wonder what Policy-Based Access Control (PBAC) is? Why is Policy-Based Access Control Crucial to the Modern Business and how PBAC overcomes the management and scalability challenges of RBAC and ABAC? In this webinar, you will gain a clearer understanding of how PBAC differs from traditional access control models and learn how to use effective policies to protect sensitive data and ensure regulatory compliance. Whether you are an IT professional, an IAM expert, a security architect, or a decision-maker responsible for safeguarding critical information assets, this webinar hosted by PlainID will provide you with practical insights and best practices to enhance your organization's access control strategy.

2023/8/29
阅读更多

Everything You Need to Know about CGRC

Governance, risk and compliance (GRC) professionals play a vital role in organizations, aligning IT goals with objectives as they manage cyber risks and achieve regulatory needs. Learn how CGRC certification demonstrates that you have the knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within an organization. Join us to learn more about: - What is GRC? - Why is GRC important for cybersecurity? - What are the core global frameworks? - How is GRC relevant in every industry? - What is the pathway to CGRC? Save your spot today! Moderator: Brandon Dunlap Panelists: AJ Yawn, Partner in Charge, Product and Innovation Mohamed Malki, Director, Enterprise Security Architecture Chris Stanley, Exam Content Developer

2023/8/23
阅读更多

SSCP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about SSCP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How SSCP proves your knowledge, skills and experience as an ISO-accredited certification • Why vendor-neutral certification is in demand • What training tools are available • And much more SAVE YOUR SPOT NOW.

2023/8/11
阅读更多

New! AI-Driven Adaptive Learning for CISSP from ISC2

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced CISSP Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder, and go into the CISSP exam with confidence. You’ll learn: • Why it makes training more efficient busy professionals • What makes it a more efficient route to exam readiness • How artificial intelligence tailors learning to your needs • And much more

2023/8/9
阅读更多

CC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about CC before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn about: • Career opportunities in cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • What to expect on exam day • And much more SAVE YOUR SPOT NOW.

2023/7/28
阅读更多

CGRC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about Certified in Governance, Risk and Compliance (CGRC) certification before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CGRC prepares you to use frameworks to manage risk • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/7/21
阅读更多

Re-thinking PKI in Modern IT Infrastructure

Public key infrastructure (PKI) today is ubiquitous – it’s in the cloud, it’s on the manufacturing floor, it’s everywhere. Why? Because, in a Zero Trust world, every device, every workload, and every connected thing must be authenticated and verified. There’s just one problem. Because of its extensive use, PKI has become incredibly complex to manage. Different teams and applications have unique trust requirements, use cases, technical and security needs, creating a distributed fabric of PKI tools and infrastructure. So, how do you manage this new “Decentralized PKI”? Join Keyfactor and (ISC)2 July 20, 2023 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific as we discuss the ins and outs of decentralized PKI, best practices for management, and how to consolidate where possible. During this webinar, you’ll learn: • How the usage of PKI has evolved and expanded • New threats, regulatory mandates and changes to PKI • Key considerations for different PKI and CA tools • Best practices for managing “Decentralized PKI”

2023/7/20
阅读更多

What You Need to Know About the Global Cybersecurity Regulatory Landscape

In addition to escalating threats, cybers professionals must also be aware of a wide range of cybersecurity laws, regulations and policies enacted around the world. During this webinar, Tara Wisniewski, EVP, Advocacy, will release findings of an intensive research project into the cyber legislative and regulatory landscape across the U.S., the U.K., the E.U., Canada, Japan, and Singapore. Find out what your team needs to know.

2023/7/19
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, July 14, 2023, at 1:00 p.m. ET Save your spot now.

2023/7/14
阅读更多

New Phishing Benchmarks Unlocked:Is Your Organization Ahead of the Curve in 2023

Cybercriminals continue to rely on proven attack methods while developing new ways to infiltrate digital environments and break through your human defense layer. But how can you reduce your organization’s attack surface? KnowBe4 looked at 12.5 million users across 35,681 organizations to find out. In this webinar on July 13, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific, KnowBe4 and (ISC)2 take a look at the 2023 Phishing By Industry Benchmarking Study findings and best practices. You will learn more about: • New phishing benchmark data for 19 industries • Understanding who’s at risk and what you can do about it • Actionable tips to create your “human firewall” • The value of new-school security awareness training Do you know how your organization compares to your peers? Watch this webinar to find out!

2023/7/13
阅读更多

New! AI-Driven Adaptive Learning for CCSP from ISC2

Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced CCSP Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder, and go into the CCSP exam with confidence. You’ll learn: • Why it makes training more efficient busy professionals • What makes it a more efficient route to exam readiness • How artificial intelligence tailors learning to your needs • And much more Presenters: Jon Duggan, Associate Director, Learning Experiences, ISC2 Benjamin Grosvenor, Chief of Staff, OBRIZUM Group Giovanni Bruere, VP of Sales, OBRIZUM Group Moderator: Brandon Dunlap

2023/7/12
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, July 7, 2023, at 1:00 p.m. ET Save your spot now.

2023/7/7
阅读更多

CSSLP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about Certified Secure Software Lifecycle Professional (CSSLP) certification before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CSSLP prepares you to incorporate best security practices into each phase of the SDLC • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/6/30
阅读更多

Bridging Gaps: Aligning NetOps & SecOps to Uplift Networking and Security

Analyst reports are increasingly emphasizing that NetOps and SecOps teams with little to no integration fall short in areas of operational efficiency and the agility to respond to business needs. Security is challenged by increasingly advanced threats driven by nation-state and organized criminals. And networking teams struggle to fully embrace multi-cloud, hybrid work, and other initiatives. The good news is that these same reports are highlighting how increased communication, cooperation and integration of NetOps and SecOps can address a multitude of challenges, making each organization more effective and efficient, and while supporting a more flexible, agile business environment. On June 27, 2023 at 1:00 p.m. Eastern/10:00am Pacific, join Infoblox and (ISC)2 to discover how NetOps and SecOps teams can align their operations to help each achieve goals more efficiently. Discussion topics include: -Nine common challenges for NetOps and SecOps -Tips to make more efficient use of limited resources -5 key areas where seemingly different objectives connect -Making compliance easier to do, and demonstrate to auditors -How tighter NetOps/SecOps integration improves visibility for all

2023/6/27
阅读更多

CC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about CC before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn about: • Career opportunities in cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • What to expect on exam day • And much more SAVE YOUR SPOT NOW.

2023/6/23
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, June 16, 2023, at 1:00 p.m. ET Save your spot now.

2023/6/16
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, June 9, 2023, at 1:00 p.m. ET Save your spot now.

2023/6/9
阅读更多

Microsoft OneDrive and Teams: Harden Your M365 Applications

Without the proper security settings, attackers have found ways to exploit Microsoft OneDrive and Teams as primary distribution mechanisms for ransomware. In this session, on June 8, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific, IANS and (ISC)2 will discuss configurations, settings and tools to help harden M365 applications. Attendees can expect to learn: - Conditional access policies to enforce for “thick” endpoints - Critical user policies and alert triggers to create for detection - Recommended M365 service policies and Teams security settings

2023/6/8
阅读更多

SSCP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about SSCP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How SSCP proves your knowledge, skills and experience as an ISO-accredited certification • Why vendor-neutral certification is in demand • What training tools are available • And much more SAVE YOUR SPOT NOW.

2023/6/2
阅读更多

CGRC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about Certified in Governance, Risk and Compliance (CGRC) certification before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CGRC prepares you to use frameworks to manage risk • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/5/26
阅读更多

Key Insights from CyberEdge's 2023 Cyberthreat Defense Report

A record 73% of organizations were compromised by ransomware last year. However, the percentage of respondents who expect a successful cyberattack in the coming year declined by 4%, from 76% to 72%. Has cybersecurity turned a corner? CyberEdge’s Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its tenth year, the 2023 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join ISC2 (a sponsor of this year’s study) and CyberEdge for highlights and key insights of the results, including: • 85% of organizations suffered at least one successful cyberattack last year • Double and triple extortion ransomware attacks are now the norm • Overall concern for cyberthreats ticked down for the second straight year, the first multi-year decline in CDR history

2023/5/24
阅读更多

Navigating the Cloud Maze:Protecting Your Workloads in a Multi-Cloud Environment

Cloud-native workloads such as virtual machines (VMs), containers, and serverless functions are foundational building blocks of applications. With the rise of hybrid and multi-cloud environments, ensuring the security of cloud workloads has become more challenging than ever. But fear not! We are here to guide you through best practices for securing these resources throughout their lifecycle. Join Prisma Cloud/Palo Alto Networks and (ISC)2 May 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a webinar on how to build a comprehensive strategy that fits your unique cloud environment. We will cover topics such as: • Agentless vs. agent-based deployment options • Understanding risk and prioritizing risks in your environment • Remediation strategies for runtime protection Gain valuable insights on how to effectively secure your cloud resources and protect yourself from potential threats.

2023/5/23
阅读更多

From Silo to Synergy between Cybersecurity and Privacy in the U.S.

Data is the lifeblood of the digital age. But it needs to be collected, processed, protected and shared in a responsible and ethical way. Privacy and cybersecurity professionals play a vital role in ensuring responsible data stewardship, but they often face different challenges and perspectives. How can they work together more effectively and align their goals and priorities? Join IAPP and (ISC)² for this webinar where we will explore the interdependence and collaboration between privacy and cybersecurity functions in U.S. organizations. We will hear from experts in both fields who will share their insights on how they overcome common obstacles and achieve cross-functional alignment. We will also discuss the professionalization of the data stewardship fields and why privacy and security familiarity is essential for proper data stewardship. IAPP’s Cobun, Managing Director, Washington, D.C., will lead a discussion of these issues with Robin Andruss, CPO, Skyflow, and Ron Woerner, Independent CISO.

2023/5/18
阅读更多

Cost Optimization: The Consensus IT and Cybersecurity Priority for 2023

Three years ago, IT and security teams were flush with cash as a result of the spending boom brought on by the COVID-19 pandemic — but today’s reality is vastly different. Economic uncertainty has resulted in nearly every organization looking to cut costs and reduce headcount, leaving IT and security teams with smaller budgets and even fewer resources. The good news? There are ways to eliminate spend without reducing headcount. Join Axonius and (ISC)2 on May 16, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a webinar on how to optimize your IT and security programs by identifying cost inefficiencies in overlapping tools and infrastructure, manual processes, unused software licenses, and more. You’ll learn: • How IT and security teams are working to identify wasted spend, overlap, and other opportunities to overcome budget limitations • Opportunities to get more out of the tools and resources already purchased • Approaches to tool justification, discovering gaps, and identifying manual processes that can be automated to focus people on more strategic tasks

2023/5/16
阅读更多

From Silo to Synergy Between Cybersecurity and Privacy in Europe

Data is the lifeblood of the digital age. But it needs to be collected, processed, protected and shared in a responsible and ethical way. Privacy and cybersecurity professionals play a vital role in ensuring responsible data stewardship, but they often face different challenges and perspectives. How can they work together more effectively and align their goals and priorities? Join IAPP and (ISC)2 for this webinar where we will explore the interdependence and collaboration between privacy and cybersecurity functions in organizations operating in Europe. We will hear from experts in both fields who will share their insights on how they overcome common obstacles and achieve cross-functional alignment. We will also discuss the professionalization of the data stewardship fields and why privacy and security familiarity is essential for proper data stewardship. IAPP’s Isabelle Roccia, Managing Director, Europe, will lead a discussion of these issues with Christian Toon, CISO, Pinsent Masons Law Company, Anna Zeiter, CPO, eBay, and Ilias Chantzos, Global & Privacy Officer, Broadcom.

2023/5/16
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, May 12, 2023, at 1:00 p.m. ET Save your spot now.

2023/5/12
阅读更多

CC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about CC before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn about: • Career opportunities in cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • What to expect on exam day • And much more SAVE YOUR SPOT NOW.

2023/5/5
阅读更多

Vulnerability Intelligence, Three Ways

You can look at vulnerability risk from several angles, but which one is best? On May 2, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join F5 Labs and (ISC)2 as they tackle this topic. The talk will start at the tactical level, where we will review vulnerability targeting data from 2022 to better understand current attacker priorities. We will then briefly cover findings and methods from the Exploit Prediction Scoring System, an open-source vulnerability intelligence project to which F5 has recently begun contributing. The talk will conclude with a big picture view of vulnerability management, exploring F5 Labs’ collaboration with the Cyentia Institute about trends in CVE publication and their implications for the future of vulnerability management.

2023/5/2
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, April 28, 2023, at 1:00 p.m. ET Save your spot now.

2023/4/28
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, April 14, 2023, at 1:00 p.m. ET Save your spot now.

2023/4/21
阅读更多

Navigating the Expanding Cloud Attack Surface

While cloud technology is not new, and many organizations have been on their cloud journey for years, cloud service providers continue evolving with new features and services. This fast change and growth make it difficult for organizations to keep up and inadvertently introduce security weaknesses. Join Palo Alto and (ISC)2 April 20, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we talk through this year’s results of the Unit 42™ Cloud Threat Report. Our experts offer insights into the most common drivers of cloud incidents and breaches today, giving security leaders and practitioners a comprehensive view of cloud security threats. These findings should enable leaders to understand the greatest risks to their cloud environment and how to manage them most effectively. Webinar attendees will also: - Get lessons from real cloud breach incidents. - Learn tips to stay ahead of cloud threat actors. - Address the most common cloud security issues. - Understand the impacts and risks of open-source software in the cloud.

2023/4/20
阅读更多

Zero Trust Metrics: Track Progress and Program Maturity

The CISA Zero Trust Maturity Model is filled with concepts and language appropriate for federal agencies, but it doesn’t always translate to the private sector, and certainly not to smaller, less-mature mid-market organizations. In this live session on April 18, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific IANS and ISC2 host a webinar to explain: • Which metrics to consider and which to avoid • Ways to use metrics to communicate with nontechnical stakeholders and/or the board • Examples of maturity models to track the long-term progress of a zero trust program

2023/4/18
阅读更多

CGRC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about Certified in Governance, Risk and Compliance (CGRC) certification before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CGRC prepares you to use frameworks to manage risk • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/4/14
阅读更多

Level Up Your Cybersecurity Scalability

Maintaining cybersecurity compliance and building reliable risk management practices isn’t a simple to-do item you check off anymore. The livelihood (and ultimately the growth) of your business depends on resilient security and compliance programs. Add in changing regulatory requirements, and the challenge becomes exponentially more complex. Join Hyperproof and (ISC)2 on April 11, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear more about: • The value of connecting compliance and risk • Optimizing stakeholder visibility and communication • Using GRC tools to scale your business • Long-term impacts of streamlining compliance, security, and risk management workflows

2023/4/11
阅读更多

AI and Cybersecurity: Perfect Match or Hack Waiting to Happen?

Artificial intelligence (AI) is no longer science fiction. Software vendors have been integrating AI into products for years, which has led to innovations such as improved threat detection and training opportunities. But the emergence of newer technologies has raised new questions about the real threats AI poses. In this presentation on April 6 at 1:00 p.m. ET / 10:00 a.m. PT, KnowBe4 and (ISC)² will discuss the benefits of AI, the potential threats, and strategies you can use to protect your network today and in the future. You’ll learn: · The key benefits and uses of AI for cybersecurity. · How AI could put your organization at risk. · Strategies for integrating AI into your cybersecurity defenses. · Why security awareness training is your best, last line of defense. Get the information you need now to protect your network!

2023/4/6
阅读更多

SAP ERP Observability with Security Monitoring

Successfully managing Systems Applications and Products (SAP) and Enterprise resource planning (ERP) in hybrid-cloud environments leaves little room for error. Learn how you can detect even subtle changes in application performance to identify the root cause faster and avoid potential problems with reporting that connects every layer of your infrastructure to critical business operations. See how adding application security monitoring in front of the ERP core provides a moat of protection around mission critical business data. Join AppDynamics and (ISC)2 on April 4, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific when we will demonstrate: • Automated Flow Maps of the entire landscape (SAP and non-SAP) • Business Transaction and code-level visibility (e.g., ABAP) • SAP Business Process monitoring Insights into SAP System KPIs • Out of the Box Dashboards for Health Rules and Alerts. • Realtime application security protection applied to SAP environments

2023/4/4
阅读更多

CISSP Concentrations (ISSAP, ISSEP, ISSMP) EXAM READY: Ask the Experts

Join us for this live Q&A where our panel of experts will answer all of your questions about the Certified Information Systems Security Professional (CISSP) Concentrations in architecture, engineering and management before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How the ISSAP, ISSEP and ISSMP concentrations build upon the CISSP • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/3/31
阅读更多

Disrupt the Ransomware Threat Actors: Focus on Attack Chains

Ransomware continues to dominate the headlines with a wide range of organizations impacted. Part of its staying power is that ransomware threat actors tackle the attack chain with the specialization and organization of a business, with different groups tasked with different roles and responsibilities. Join us for this Proofpoint and (ISC)2 webinar March 28, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn how threat actors are adapting to maintain their business model, and what organizations can do in response. We’ll discuss best practices to: - Minimize the probability and impact of ransomware incidents by focusing on the entire attack chain - Minimize the damage when ransomware incidents do occur by detecting and limiting the action of compromised identities - Minimize recovery time by protecting the primary target of ransomware attacks, your data

2023/3/28
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, March 24, 2023, at 1:00 p.m. ET

2023/3/24
阅读更多

Understanding the Modern Threat Landscape

The 2022 cyber threat landscape was one of persistence, increased scope, and relentless determination. As businesses began to ease pandemic-driven operating environments and adjust to geopolitical shifts—as well as growing economic hardships—adversaries supporting nation-state, eCrime, and hacktivist motivations started the year with a relentless show of effort that ultimately defined 2022. Join CrowdStrike and (ISC)2 March 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for an in-depth review of how the cyber threat landscape has evolved over the last year, including notable threats, events and trends outlined and explained in the CrowdStrike 2023 Global Threat Report. In this session, we’ll discuss: • The most relevant threat issues that organizations face today • New adversaries uncovered in 2022 and their growing speed and sophistication • Useful best practices in how you can combat the modern-day threat

2023/3/23
阅读更多

CSSLP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about Certified Secure Software Lifecycle Professional (CSSLP) certification before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CSSLP prepares you to incorporate best security practices into each phase of the SDLC • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.

2023/3/17
阅读更多

The State of Cloud-Native Security 2023

Global survey spotlights industry vitals and actionable insights. The State of Cloud-Native Security Report 2023 is the result of a months-long survey traversing seven countries and five sectors of industry to consult with cloud security and DevOps professionals — from chief executives to developers to security technicians — with the goal of identifying pivotal decisions affecting cloud-native development and security outcomes. This webinar will be hosted by Prisma Cloud/Palo Alto and (ISC)2 on March 16, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific. Join us to hear the results of this year’s survey, presenting a fresh look at the top challenges and best practices in cloud-native security, including these outstanding findings: • New deployment frequency has increased by 67% in the past 12 months. • 76% of respondents deploy new or updated code to production weekly. • 72% of organizations report an above average turnover rate in cloud security roles. • 78% of respondents want better Day-1 security from tools. • 77% of organizations say aligning security tools with security goals is challenging. You do not want to miss this session!

2023/3/16
阅读更多

Get a Handle on Multi-Cloud Management

A well-managed multi-cloud deployment can increase reliability, reduce the risk of vendor lock-in and add essential business capabilities. But the more cloud services an enterprise employs, the more complex the solution is to manage. On March 14, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific IANS and ISC2 discuss: • The most common pitfalls of multi-cloud adoption and recommendations to navigate them • What you need from your CSPs to enable success • Types of tools best suited for multi-cloud

2023/3/14
阅读更多

CC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about CC before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn about: • Career opportunities in cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • What to expect on exam day • And much more SAVE YOUR SPOT NOW.

2023/3/10
阅读更多

API Security Best Practices in the Hybrid, Multi-Cloud Digital World

"You can't protect what you can't see" and "it takes a village" are familiar expressions within security and risk teams. Visibility and policy enforcement are fundamental pillars in cybersecurity and critical components within a holistic API security strategy. But the existing landscape complicates those efforts. Why? Architecture is becoming de-centralized and distributed, transforming apps into a digital fabric of business logic interconnected by APIs. Yet the enterprise catalog continues to be powered by a mix of legacy and modern apps across data centers, clouds, and at the edge. This hybrid, multi-cloud digital world introduces major risks driven by third-party integrations, inconsistent security controls across cloud providers, and continuous code updates across complex software supply chains and CI/CD pipelines. So how can you secure APIs in this modern digital fabric? Well, it takes a village. Join this webinar March 9, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear: • The challenges of API security in a hybrid, multi-cloud digital world • How to get a handle on API and tool sprawl • Insights on trends and solutions for API security

2023/3/9
阅读更多

SSCP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about SSCP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How SSCP proves your knowledge, skills and experience as an ISO-accredited certification • Why vendor-neutral certification is in demand • What training tools are available • And much more SAVE YOUR SPOT NOW.

2023/3/3
阅读更多

A DNS Security Architecture as SecOps Force Multiplier

The Domain Name System (DNS) is essentially the central nervous system of the internet—everyone needs it to work because without DNS services, digital business could come to a halt. Cybercriminals know this too, and exploit DNS services to launch their attacks while simultaneously attacking the DNS services of their targets. Therefore, it’s not only important to protect your organization’s DNS service, but also to use the data available from DNS services to more rapidly detect and surgically block threat activity such as phishing, DNS tunneling-based data exfiltration, and ransomware. On March 2, 2023 join Infoblox and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear best practices for an effective DNS security architecture.

2023/3/2
阅读更多

Security Essentials for Modern Application Stacks

The speed of application development has increased exponentially in recent years, in line with a dramatic acceleration of digital transformation across all industries. In a recently published application security report by AppDynamics, organizations in all sectors reported feeling more exposed to security threats, including lack of visibility while prioritizing speed of application development & keeping pace with the evolving threat landscape. A few key findings from the research include: • 93% of technologists believe that it’s important to be able to contextualize security so that they can correlate risk in relation to other key areas such as application performance, end user experience, and business metrics, and in doing so prioritize vulnerability fixes based on potential business impact. • 89% of technologists report that their organization has experienced an expansion in its attack surfaces over the last two years. • 58% of respondents admitted that their organization often ends up in ‘security limbo’ because they don’t know what to prioritize. IT teams are battling to stay ahead of an ever-expanding attack surface. However, current efforts to bolster application security are being hampered by information and activity silos. This means application and security teams lack the visibility and tools required to work together to address new risks. The potential implications of this are profound. Is your organization exposed to catastrophic service disruption which could damage customer experience, destroy brand credibility and shrink revenues and market share? Join AppDynamics and ISC2 February 28, 2023 at 1:00 pm Eastern/10:00 a.m. Pacific for a discussion surrounding the importance of developing a security centric approach for the full application stack throughout the lifecycle from development to production and breaking down silos between IT operations & security teams.

2023/2/28
阅读更多

The Future of AppSec: Adopting a Modern Approach for a Cloud-First World

Is your security team being hindered by a lack of visibility into security issues across development environments, lack of context to effectively prioritize and remediate security issues, and a scant forensic trail to investigate issues when they occur?   As development processes evolve in a cloud-first world, it’s clear that traditional security tools and processes are no longer sufficient to secure software supply chains and provide secure application delivery. Organizations must change their AppSec approach or risk getting caught in an accelerating cycle of vulnerabilities and threats.   On February 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join Legit Security and ISC2 to learn: • Why traditional AppSec is insufficient to secure modern, cloud-first development • How CISOs and security teams can work better with their development counterparts to enable secure application delivery • How to collect data and context to effectively drive security accountability across both Dev and AppSec teams • Real-world examples of companies that have successfully adopted a new AppSec approach

2023/2/23
阅读更多

API Security 101: Best Practices for Securing APIs

API security has been gaining a lot of attention in recent years due to the move of modern applications to cloud-native environments and microservice-based architectures. Securing the APIs that underpin these architectures can be a challenge for security teams due to their ever-changing nature and the lack of visibility in existing web security solutions. APIs are sprawling across your organization and increasing risk. You cannot protect what you don’t know. Join Prisma Cloud/Palo Alto and (ISC)2 February 21, 2023 at 1:00 p.m. Eastern, 10:00 a.m. Pacific as they discuss best practices all organizations should adopt to secure APIs. Get actionable insight into discovering and cataloging APIs, understanding attack surface, to applying protection and evaluating your security posture. A live simulation to follow. Take your API security to the next level.

2023/2/21
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, February 17, 2023, at 1:00 p.m. ET Save your spot now.

2023/2/17
阅读更多

CC EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about CC before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn about: • Career opportunities in cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • What to expect on exam day • And much more SAVE YOUR SPOT NOW.

2023/2/10
阅读更多

NEW-LIVE Ransomware Crisis Simulation with You in Control

Ransomware readiness is the #1 board-level directive when it comes to cyber security with attacks becoming increasingly complex. Join Cyberbit and (ISC)² on February 7th, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we prepare information security executives and incident responders for ransomware with a live-fire simulation of a recent attack vector. Participants will experience a new live simulation of a corporate ransomware crisis. As they are presented with an unfolding cyberattack scenario – one of the latest in the cyber threat landscape - they will be required to make critical incident response decisions. The session will combine the C-level, decision-making challenges encountered in a ransomware crisis with a hands-on, ransomware investigation simulated in a cyber range. The range will emulate a real-world SOC and demonstrate how IR experts can successfully investigate and eradicate a ransomware attack. The simulation allows the audience to impact the flow of the scenario by suggesting actions while our experienced instructor provides helpful tips. Whether you’re a first-timer or a returning participant, this webinar will take your ransomware readiness levels to the next level!

2023/2/7
阅读更多

SSCP EXAM READY: Ask the Experts Before You Sit

Join us for this live Q&A where our panel of experts will answer all of your questions about SSCP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How SSCP proves your knowledge, skills and experience as an ISO-accredited certification • Why vendor-neutral certification is in demand • What training tools are available • And much more SAVE YOUR SPOT NOW.

2023/2/3
阅读更多

Integrating Secure Code Signing in the CI/CD Pipeline

Code signing is a powerful method to protect the integrity of containers, artifacts, and software across the continuous integration and continuous deployment (CI/CD) pipeline. However, signing is more than just certificates and signatures. It’s about integrating the sign and verify process into your pipeline while keeping sensitive keys secure and in the right hands. If signing processes aren’t secure, it opens the door to malware, exploits, and supply chain attacks. On January 31 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, join (ISC)² and Keyfactor to learn how your organization can take steps toward integrating fast and secure signing within your CI/CD pipeline. We’ll discuss: - Where code signing fits into the CI/CD pipeline - Best practices for signing key protection and policy control - Recommended methods for safeguarding your organization’s keys.

2023/1/31
阅读更多

Avoid Becoming a Victim of Cryptojacking

Cloud adoption is the trend of the decade, and threat actors are tailoring their methods to this new attack surface. Cryptojacking is the most prevalent type of cloud attack due to the low risk and high reward for the perpetrator. But even containers are being used for evil as attackers’ plant unpleasant surprises in public repositories, exposing you and your business to potential supply chain compromise. On January 26, 2023 at 1 p.m. Eastern/10:00 a.m. Pacific join Sysdig and (ISC)2 to learn what you can do to protect yourself. We look forward to discussing: -What types of attacks are popular in the cloud and why. -How cryptojacking works and how to avoid becoming a victim. -What can be hiding in malicious Docker images and how to protect yourself.

2023/1/26
阅读更多

A Master Class on Cybersecurity: Password Best Practices

What really makes a “strong” password? And why are you and your end-users continually tortured by them? How do hackers crack your passwords with ease? And what can/should you do to improve your organization’s authentication methods? Password complexity, length, and rotation requirements are the bane of IT departments’ existence and are literally the cause of thousands of data breaches. But it doesn't have to be that way! Join KnowBe4 and (ISC)2 January 24, 2023 1:00 p.m. Eastern/10:00 a.m. Pacific for this thought-provoking webinar where we’ll discuss the most common risks associated with passwords and how to develop password policies that work. You’ll learn: • What you need to know about password length and complexity • How password attacks work and which ones you should be most worried about • What your password policy should be and why • Why your organization should be using a password manager Start improving your password defenses now!

2023/1/24
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, January 13, 2023, at 1:00 p.m. ET Save your spot now.

2023/1/20
阅读更多

How to Perform an Attack Surface Assessment

You can’t protect what you can’t see. This is true — especially for cybersecurity teams attempting to manage and shrink the attack surface of their organization. According to the Cloud Security Alliance, misconfigurations are responsible for up to 63% of security incidents. To combat this misgiving, organizations should perform an attack surface assessment to identify critical assets and risks associated with them. An attack surface assessment is an effort that's focused on increasing visibility by examining the entry points to all of your assets and data. This assessment is unique to each organization, leading to the detection of assets, vulnerabilities, and misconfigurations. In this session, January 17, 2023 at 1:00 p.m., Eastern/ 10:00 a.m. Pacific Axonius and (ISC)2 will share insights on how an attack surface assessment can help you with: • Discovering asset identification and inventory • Identifying previously unknown misconfigurations and vulnerabilities • Prioritizing security risks

2023/1/17
阅读更多

2022: A Year of Wrangling Assets and Reducing the Attack Surface

We’ve talked with hundreds of IT and Security professionals to understand the challenges, discoveries, strategies, and priorities related to managing and securing assets and reducing the attack surface in 2022. After analyzing these conversations and identifying several trends, we compiled the top lessons learned. In this straight-to-the-point session, on December 15, 2022 at 1:00 p.m. Eastern, 10:00 a.m. Pacific we will: • Identify challenges and pain points. • Deep-dive into some surprising discoveries. • Develop priorities for the future

2022/12/15
阅读更多

Everything You Need to Know about Certified in Cybersecurity

Join us for a deep dive into Certified in Cybersecurity (CC), the new entry-level credential from (ISC)², creator of the CISSP®. Cyberthreats continue to escalate worldwide, and the need for cybersecurity experts is critical. But talent is scarce. Research shows the workforce needs an influx of 3.4 million cybersecurity professionals to meet global demand. (ISC)² seeks to help close the skills gap with CC by opening opportunities in the industry to a new pool of professionals. With no experience required, it creates a clear pathway and breaks down traditional barriers to entry, enabling candidates to build confidence and enter their first cybersecurity role ready for what’s next. You’ll learn about: • Career opportunities in cybersecurity • Recommended core skills • Three ways to train for the exam • What to expect on exam day • And much more! Save your spot now. Presenters: Adesoji Ogunjobi, CISSP-ISSAP, CCSP, CSSLP Chad Kliewer, CISSP-ISSMP, CCSP, Professional Development Content Manager, (ISC)² Janet Gray, CC Moderator: Brandon Dunlap

2022/12/14
阅读更多

CISSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CISSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • How CISSP builds your end-to-end foundational understanding of cybersecurity • Why vendor-neutral certification is in demand • What training tools are available • And much more Bring your questions and join us on Friday, December 9, 2022, at 1:00 p.m. ET Save your spot now.

2022/12/9
阅读更多

Top Five Cybersecurity Predictions for 2023

Cybersecurity professionals have endured many challenges this year, including record-setting ransomware attacks, expanded attack surfaces, and shortages of skilled IT security personnel. However, we’ve seen security budgets rebound, increased reliance on cloud security deployments, and increased adoption of promising security technologies, such as zero trust network access (ZTNA), API security, and network/endpoint deception. So, what does next year have in store for the cybersecurity industry? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2023.

2022/12/7
阅读更多

Ransomware, Ransom-war and Ran-some-where

We've all heard about ransomware and its impact on organizations as they suffer an attack almost every two seconds. How can one of these cybercriminal organizations operate, what are their business models, and what is the level of experience needed to work for them? Last year, the Conti ransomware group was a victim of their own style of operations when their playbook, chat sessions, and other critical information ended up on the dark web. Join KnowBe4 and (ISC)2 December 6, 2022 at 1:00 p.m. Eastern, 10:00 a.m. Pacific to learn about: • The tactics, techniques, and procedures used by various cybercriminal groups, including one that provides a ransomware service • Understanding their modus operandi • How to defend against their styles of attacks

2022/12/6
阅读更多

CCSP EXAM READY: Ask the Experts Before You Sit

Join us for a live Q&A where our panel of experts will answer your questions about CCSP before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training strategies, career paths and more to help you build confidence so you’re ready on exam day. You’ll learn: • Why vendor-neutral certification is in demand • How CCSP complements vendor certifications • What training tools are available • And much more Bring your questions and join us on Friday, December 2, 2022, at 1:00 p.m. ET Save your spot now.

2022/12/2
阅读更多

Be Prepared; DDoS Attackers are Using New Tactics

DDoS (distributed denial of service) attacks continue to increase in frequency and sophistication as attackers innovate with new adaptive DDoS attack tactics and techniques. Dive into NETSCOUT’s latest DDoS Threat Intelligence Report that reveals multiple noteworthy findings and trends followed by a simulated DDoS attack against stateful devices. Join NETSCOUT and (ISC)2 on December 1, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific us as we explore the report and recommend best practices in adaptive DDoS defense: - Global and regional DDoS attack stats and trends. - DDoS attacks are increasing being linked to worldwide geopolitical events (e.g., the Russian-Ukraine war.) - Attackers are conducting more pre-attack reconnaissance to determine attack vectors, avoid detection, and maximize impact on targets. - Attackers are moving away from reflection/amplification attacks towards direct path, state exhausting attacks that target stateful devices like firewalls and load balancers.

2022/12/1
阅读更多

Attacker Automation: How Bots Are Evading Your Defenses For Fraud And Profit

As defenders, we increasingly look to automation and machine learning to detect attacks and tune our defences. But we’re not alone. Organised crime constantly develops their capabilities and continuously looks for ways to attack applications without being detected. Automation plays a huge part in this. This talk uncovers the modern automated methods which attackers are using to bypass CAPTCHAs, multi-factor authentication, client finger printing, and bot detection systems. We will explain the methods they use and take you through some real attack stories so that you will better understand the capabilities of organised threat actors. Attend this talk November 29, 2022 at 1:00 p.m.Eastern/10:00 a.m. Pacific to learn: 1. The tools and techniques attackers are using to bypass bot detection 2. Examples of real bot attack stories 3. Recommended methods for detecting and dealing with heavily automated attacks

2022/11/29
阅读更多

BlueVoyant #2- A Look Into The SOC: A Purple Team Exercise

Purple teaming, or a method of working between Red attack teams and Blue defense teams, is a way to measure detection fidelity and offer test and retest reliability for detection content. But what does it look like when we put this method into action? Join us as we show you the BlueVoyant Security Operations Center (SOC) to learn more about what goes into purple team exercises, and how they benefit organizations. Plus we’ll cover: • A breakdown of a purple team exercise and how we measure success • Tips and tricks SOC teams can apply today • Why having purple teaming as a feature in your MDR service matters

2022/11/18
阅读更多

2022 Cybersecurity Workforce Evolution

A critical need for cybersecurity professionals persists amidst a year of cultural and workplace evolution. Join guest speaker Forrester Principal Analyst Heidi Shey as she shines a light on key topics within this year’s (ISC)2 Cybersecurity Workforce Study: - Certifications. They are evolving as an instrument of skills growth, rather than just a career launchpad - Generation Gaps. A look into the unique perspectives of both younger and more tenured employees, and how their views differ on topics like emerging challenges within the industry and cultural dynamics at an organizational level. - Diversity, Equity and Inclusion (DEI). Across the world, the cybersecurity profession is rapidly changing and experiencing profound demographic shifts in age, gender, race and ethnicity. We will shine a spotlight on how they are changing and what it means.

2022/11/15
阅读更多

External Cyber Defense for when Your Attack Surface is Everywhere

The CISO’s job now includes much more than just securing an organization’s internal network. The evolving cyber threat landscape has security teams scrambling to respond to an onslaught of attacks from all angles. Between sophisticated phishing kits used by even novice hackers, to vulnerabilities across the global supply chain, and the sheer volume of emerging attack vectors. Enter external cyber defense. By combining the most comprehensive digital risk protection (DRP) solution with cutting-edge third-party cyber risk management, you can extend visibility outside your perimeter to identify, validate, and shut down cyber threats as they emerge in the darkest corners of the internet and across your vendor ecosystem. Join BlueVoyant and (ISC)² on November 10, 2022 1p.m. Eastern/ 10am Pacific to learn how our solution can help your security team: • Advance from a reactive to proactive security posture to thwart attacks at the source • Identify and remediate risks across the entire third-party vendor and partner ecosystem • Scale threat response regardless of organization size and improve patch time for identified vulnerabilities

2022/11/10
阅读更多

5 Best Practices for Securing Modern Web Applications and API’s

Today, web apps and APIs are the most common medium for sharing and modifying data. The boom in cloud-native architecture has led to increased economies of scale and the ability to speed the delivery of services like never before. But as web applications continue to evolve, so does your attack surface, creating new complexities and vulnerabilities. The bottom line: If you’re not protecting your web apps and APIs, you’re not adequately protecting your valuable data. So what do you do? Join Palo Alto and (ISC)² November 3, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn 5 best practices to help you secure your critical web applications, APIs and ALL data on ANY cloud-native architecture.

2022/11/3
阅读更多

Is A Career in Cybersecurity Right for Me? Why to Pursue a Cybersecurity Career

Why cybersecurity? With the current threats to cyber stability around the world, there’s never been a greater urgency for cybersecurity professionals than now. The result: a boom in demand for skilled cybersecurity professionals. Whether you’re just starting out in your professional career or looking to do something new, here are four reasons to consider joining the exciting and rewarding field of cybersecurity: 1. Work where life lands you with near limitless employment potential. 2. Choose any industry that intrigues you. Every industry needs skilled cybersecurity professionals. 3. Work in the area of cybersecurity that interests you most. There are many different career pathways. 4. Find job security in a field that’s future-proof. Join us for this webinar and learn why cybersecurity is reliant on teams with diverse skills, experiences and ideas and how you fit in. Save your spot now.

2022/11/2
阅读更多

Your Ransomware Hostage Rescue Guide

Ransomware attacks are on the rise — and they’re estimated to cost global organizations billions of dollars in damages and downtime. As ransomware attacks become more targeted and damaging, your organization faces increased risk that can have your networks down for days or even weeks. So, how can your organization avoid getting held hostage? On October 27, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific join KnowBe4 and (ISC)² as we look at features of new ransomware strains, give actionable info that you need to prevent infections, and provide tips on what to do when you are hit with ransomware. In this webcast we will cover: · What new scary ransomware strains are in the wild · Am I infected? · I’m infected, now what? · Proven methods of protecting your organization? · How to create a “human firewall”

2022/10/27
阅读更多

Identity-In-Depth: How to Build Your Identity Security Practice

Technology and identities are inseparable today. Together they drive digital transformation and fuel business innovation. However, they also represent a tremendous attack surface. Statistically most data breaches have an identity angle. The rates of successful attack are causing organizations to rethink their security strategy by putting identity security at the core of their cyber initiatives. The challenge organizations face is how to protect the connection between technology and identities without compromising the power that this pairing provides. This can be a daunting task for any organization. The good news is that years of research and development have taught us there are best practices to consider. Whether you are seeking information on how to get started, how to lower cyber insurance costs, how to move towards zero trust, or how to enhance your already seasoned identity programs, this session will offer insights and information to assist you on your journey. Join SailPoint and (ISC)² October 25, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as they talk about Identity Security with focus on: -Understanding risks posed by the marriage of technology and identity -Discussing how your identity security program impacts your end users – and why it’s a good thing! -Discovering how to develop a clear roadmap for your Identity Security program

2022/10/25
阅读更多

Unconscious Bias Series (Part 3): Managing Bias

Many professions value and leverage pattern recognition and informed judgment based on limited information. While this is a huge strength for our employees, managers and practitioners, it could also lead to unconscious biases in our decisions making when it comes to day-to-day issues like hiring, mentoring, promoting, staffing, developing people, and engaging with clients. On October 24th at 1:00 p.m. Eastern/10:00 a.m. Pacific Cyversity and (ISC)² discuss Managing Bias, as part 3 of this 3-part Unconscious Bias Series. This webinar will share an engaging mix of insights, exercises, illustrations, activities, polls, and videos, will enable participants to understand their unconscious biases in a constructive manner to help obtain the highest level of inclusiveness and performance.

2022/10/24
阅读更多

What You Need to Know About Securing Developer Environments Before It’s Too Late

The pace of new software releases has grown rapidly since the shift to DevOps, which in turn has created a dynamic attack surface in need of immediate protection: the development environments in your software supply chain. Attackers are compromising your source code management systems, build servers, and artifact registries in your CI/CD pipelines. As seen in the recent LastPass security incident, a compromise of one development system led to business interruption and the exfiltration of LastPass’s source code and proprietary data. Join Legit Security and (ISC)² October 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we discuss techniques you can use to effectively harden your developer environments. In this webinar you will also learn: • How to prevent your business from falling victim to the type of attack that recently compromised LastPass • Methods for security practitioners to secure decentralized developer environments at scale • Best practices to reduce the likelihood of lateral movement in the event of a compromised developer environment

2022/10/20
阅读更多

Cybersecurity Career Hacks for Newcomers: No Work Experience? No Problem

Cybersecurity is hot. New opportunities are constantly opening in the expanding global market. The ongoing threat of data breaches and cyberattacks mean organizations everywhere need professionals on their teams to protect their data and critical assets. How can you get started in this exciting and rewarding field? It depends where you are in your career, what you want to do and where you see your future. If you’re a problem solver, like helping people and are excited at the prospect of working in a constantly evolving field, you already have a lot in common with today’s cybersecurity workforce. Join us for this webinar and get a leg up on your future in cybersecurity with tried-and-tested career hacks from three different entry points: students, incoming professionals and career changers. You’ll learn about: • Current cybersecurity market conditions • Where entry-level lands you on a team of professionals • How to get a certified advantage with no prior experience Save your spot now.

2022/10/18
阅读更多

Strategies for Recruiting and Retaining Top IT Security Talent

Recruiting and retaining qualified IT security talent has never been more challenging. Seven in eight organizations are experiencing a shortfall, according to CyberEdge’s 2022 Cyberthreat Defense Report. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can smart security organizations do to mitigate the effects of this talent shortage? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Examines the shortage of IT security personnel by job role - Proposes creative ways for recruiting new security talent - Suggests clever ways for retaining the talent you already have - Identifies technologies and services that enable security teams to do more with less

2022/10/12
阅读更多

Cybersecurity’s Impact on Patient Safety and Trust

For an industry whose mission is to improve our quality of life, it’s interesting that the top cybersecurity concerns tend to focus around financial losses such as costs of mitigation, noncompliance, or lawsuits. IT and Security leaders need to rethink the importance of cybersecurity through a new lens — patient safety and trust. On October 6, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss where patient safety is being impacted by cyber-attacks, the favored attacks being deployed by threat actors, and what can organizations do to properly address cybersecurity risks and engender increased patient trust.

2022/10/6
阅读更多

Hacking the Hacker: Assessing & Addressing Cyber Defense Weaknesses

Cybercriminals are out there, watching and waiting for the perfect opportunity. They are gathering information about your organization and users, devising the perfect plan to infiltrate your defenses. But with a strategic approach to cyber defense you can hack the hacker before they strike! In this session, we'll share insights into their strategies and their motivations. You’ll learn how to use that understanding, along with simple strategies to make your organization a hard target. Join KnowBe4 and (ISC)² September 29, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar where we will expose the mind of a hacker to help you see your cyber risks from the outside in. In this session you’ll learn: • How hackers collect “private” details about your organization and your users • The most common root causes that lead to damaging cyber attacks • Common mistakes made when designing cyber defenses and how to fix them • Data-driven strategies for mitigating your biggest weaknesses • Why a strong human firewall is your best, last line of defense Get the details you need to know now to outsmart cybercriminals before you become their next victim

2022/10/4
阅读更多

Know Your Adversary:Key Findings from NETSCOUT DDoS Threat Intelligence Report

Cybercriminals use an ever-increasing array of DDoS attack vectors to target business and governments. Today, the question isn’t if, but when, you will be a target. Knowing your adversary's latest tactics and techniques are key to your defense. Join NETSCOUT and (ISC)² to explore the findings and trends from the latest NETSCOUT DDoS Threat Intelligence Report. • Global and regional DDoS attacks stats (e.g. size, frequency, vectors.) • How attackers are getting more sophisticated in their DDoS attack techniques, and the most common attack vectors. • The relationship between DDoS attacks and geopolitical events. • The increasing number and size of botnets that are being used to launch DDoS attacks. • Best practices in DDoS attack defense and suppression.

2022/9/30
阅读更多

Bringing Zero Trust to Applications From Code to Cloud

Never Trust, Always Verify. Cloud workloads are constantly evolving and changing. Third-party providers operate outside of company networks. With data in various places, companies can't keep up with who and what have access, and they don't know how critical data might be being exploited. Now you can take an evolutionary step in security with a Zero Trust framework that eliminates implied trust with continuous validation at every stage of a digital interaction, enables developer teams to modernize applications with cloud native development, allows security teams to strengthen defenses across the application lifecycle. On September 28, 2022 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, join Palo Alto Networks and (ISC)² to learn how you can apply an enterprise-wide Zero Trust strategy with integrated capabilities for complete cloud native application protection in your organization. You’ll also find out why organizations that tightly integrate DevSecOps principles into their development lifecycles are: - Over 7X more likely to have strong or very strong security postures - 9X more likely to have low levels of security friction

2022/9/28
阅读更多

From Pandas To Unicorns: Using Artificial Environments To Solve Problems

With successful cyber-attacks and breaches at an all-time high, a continually increasing cybersecurity workforce gap, and the specter of the “great resignation,” organizations are finding it increasingly difficult to hire and retain sufficiently experienced cybersecurity professionals. When faced with a dwindling giant panda population in the late 1900s, conservationists the world over poured their time and effort into restoring the population from its critical lows. The use of artificial environments gave the pandas the stimulation and experience necessary to return their species from the brink of extinction. Similarly, our industry faces a species on the brink, the cyber unicorn. They are under threat from burnout, headhunters, and other natural and artificial phenomena. On September 27, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific we will explore real-world case studies on how large organizations are using cyber ranges to combat team burnout, build practical expertise, and assess readiness. Topics covered include Red-, Blue-, and Purple-team events, automated user behavior, and threat presentation - manual and automated.

2022/9/27
阅读更多

Unconscious Bias Series (Part 2): Identifying Bias

Many professions value and leverage pattern recognition and informed judgment based on limited information. While this is a huge strength for our employees, managers and practitioners, it could also lead to unconscious biases in our decisions making when it comes to day-to-day issues like hiring, mentoring, promoting, staffing, developing people, and engaging with clients. On September 21, 2022 at 1:00p.m. Eastern/10:00 a.m Pacific, Cyversity and (ISC)² present part 2 of this 3-part Unconscious Bias Series. this webinar will share an engaging mix of insights, exercises, illustrations, activities, polls, and videos, will enable participants to identify their unconscious biases. Session participants will leave with specific understanding of the various types of biases we all have and how to diagnose them.

2022/9/21
阅读更多

Zero Trust: Use Cases to Accelerate Your Program’s Maturity

Applying zero trust architectures in an iterative way – one project at a time – has proven a sustainable method to deepen zero trust capabilities across a program. On September 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, IANS and (ISC)² discuss specific zero trust use cases to help accelerate your organization’s zero trust maturation, including: • Walking through zero trust use cases within various domains: people, devices, applications • Discussing the available tooling options and considerations necessary to implement the use case • Words of caution and recommendations to help your organization advance in its zero trust journey

2022/9/20
阅读更多

How to Implement Posture Management to Address Cyber Risks

In a recent edition of its CISO Workshop, Microsoft emphasized posture management for addressing cyber risk. This new discipline goes far beyond traditional vulnerability management, looking into operations and processes to help organizations further prevent harm. On September 15, 2022 join Netwrix and (ISC)² at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn the following in this “plan & build” session: • How to implement posture management in your organization and who needs to be involved • Metrics for success and pitfalls that can lead to failure • How posture management helps with compliance and incident management • What types of tools map to the various aspects of posture management

2022/9/15
阅读更多

The Evolution of Risk-based Vulnerability Management

Vulnerability management has been a staple of security teams for decades. But if you haven’t noticed, this space has evolved considerably over the last half decade. Long gone are the days of lengthy, hard-to-digest vulnerability scanning reports often created to check the PCI compliance checkbox. These days, smart IT security teams are investing in risk-based vulnerability management (RBVM) technologies and best practices to help prioritize which vulnerabilities to remediate first based on a variety of internal and external factors. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps the evolution from VA, to VM, to RBVM - Defines key elements of modern-day RBVM solutions - Reviews internal and external factors to help prioritize vulnerability remediation - Describes what to look for when evaluating best-of-breed RBVM offerings - Summarizes the extraordinary benefits derived from RBVM deployments

2022/9/14
阅读更多

Unmasking VENOM SPIDER— the Hacker Behind Golden Chickens Malware

For the past 16 months, eSentire’s security research team, the Threat Response Unit (TRU), has been tracking one of the most capable and stealthy malware suites—Golden Chickens. This malware is the “cyber weapon of choice” for two of Russia’s top cybercrime groups: FIN6 and Cobalt Group. TRU not only detected a new Golden Chickens threat campaign targeting e-commerce organizations but has also discovered the identity of the threat actors behind it. With this intelligence we deciphered the threat actor’s Tactics, Techniques and Procedures (TTPs), as well as the origins of the Golden Chickens Malware-As-A-Service (MaaS) and its ongoing operations. In this webinar on September 13, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific eSentire and (ISC)² walk you through the Golden Chickens malware suite and the reconnaissance to unmask the identity of the VENOM SPIDER. Learn more about: • A detailed account of the investigation and subsequent identification of the Golden Chickens MaaS operator • An analysis of the Golden Chickens malware and the current cyberattack campaign • Insights and threat detection recommendations on how to defend your organization from the Golden Chickens threat • An overview of the FIN6 and Cobalt Group cybercrime organizations

2022/9/13
阅读更多

The Top 5 Cloud Native Risks

Nearly 70% of organizations host more than half their workloads in the cloud, which has more than doubled since 2020. There’s a dangerous pothole on the fast track to cloud migration, and it grows larger the longer it’s ignored: application development security. The good news is that wherever you are on the journey, you can rethink your cloud native development strategy and confidently steer clear of damage. Our webinar “Top 5 Cloud-Native Risks” is a smart place to start. Join Palo Alto and (ISC)² September 8, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to see the latest research, insights and recommendations from pros in security, DevOps technical, and line of business leadership. Learn how to balance the benefits of cloud native development with new best practices for protecting applications, and ensure that your environment stays resilient, flexible and secure.

2022/9/8
阅读更多

The Reason Why Ransomware is Really HEATing Up

When entire workforces went remote in 2020 because of the global pandemic, organizations pivoted quickly to new business models by migrating apps and services to the cloud to enable the anywhere, everywhere workforce. Many business users are spending a majority of their workday in a browser which accesses unmanaged sites, too. These same digital enhancements, also ushered in widespread transformation that expanded attack surfaces and created new opportunities for cyber miscreants, giving rise to Highly Evasive Adaptive Threats (HEAT), which are used as entry points for initiating ransomware, data theft, and account takeovers. During this insightful session taking place on Tuesday, August 30, 2022 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, (ISC)² and Menlo Security will discuss why HEAT attacks are the next-class of browser-based attacks taking advantage of today’s remote and hybrid workforce.

2022/8/30
阅读更多

Why Legacy Network Firewalls Are Unfit To Deliver Zero Trust Security

72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us for this live replay session as Zscaler and (ISC)² discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster

2022/8/25
阅读更多

The First Step to Zero Trust: Cybersecurity Asset Management

“How can we implement a zero trust strategy?” is a question asked by nearly every security team that wants to avoid increasing their attack surface and being the victim of a high-profile breach. A zero trust strategy is rooted in the principle of “never trust, always verify” — which minimizes risk by securing sensitive data, systems, and services. However, all too often security teams discover that they don't have the visibility they need to do this. The first step to implementing a zero trust strategy and achieving exceptional security hygiene? Building and maintaining an inventory of your critical assets. Please join Axonius and (ISC)² on August 23 at 1:00pm Eastern/10:00 a.m. Pacific as we share how teams can approach zero trust principles and how keeping an asset inventory can help answer the toughest zero trust questions: What device is trying to access corporate assets? What vulnerabilities exist on my applications and services? Which users have access to critical resources? Is my zero trust application managed or unmanaged?

2022/8/23
阅读更多

OWASP Automated Threats: 21 Fraud Street

The OWASP® Foundation works to improve the security of software through its community-led open source software projects and is the de facto authority on bots and malicious automation. Join this webinar to dive into the OWASP Automated Threats (OAT) project and get important guidance that you can immediately put into practice. We will dive into the ontology and countermeasures of the OAT, discuss example scenarios, and get real on some widely deployed security controls (apologies in advance to any CAPTCHA fans). Learn the importance of mitigating attacks like credential stuffing, which is a part of the OWASP Automated Threats project, and is a top software security risk as detailed in the OWASP Top 10.

2022/8/22
阅读更多

2022 Application Protection Report: Data Breaches, Cloud Incidents, & APTs

No doubt, you’ve seen it, the threat landscape is evolving year over year. How do you fine tune your defenses against an ever-changing adversary? On August 18, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific join F5 Labs and (ISC)² for a multifaceted analysis of the application security threat landscape based on F5 Labs’ 2022 Application Protection Report. The report analyzes nearly 1,000 data breaches from 2021, focusing on three specific threats: ransomware, which played a role in nearly half of the successful attacks in 2021; formjacking attacks like Magecart; and data exfiltration, which was featured in nearly 80% of breaches. F5 Labs and will share additional perspectives of the threat landscape, with a look at cloud risks, cryptocurrency theft, and some case studies about well-resourced attackers. The session will conclude with recommended best practices using prioritization methods for different scenarios.

2022/8/18
阅读更多

Ransomware Deep Dive: Preparing for the Inevitable

More than seven in 10 organizations were victimized by successful ransomware attacks last year. These days, it’s more of a question of “when” than “if” your organization will be next. Are you ready? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews the latest ransomware statistics from the 2022 Cyberthreat Defense Report and describes what it takes to be prepared for the inevitable. Specifically, Steve will: - Examine disturbing ransomware trends, by country and by industry - Evaluate key factors that go into deciding whether to pay ransoms - Outline ways to be prepared for a successful ransomware attack - Review technologies to help give security teams the upper hand

2022/8/17
阅读更多

BlueVoyant #1- Using purple teaming to improve your SOC operations

Red and Blue Teams have historically been siloed, meaning the Red Team conducts exercises such as penetration testing, social engineering, and web app scanning to test the organization’s defenses, the Blue Team handles defensive security, including threat hunting and digital forensics, but what about working together? What is Purple teaming? Purple teaming has been adopted by BlueVoyant as a way to measure our detection fidelity and have test/retest reliability for our detection content used by our MDR customers. In our quest to be the most transparent, data privacy centric MDR, we want to share what purple teaming means to BlueVoyant and why choosing implementing purple teaming may be right for your organization as well. Save your spot now to learn: • Purple teams save organizations time • How to implement this framework within your organization • Why having purple teaming as a feature in your MDR service matters

2022/8/17
阅读更多

Securing Modern Applications: Serverless, Containers and Cloud

As organizations move more workloads to the cloud, security teams need to adapt their workflows to keep up. On August 11, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific IANS and (ISC)2 discuss: • Best practices for securing containers, serverless and SaaS/PaaS/IaaS applications • How best to insert security into the software development life-cycle • How to ensure every app in production is as secure as it can be

2022/8/11
阅读更多

Craziest Cyberattacks Seen In the Wild and How You Can Avoid Them

It feels like we hear about a new devastating cyberattack in the news every day. And attack methods seem to be proliferating at an exponential rate. So, which tactics should you be aware of beyond standard “click and infect” attack vectors? Join Roger Grimes KnowBe4's Data-Driven Defense Evangelist and popular cybersecurity author for this eye-opening webinar. He will share his take on several significant, advanced, and yes, crazy cyberattacks he’s seen in the wild. Plus, he’ll share defensive strategies you’ll want to implement to prevent them from affecting your network. You’ll see examples of some amazing hacks showing how: Your users’ passwords can be cracked in mere minutes Cybercriminals easily bypass Multi-Factor Authentication Automated malware can devastate your network Hackers can completely take over your network with a few simple steps And more! Find out what you can do to mitigate these advanced hacking techniques instead of becoming the next unknowing victim.

2022/8/4
阅读更多

Securing Your Cloud Migration

This session will focus on methods for security teams to better monitor and secure hybrid cloud environments while logging compliance data. Learn best practices to analyze, prioritize, and investigate security alerts within cloud resources faster and more accurately through a variety of cloud-agnostic security strategies while reducing downtime and security incidents. On July 28, 2022 at 1:00 p.m. Eastern/10:00 am. Pacific Sumo Logic and (ISC)² will: • Discuss business motivations for cloud migration. • Identify common challenges while monitoring applications throughout the migration. • Explore solutions for typical security operations constraints during the migration.

2022/7/28
阅读更多

Stop Threats Earlier by Integrating NDR and Other Cybersecurity Solutions

Having a strongly aligned and integrated ecosystem of cyber tech and tools is required to protect and preserve the business in today’s digital infrastructures. Over the last several years, more and more traffic has migrated from plaintext protocols to encrypted protocols. While this provides better privacy and security, it also makes it more difficult to troubleshoot this traffic when problems inevitably arise. Although security and network monitoring tools can still analyze some encrypted traffic without decryption, lots of details cannot be analyzed adequately. This session, sponsored by Netscout and hosted by (ISC)² on July 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, will show how integrating decryption with NDR solutions can provide an even more robust monitoring experience. To further the dialogue regarding a healthy cybersecurity solution ecosystem, this session will also explore the critical aspects to integrating NDR with EDR, SIEM and SOAR technologies.

2022/7/26
阅读更多

Use a People-Centric Defense to Build Resilience to Today's Cyber Threats

“SMS-based phishing attempts doubled in the U.S. year over year”-- that is just one key finding in Proofpoint’s 2022 Human Factor Threat Report. The report is the culmination of a year’s worth of threat research and insights drawn from more than 5 billion email messages, 35 billion URLs, 200 million attachments, 35 million cloud accounts and 1.7 billion suspicious SMS messages. It reveals surprising trends and offers actionable insight that sheds light on the nature of today’s cyber threats. Join us July 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Proofpoint and (ISC)² take a deep dive into: • The developing relationship between cyber-criminal groups and what it means for the rest of us • How the most critical variable, people, can help mitigate attacks and manage privilege • The threats detected, mitigated and resolved during 2021 and our deployments

2022/7/21
阅读更多

Accelerate Your Third-Party Risk Management (TPRM) Program

With the current push for digital business transformation, organizations are increasingly dependent on external parties, increasing their vulnerability to vendor cyber risk. Because many vendor risk management programs are developed as tactical responses to ensure compliance with a growing list of data privacy and cybersecurity regulations, they often result in labor-intensive and inefficient processes that deliver marginal value. Industry best practices for effective Third-Party Cyber Risk Management can improve your program and may provide cyber defense for your third parties. In this webinar, July 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, BlueVoyant and (ISC)² will discuss: • Industry recognized best practices for an effective TPRM program • How to transform your TPRM program with continuous monitoring and active risk identification and mitigation • Ways to solve your toughest TPRM challenges

2022/7/20
阅读更多

Ransomware Resilience: Build a Holistic Data Protection Strategy

Ransomware continues to hit organizations of all sizes, and with the latest iterations, a more holistic approach is warranted. On July 14, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific join IANS and (ISC)² to learn ways to improve overall resilience, including: • Unpacking different backup strategies (offline, immutable storage, data-only) and the advantages and drawbacks of each • How to use multiple methods (e.g., DLP, app-native auditing, etc.) to monitor and alert on data theft • Ways to minimize attacker lateral movement

2022/7/14
阅读更多

Why Legacy Network Firewalls Are Unfit To Deliver Zero Trust Security

72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us July 12, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific when Zscaler and (ISC)² 's webinar session will discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster

2022/7/12
阅读更多

Planning for COMPLETE Recovery from a Ransomware Attack

Accidents and attacks can happen – no matter how airtight your security practices are. As ransomware threats continue to surge, businesses struggle to manage data security and associated costs. Recovering from a ransomware attack, in particular, is often a costly endeavor, with victims scrambling to minimize downtime, revenue loss, and reputation damage. When things go wrong, the organization needs a comprehensive disaster recovery plan in place to restore all data and resume normal operations. Join Synology and (ISC)² on July 7, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webcast where we will examine the fundamental elements of a complete disaster recovery plan, such as endpoint and cloud backup, off-site failover, and remote archives. In this session, we will also walk through several case studies identifying opportunities to enhance restoration efficiency and minimize work disruptions.

2022/7/7
阅读更多

Second Order Cyber Risk: Exposing Your Blind Spots

The very activities that cybersecurity teams do to make their organizations safe can create additional risk for the organization. Defenders can unintentionally create new ways for attackers to target their organization through inadvertently introducing new vulnerabilities, placing too much trust in their security strategy, ignoring alert fatigue, and by making their mitigation activities too predictable. During this session, we will: • Explore why blindly applying vendor patches may not always be the best strategy. • See examples of how overconfidence in any single line of defense can be dangerous. • Identify opportunities to streamline incident alerts and monitoring so critical notifications are not missed. • Learn why following an incident response playbook may not always be in your best interest. Join us on June 30, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific when SimSpace and (ISC)² will discuss the four types of second-order cyber risk and offer practical advice on best practices that form a continuous improvement approach to improve overall cyber hygiene while minimizing second-order cyber risks.

2022/6/30
阅读更多

Unconscious Bias Series (Part 1): Understanding Bias

Many professions value and leverage pattern recognition and informed judgment based on limited information. While this is a huge strength for our employees, managers and practitioners, it could also lead to unconscious biases in our decisions making when it comes to day-to-day issues like hiring, mentoring, promoting, staffing, developing people, and engaging with clients. On June 29, 2022 at 1:00p.m. Eastern/10:00 a.m. Pacific Cyversity and (ISC)² present part 1 of this 3 part Unconscious Bias Series. This engaging mix of insights, exercises, illustrations, activities, polls, and videos, will enable participants to understand their unconscious biases. Session participants will leave with specific strategies and tactics that they can deploy in their day-to-day work as they learn the definition, domains and impact of bias.

2022/6/29
阅读更多

Zero Trust: Real-World Tactics and Strategies

No doubt, you’ve heard the buzz about zero trust. Zero trust isn’t a product but rather a journey. While the end goal is worthwhile, like most things in security, getting there won’t be fast or easy. In this live session, June 28, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific IANS Faculty and (ISC)² discuss: • Exactly what a strong zero trust architecture requires • Concrete steps to take and products to consider to that help keep you moving on the right path • Ways to measure progress, set realistic milestones and ensure goals are obtainable

2022/6/28
阅读更多

CyberRisk Alliance Global Security Report: Remote Workers Spell Trouble

The business disruptions from COVID have had a profound effect on information security for organizations around the world, and the U.S. has grappled right along with the rest of the world. A new report from the CyberRisk Alliance and Infoblox brings those effects into sharp focus—and in an easily consumable way. The report, 2022 Global State of Security Report, gives you a one-of-a-kind picture of the global state of security at the end of the second year of the pandemic, with a focus on the U.S. as it has also had to contend with the ongoing economic instability brought about by a labor market in turmoil. Join Infoblox and (ISC)² June 16, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar and learn more about: ● The measures organizations worldwide took to mitigate risks associated with a remote workforce ● The most urgent security challenges posed by remote and hybrid work—and which ones U.S. organizations are prioritizing for mitigation ● Which attack vectors malicious actors targeted the most

2022/6/16
阅读更多

DDoS Attack Trends and Predictions for 2022

Denial of service attacks became larger and more complex in 2021 with peak attack bandwidth now more than five times larger than it was in 2020. From disgruntled customers, to organized cybercrime and even modern day cyber warfare, DDoS attacks are still a go-to for many threat actors with effects of successful denial of service attacks ranging from temporary disruption of an online event to outages of critical infrastructure. Increasingly, DDoS attacks also used by cybercrime gangs to coerce payments of ransomware demands. While DDoS mitigation services are getting better at deflecting large volumetric DDoS attacks, the shift in tactics to focus on protocol and application DDoS makes mitigation a more complex task. On June 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and F5 Labs discuss the F5 DDoS Trends report which analyzed thousands of attacks over the past two years to uncover how DDoS attacks are changing. We will showcase which industry sectors are most frequently attacked, which suffer the largest and most complex attacks, and some of the relevant security controls which can be employed to counter the growing threat. Join this webinar to learn: -What the most common forms of DDoS attacks are -Which industries are most effected -How attackers are building botnets and changing tactics -How to use the MITRE ATT&CK framework to map effective security controls

2022/6/14
阅读更多

Cloud Threat Report: IAM the first line of defense

The ongoing transition to cloud platforms has meant that more sensitive data is stored in the cloud, making it more tempting for adversaries to exploit. When it comes to securing the cloud, identity is the first line of defense. Proper identity and access management (IAM) policies are the foundation of comprehensive cloud security principles. To understand how IAM policies affect organizations' cloud security posture, Unit 42 researchers analyzed 680,000+ identities across 18,000 cloud accounts from 200 different organizations. The results of our research were shocking - nearly all organizations we analyzed lack the proper IAM management policy controls to remain secure. Misconfigured IAM policies open the door for cloud threat actors. We define a cloud threat actor as "an individual or group posing a threat to organizations through directed and sustained access to cloud platform resources, services or embedded metadata." Cloud threat actors merit a separate definition as they employ a fundamentally different set of tactics, techniques and procedures (TTPs) that are unique to the cloud – such as taking advantage of the ability to perform both lateral movement and privilege escalation operations simultaneously. Join Palo Alto and (ISC)² June 2, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar where the audience will be guided through the latest research in overprivileged IAM identities in real-world cloud environments and how cloud threat actors are zeroing in on these excessive permissions to expand their control of cloud environments. Detection and mitigation of these risks are possible, join us to find out how!

2022/6/2
阅读更多

The Future of Security Operations: Strategies from Successful Leaders

While understaffing and low budgets have always been challenges for any team, security teams face many unique roadblocks that divert attention from working on higher-impact projects that contribute to their organization's security posture. On May 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Tines discuss the learnings of security leaders who have found a way to free their teams from manual tasks and remove the barriers so they can focus on high-value strategic work that truly matters. We'll distill their best practices and leave attendees with actionable insights that they can immediately put to work with their team, including: • What to look for when choosing a security tool. • What security leaders are doing to address burnout and mental health issues within their teams. • How to make security roles more accessible via Diversity, Equity, and Inclusion. • What endpoint hygiene means and lessons they learned while working at multinational corporations.

2022/5/26
阅读更多

Key Insights from CyberEdge’s 2022 Cyberthreat Defense Report

A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration

2022/5/25
阅读更多

Holistic Application Security for PCI DSS Compliance

As the old adage goes “an ounce of prevention is worth a pound of cure.” A holistic application security (AppSec) program is essential for validating your applications’ security. AppSec experts perform a variety of security assessments that identify your software’s flaws and vulnerabilities. These bugs are then prioritized for remediation according to their severity and in accordance with your unique risk profile. In this webinar May 24, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Synopsys and (ISC)² will focus on how you can mature your AppSec program with the Payment Card Industry Data Security Standard (PCI DSS) in mind. You will learn how to • Establish an AppSec program that meets or exceeds PCI requirements • Leverage the OWASP and NIST frameworks • Perform thorough code review, pen testing, and vulnerability assessments

2022/5/24
阅读更多

Multi-Signal Defense Kill Chain: Strengthening Combat Capabilities in Intrusions

Cybersecurity teams are fighting a losing battle trying to keep up with complex business requirements and the expanding attack surface. Although traditional security controls and MSSPs (managed security service providers) were once effective, they are no match for the growing speed and sophistication of modern threats. Unfortunately, you can’t protect your organization from cyber threats if you don’t have complete visibility across your attack surface. Even if your team utilizes a global threat hunting and threat intelligence team, they must be armed with data correlation and contextualization capabilities across multiple signals (e.g., endpoint, log, network, cloud) to effectively contain and remediate advanced persistent threats. Join eSentire and (ISC)² May 19, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific to hear how threat intelligence teams can use data from multiple signal sources for enhanced threat detection, investigation, and response. Learn more about: • What multi-signal data correlation and contextualization means in the context of threat intelligence and threat hunting • Mapping tactics and techniques threat actors use to fulfill their objectives back to each phase of the overall attack workflow • Deep dive into how eSentire’s Threat Response Unit (TRU) used data from log, endpoint, and network to build detection content for threats like Log4j and Cobalt Strike • How threat intelligence teams can adopt a multi-signal approach to enrich their detection engineering content

2022/5/19
阅读更多

A Persistent Cyber Target for Threat Actors: HealthCare

Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.

2022/5/18
阅读更多

BlueVoyant#3 Adapting Proactively to an Evolving Third-Party Risk Landscape

Effectively managing and mitigating cyber risk in your supply chain today means moving away from trust-based approaches and investing in a more proactive third-party risk program. A variety of factors from global digitalization to geopolitical conditions have drawn more reliance on and attention to supply chain connections, and threat actors are more motivated than ever to exploit these connections as attack vectors. Mitigating these threats requires overcoming both external cooperative and internal organizational challenges. This highly pertinent webinar will share insights on these challenges as well as best practices for evolving your third-party risk management program to keep up with an evolving supply chain-focused threat landscape. This webinar will explore: • The current challenges facing organizations in keeping up with and managing evolving cyber risk in constantly expanding supply chains • Differences in traditional and more adaptive, SOC-inspired approaches to third-party cyber risk and what programmatic strategies work best for modern organizations • How to improve your organization’s overall security posture by adopting a proactive risk reduction strategy in managing your vendor ecosystem

2022/5/17
阅读更多

Modernizing Supply Chain Cybersecurity Via Multi-Signal Threat Investigation

In the last year alone, the number of supply chain attacks has grown exponentially as they offer threat actors stealthy, scalable, and privileged access to your organization’s on-premises, cloud, and hybrid environment. Addressing supply chain attacks requires a multi-layered defense strategy in which third-party integrations are audited, endpoints are monitored for post-compromise actions, and an Incident Response plan that considers supply risks is put in place to minimize the overall impact to your organization. On May 10, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Sumo Logic share insights from original threat research and supply chain attacks to demonstrate how multi-signal investigations can effectively secure your organization against supply chain attacks. Key takeaways from the webinar include: • The three primary attack vectors that cybercriminals rely on to launch supply chain attacks against organizations • The challenges that organizations face related to supply chain risk (e.g., technical complexity, access requirements, stealth of cyberattacks) and how they impact business operations • Tactical and high-level strategic recommendations on how your organization can minimize supply chain risk and reduce the attacker dwell times and impact • How 24/7 log monitoring and management can improve cyber resilience and prevent zero-day threats • A case study on how original research and curated threat intelligence conduct stronger post-exploitation investigations.

2022/5/10
阅读更多

BlueVoyant #2- Continuous Monitoring for Third-Party Risk: A Customer Journey

Organizations across all sectors have long relied on risk ratings or in-house risk management programs to keep track of the security posture across their shared third-party network and identify where there may be vulnerabilities in their vendor ecosystem. However, a growing focus on supply chain security requires a more comprehensive and advanced approach to third-party risk management. In this webinar, Cybersecurity Assurance Manager, Richard Furze of Lloyd’s Bank, will facilitate a highly apt discussion on the need for organizations to evolve their vendor risk management programs and the experience of doing so. This webinar will explore: • What challenges and pitfalls an organization can face utilizing traditional risk management methods or in-house programs • How an organization can go about transitioning their risk management program • How continuous monitoring can improve relationships with suppliers, incident management, and risk remediation • Major lessons learned from the evolution of a third-party risk management program

2022/5/10
阅读更多

Levers of Human Deception: The Science & Methodology Behind Social Engineering

No matter how much security technology we purchase, we still face a fundamental security problem: people. This (ISC)² and KnowBe4 webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding. On May 5, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific, join Erich Kron, Security Awareness Advocate for KnowBe4 as he provides fun and engaging examples of mental manipulation in everyday life: from the tactics used by oily car dealers, to sophisticated social engineering and online scams. Additionally, we’ll look at how to ethically use the very same levers when educating our users. Key Takeaways: • The Perception Vs. Reality Dilemma • Understanding the OODA (Observe, Orient, Decide, Act) Loop • How social engineers and scam artists achieve their goals by subverting OODA Loop's different components • How we can defend ourselves and our organizations

2022/5/5
阅读更多

Preparing for the Inevitable: How to Detect and Respond to Cyberattacks

It’s what keeps many of us awake at night-- knowing that a cyberattack is inevitable. Still there are things you can do to help strengthen your security posture. Join NETSCOUT and (ISC)² on May 4, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a discussion that will expose critical factors in understanding the global threat landscape as Dr. Eric Cole, Founder, and CEO of Secure Anchor Consulting, sheds light on cyber vulnerabilities that organizations are currently ignoring and outline strategies to reduce cyber risk. Paul Barrett, CTO for NETSCOUT, will unpack strategies to minimize the risk through network visibility. Presenters will also share regional examples from North America and expand upon the highly correlated risk reduction factors associated with network visibility in cyber.

2022/5/4
阅读更多

Demystifying Managed Detection and Response (MDR)

Cyberattacks continue to challenge many organizations. With a growing attack surface, limited access to expensive security talent, frustration with managed security service providers (MSSPs), and constrained budgets, leading security and IT leaders are looking for alternatives like managed detection and response (MDR) services to help reduce their risks. There are many options for security service providers, and with all the options, it may be hard to choose the best for your needs. Join Pondurance’s Chief Strategy Officer, Lyndon Brown, as he clears the fog around MDR and will discuss: -The biggest cybersecurity challenges for mid-market and enterprise organizations. -The difference between a SIEM, MSSP, XDR, MDR and Modern MDR Components of MDR and how to choose the right provider for your organization.

2022/4/29
阅读更多

Looking Glass#2:Leveraging Intelligent Attack Surface Management

Getting asset visibility and insights into exposures, such as what services or ports might be exposed to the internet, is great. But should you start closing all those ports or shutting down risky services? How do you know what actions to take next? This is where layering threat intelligence onto your attack surface can help prioritize actions or response from your security team. This kind of actionable intelligence can support a wide range of cybersecurity activities, from cyber hygiene and patching to optimizing threat hunting operations. In this session, Looking Glass and (ISC)² will discuss: • How threat intelligence can be applied to your attack surface to prioritize action • Real-world examples of organizations effectively using intelligent attack surface insights to improve their cybersecurity program

2022/4/27
阅读更多

Essential DevSecOps: Securing Modern Apps with Help of High Performing Dev Teams

As more companies undergo digital transformation and software is released more frequently, application security is moving from an opportunity to an imperative. However, AppSec as a process requires cooperation with software developers - a team whose time is heavily in demand from every customer-facing part of the organization. How do security teams improve AppSec without slowing down business and finding themselves at odds with the rest of the organization? For DevSecOps to succeed it must take cues from the DevOps revolution that came before it. Teams need to learn new tools that address the new problems that arise from the evolution of IT. Smart use of automation can create transparent processes that handle routine work between teams without creating friction. And most importantly, adopting a supportive, rather than authoritative, mindset makes it possible for teams to move quickly together while achieving their respective missions. On April 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, ShiftLeft and (ISC)² will provide an overview of application security that covers key tools, best practices, and a primer on working effectively with your colleagues in AppDev and DevOps in order to make modern software more secure.

2022/4/26
阅读更多

Looking Glass #3: Implementing Attack Surface Management Successfully

As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.

2022/4/22
阅读更多

OWASP Top 10 2021: The New Risk Order

The nonprofit Open Web Application Security Project (OWASP) works to improve the security of software, web applications, and APIs. Since 2003, the OWASP Top 10 has raised awareness of the most critical security risks to web applications. The latest Top 10 list, released in late 2021, includes significant updates from previous lists. For nearly 20 years the top risks remained largely unchanged, but modern application architectures have shifted the calculus—bringing a new wave of risk to web applications. Join F5 and (ISC)2 on April 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore: • Key changes in the 2021 OWASP Top 10 including alignment of symptoms to root causes and new risk categories • Ways to use the OWASP Top 10 as a foundation to protect applications • How F5 solutions can help mitigate critical risks with effective and easy-to-operate security

2022/4/21
阅读更多

A Field Technologist’s Guide to Fast-Track Your Zero Trust Journey

It’s now or never to modernize security. Our networks can no longer stretch to the apps living in the cloud and teams working remotely, plus cyber threats routinely exploiting the excessive trust built into them. Network transformation projects are always daunting – especially when you can never know exactly what your business will need tomorrow. New risks to mitigate, standards to comply with, and use cases to scale will inevitably emerge. Join (ISC)² and Cloudflare April 20, 2022 at 2:00 p.m. Eastern, 11 a.m. Pacific to hear Cloudflare Field Technologist, Trey Guinn share perspectives on how to both fast-track and future-proof your security approach. He has seen organizations commit to network and security architectures that were complex and costly to keep changing to adapt to future needs. Trey will advise us on the most important principles to evaluate new technology platforms with confidence that it’ll enable your organization to evolve and innovate faster than ever before. In this webinar you’ll also hear about: • The most pressing business and IT drivers of digital transformation • The emergence of the Internet as the new corporate network • The key criteria to evaluate Zero Trust security and SASE networking investments

2022/4/20
阅读更多

Looking Glass #1: Understanding Your Attack Surface

Increasing efforts to modernize and digitally transform business operations means it’s easy for organizations to lose track of their assets, or not know about assets acquired by business or operating units (“shadow IT”). But how can you protect what you don’t know about? That’s why understanding your attack surface is critical. In this session, Looking Glass cybersecurity expert, Cody Pierce, will discuss what an “attack surface” is, how to determine your digital footprint, and why your organization’s attack surface is likely growing rapidly. He will also share how managing your attack surface by taking the adversary’s view – a different perspective than most cyber defense strategies – is critical to identifying assets, maintaining effective inventory, and prioritizing mitigations. In this session, you’ll learn: • What attack surface management is and why it’s important • How attack surface management can fit into your existing cybersecurity program • Use cases where attack surface management can inform, optimize, and enhance a variety of cyber operations

2022/4/18
阅读更多

LIVE Ransomware Crisis Simulation with You in Control

Ransomware readiness is the #1 board-level directive when it comes to cyber security. Join Cyberbit and (ISC)2 on April 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we prepare information security executives and incident responders for ransomware by running a live simulation of a corporate ransomware crisis. You will be presented with an unfolding cyberattack scenario, confronting you with critical decisions ranging from the C-Level to the SOC manager level. We will then shift gears to the cyber range, which will emulate a real-world SOC and demonstrate how IR experts can successfully investigate and eradicate a ransomware attack. The session will combine the C-level, decision-making challenges encountered in a ransomware crisis with a hands-on, ransomware investigation simulated in a cyber range. The simulation allows you, as the audience, to impact the flow of the scenario by providing your suggested actions while our experienced instructor will provide you with helpful tips.

2022/4/14
阅读更多

Supply Chain Security Today: What You Need to Know

Recently, we saw the disastrous effects of numerous far-reaching supply chain breaches and third-party code vulnerabilities, including SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. Unfortunately, we can expect to see more of the same in 2022 and beyond. When we consider these latest cyber events, it’s important to prepare—with the right people, processes, and tools—for what’s unquestionably yet to come. This is why every organization must be sure to have a robust third-party security risk strategy in place. Join Panorays Co-Founder and CTO, Demi Ben-Ari as he shares tips on how to best reduce supply chain risk and contain attacks. Plus he’ll discuss: 1. Why supply chain security is critically important right now 2. What actually happened with SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. 3. How to take action when a supply chain attack happens, and how to minimize the blast radius.

2022/4/14
阅读更多

Improving Cyber Defense with Cloud MLOps and Cloud SIEM

The security threat landscape is evolving fast and continues to be challenging for defenders. Even though more sophisticated approaches using Machine Learning (ML) are growing in importance, they are difficult for non-experts to adapt to their particular use case and require sufficient training data. There is growing reliance on inflexible analytics and ML tools and the burden grows on security analysts to be data scientists. This (ISC)² and Sumo Logic webinar on April 12, 2022 at 1:00 p.m. Eastern/10:00 a.m., Pacific will cover: • How can non-experts leverage and benefit from using ML in security • Leveraging ML for security services that address the expertise problem by adapting ML to security use cases • Solving the data problem by pooling or crowdsourcing across the customer base • How to use Cloud MLOps with Cloud SIEM to help address current and emerging threats.

2022/4/12
阅读更多

Breaking the Vicious Cycle of Ransomware Incidents

As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.

2022/4/7
阅读更多

Cloud-Native Security Tools You Don't Know About

The cloud has become the primary location for businesses to store data. As usage of the cloud has grown, many organizations simply try to lift and shift their tools to the cloud, unaware that better, more tailored and cost-effective cloud-native solutions exist. On April 5, 2022 at 1:00 p.m. Eastern/10:00a.m. Pacific, join IANS and (ISC)² to hear: • Which AWS/Azure/GCP cloud-native tools to consider • Which cloud-native tools aren’t quite ready • When and how to use cloud-native firewalls, vulnerability scanners, DLP and incident response tools for a more scalable, cost-effective and secure environment.

2022/4/5
阅读更多

BlueVoyant #1: Operationalizing Third-Party Cyber Risk Management

When it comes to keeping up with an organization’s critical threats, it’s important to have visibility into your third parties. Traditionally, organizations have relied on risk ratings to keep track of the security posture across their shared third-party network, and identify where they may be most vulnerable. Useful as they are, however, risk ratings have their limitations. Users have difficulty deploying and wrapping an efficient process around them. Just trying to keep up with vendors and services in-house is time and resource intensive. So how do you effectively “get good” at risk scores and extract the real value behind them for your business? Enter the Risk Operations Center (ROC). Similar to the model that’s long been used by security teams via Security Operations Centers, a ROC is staffed with cyber security experts who continuously monitor and curate alerts to evaluate potential risks to your third-party ecosystems. Unfortunately, ROCs are difficult to create and maintain, which is why enterprise solutions have been created to lower the barrier to entry for organizations that want to leverage these benefits. In Part one of this series, we'll explore how a Risk Operation Center effectively operationalizes security rating by: ● Creating and utilizing ratings for continuous monitoring ● Validating ratings with expert oversight ● Modifying ratings based on an organization's tailored risk appetite ● Refining ratings with automated tools and techniques to scale approach

2022/4/4
阅读更多

A Master Class on IT Security: Roger Grimes Teaches You Phishing Mitigation

Phishing attacks have come a long way from the spray-and-pray emails of just a few decades ago. Now they’re more targeted, more cunning and more dangerous. And this enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Join (ISC)² and KnowBe4 March 31, 2022 at 1:00 p.m., Eastern and 10:00 a.m. Pacific to hear Roger Grimes, KnowBe4’s Data-Driven Defense Evangelist, share a comprehensive strategy for phishing mitigation. With 30+ years experience as a computer security consultant, instructor, and award-winning author, Roger has dedicated his life to making sure you’re prepared to defend against ever-present IT security threats like phishing. In this webinar you’ll learn: How to develop a comprehensive defense-in-depth plan for phishing mitigation Ideas for security policies you can implement now Technical controls all organizations should consider Gotchas to watch out for with cybersecurity insurance Why it’s critical to develop your organization’s human firewall

2022/3/31
阅读更多

CSPM Best Practices for Multi-Cloud: Beyond Native Tools

As multi-cloud adoption accelerates, security teams are navigating the delta between each cloud provider’s native capabilities and comprehensive protection from bad actors. Understanding cloud terminology, principles, and security issues is critical. Join (ISC)² and Sysdig March, 29, 1:00 p.m., Eastern/10:00 a.m. Pacific to understand the fundamentals on cloud categories and terms like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform), etc. so you can move past the acronyms and onto implementing them as best practices. In this session we will: • Debunk new industry acronyms and explain how they fit into your overall cloud security strategy • Explain why native cloud provider tools aren’t always sufficient • Provide CSPM best practices: Detecting misconfigurations, excessive permissions and suspicious activity • Showcase how open-source Falco can be used to detect cloud threats in real-time

2022/3/29
阅读更多

The 2022 CrowdStrike Global Threat Report – Findings and Trends You Should Know

For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join this webinar featuring CrowdStrike Director of Strategic Threat Advisory Group, Jason Rivera, as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond.

2022/3/23
阅读更多

Zero-Day Attacks: A 2021 Review and What to Expect in 2022

Zero-day exploits serve as a master key for cybercriminals to launch crippling cyberattacks which are only increasing in frequency. In fact, research from Google's Project Zero shows that as of November 2021, a total of 57 zero-day exploits in the wild have been discovered, compared to an average of 22 exploits in past years. In the past year, eSentire’s Threat Response Unit (TRU) detected and responded to a significant increase in zero-day exploit activity in client environments that included defending against critical Exchange vulnerabilities ProxyLogon, ProxyShell, the REvil attack against Kaseya and most recently, mass exploitation of Log4j vulnerabilities. Join eSentire and (ISC)2 on March 22, 2022 at 1:00p.m. Eastern/10:00a.m. Pacific as key findings from new research on zero-day attack patterns are shared including how to triage vulnerabilities, and the response capabilities needed to effectively tackle future zero-day attacks. We’ll also examine: • Factors contributing to the rise of zero-day attacks • Notable Vulnerability analysis of SolarWinds, ProxyLogon, ProxyShell, and Kaseya VSA • Opportunity windows for zero-day exploits (n-day attacks) • Recommendations on how you can defend against zero-day exploits

2022/3/22
阅读更多

Data Breach Trends from F5 Labs’ Application Protection Report 2022

Last year was a record-breaking year for data breaches. What can we learn from this growing trend? On March 17, 2022 at 1:00 p.m. Eastern/10:00 am Pacific join F5 Labs and (ISC)² as they share findings in a hot-off-the-presses report exploring those trends. This discussion will analyze the continuing growth of malware, the threat that Magecart and similar web attacks pose to e-commerce, business email compromise, and more. As in the 2021 report, they will use MITRE’s ATT&CK framework to visualize attack chains at large scale to explore the relationships between attacker behaviors. The talk will conclude with a discussion of different mitigation strategies so that organizations can tune their defenses to adapt to the latest in attacker trends.

2022/3/17
阅读更多

An Integrated Ecosystem of Security Tools – Is It Worth It for SecOps?

Your cybersecurity teams are overwhelmed managing dozens of security tools and dealing with hundreds or thousands of alerts every day. That’s why organizations need a modern approach to total enterprise security to be able to automate manual processes and build a security ecosystem for a faster and more coordinated response to threats. Integrating DNS security with your existing SIEM/SOAR, Threat Intelligence, Vulnerability Management, NAC, NGFW, EDR, etc. could help the security operations team gain better visibility and context around threats for a prioritized security response. Join Infoblox and (ISC)² on March 15, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn some key tips and benefits of an efficient cybersecurity ecosystem: • How to get 360° view of all the assets on your network • How to overcome the challenge of working with siloed security tools • Decrease time to remediation by using network and threat context • Automatically trigger response to events detected by DNS security

2022/3/15
阅读更多

Rethink Your Approach to Data Loss Prevention and Insider Risk

According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security

2022/3/10
阅读更多

Hard Lessons from 468 Security Analysts

We all have a general idea about the day-to-day struggles that analysts face on security teams/in the SOC, but there’s a lack of up-to-date data, meaning it’s hard to form a clear picture of just what it’s like to be an analyst today. So Tines set out to understand better, and conducted a survey of 468 real-life analysts. What they discovered was a fascinating set of contrasts: analysts predominantly love their work, and yet most feel burned out right now. Analysts tend to feel respected by their organization, but a staggering number are expecting to leave their job in the next year. And while analysts are keen to develop more technical skills and influence, the majority of their time is still spent on tedious, manual work. These findings will be interesting to anyone in security, but we think security leaders have by far the most to learn from this data. On March 8, 2022 at 1:00 pm. Eastern/10:00 a.m. Pacific, join Tines Security and (ISC)² to learn how you can streamline your processes, decrease burnout, increase retention, and create compelling environments for your frontline staff.

2022/3/8
阅读更多

Zero Trust Customer Stories: Lessons from Two Years of Securing Remote Work

Two years into the global pandemic and the stakes for remote work security have never been higher. Even as ransomware, phishing, and shadow IT reach all-time highs, admins must ensure users stay safe and productive across all devices, apps, and locations. As work-from-home flexibility settles in as the new normal, Cloudflare has seen organizations start to re-evaluate the temporary IT scaffolding they put in place in early 2020. For many, this has meant taking steps towards more sustainable and secure Internet-native Zero Trust architectures. Join Cloudflare, (ISC)2 and special guest OneTrust on March 3, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific as they share lessons learned evolving their remote work security over the past two years. Tune in to learn how organizations: · Prioritize starting points to address remote work security problems · Balance user experience with more rigorous security · Motivate Zero Trust initiatives within their organization

2022/3/3
阅读更多

Managing Risk and Your Vendor Relationships

51% of businesses have experienced a third-party data breach. In other words, there’s a one-in-two chance a vendor will expose your sensitive data. Practically every company relies on third parties to provide critical services or software to their business. But while you can outsource processes, you can’t outsource the associated risks. Knowing who your vendors are, how they manage their risks and their potential impacts on your company is a crucial piece of your InfoSec program. However, contracting is often overlooked from a security perspective, and it shouldn’t be. An effective vendor risk management program can minimize the impact of disruptive events and reduce a company’s overall risk exposure. In this webinar, Jose Costa, Chief Information Security Officer at Tugboat Logic, and Zach Payne, Senior Corporate Counsel at OneTrust, will deep dive into: - How to build an ideal vendor management framework - The issue with vendor contracts and how to overcome common pitfalls - Practical advice to streamline complex client and vendor points of view - Liability limitations, intellectual property, and confidential information.

2022/2/28
阅读更多

Cover Your SaaS: Managing Misconfigurations, Shadow Users & Excessive Spending

Cloud adoption — especially software-as-a-service (SaaS) — is showing no signs of slowing down. SaaS models are already a go-to for many organizations — and consumption will only increase as more businesses shift to remote and hybrid work. While the growth of SaaS offers many positives, it also drives an exponential increase in IT, security, and business complexity. Shadow users, data sprawl, misconfigurations, and excessive spending are just a few examples of the challenges SaaS applications pose. Join Axonius and (ISC)2 on February 24, 2022 at 1:00 p.m. Eastern as we examine the relationship between SaaS apps and IT and security teams, along with the challenges at hand and several actionable solutions. Through a renewed focus on SaaS security posture management, we’ll share how you can: • Discover both known and unknown SaaS apps • Uncover and mitigate various security risks that put sensitive customer and business data at risk — including identifying misconfigured SaaS settings and suspicious or malicious behavior • Deliver the insights on user access and app utilization needed for better IT management and cost optimization across all SaaS apps

2022/2/24
阅读更多

Ransomware & C-Suite: What the Data Reveals About How Executives View the Threat

A recent research study published by (ISC)2 provides insights for cybersecurity professionals into the minds of C-suite executives and how they perceive their organizations’ readiness for ransomware attacks. This data underscores the need for clearer and more frequent communications between cybersecurity teams and executives and offers best practices security leaders should implement to improve those interactions. Join (ISC)2 CISO Jon France on February 22, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he guides attendees through a summary of the data, discusses what we can learn from it and answer questions about ransomware topics.

2022/2/22
阅读更多

IT Security Career Journeys: Life After Being a CISO

IT security is a highly rewarding, impactful, and profitable profession – but it’s one that faces a massive talent gap that’s been plaguing the industry for years. According to the annual (ISC)2 Cybersecurity Workforce Study, there are currently 2.72 million unfilled cybersecurity job openings. While that number finally seems to be declining as the benefits of these roles continue to gain popularity, it’s still one that’s cause for concern. How has the industry gotten to this point? Considered the pinnacle position in the field – the Chief Information Security Officer (CISO) – has a notoriously high turnover rate. Some may view the position as a “turnoff” and perceive this security leader role to be “Chief Scapegoat”. But that’s all changing. In fact, the CISO role has evolved into one that is integral to the fabric of the business and accelerating it by protecting productivity. Join Jack Miller of Menlo Security and Brandon Dunlap on February 15, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific as two former CISO have a fireside chat to discuss their career journeys: paradigm shifts, highlights and how best to chase your passion for security

2022/2/15
阅读更多

You Are Here: Navigating the Global Cloud Native Security Landscape

To understand where you’re going, you must first know where you are. But in the world of cloud-native security, where technologies and best practices seem to change by the month, finding your baseline can sometimes feel impossible—let alone benchmarking your peers. To help organizations find their way, the team at Prisma Cloud has put together the second annual State of Cloud-Native Security report, a survey of 3,000 professionals across five countries that helps answer the question What’s happening in cloud-native security today, and what are successful organizations doing right. On January 25, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Palo Alto Networks, Prisma Cloud, and (ISC)², as we reveal for the first time the trends that are driving the world’s most successful cloud security programs, analyze the best practices that help leading enterprises excel, and demystify the evolving cloud security landscape.

2022/2/10
阅读更多

Protecting the Enterprise: 5 Components needed for Cybersecurity Training

It’s difficult to prescribe a one-size-fits-all approach to training your cybersecurity team. While cybersecurity training needs to be structured and adhere to industry standards, it also must be purposeful and tailored to your organization’s needs. No one organization has precisely the same security needs as another. However, many of the fundamentals of a training and education program apply across different organizations and sectors. Join (ISC)2 for a panel discussion on Tuesday, April 13, 2021 at 1:00PM Eastern as industry leaders share tips they’ve learned and strategies they’re working towards to conquer a secure and compliant cybersecurity training program. Areas for discussion will include: · Who needs training · Who is responsible for training · Determining the curriculum · Training and certification · Ensuring training effectiveness Be prepared for an hour well-spent and discover how to create a cybersecurity training plan that maps to your organization’s specific needs.

2022/2/9
阅读更多

Identity Security: The Foundation of Zero Trust

“Identity Security is the foundation for Zero Trust”. This statement has been widely accepted within the cyber-security industry since most breaches result from weak credentials and unmanaged accounts. Identity is the foundation by which you assert your relationship with an organization. How you justify the applications and data, you should be allowed to access and what you can do with it. Join SailPoint and Optiv, along with (ISC)2 for a discussion on why Identity Security is decidedly the foundation for Zero Trust, how it enables the other Zero Trust pillars, and how to set the foundation for your entire Zero Trust journey.

2022/2/1
阅读更多

The Evolution of Meris: A 250K Strong Botnet Breaking DDoS Attack Records

A new botnet comprising nearly 250,000 malware-infected networking devices was the reason behind some of the largest DDoS attacks over the last few months. Known as Meris, this botnet was deployed by threat actors to demand ransom from target companies. In fact, Meris was responsible for breaking the record of the largest volumetric attack twice just in the past few months. While there are no signs of DDoS attacks going away anytime soon, how do organizations ensure that their Internet assets are protected against threats of any size or kind? Join Cloudflare and (ISC)2 on January 27, 2022 at 1:00 p.m. Eastern as we examine: • What is the Meris botnet? • Evolution of Meris over time and its distribution across countries and industries • What organizations can do to stay protected against Meris DDoS attacks

2022/1/27
阅读更多

A Former FBI Agent Shows How to Fend off Inherent Vulnerabilities Attacks

There are a myriad of bad actors leveraging multiple attack vectors and vulnerabilities on an on-going basis. Detecting and preventing attacks against inherent vulnerabilities can be paramount in keeping an organization safe and secure. During this webinar, Dan Woods, former FBI Agent and CIA Cyber Operations Officer, and current Global Head of Intelligence for F5, will show you actual attacks against Global 2000 organizations He'll explain how F5 Shape used client-side signals to detect and mitigate the attacks and he'll do it using the phrase AI/ML only once. No death by PowerPoint here.

2022/1/26
阅读更多

Cloud Data Loss & SaaS Backup: Critical Steps to Protect Yourself from Disaster

Does your organization rely heavily on SaaS solutions like Microsoft 365 and Google Workspace? That critical data may be at more risk than you realize. There are hidden risks with compliance issues associated with SaaS solutions and other concerns. Join Synology and (ISC)2 on January 20, 2022 at 1:00 p.m. Eastern as we examine the importance of Cloud backup and the practical strategies that can protect your organization from detrimental data loss. Additionally, we will discuss real-life case studies that exemplify the importance of SaaS backup and walk through the elements of their backup strategies that made them so successful.

2022/1/20
阅读更多

Migration to Monitoring & Response: How to Build & Secure a Cloud Infrastructure

Cloud adoption is accelerating at an exponential rate. Whether it’s for business collaboration or to store critical data assets, organizations are increasingly relying on the cloud. In the next 3 years, it is anticipated that 70% of workloads will be hosted in a cloud environment. The ease of deploying these workloads within cloud-based infrastructure enables rapid adoption of cloud services and greater business agility, but what about the risks? We have seen a sharp rise in the number of data breaches stemming from misconfigurations in the cloud. These misconfigurations occur as a result of improper settings being used when architecting and deploying services within the cloud platform. Ultimately, this means that cybercriminals have an expanded attack surface to access any data stored within the cloud environment, increasing the risk of a cyber attack. Join eSentire and (ISC)2 on January 18, 2022 at 1:00 p.m. Eastern for a discussion on the top threats associated with utilizing cloud-based infrastructure and explore how they are different from threats to your on-premises infrastructure. Key takeaways will include: • Cloud migration strategy: should you go all in? • Shared responsibility model: what are you on the hook to secure? • Top threat trends: how is cloud different? • Monitoring and response: what solutions should you consider?

2022/1/18
阅读更多

Identity Market Trends & Insights

The identity and access (IAM) management market is experiencing a watershed moment in the wake of the global pandemic. The implementation of cloud, data analytics, and other digital initiatives. Have accelerated, but so too have cyber threats. IAM initiatives have risen in priority as organizations look to enable the digital business, while simultaneously tightening their belts on security. Join SailPoint and BeyondTrust, along with (ISC)2 on January 11, 2022 at 1:00 p.m. for a discussion on the ever evolving threat landscape and how it is shaping IAM business drivers. We’ll explore how regulations like GDPR, CCPA and the recent Biden Administration’s Executive Order on Improving the Nation’s Cybersecurity are impacting the IAM market. Lastly, we’ll outline the Top 5 IAM Market trends for 2022.

2022/1/11
阅读更多

Incredible Email Hacks You'd Never Expect

Email is still a top attack vector cybercriminals use. A majority of data breaches are caused by attacks on the human layer, but email hacking is much more than phishing and launching malware! Join Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist and (ISC)2 on January 6, 2022 at 1:00 p.m. Eastern as we explore the many ways hackers use social engineering to trick your users into revealing sensitive data or enabling malicious code to run. Plus, he'll share a (pre-filmed) hacking demo by KnowBe4's Chief Hacking Officer Kevin Mitnick. Also to be covered: • How silent malware launches, remote password hash capture, and how rogue rules work • Why rogue documents, establishing fake relationships and getting you to compromise your ethics are so effective • Details behind clickjacking and web beacons • Actionable steps on how to defend against them all

2022/1/6
阅读更多

Web Honeypot Attacks: Tactics, Techniques and Trends

We’ve collected over 9 million events from hundreds of web honeypots around the world for past 52 months. This webcast will present the results of our analysis of that data to help answer the question: what attacks should I expect? Using this honeypot data, we’ve been able to identify specific CVEs being targeted in large global attack campaigns. From this, we have clues on attacker tactics regarding which platforms and technologies receive attention time after time, and which fade from usage. This kind of data is vital in building a data-driven defense. Join F5 and (ISC)2 on December 21, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we learn what kinds of attack are commonplace on the Internet, so the ones targeting them uniquely will stand out. Additionally, we will explain techniques to investigate and classify web attack log traffic at scale. To quote Deming: In God we trust. Everyone else, bring data. We’re bringing the data.

2021/12/21
阅读更多

Red Canary #3: How to Incident Manage a Sweeping Supply Chain Attack

In Part 3 of this webinar series, we’ll examine the operational components of our incident management process, exploring everything from how and when incidents are declared to the automated playbooks we leverage in customer environments to isolate endpoints, ban binary hashes, and bring incidents toward resolution. In the end, we’ll show you how our incident management process and incident handling team brought our full CIRT to bear in preventing the effects of the wide-reaching Kaseya supply chain attack.

2021/12/17
阅读更多

Putting Risk, Management and Governance in Perspective

Cybersecurity is always evolving. The 2021 (ISC)2 Cybersecurity Workforce Study has found how the profession has evolved and matured with respect to risk and governance as well. Join (ISC)2 on December 16, 2021 at 11:00am Eastern/8:00am Pacific and learn how organizations and professionals are evolving from: · "How secure are we?" to "What's our security-related risk, and is it acceptable to the business?" · Risk as a purely technical issue to risk as a key business issue · Subject-matter experts to both subject-matter experts and trusted advisors

2021/12/16
阅读更多

Top Five Cybersecurity Predictions for 2022

This year was particularly challenging for IT security professionals. For a short while, we thought we finally had this pandemic kicked. Then the Delta variant came along, further extending the work-from-home movement and its associated cybersecurity risks. Meanwhile, we saw record-setting ransomware attacks, including high-profile attacks on critical infrastructure, while the shortage of IT security talent worsened. On a brighter note, we saw increased adoption of promising security technologies, such as zero trust network access (ZTNA) and secure access service edge (SASE). So, what does next year have in store for the cybersecurity industry? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2022.

2021/12/15
阅读更多

(ISC)2: Quarterly Board Chairperson and CEO Update

CEO Clar Rosso will be joined by (ISC)² Board of Directors Chairperson, Zachary Tudor, CISSP to provide the Q4 2021 update to members. Join us on December 15, 2021 at 10:00 am Eastern/7:00 am Pacific to hear the latest updates from the most recent board meeting, what the association has planned for 2022 and beyond, and to ask your questions live.

2021/12/15
阅读更多

Beyond 2021- The Potential Post-Pandemic Cybersecurity Environment

The development of the COVID-19 epidemic into a global pandemic has presented a unique once-in-a-lifetime opportunity for fraud and predation which cyber threat actors, both criminal and otherwise, have been quick to exploit to the fullest. On December 14, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific, join (ISC)2 and Francis Gaffney, Director of Threat Intelligence and Response at Mimecast, as he discusses the post-2021 environment with a particular focus on the current state of cyber threats in relation to geopolitical events and how they can have an impact on what arrives in one’s inbox. He will explore events like Black Friday, national elections, and global sporting events. He will include examples of how pattern-of-life analysis is undertaken to social engineer victims to interact with cyber threat actors and then offer target hardening methodologies to enable attendees to be more resilient to these threats.

2021/12/14
阅读更多

Inside (ISC)2: Updates on Advocacy, Global Markets and Member Engagement

Clar Rosso, CEO of (ISC)2 shares her insights on what’s happening at our association. Join us for this quarterly update in which we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. On December 7, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Clar will be joined by Tara Wisniewski, EVP of Advocacy, Global Markets and Member Engagement at (ISC)2, to provide some updates on the strides being made to increase the association’s influence on emerging cybersecurity policy issues, and the expansion of (ISC)2’s reach both in terms of global capabilities and supporting its members.

2021/12/13
阅读更多

Container Security: Top Security Risks and How to Address Them

Many organizations are examining the use of Containers, but how to secure them can be difficult. On December 9, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific, join Palo Alto and (ISC)2 for a discussion on containers and the main risks while using them. We’ll cover what containers are as well as a deep dive into zero-day vulnerabilities, one-day vulnerabilities, misconfigurations, and excessive container permissions.

2021/12/9
阅读更多

Red Canary #2: Using Intelligence to Improve Threat Detection & Inform Decisions

While the Kayesa ransomware attack was still in its nascent stages of infection, Red Canary’s intelligence team had already uncovered a pair of suspicious registry key modifications that we had previously associated with REvil’s ransomware of choice. But what was it that tipped us off? In Part 2 of this webinar series, you’ll learn how our team performs tactical and operational intelligence to expedite analysis, improve detection engineering, and inform decision makers. Further, we’ll examine how security teams can apply cyber threat intelligence during an active incident to gain critical context that can be applied across other security operations functions.

2021/12/8
阅读更多

Open Doors with CCSP- How to Start Your Career in Cloud Security

Cloud is an intrinsic part of our everyday lives both personally and professionally. With more organizations running vital business functions in the cloud, the demand for cloud security professionals has never been higher. (ISC)2 interviewed about 50 Certified Cloud Security Professionals (CCSPs) who achieved this credential mid or later in their careers and asked them why they chose to add the CCSP to their skillset and the benefits they experienced as a result. And we want to share their answers with YOU! Join our live panel of distinguished CCSPs and host Brandon Dunlap on Wednesday, December 8th at 1pm EST to find out why our panelists and thousands of others have pursued the CCSP credential. Accelerate Your Career in Cloud Security – with CCSP Save your spot today!

2021/12/8
阅读更多

Protecting Stateful Devices on Your Network Edge from DDoS Attacks

Firewalls, VPN concentrators, IDS/IPS, load balancers, etc., all have one thing in common. They are stateful devices. That makes them very susceptible to DDoS attacks – more specifically, state exhaustion attacks. To protect these devices from DDoS attacks, you need dedicated, stateless DDoS attack protection technology deployed in front of your stateful infrastructure. Join Netscout and (ISC)2 on December 6, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we examine: · Why stateful devices like firewalls are susceptible to DDoS attacks. · Why industry best practices (and firewall vendors) suggest deploying stateless DDoS protection in front of your firewall to protect it and other stateful devices. · How and why organizations should prepare and defend around the first and last line of network perimeter defense to protect the availability and performance of firewalls and other stateful infrastructure from cyber threats.

2021/12/6
阅读更多

Red Canary #1: Detecting the Unknown with Broad Behavioral Analytics

Using the recent Kaseya supply chain incident as an example, this webcast will demonstrate that you don't need a magical security box to detect unknown threats or zero-day exploits. By focusing on malicious and suspicious behaviors, you can detect threats you didn't even see coming. In Part I of this webinar series, we'll walk you through the following: o An overview of the Red Canary detection engineering philosophy o How to develop broad detection analytics to catch all varieties of threats, even unknown ones o How security teams can operationalize detection engineering to achieve better security outcomes

2021/12/1
阅读更多

Lessons from a Security Practitioner Turned CEO

A common challenge experienced by security practitioners is communicating with business leaders, from the C-suite to the board. In this presentation, Eoin Hinchy, a former security leader and now CEO of the award-winning, fast-growing start-up, Tines, will share the lessons he's learned transitioning from a security practitioner role to that of a business leader. Join Tines and (ISC)2 on November 30, 2021 at 1:00 p.m. Eastern for insights on to balance security risk with the other requirements of the business. Attendees will come away with tips on how best to engage the business leaders in their companies.

2021/11/30
阅读更多

LIVE Response to Simulated Incident with You in Control

Responding to an incident takes more than theoretical knowledge. To effectively detect, investigate, and mitigate a live incident requires strong knowledge, technical skills, and practical experience, many of which current cyber pros are missing. Join Cyberbit and (ISC)2 on November 23, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to experience a live incident response, simulated on the cyber range included in Cyberbit’s cyber team preparedness platform. Here’s the twist: you, as the audience, are in control. You will vote to control the actions taken by the responder and see how quickly the audience can resolve the attack!

2021/11/23
阅读更多

The Cloud Gambit: Advanced Moves for a Cloud Security Career

Taking the step toward earning the (ISC)² Certified Cloud Security Professional (CCSP) credential puts you on a path to excel as an expert in cloud security. CCSP empowers individuals and organizations with the highest level of mastery in cloud security. But how do you get started? How do you prepare? And why…what tangible benefits will you gain? Join (ISC)² for a panel discussion as industry professionals share their stories, experience and tips toward preparing for the Certified Cloud Security Professional certification. Areas for discussion will include: - Why you should consider CCSP - How to prepare for CCSP - How CCSP can accelerate your career progression

2021/11/17
阅读更多

Cloud Threat Report: Supply Chain Attacks - The Early Bird Injects the Worm

Palo Alto Networks Unit 42 cloud threat researchers wanted to understand how supply chain attacks occur in the cloud native applications. To gain insight into this growing threat, they analyzed data from a variety of public data sources around the world. Additionally, they executed a red team exercise at the request of a large SaaS provider against their cloud-based software development environment. Unit 42’s findings indicate that many organizations are still have a long way to go in achieving supply chain security in the cloud. Join Palo Alto Network and (ISC)2 on November 16, 2021 at 1:00p.m. Eastern for the Unit 42 Cloud Threat Report and how supply chain attacks in the cloud can occur and provide actionable recommendations organizations can adopt to protect their cloud native supply chains.

2021/11/16
阅读更多

Cyber Insurance: Optimizing Costs While Minimizing Risk

With hybrid workplaces now the new norm and supply chain attacks on the rise, there’s an increased exposure to cyber-attacks, which can cause substantial disruption to any organization or industry. This increased exposure is forcing companies to not only invest and improve their own cybersecurity posture, but also manage third party risk and protect against cyber risks with cyber insurance. Certain best practices and technologies help reduce your risk and improve your security score while helping to keep insurance premium costs low. DNS security is one such approach that provides extended visibility, protection and security automation to improve a company’s security posture. Join Infoblox and (ISC)2 November 11th, at 1 p.m., ET/ 10 a.m. PT for this webinar to learn more about: o Why organizations invest in cyber insurance o Getting the most out of cyber insurance o How DNS security improves security scores and reduces cyber insurance premiums

2021/11/11
阅读更多

Strategies for Recruiting and Retaining Top IT Security Talent

Recruiting and retaining qualified IT security talent has never been more challenging. Nearly nine in 10 organizations are experiencing a shortfall, according to CyberEdge’s 2021 Cyberthreat Defense Report. That’s up from eight in 10 organizations just three years ago. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can organizations do to mitigate the effects of this talent shortage? Well, if you’re willing to ‘think outside the box,’ there is hope. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: Examines the shortage of IT security personnel by job role Proposes creative ways for recruiting new security talent Suggests clever ways for retaining the talent you already have Identifies technologies that enable security teams to do more with less

2021/11/10
阅读更多

CISSP: The Time Is Now

The future is created by what you do today. Oftentimes we don’t feel we are ready to take what seems like a big step forward. But we want to show you why now is the best time to make that first step on your CISSP journey. People from all walks of life, of various generation, from every industry and with different lifestyles have all succeeded in their mission to achieve the CISSP. Through this webinar our panel of CISSPs want to share the different paths you can take to achieve the CISSP and the benefits that the CISSP brings to your career. Join our live panel of distinguished CISSPs and host Brandon Dunlap on Tuesday, November 9th at 1pm ET to take that first step on the ladder to harnessing the CISSP credential. Stronger cybersecurity starts with CISSP! Save your spot today!

2021/11/9
阅读更多

Of Ransom and Redemption: Findings from the 2021 Application Protection Report

F5 Labs, one of F5 Networks’ information security research teams, publishes the Application Protection Report to help bridge the divide between tactics and strategy in information security. Join F5 Labs and (ISC)2 on November 4, 2021 at 1:00p.m. Eastern as we will share the findings from the 2021 Application Protection Report, which covers the explosion of ransomware in 2021, formjacking attacks such as Magecart, API security, and cloud misconfigurations, among others. We will wrap up by recommending mitigations for the most frequently observed attack vectors, as well as some strategic insights on the direction of information security as a whole.

2021/11/4
阅读更多

ExtraHop #2: Take the Fight Against Ransomware to the Cloud

Ransomware is on the rise, with almost 69% of organizations falling victim to a successful attack according to the 2021 Cyberthreat Defense Report. Those attacks are increasingly shifting to the cloud, either through starting in those environments or moving there from infected on-premises assets. It’s time to take a cloud-based approach to defending against ransomware. In this webinar, the ExtraHop team will show you how analysts and incident responders can use cloud-native network detection and response (NDR) to: o Detect early indicators of compromise, data staging, and exfiltration o Speed investigation to get to ground truth faster o Respond quickly to stop the attack before it gets out of control

2021/10/28
阅读更多

The Many Ways to Defeat Multi-Factor Authentication

Everyone knows that multi-factor authentication (MFA) is more secure than a simple login name and password, but too many people think that MFA is a perfect, unhackable solution. It isn't! Join Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist, and security expert with over 30-years experience, and (ISC)2 on October 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he explores the many ways hackers can and do get around your favorite MFA solution. This webinar includes a (pre-filmed) hacking demo by KnowBe4's Chief Hacking Officer Kevin Mitnick, and real-life successful examples of every attack type. It will end by telling you how to better defend your MFA solution so that you get maximum benefit and security. We’ll also examine the good and bad of MFA and how to become a better computer security defender in the process, including: · Ways hackers get around multi-factor authentication · How to defend your multi-factor authentication solution · The role humans play in a blended-defense strategy

2021/10/28
阅读更多

ExtraHop #3 Stopping Ransomware: Why 80% of Victims See Repeat Attacks

Ransomware gangs know a good thing when they see it. That's why 80% of ransomware victims experience repeated attacks. After dealing with the tedious restoration process, the cost of downtime, and the stress of extortion, victims’ incident responders need network forensic insights to close the door on a repeat performance. In this demo-filled webinar, an expert threat hunter will show you how to use network detection and response (NDR) to close the door on future IT infrastructure ransomware damage. We’ll show you how NDR can use tamper-proof network data to: • Quickly scope the impacted systems and compromised data • Investigate historic traffic records to find the root cause, and close it for good • Stay vigilant for future indicators of ransomware pivoting toward your data • Collect the evidence you need to protect your organization during disclosure

2021/10/27
阅读更多

BT Sets the Bar Higher with Official (ISC)2 CISSP Team Training

Building a strong cybersecurity team takes grit. The best results don’t always come at the first pass. When BT, a world-leading communications provider headquartered in London with offices globally, tasked CSIRT Training Specialist Jonathan Kilgannon with raising the bar for success among the company’s CISSP candidates, he delivered. Average exam pass rates jumped to 90% percent — a 40% increase — following the changes he implemented in the training process. Find out how identifying the right candidates, preparing them in advance and (ISC)2 Official In-Person Team Training made all the difference.

2021/10/27
阅读更多

ExtraHop #1: Five Ways Attackers Leave Ransomware Vulnerable to Detection

Enterprise ransomware has evolved. Ransomware-as-a-service and simple-to-use intruder tools like Cobalt Strike give greedy attackers both the motivation and the playbook to search for the data they need to ensure that you will pay. Time may not be on your side, but every action an attacker takes leaves a trail for defenders to follow. This is where you regain the advantage—if you know what to look for. Intrusions are a terrifying thing to consider, but they don’t spell doom: Visibility and response inside the perimeter are your best hope against the enterprise ransomware menace. In this demo-filled webinar, an expert threat hunter will share techniques for eradicating the extortion adversary at each critical phase before encryption begins. Join ExtraHop and (ISC)2 for the first part of a three part series where we’ll look at the indicators that leave attackers open, such as: o Scanning and enumerating your environment o Moving laterally toward your valuables o Domain escalation attempts from owned assets o Staging data exfiltration for second-phase extortion o Preparing to write over DB and file systems

2021/10/26
阅读更多

Is Zero Trust a Pipe Dream? Debunking Five Zero Trust Security Myths

Zero trust network access (ZTNA) has been one of the most widely discussed and debated security technology categories in recent years. While most enterprise IT security teams have already started drinking the zero trust Kool-Aid, there are still some skeptics who are hesitant to embrace zero trust architectures for a variety of reasons. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he debunks five common zero trust security myths so you can distinguish between fact and fiction.

2021/10/12
阅读更多

Surviving a Ransomware Attack: Disaster Recovery for Critical Cloud & PC Data

During 2020, the worldwide shift to remote work led to a staggering rise in cybercrime, as criminals targeted gaps in previously secure on-site networks. With over 50% of employers expecting to keep employees working remotely, and payments for a ransomware attacks averaging $100,000, businesses must work proactively to protect their data. It is essential for business to have an effective plan in place to protect at-risk systems, detect and mitigate ransomware attacks in real time, and quickly restore affected systems. Join Synology and (ISC)2 on September 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. as we discuss actionable strategies for ransomware preparedness and look at real-world examples and case studies. Key takeaways include: Actionable ransomware preparedness tips Protecting PC data and the elements of a robust ransomware recovery plan Why and how to backup Microsoft 365 & Google Workspace data Setting up remote backup to a secondary server or cloud

2021/9/28
阅读更多

Prioritizing Security for Your Cloud Native Initiatives – A Maturity Model

Aqua Security and ESG Research have partnered to survey and understand how organizations go about addressing challenges of security cloud native applications. With multiple stakeholders across engineering, DevOps, cloud, security and compliance teams, and competing priorities for addressing security pain points, many organizations are either stopping short of fully implementing the needed processes and tools, or conversely fail because they try to do too much at once. Join Aqua Security, ESG Research and (ISC)2 on September 23, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we review some of the key considerations as well as benchmark results from our survey to date.

2021/9/23
阅读更多

CISSP- Tales of the Unexpected

When you tell people you’re thinking about CISSP, you’ve probably been told: • CISSP is globally renowned - those holding it are highly sought-after. • Achieving certification means you get paid more. • CISSP is HARD to earn. • It’s a LONG exam. But what you probably haven’t heard are the unexpected surprises along the way CISSPs never imagined in their certification journey. For example, learning that CISSP is a broad certification that focuses on governance: Do you understand the technology? The people? The management? Join us for a panel discussion as CISSP-certified members share their personal stories and the unanticipated ways certification continues to benefit their careers. After all is said, you’ll be amazed at what CISSP can do for you in your professional growth and career. Hear expert insights from: AJ Yawn, Jerome Leach and Angus Macrae

2021/9/21
阅读更多

Crossing the CAASM: The Evolution of "Asset Management"

As IT and security teams struggle to manage a complex sprawl of devices, users, cloud services, and software, there's one certainty we can rely on (thanks to the second law of thermodynamics): things will only get more complex. But there's good news. What we previously thought of as "asset management" has evolved. Today, we have “asset intelligence”, which moves from a spreadsheet approach — focused on getting an inventory of devices — to an API-driven, always up-to-date way of seeing all assets through integrations of existing tools, data correlation at scale, and querying capabilities to find and respond to gaps. Join Axonious and (ISC)2 on September 16, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific and hear from Ronald Eddings and Chris Cochran, producers and hosts of the Hacker Valley Studio Podcast and learn how this new approach to asset intelligence and the emerging Cyber Asset Attack Surface Management (CAASM) category helps IT and security teams improve security hygiene, reduce manual work, and remediate gaps.

2021/9/16
阅读更多

DoD 8570 and Beyond: (ISC)2 Certifications to Get Your Team in Compliance

The U.S. Department of Defense (DoD) Directive 8570.1 requires every full- and part-time military service member, defense contractor, civilian and foreign employee with "privileged access" to a DoD system — regardless of job series or occupational specialty — to get an approved IA baseline certification. Which certifications are the right fit for your team? Government agencies have trusted (ISC)² to train and certify their cybersecurity personnel for more than two decades. With the recent addition of (ISC)2 Certified Cloud Security Professional (CCSP) and HealthCare Information Security and Privacy Practitioner (HCISPP) certifications, the entire portfolio of (ISC)² certifications now meet the requirements for different security workforce categories within the Department, depending on the functional area the role covers. Discussion topics include: • How to Become DoD 8570 Compliant • (ISC)2 Certifications Overview: IA Baseline Certification Requirements • How to Maximize Your Training and Certification Budget • Keep Your Team’s Cybersecurity Skills Sharp Be prepared for 45 minutes well-spent and discover how (ISC)2 can help you train and certify your team to become DoD 8570 compliant.

2021/9/15
阅读更多

Building Cyber Resilience with Managed Phishing and Security Awareness Training

The majority of crippling cyberattacks begin with a simple phishing email. And while most companies provide some form of annual training, they focus on overly simplistic lures taken from public events that fail to represent the real danger of targeted criminal campaigns. Join eSentire and (ISC)2 on September 14, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as they explore how to build a comprehensive training and testing program that leverages realistic threat scenarios to foster context-relevant security awareness that drives behavioral change: · Use risk management data and accurate phishing lures to build comprehensive awareness training · Maximize your resources and programs to increase return on investment · Conduct testing that improves resilience · Meet regulatory requirements and demonstrate program success to your leadership

2021/9/14
阅读更多

Ransomware Deep Dive: To Pay or Not to Pay?

Colonial Pipeline, CNA Financial, JBS Foods, Garmin, and Travelex. All victimized by high-profile ransomware attacks. All paid ransoms. Did these companies do the right thing by paying ransoms to accelerate data and system recovery? Or are they merely funding the ransomware industry and prompting even more attacks? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews key findings from CyberEdge’s 2021 Cyberthreat Defense Report. In this webinar, Steve will: - Examine disturbing ransomware trends, by country and by industry - Evaluate key factors that go into deciding whether to pay ransoms - Outline ways to be prepared for a successful ransomware attack - Review technologies to help give security teams the upper hand

2021/9/9
阅读更多

Inside (ISC)2: Updates on Global Events Program

Clar Rosso, CEO of (ISC)2 shares her insights on what’s happening at our association. Join us for this quarterly update in which we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. On August 31, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Megan Gavin, Director of Events at (ISC)2 joins Clar to provide an overview of what to expect at this year’s annual Security Congress taking place this October 18-20, as well as the new global (ISC)2-hosted events being planned for 2022.

2021/8/31
阅读更多

Inside (ISC)² Quarterly Board Update, 2021 (Q3)

(ISC)² Board of Directors Chairperson, Zachary Tudor, CISSP and CEO Clar Rosso update members on accomplishments in Q3 of 2021 including the association’s strategic roadmap, new achievements and milestones, the latest on our certifications, new professional development opportunities, member offers and more. The Q3 2021 update includes membership milestones, association accreditations and new executive leadership focused on member benefits and advocacy. (ISC)² continues to concentrate on global diversity, equity and inclusion initiatives and examining the workforce gap.

2021/8/20
阅读更多

DDoS Trends and the Ransomware Threat

DDoS attacks have dominated the charts in terms of frequency, sophistication, and geo-distribution over the last year. More recently, we have seen a surge in Ransom DDoS attacks — that usually accompany or follow ransomware attacks. This can cripple an organization’s attempt to respond effectively to these threats. Join Cloudflare and (ISC)2 on August 19, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we examine key DDoS attack trends from Q2 2021, ransom DDoS threats (and what you can do if you are affected) and steps organizations can take to make the impact of DDoS attacks a thing of the past.

2021/8/19
阅读更多

The 'Hottest' IT Security Technologies in 2021

Want to know which IT security technologies are hot and which ones are not? Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP), and (ISC)2 as Steve reviews key purchase insights from the 2021 Cyberthreat Defense Report. Specifically, this webcast will identify those security technologies most widely deployed and most planned for acquisition in 2021 so you can benchmark your company’s current and planned investments against your peers. We'll review adoption rates of emerging technologies, such as ZTNA and SASE, and examine purchase intent across five key security technology categories, including: • Network security • Endpoint security • Application and data security • Security management and operations • Identity and access management

2021/8/18
阅读更多

Ransomware and Your Remote Workforce: Zero Trust for the Endpoint

How well is your remote workforce secured against Ryuk and other ransomware – or will you find out once they return to the office? How businesses are protecting employee endpoints, on or off the corporate network, as we shift to a hybrid work model? Join Illumio and (ISC)2 on July 29, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to find out how to benchmark your own IT efforts to prevent mass infections, and learn how to achieve Zero Trust for the endpoint, with default containment to stop the spread before it starts. We will also cover: · What security visibility and control does IT have into endpoints on ungoverned home networks? · How can businesses prevent the spread of ransomware like Ryuk to avoid mass endpoint infections? · How can Zero Trust security support a hybrid model as employees – and their endpoints – start returning to the office?

2021/7/29
阅读更多

Darktrace #3: Securing Smart Cities with Cyber AI

In recent months, major incidents such as the attack related to SolarWinds has led organizations to reevaluate their cyber security strategy. Governments and municipalities in particular, who are facing threats from increasingly professional threat-actors, need robust and adaptive defenses to secure critical data and infrastructure. While traditional tools rely on rules and signatures to spot signs of known threats, cyber-criminals continue to innovate and circumvent these defenses with new tools, techniques, and procedures. For this reason Cyber AI is becoming increasingly critical for its ability to understand ‘normal’, and detect and respond to subtle deviations indicative of a cyber-threat. Join Darktrace and (ISC)2 on July 27, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Darktrace’s Director of Strategic Threat, Marcus Fowler explores: o The unique challenges facing the digital infrastructures of cities and nations o Top cyber incidents of 2021 and what they show us about government cyber-risk o Case studies of Darktrace municipal customers

2021/7/27
阅读更多

Is your Network Security Prepared for the Post-Pandemic World?

The pandemic Work From Home (WFH) era fueled a dramatic shift to edge networking using technologies like SASE, SD-WAN, and cloud. With all the changes in the network, it is only reasonable to expect change in how you test and troubleshoot these new technologies and approaches. Join Keysight and (ISC)2 on July 22, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore the industry’s first cloud-native test solution, Keysight CyPerf as a new way of testing.

2021/7/22
阅读更多

Key Results from the 2021 Cloud Security Report

The 2021 Cloud Security Report, sponsored by (ISC)2, explores current cloud security trends and challenges, how organizations are responding to security threats in the cloud and reveals tools and best practices organizations are considering. Based on a comprehensive survey of 783 cybersecurity professionals conducted in early 2021 to uncover how cloud user organizations are responding to security threats in the cloud, and what training, certifications and best practices IT cybersecurity leaders are prioritizing in their move to the cloud. Join (ISC)2 on July 21, 2021 at 1:00PM Eastern for highlights of the results and to get key insights including: •A majority of cybersecurity professionals (96%) confirm they are at least moderately concerned about public cloud security, a small increase from last year’s survey. •For the second year in a row, the key barrier to cloud adoption, organizations mention was a lack of qualified staff (39%) as the biggest impediment to faster adoption. •More than half of organizations (57%) expect their cloud budgets to increase over the next 12 months. •When asked how organizations rate their overall security readiness, 73% rate their team’s security readiness average or below average. Of those, 78% believe their teams would benefit from cloud security training and/or certification.

2021/7/20
阅读更多

Your Ransomware Hostage Rescue Guide

Ransomware attacks are on the rise — and they’re estimated to cost global organizations $20 billion by 2021 with government agencies, healthcare providers, and educational institutions in the U.S. impacted by ransomware attacks at a cost of more than $7.5 billion in 2019 alone. As ransomware attacks become more targeted and damaging, your organization faces increased risk that can have your networks down for days or even weeks. So, how can your organization avoid getting held hostage? Join KnowBe4 and (ISC)2 on July 15, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Erich Kron CISSP, Security Awareness Advocate at KnowBe4 looks at the scary features of new ransomware strains, gives actionable info that you need to prevent infections, and provides tips on what to do when you are hit with ransomware.

2021/7/15
阅读更多

Darktrace #2: Cyber AI and Protecting the Innovation that Drives Transportation

Organizations in the automotive industry and cyber-physical transportation ecosystems face unique security challenges. Self-learning AI has provided an answer to keep pace with the rapid changes in the threat landscape and industrial technologies, with its ability to detect never-before-seen attacks and adapt to any changes in infrastructure. Join Justin Fier, Darktrace’s Director of Cyber Intelligence & Analytics and (ISC)2 on July 13, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he examines the security challenges facing the automotive industry and cyber-physical transportation ecosystems. We’ll also examine: o How CASE innovations in the transportation sector complexify the cyber threat landscape o How McLaren Racing is using AI to protect their critical systems o The benefits of Autonomous Response in fighting back against emerging cyber-threats at machine speed

2021/7/13
阅读更多

Inside (ISC)2: Updates on Member Services, Benefits and Experience

Clar Rosso, CEO of (ISC)2 shares the latest insights on what’s happening at our association. Join us for this quarterly update where we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. On July 1, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Beth Paredes, Director of Member Services at (ISC)2 join Clar to provide an overview of the wealth of benefits and services available to members and associates.

2021/7/1
阅读更多

Defending Against the Modern Threat Landscape with Zero Trust

Defending against the modern cyber threat landscape requires a modern approach to security. Today’s threats are highly evasive and commoditized to the point where even low skill adversaries can execute successful and devastating attacks. Join Watchguard and (ISC)2 as we cover the 2021 cyber threat landscape, including the top attack categories adversaries are using today, and how a zero trust approach to security can keep your systems safe.

2021/6/24
阅读更多

Darktrace #1: Cyber-Threats Facing Global Healthcare

Attackers are hitting healthcare organizations with targeted and topical email attacks, exploiting concerns about the pandemic. There has been a global rise of ‘fearware’ hitting health organizations around the world, including attackers posing as the Center for Disease Control (CDC) and World Health Organization (WHO). Attackers continue to launch evolving campaigns to convince people to open emails and click on malicious links, using newly-created email domains to bypass traditional gateways. Join Darktrace and (ISC)2 on June 22, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific for Part 1 of a 3 part series as we explore how Cyber AI fights back against increasingly targeted attacks, from advanced phishing to ransomware designed to compromise healthcare workers and organizations as they work on the frontlines against the pandemic.

2021/6/22
阅读更多

Countering Threat Evasion: You Cannot Stop What You Cannot See!

Cybercriminals must become masters of evasion if they are to be successful. Many threats, such as APT’s, are designed to remain hidden for weeks or longer as they slowly monitor their victim, compromising select information in a way that is also intended to go unnoticed. Others, like ransomware, may only need to hide their malicious intentions long enough to infect and begin encryption processes. And even when these attacks trip some defensive sensor, it can take analysts days to investigate and launch an effective incident response, often too late to prevent significant damage. Join Infoblox and (ISC)2 on June 17, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we assess evasion methodologies and the value of DNS, with some unique North American callouts, to counter them across the kill chain including: · Why does DNS visibility expose threat activity other solutions miss? · How can DNS visibility be used to make other solutions more effective? · What role does DNS play in investigation and response?

2021/6/17
阅读更多

Secure Modern Apps, Regain Network Visibility & Enhance Your Team’s Value

Cisco is redefining network security by offering superior threat visibility, ensuring protection for modern apps & hybrid workforce, and empowering firewall users with dynamic policies for application environments. Join Cisco and (ISC)2 on June 10, 2021 at 1:00 p.m Eastern/10:00 a.m. Pacific as we reimagine network security and learn how the firewall can keep pace with DevOps and the application team and offer threat defense with encrypted traffic, TLS 1.3, and accelerate investigation & remediation with the platform approach.

2021/6/10
阅读更多

Become Cyber Resilient - The Next Generation of Cyber Investigations & IR

Cyber investigations and Incident Response (IR) stand to benefit more from disruption than any proficiency in security. What should and could be on the leading edge still relies on outdated, people-heavy approaches, and circa 2005 technologies. Shockingly, this is still how some of the biggest players in the industry tackle the most brand damaging cyber events today. This traditional engagement model is tedious; takes too long and costs too much. Smarter, better and faster options are within our grasp. Join eSentire and (ISC)2 on June 8, 2021 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific for an examination of some of the big rock innovations that are accelerating and revolutionizing the IR world. We’ll cover advancements in endpoint and network sensors, and process improvements in evidence acquisition and analysis and will pivot to forward-leaning engagement models converging IR, cyber intelligence and SOC analyst expertise. Other topics to be covered include: - How modern day cyber investigations and Incident Response can leap off the starting blocks more quickly, with faster time-to-execution and time-to-value for customers. - How the next generation of cyber investigation and Incident Response will change the game for information security executives who are looking for a leg up when going into battle to protect their businesses from cybersecurity incidents.

2021/6/8
阅读更多

Building Your Cybersecurity Bench: (ISC)2’s Cybersecurity Career Pursuers Study

As organizations continue to struggle to find trained cybersecurity professionals to build out their teams, recruiters and hiring managers may need to adjust the tactics they use to proactively identify internal and external candidates. Developing bench strength by targeting candidates who have transferable skills can lead to long term depth and stability on security teams. Understanding who to look for and managing their expectations of what cybersecurity roles entail is critical to success. Join Clar Rosso, CEO of (ISC)2 on May 18, 2021 at 1:00 p.m, Eastern/10:00 a.m. Pacific as she provides an overview of the 2021 (ISC)2 Cybersecurity Career Pursuers Study, which surveyed both experienced cybersecurity professionals as well as jobseekers considering a career in the field. The study examines such topics as which tasks and experiences make a cybersecurity professional successful, the value of mentorship, at what point in their careers pursuers seem likely to seek a cybersecurity path, what attracts people to the profession and which qualities rank as strong indicators of future success for team members.

2021/5/18
阅读更多

Demystifying WAN-as-a-Service

The building blocks of traditional WAN architectures are showing their age. MPLS is expensive and has painfully slow deployment times. Broadband Internet does not deliver the millisecond performance and constant reliability needed for most business applications today. And neither infrastructure was designed with security in mind. Compounding matters further, the surge in remote work and increased cloud adoption is straining traditional WAN architectures. WAN-as-a-service is a cloud-based WAN architecture that offers global scale, integrated enterprise network security functions, and direct, secure connectivity to remote users. Join Cloudflare and (ISC)2 on May 13, 2021 at 1:00PM Eastern for an examination on how WAN-as-a-Service can increase operational agility and lower total costs of ownership and solve the inherent challenges associated with MPLS and broadband Internet. We’ll also cover: · What is WAN-as-a-service and what are its advantages over traditional WAN architectures · How can enterprises build and deploy a successful WAN strategy with fast connectivity and robust security built-in · How enterprises can increase your operational agility with easy deployment and management of network services

2021/5/13
阅读更多

Key Insights from CyberEdge’s 2021 Cyberthreat Defense Report

Did you know that 86% of organizations experienced a successful attack in 2021? Up from 81% the prior year, the largest year-over-year increase in six years. CyberEdge’s 2021 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. Now in its eighth year, the 2021 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 11, 2021 at 1:00 pm ET/10 am PT for highlights of the results and get key insights including: - The chronic shortage of IT security skilled staff is still prevalent; hiring gaps exist across all major IT security roles - Lack of skilled personnel is the #2 obstacle to effective defense against cyberthreats - The fastest and most economical solution is to train existing IT members to fill security positions - IT security professionals see personal and organization-wide benefits of cybersecurity certifications, especially for cloud security, software security, security administration, and management - And more!

2021/5/11
阅读更多

Crypto Service Mesh - A New Perspective to Enterprise Cryptography

Cryptography is omnipresent. Every business unit uses crypto in some shape or form. A marketing web page uses a TLS certificate to assert its identity. A CRM solution that stores customer data uses symmetric key cryptography to encrypt data at rest. An organization's digital security is only as strong as its business units' weakest crypto practices. This has forced organizations to rethink the way teams consume crypto services and driven the need for centralized orchestration and control. Join AppviewX and (ISC)2 on May 6, 2021, at 1:00 PM Eastern Time for a discussion on how a Crypto Service Mesh orchestrates all the diverse crypto services in an organization, abstracts the nitty-gritty details, and provides a standardized, user-friendly, policy-controlled way for different business units to consume these services. We’ll examine: · How various business units consume crypto today · An introduction to Crypto Service Mesh · How a Crypto Service Mesh weaves together people, process, and technology

2021/5/6
阅读更多

Inside (ISC)² Quarterly Board Update, 2021 (Q2)

(ISC)² Board of Directors Chairperson, Zachary Tudor, CISSP and CEO Clar Rosso update members on accomplishments in Q2 of 2021 including a significant increase in professional development opportunities, record numbers of exam offerings, and sharing new research findings to help fill the cybersecurity profession pipeline. Tune in to hear what the organization has planned for the rest of 2021, including an update on this year’s (ISC)² Security Congress event.

2021/5/6
阅读更多

Beyond the Buzzwords – The Trends Behind SASE and Zero Trust

Zero Trust has generated a great deal of “buzz” in the last few years. Many solution providers tout the benefits of Zero Trust, but the approach may not be a fit for you and your organization. Join iboss and (ISC)2 on May 4, 2021 at 1:00PM Eastern as we explore the evolution of network security design principles in order to gain a deeper understanding of how technology can be leveraged to meet evolving user needs and the behavioral and technological direction behind SASE and Zero Trust.

2021/5/4
阅读更多

ExtraHop #1: How To Stop Breaches Faster with Integrated NDR & EDR

Defending against advanced threats requires advanced insights from the three foundational data sources for security operations: endpoint data, log data, and the network. In the first part of a three-part series, we'll discuss: ·advanced threat behaviors, how they gain access to the network through both commonplace and sophisticated means, how they act once they're inside. ·how to leverage the three foundational data sources, integrated into a best-of-breed XDR approach to detect and investigate advanced threats like supply chain attacks, insider threats, and more ·how to rapidly respond to minimize the blast radius and reduce business impact when an advanced threat gets inside.

2021/4/26
阅读更多

Cloud Native Vulnerability Mgmt: Securing Container Images, VMs, and Functions

Full cloud native security requires more than application security testing and network monitoring. It requires a concerted approach to vulnerability management within CI/CD pipelines, in pre-production testing, and at runtime. Join Aqua Security and (ISC)2 on April 22, 2021 at 1:00PM Eastern for an examination on how to secure applications in complex cloud native ecosystems, including: · Detecting vulnerabilities and exploits in container images, VMs, and serverless functions · Prioritizing and triaging security risks to accelerate remediation · Uncovering hidden malware and attack kill chains before they’re executed in production

2021/4/22
阅读更多

ExtraHop #2: Stopping Advanced Threats Doesn't Require a Big Budget

Security and compliance frameworks from CIS, NIST, and PCI SSC point to long lists of must-have technology to build secure and compliant defenses. But they don’t tell us which ones to do first or how to allocate our limited budgets. Advanced Threats follows a land and pivots toward your valuables workflow. This knowledge gives you a roadmap to prioritize investments while leaving others as “good enough” that fit your budget and time constraints. Join ExtraHop experts to get insights into building effective layered defenses that prioritize your budget: - How the “Defender’s Dilemma” should guide your investments at the edge - How “Intruder’s Dilemma” sets the network trap for intruders and advanced threats - Why your IDS needs a next-gen upgrade against advanced threats - See how NG-IDS stops advanced threats (demonstration)

2021/4/21
阅读更多

Modernize Security Operations using MITRE ATT&CK with a Cloud SIEM

Modernizing Security Operations involves a combination of people, process, technology, and services to manage risk, monitor, detect, and respond to cybersecurity threats and incidents. Security leaders seeking to modernize security operations face serious challenges in identifying the resources, expertise and tools to meet their goals. Over the past few years, MITRE ATT&CK® a globally-accessible knowledge base of adversary tactics and techniques has gained prominence as a way to determine the effectiveness of Security Operations to detect, analyze, and respond to attacks. Join Sumo Logic and (ISC)2 on April 20, 2021 at 1:00PM Eastern for an exploration on how security practitioners can leverage the MITRE ATT&CK framework and integrate using the Sumo Cloud SIEM.

2021/4/20
阅读更多

Top 3 Trends in Today’s Cyber Attack Landscape

Cyber attacks are at an all-time high and threat actors are becoming more sophisticated in their attempts. When considering today’s trends (and threats) in the industry, three recurring themes often come up amongst Cybersecurity professionals: the continued growth of ‘double extortion’ ransomware attacks, the increased risk that employee identity theft poses to organizations, and the additional fallout from supply chain attacks. Join Aura, NXTsoft, and (ISC)2 on April 15, 2021 at 1:00 PM Eastern as we discuss these three cyber threat trends and different ways you can address them within your organization.

2021/4/15
阅读更多

Protecting the Enterprise: 5 Components needed for Cybersecurity Training

It’s difficult to prescribe a one-size-fits-all approach to training your cybersecurity team. While cybersecurity training needs to be structured and adhere to industry standards, it also must be purposeful and tailored to your organization’s needs. No one organization has precisely the same security needs as another. However, many of the fundamentals of a training and education program apply across different organizations and sectors. Join (ISC)2 for a panel discussion on Tuesday, April 13, 2021 at 1:00PM Eastern as industry leaders share tips they’ve learned and strategies they’re working towards to conquer a secure and compliant cybersecurity training program. Areas for discussion will include: · Who needs training · Who is responsible for training · Determining the curriculum · Training and certification · Ensuring training effectiveness Be prepared for an hour well-spent and discover how to create a cybersecurity training plan that maps to your organization’s specific needs.

2021/4/13
阅读更多

ExtraHop #3: How NG-IDS Stops Advanced Threats Legacy IDS Misses

Supply Chain attacks, Zero-Days, and Advanced Persistent Threats (APTs) are effective because they target the trust models traditional security products were built on. The result is a post-compromise world where traditional IDS technology is looking in the wrong direction based on outdated assumptions to detect and stop modern attacks. Join John Oltsik from ESG and ExtraHop experts to learn how machine learning NG-IDS gives you back the edge against Advanced Threats : · Why Advanced Threats require a post-compromise posture · How time has been unkind to that noisy 90s IDS · How to fill IDS compliance gaps and increase security efficacy · How NG-IDS stops Advanced Threats before they do real damage

2021/4/9
阅读更多

Gigamon #3: Securing the Hybrid Cloud: 5G Networks

5G networks, almost by definition, are hybrid cloud networks. Any company adopting 5G is in effect adopting a hybrid cloud model. As mobile network service providers launch their 5G services around the world starting with radio access network (RAN) deployment followed by the core network, security vulnerabilities, including preventing or mitigating their effects, are top of mind. Whether the network functions and services are physical, virtual on-prem, or public cloud, ensuring comprehensive continuous visibility into the network is crucial to ensuring and maintaining adequate security. Join Gigamon and (ISC)2 on April 9, 2021 at 1:00PM Eastern for a discussion on understanding how coherent, high-fidelity network data can enable a strong security posture without breaking the bank.

2021/4/8
阅读更多

The Security Outcomes Study: A Blueprint to Enable Growth and Mitigate Risk

Cybersecurity is about priorities, but the challenge is knowing what works and what doesn’t. What if you could learn from thousands of peers, around the globe, about how they’re succeeding? You can. Cisco recently commissioned the Security Outcomes Study, outlining which security best practices lead to the most impactful results. Join Cisco and (ISC)2 on April 6, 2021 at 1:00PM Eastern for a discussion that will cover: · The business outcomes that cyber professionals are working to achieve · The specific security practices that contribute the most · How to use their advice to improve your cyber program today

2021/4/6
阅读更多

SolarWinds Fallout Has Execs Asking: How Secure is Our Supply Chain?

The ramifications of the SolarWinds incident continue to evolve as more details emerge about the impact it had on a wide range of organizations. A recent survey of more than 300 cybersecurity practitioners by (ISC)2reveals just how concerning the incident was and what these professionals recommend to shield organizations from similar supply chain threats. Join this panel discussion on March 30, 2021 at 1:00pm Eastern to hear anecdotes and best practices related to third-party technologies in the security stack, and how peers in cybersecurity leadership positions are future-proofing their defenses while planning for worst case scenario.

2021/3/30
阅读更多

Inside (ISC)²: Updates on Exams and Certifications

Clar Rosso, CEO of (ISC)2 shares the latest insights on what’s happening at our association. Join us for this quarterly update where we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. Joining Clar this quarter is Dr. Casey Marks, chief product officer and VP of (ISC)2, to discuss the latest in Exams and certifications.

2021/3/23
阅读更多

Global Impressions: Endpoint Security Strategies for the Long-Term

After a painful but relatively successful response to workplace changes driven by the pandemic, how well are those security measures working and what is next for the evolution of the SOC and endpoint security in specific? For most organizations, the future involves a larger remote workforce, of both full and part-time workers, including those in traditional HQ office roles. But many of the measures taken in response to pandemic conditions are proving less-than-ideal as long-term solutions. Join Infoblox and (ISC)2 on March 18, 2021 at 1:00PM Eastern for a session that will draw on recent analyst reports and surveys conducted globally, with some North American specific call-outs, to help attendees to better understand…· Which security alternatives are leaders considering as long-term solutions, and why? · What techniques are helping to improve visibility for users and devices regardless of their location? · Why are security leaders evolving methods for obtaining and using cyber threat intelligence? · How can embracing automation improve response times and overall operational efficiencies?

2021/3/18
阅读更多

Inside (ISC)² Quarterly Board Update, 2021 (Q1)

Join us for (ISC)² Insights, a quarterly review of our association’s latest accomplishments. Each quarter, the (ISC)² Board of Directors Chairperson and CEO will update members on the association’s strategic roadmap, new achievements and milestones, the latest on our certifications, new professional development opportunities, member offers and more.

2021/3/12
阅读更多

Gigamon #2: Securing the Hybrid Cloud: Optimizing SIEM

SIEM systems are pivotal to IT organization’s security operations. Many companies are adopting a hybrid cloud model, and cloud-based SIEMs are becoming common as a result. Regardless of on-prem or cloud deployments, the challenges around SIEM remain the same, from data overload, lack of contextual information, to high costs. Security best practices in deploying SIEMs also remain unchanged, which include establishment of use cases, data ingestion types and development of parsers for various tool vendors. On March 9, 2021 at 1:00pm Eastern, Gigamon and (ISC)2 will present a webinar that will cover solutions to these challenges such as Gigamon’s Application Metadata Intelligence as well as various smart filtering techniques.

2021/3/9
阅读更多

Gigamon #1: Securing the Hybrid Cloud: Visibility Best Practices

With the move to cloud and the multitude of approaches, your ability to effectively monitor and secure workloads gets even more difficult. IT complexity, the rate of change, lack of skills, and organizational silos have made confidently managing security and performance nearly impossible. Visibility is critical. Join Gigamon and (ISC)2 on February 25, 2021 at 1:00pm Eastern for a discussion of the security considerations for on-prem private, public and hybrid clouds. You’ll learn best practices and see how a little planning and design can go a long way. Achieve a secure and viable hybrid cloud implementation and get a high return on your investment. Join our session to learn how.

2021/2/25
阅读更多

What's This Thing? Solving Asset Management for Security Ops

SecOps teams struggle to quickly gather useful, accurate and up-to-date asset date to inform investigations. It’s important to correlate datea from multiple sources to understand the intersection of connected devices, cloud instances, user and security controls. Ultimately SecOps teams care most about alerts and investigations, but some of the most basic asset data challenges make getting context a massive pain. Join Axonius and (ISC)2 on February 18, 2021 at 1:00PM Eastern as we look at asset management and its impact for security operations.

2021/2/18
阅读更多

Engaging Your Line of Business for Cybersecurity Initiatives

Security cannot be done in a silo. The extent and nature of data shared across lines of business functions, both internally and externally, fuels instances of system and organizational vulnerabilities. GRC must transcend the traditional lines of defense, specifically risk managers and audit professionals. In this webinar, we’ll discuss roles and responsibilities of effective risk management practices. What can businesses do to better align key stakeholders? How can businesses incorporate Security by Design process and practices and where can technology support with structured data sets and automation? We’ll look at: · Aligning organizational goals, and department objectives to translate risk into business impacts.    · Automating GRC touchpoints into your line of business functions   · Integrating Audit to document and support continuous improvement initiatives

2021/2/10
阅读更多

Darktrace #3: The Industrial Immune System: Securing IT/OT Converged Ecosystems

The increasing convergence of information technology (IT) and operational technology (OT) in ICS environments creates significant challenges from a security perspective. Attacks originating in the inbox can now more easily disrupt processes on the factory floor. Further, many organizations are unaware of the extent of IT/OT convergence in their own ecosystems. Join Darktrace and (ISC)2 on February 9, 2021 at 1:00pm Eastern as we look at how Darktrace’s Industrial Immune System helps organizations tackle these challenges by providing a unified view of IT and OT networks. The self-learning AI detects threats throughout the ecosystem and the AI analyst also automates the investigation process in both IT and OT-specific contexts in order to augment human teams. The session will also include a discussion on how the system defended against a Serpent ransomware infection in real time.

2021/2/9
阅读更多

From the Front Lines – Incident Response at Scale

In this session from our recent Security Congress event, you hear stories of CrowdStrike incident response engagements and how they have changed the model for how companies respond to a breach. Learn the methods CrowdStrike uses to disrupt and ultimately remove bad actors from networks.

2021/2/4
阅读更多

Entrust #3: What Type of Passwordless Solution is Right for You?

Passwords are easily the most irritable thing for securing your digital identity. Be it workforce or consumers, everybody gets bogged down with the task of remembering passwords for multiple websites and applications. They are also the weakest form of security, often hacked by cybercriminals. With the advent of biometrics and their widespread reach (thanks to smartphones), passwordless access became a reality with mobile push authentication. As biometrics are unique to every individual, it is a pretty secure way to access applications and authorize transactions. Passwordless techniques were further modified with the introduction of physical keys (USB devices). But the foremost approach to passwordless access is credential based authentication which works on the principal of securing both your device and identity. Join us for a session where we will talk about all things passwordless. We’ll examine: · How security paradigms changed with COVID-19 ? · Why is the world moving towards passwordless ? · Different types of Passwordless solutions offered by Entrust Identity · How to secure your workforce with Entrust Identity's high assurance passwordless solution

2021/1/28
阅读更多

Darktrace #2: Threats in Focus: Nation-State Cyber Attacks

Among rapidly evolving global challenges, the escalation of nation-state attacks is making cyber-attacks exponentially more dangerous and harder to identify. Mounted at speed and scale and backed by thorough resources, nation-state cyber-attacks often do damage under great stealth, steal sensitive data, and have even resulted in manipulation and distortion of information. In the face of sophisticated nation-state attacks, organizations are turning to Cyber AI, which detects the subtle signs of targeted, unknown attacks at an early stage, without relying on prior knowledge. Join Darktrace and (ISC)2 on January 26, 2021 at 1:00PM Eastern as we examine: · Paradigm shifts in the tide of nation-state cyber threat landscape · How Cyber AI singularly detects never before seen threats · Real-world examples of nation-state campaigns stopped with Cyber AI

2021/1/26
阅读更多

Entrust #2: Rethinking Enterprise Security with a Zero Trust Approach

Organizations around the world have transitioned to working from home in past months, and this transition has challenged advanced security models and user behaviors in a COVID-19 world. A significant number of users discovered that poor technology and/or infrastructure was the biggest barrier to effective remote working. As we speed towards the new normal of hybrid workplaces, organizations are reviewing their business continuity plans and restoring productivity to pre-covid times. Cybercriminals are getting smarter; work from home has expanded the enterprise perimeter; and the digital ecosystem is growing rapidly including new cloud applications. A significant part of IT Security effort is to ensure appropriate infrastructure and tools for their employees as well as top of the line cyber hygiene controls. Therefore, companies need a cyber security strategy that is consistent and crosses their on-premises perimeter. “Never trust, always verify”, is the bedrock of Zero Trust. With a Zero Trust model, every request to access information/data must be authenticated, authorized, and encrypted before permission is granted. It is not a product but an enterprise cybersecurity plan to protect its resources. In this session the participants will learn about: o Enterprise challenges in Zero Trust implementation o How Zero Trust responds to different risk factors o Ways to secure enterprise Hybrid environment o How Entrust's high assurance IAM solution helps in achieving Zero Trust

2021/1/26
阅读更多

Entrust #1: Quickly and Securely Verify Individual Identities Online

2020 has accelerated digital transformation efforts across the board. Projects with multi-year timelines are being executed in a matter of months and, in some cases, weeks. Increasingly, people are being interviewed, hired, and onboarded without ever having an in-person meeting. Customers are transacting online in record numbers out of necessity, convenience, and even safety. This new normal introduces the challenge of securely verifying individual identities, especially when an in-person identity check is not feasible. Modern identity proofing keeps your workers and customers safe and protects your organization. In the first part of this series, join us to learn best practices to: o Securely verify personal identities o Limit user friction in the verification process o Protect workforce and consumer identities o Mitigate risk of identity fraud

2021/1/25
阅读更多

Threat Hunting: A Proactive Approach to Breach Defense

Did you know that 1 in 4 companies are at risk for a major breach in the next 24 months? And with nearly half of alerts going uninvestigated at organizations around the globe, it’s no wonder this risk is so high. Reducing your organization’s mean time to detection can minimize the impact of a breach, but without a focused detection capability giving you visibility, breaches can go undetected for months, by which time extensive damage has already been done. Join Cisco and (ISC)2 on January 21, 2021 at 1:00PM Eastern for a discussion to learn about the value of adding threat hunting to your breach defense. We will examine the differences between starting an internal threat hunting team versus acquiring services from a third party and how you can leverage a hybrid model to take a more proactive approach to breach prevention.

2021/1/21
阅读更多

August 2020 Summit #3: Technical Blue Print for Data Protection

This session will lay out the technical blue print to achieve data protection success. Discover why Forcepoint is a 9x Gartner MQ Leader for DLP. Forcepoint Dynamic Data Protection can allow your organization to prioritize high-risk activity and automate policies to protect data in near real-time, providing the highest security & workforce productivity. During this final session to the Path to Smart Data Protection learn how Forcepoint can help your organization: • Profile high-risk activity based on data incidents, data models and endpoint collector events • Dynamically allocate individual risk scores based on a person’s behavior and the value of the data they access • Apply automated controls to any interactions with sensitive data based on individual risk level.

2021/1/13
阅读更多

August 2020 Summit #2: Explorations in Data Protection

During this session hear from a Forcepoint customer on why they chose Forcepoint as their Data Protection partner. Learn how a healthcare organization leveraged Forcepoint’s solution to span across multiple businesses, ingest and fingerprint data, support regulatory requirements, customize policies, implement across multiple domains, provide OCR and use a single pane of glass for policy configuration and enforcement.

2021/1/13
阅读更多

August 2020 Summit #1: Data Protection Essentials

What data does your organization process? What policies exist? Who are your internal stakeholders? What is your organizations risk tolerance? What compliance regulations apply to your organization? This session will walk dig into how to operationalize a successful data protection program from the basics to demonstrating effectiveness.

2021/1/13
阅读更多

May 2020 Summit #3: SASE for Data - Data Protection with Cloud DLP

Data context is a core principle of SASE architecture and it requires visibility to data-at-rest and data-in-motion for data loss protection (DLP) policies and rules. Intersect these objectives with the overwhelming use of cloud apps freely adopted by business units and users, and you need cloud DLP. Legacy SWG solutions using ICAP for file-based DLP analysis are blind to cloud apps and the majority of data movement and use. While traditional cloud access security broker (CASB) deployments use API protection into several dozen managed cloud apps, it is the inline deployment that provides granular control for thousands of cloud apps in use, plus web traffic. Here are five areas to consider when updating your blueprint for data loss protection. 1. First, your users are in the cloud and are now working remote. Plus, the majority of your data now resides in the cloud with wide SaaS adoption, so your DLP needs to be in the cloud. SASE involves a single pass design for data and threat protection, meaning your cloud SWG requires strong DLP for cloud and web traffic. 2. Allow/block faces the same challenges for DLP, it needs to mature to ‘allow’ with granular policy controls for data protection. The cloud brings boundary crossings between company and personal instances, managed and unmanaged cloud apps, activity and context, plus app risk factors to recommend safer alternatives. 3. While inline cloud SWG provides the foundation for cloud DLP, the benefit of SASE architecture is using the same DLP policies and rules for data-at-rest in managed apps with CASB, public cloud environments with cloud security posture management (CSPM), plus securing private access with ZTNA.

2021/1/13
阅读更多

May 2020 Summit #2: SASE for Users - Secure Remote Users for Any Device

In the current environment, many legacy VPN and remote access solutions are being overwhelmed, and organizations are reacting with ‘band aid’ fixes. The goal is to enable business critical users with cloud-based private access as quickly as possible with the least amount of friction. Strategically, this will mean combining a cloud-based Next Gen Secure Web Gateway (providing cloud and web inline security) and a zero trust network access (ZTNA) solution (providing scalable and fast remote access) as part of your SASE architecture. Here are five areas to consider when updating your blueprint for remote access security: 1. Most legacy VPNs were deployed to handle around a third an organization’s workforce, but they are being pushed to handle two-thirds or more in the current crisis. The poor performance and user experience of overloaded VPNs can be easily replaced with cloud-enabled private access - for critical business use cases. 2. Shift your remote access strategy from VPNs providing network access, with the opportunity for lateral movement by malicious insiders and compromised accounts, to secure, cloud-enabled, zero trust application access. 3. ZTNA maintains the traditional remote access features of device posture checking and strong authentication, but improves the security of data centers and public cloud environments by not exposing any IPs, ports or services to the public internet. 4. The deployment of legacy VPNs to multiple data centers and multi-cloud environments can be complex for IT and users. Cloud-enabled ZTNA seamlessly and transparently provides access to hybrid IT environments with high performance, global scale, and much less complexity.

2021/1/13
阅读更多

May 2020 Summit #1: SASE at-the-Core - Content and Context with Next Gen SWGs

Transformations are disruptive by nature driving the need to review the challenges for cloud and web use in our organizations. Secure web gateways (SWGs) are also part of the disruptive transformation cycle we are all experiencing and becoming the core of SASE architecture to provide vital content and context for granular policy controls. Here are five areas to consider when updating your blueprint for securing web and cloud use. 1. The web is no longer just web, over half of secure web gateway (SWG) sessions are now cloud apps where the average organization uses 2,415 cloud apps and 89% of users are active in the cloud. Adding more fuel, over 98% of cloud apps are unmanaged by IT and freely adopted by business units and users. 2. Web content and filtering needs to advance to decoding cloud app traffic inline, or SWGs will remain blind to cloud content and context for real-time threat and data protection where 44% of threats were cloud-enabled in 2019. 3. The general allow/block model no longer works for cloud. Allow now requires granular controls such as understanding cloud app instances and activity to detect cloud phishing or cloud-enabled threats using trusted domains and valid certificates to evade legacy defenses. 4. Appliance limitations are being replaced with cloud native platforms with on-demand performance and global scale. These microservice designed platforms are enabling an integrated SASE architecture with an understanding of data context and expanding capabilities to end appliance sprawl. 5. SWG control points for main and remote offices now must include a growing base of remote workers. For cloud SWG optimization, they require a hyperscale carrier grade access network providing the fastest round trip time possible. This eliminates the performance versus security trade-off and the uncertainties of the internet.

2021/1/13
阅读更多

April 2020 Summit #3: Insider Threats & Compliance

Once your security operations center (SOC) team has identified and remediated the insider threat, the job is only partially done. It is then essential for your SOC to respond to the alert, which includes reporting and auditing necessary for compliance. In this final presentation, we will take a deep dive into how you can use a security orchestration, automation and response (SOAR) solution to respond to and then report on insider threats at machine speed.

2021/1/13
阅读更多

April 2020 Summit #2: How to Remediate Insider Threat Alerts Automatically

Whether your security operations center (SOC) uses a security information and event management (SIEM) solution, data loss prevention (DLP) tool, or some other product to detect anomalous activity, responding to the insider threat alert swiftly enough to limit your organization’s exposure is the real battle. In this presentation, we’ll examine a typical use case for automated insider threat response, demonstrating a significant reduction in risk for the organization.

2021/1/13
阅读更多

Darktrace #1: Ransomware in Focus: How AI Stays One Step Ahead of Attackers

As the world continues to endure ongoing global disruption, cyber-attackers have been constantly updating their tactics in light of emerging trends. According to MIT Technology Review, 121 million ransomware attacks were recorded in the first half of 2020, each one attempting to encrypt private data and extort payment for its release. The automated elements of these attacks, featuring malware that moves faster than security teams can respond, is one of the most damaging hallmarks of these ransomware campaigns. Join Darktrace and (ISC)2 on January 12, 20201 at 1:00pm Eastern as Justin Fier, Director of Cyber Intelligence & Analytics at Darktrace, unpacks the nuances of some of today’s most costly and advanced ransomware and shares how self-learning AI uniquely empowers organizations across industries to fight back.

2021/1/12
阅读更多

April 2020 Summit #1: Why Insider Threats Should be on your Radar Now

A Fishtech Group subsidiary, Haystax, in cooperation with Cybersecurity Insiders recently released the “2019 Insider Threat Report” claiming “70% of the organizations surveyed think insider attacks have become more frequent in the past 12 months.” Ostensibly, the threat of insider attacks is growing, and it’s critical that we understand where we are and where we’re going in terms of insider threats. In this presentation, we’ll examine the current insider threat landscape and how top companies are using different security tools and strategies to weed through the complexity and mitigate risk to their organizations.

2021/1/12
阅读更多

January 2020 Summit #3: Carding Attacks and Its Impact on Websites

Two new carding bots are threatening websites and putting customer PII data at risk. The increase of credit card usage has led to an unexpected growth of carding bot attacks. The result is significant revenue loss for e-commerce sites. Not only is revenue at stake, but these threats jeopardize a company’s reputation, customer trust and online user experience. Carding attackers target websites and platforms, exploring new methods and tools to automatically validate stolen credit cards. In this session, you’ll learn about the new carding bots that threaten e-commerce sites and put customer PII data at risk. We will also show how to better protect your websites, mobile applications and APIs from these new bots.

2021/1/12
阅读更多

January 2020 Summit #2: New Trends in Magecart Attacks

In late 2019, British Airways was fined $229M for loss of customer data from their website that was caused by a Magecart attack. Digital skimming and Magecart attacks continue to be a major threat to online businesses, exposing payment card data and customer PII. The research team at PerimeterX has uncovered a new trend where multiple independent Magecart groups are skimming data from websites concurrently. In this part. We’ll examine two major incidents uncovered by the PerimeterX research team, where attackers infiltrated digital services through Magento-based applications.

2021/1/12
阅读更多

January 2020 Summit #1 - Top 5 Threats to Online Businesses

Cyberattacks continue to threaten online digital experiences. Automated bots and compromised third-party code outsmart existing defenses and compromise the integrity of your websites and mobile apps. This impacts an organization’s ability to be effective in conducting and securing online business. In this webcast, we’ll examine the top five security threats to online business, how to stay ahead of these attacks and proactively address client-side vulnerabilities and the practical strategies needed to protect customers, online revenue and company reputation.

2021/1/12
阅读更多

How XDR Can Provide Complete Breach Protection to Even Small Security Teams

New Extended Detection and Response (XDR) solutions are built to unify multiple prevention, detection and response technologies into a single platform to provide comprehensive visibility and protection. However, as cyber-threats become more sophisticated and niche protection solutions remain frustratingly disconnected, a pre-built, unified protection solution provides many benefits to overburdened security teams. Join Cynet and (ISC)2 for an examination of the capabilities and benefits provided by emerging XDR solutions. The webcast will examine the following areas: · The business and technology value drivers for XDR solutions · Capabilities security practitioners should look for in emerging XDR offerings · How and why XDR should not only provide Extended Detection, but also Extended Response capabilities · A live demo of a fully automated XDR Incident Response workflow, including investigation, root cause analysis, impact analysis and automated remediation actions

2021/1/11
阅读更多

Swimlane #3: Reactive to Proactive Threat Hunting: Changing the SOC w/Automation

Are your analysts drowning in low-value, high-noise alerts and constantly playing catch-up? Is this hurting your mean time to detect (MTTD) and mean time to resolution (MTTR)? A security orchestration, automation and response (SOAR) solution can help in this area. A SOAR solution can enable an organization to realize some time and resource savings which can result in more research and active threat hunting for a more proactive approach to cybersecurity. On December 17, 2020 at 1:00 p.m. Eastern, Swimlane and (ISC)2 will explore how automation can help you dedicate your limited security resources to proactive threat hunting. We’ll also discuss how to: · Integrate your threat intelligence sources with a SOAR platform for faster and more accurate threat identification and verification. Use information from analyst research or automated feed ingestion to facilitate threat hunting across your security toolset and environments. · Reduce MTTD/MTTR by automating repetitive, manual tasks.

2020/12/17
阅读更多

Darktrace #3: Mimicking Human Intuition: The Cyber AI Analyst

Alongside the rise of today’s dynamic workforce, the speed and scale of sophisticated cyber-attacks is rapidly increasing. As the cybersecurity industry continues to endure an ongoing skills shortage, over-worked and under-resourced teams urgently need augmentation in order to defend against evolving, sophisticated threats. AI technology can help augment an overworked and understaffed security team. But can AI be programmed to think like a living breathing cybersecurity analyst? Join Darktrace and (ISC)2 on December 10, 2020 at 1:00pm for an examination of Darktrace’s Cyber AI Analyst and how this capability detected and prevented a large-scale worming attack in real-time.

2020/12/10
阅读更多

Digging Into the 2020 (ISC)2 Cybersecurity Workforce Study

The (ISC)2 Cybersecurity Workforce Study is one of the most highly-anticipated annual research reports each year. Not only has it come to be considered the industry standard for measurement of the global “skills gap” in cybersecurity, but it offers nuanced insights into subjects like job satisfaction rates, salaries, role alignment, the profile of the cybersecurity professional, diversity and how to strengthen teams and improve hiring practices. The 2020 edition of the study was released in early November and also includes data on the cybersecurity community’s response to COVID-19 and the transition to remote work environments. This panel discussion brings together several of the (ISC)2 architects behind the research to provide a deeper look beyond the numbers and explore some of the key themes of this year’s findings.

2020/12/9
阅读更多

Securing Your Expanded Remote Workforce

The COVID-19 pandemic has caused dramatic increases in remote workforces and BYOD policy adoptions, making it more challenging than ever to secure company applications and data. Now that organizations have increased their remote access capacities, it’s now time to explore ways to help secure these remote managed and unmanaged devices to help mitigate the elevated risks of ransomware, data breaches, and other cyberattacks. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps key findings from a recent COVID-19 impact study - Examines the challenges facing today’s IT security teams - Suggests ways to invest more in your human firewalls - Explores current and emerging security technologies

2020/12/1
阅读更多

Maximizing the Value of Threat Intelligence

‘Threat intelligence’ has become a general term that may refer to many different types of data sets used to meet very different security needs. Threat prevention and detection solutions (i.e. NGFW, SWG, EDR) are only as good as the threat intelligence driving their analytics. Threat investigation and incident response activities are limited and slow without timely access to sufficient event, network, and threat intelligence. This requires defenders to better understand their intelligence needs, how to identify and map appropriate threat feeds to each need, and the tools available to drive maximum value from threat intelligence. Join Infoblox and (ISC)2 as we review the state of the threat intelligence industry, using public and private research from the last year on the quality and applicability of public, private, and proprietary feeds. We’ll also examine areas such as: - Automating multi-feed normalization into a ‘super-feed’ for a more effective defensive security stack - Speeding investigation and response through event, metadata, and threat intelligence correlation - Leveraging threat intelligence of threat actor objectives, methods, and tactics to drive quick incident resolution

2020/11/30
阅读更多

What is a Cryptographic Center of Excellence and Why is it Important?

An overall explosion in cryptographic dependencies has given way to an urgent need for enterprises to define their crypto strategies and gain visibility into the many new cryptographic instances that are hidden across their IT environment. As enterprises adopt new IT practices such as DevOps, Internet of Things (IoT), cloud and multi-cloud environments, their cryptographic footprint expands exponentially increasing the risk for business disruption and security threats. This presents an urgent need for enterprises to define new strategies for both crypto and PKI environments in order to balance that risk. A Cryptographic Center of Excellences (CryptoCOE) prepares security, compliance and risk teams for crypto agility and methods for mitigating crypto related threats. Join this session as we discuss important insights on how to protect your digital business with strong digital trust protocols that support the expanding use cases for cryptographical instance.

2020/11/23
阅读更多

The Impact of COVID-19 on Enterprise IT Security Teams

The pandemic and its shock to world economies have profoundly altered work environments and cybersecurity priorities. COVID-19 has prompted a massive work-from-home (WFH) movement, increased BYOD policy adoptions, and unfortunately a spike in cyberthreats, ransomware, and data breaches. To help enterprises understand the enormous impact to their IT security teams, (ISC)2 co-sponsored a study that surveyed 600 security professionals from seven countries and 19 industries. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews key insights from this study, including: - Challenges of supporting an expanded remote workforce - Mid-year changes to IT security budgets and personnel - Change in preferences for cloud-based security solutions - Security technologies best suited to address pandemic-fueled challenges - The positive impact of IT security professional certifications

2020/11/10
阅读更多

What to Expect at (ISC)² Security Congress 2020

Join (ISC)² Chief Operating Officer, Wesley Simpson for a lively and informative panel discussion on the many new features and offerings provided at the 2020 virtual Security Congress! Security Congress veterans and session panelists, Brandon Dunlap, James McQuiggan, & Sharon Smith will share how to leverage many of the unique features of the virtual Security Congress, guide you through the various educational, networking and engaging social activities driving the 2020 (ISC)² Security Congress experience. Whether it's your first Security Congress or 10th, there's something here for everyone. Key topics discussed: - What makes Security Congress is the marquee security conference of the year: - Content quality, notable speakers, & keynotes - Network with thousands of professionals from around the globe & career coaching opportunities - Ability to obtain up to 45 CPE Link to event page in the attachments. (ISC)² is an international, nonprofit membership association for information security leaders like you. We’re committed to helping our members learn, grow and thrive. More than 150,000 certified members strong, we empower professionals who touch every aspect of information security. (ISC)² Security Congress brings together industry colleagues, offers educational and thought- leadership sessions, and fosters collaboration with other forward-thinking companies. The goal of our annual global cybersecurity conference is to advance security leaders by arming them with the knowledge, tools and expertise to protect their organizations.

2020/11/9
阅读更多

Swimlane #2: SOARing Beyond Expectations - Automating Atomic Red Team Testing

Organizations around the world struggle protecting their environments and determining where vulnerabilities exist. Open-source projects, such as Red Canary’s Atomic Red Team, can help by providing methods for evaluating defensive security controls and identifying areas of vulnerability. Additionally, a framework like MITRE ATT&CK can give the organization a full security view, ensuring a comprehensive strategy is in place. Such resources provide useful information for security teams, but the manual processes still needed to execute tests and map them to active detections from existing SIEM, EDR or other tools is too time consuming for many security operations centers (SOCs) to conduct effectively. Join Swimlane and (ISC)2 on November 5, 2020 at 1:00 p.m. Eastern as we examine how to do automate testing with a security orchestration, automation and response (SOAR) solution. In this session you will: · Learn how to automate the testing of your security controls · See how SOAR can help you visualize areas of concern with the MITRE ATT&CK dashboard · Get an overview of a helpful open-source tool recently developed by the Swimlane Deep Dive Research Team

2020/11/5
阅读更多

Don't Miss the BIGGEST (ISC)2 Security Congress Yet!

Join thousands of cybersecurity professionals at all levels for three days of industry discussion, continuing education and networking, November 16 – 18. Get your passes at: https://securitycongress.brighttalk.live/passes/

2020/11/3
阅读更多

Darktrace #2: Securing the New Normal: Immune System Technology for Cloud & SaaS

As workforces look to remain remote for the long term, the cloud has become ubiquitous. Yet human security professionals relying only on conventional security tools continue to struggle to secure the complexity of today’s hybrid and multi-cloud topologies - in fact, only 22% of organizations feel they have adequate visibility into their cloud applications and infrastructure. Join Darktrace and (ISC)2 on October 22, 2020 at 1:00 p.m. Eastern for a an examination of businesses as they increasingly turn to AI as a uniquely dynamic solution to detect and defend from novel threats that emerge on cloud and SaaS environments – which the global workforce continues to rely on in today’s remote working landscape. The webcast will also explore: · Exploration of the latest cloud and SaaS real-world threat trends · How Darktrace’s groundbreaking AI Immune System technology keeps pace with the dynamic workforce · Case studies and unique threat finds from industry leading customers

2020/10/22
阅读更多

Session #3 - SASE for Data - Data Protection with Cloud DLP

Data context is a core principle of SASE and requires visibility of data-at-rest and data-in-motion making Cloud DLP a requirement for thousands of cloud apps freely adopted by business units and users. Here are five areas to consider for your blueprint for data protection. •Users and data are increasingly in the cloud and working remote. •Data protection focuses on boundary crossings for apps, instances, and activity. •Unintentional and unapproved data movement is a leading use case for SASE. •DLP is compute intensive and SaaS architecture provides cloud performance and scale. •One solution applies DLP to data-at-rest and in-motion with SASE.

2020/10/21
阅读更多

Session #2 - SASE for Users - Securing Remote Workers for Any Device or Location

Today, many legacy VPN solutions are overwhelmed. The solution is SASE: enabling employees to work from anywhere with a cloud-based combination of Zero Trust Network Access (scalable and fast remote access) and NG SWG (inline cloud and web security). Here are five areas to consider when transforming security to enable working from anywhere: •Fixing the poor user experience caused by overloaded VPNs. •Preventing lateral movement of malicious actors over VPNs. •Using ZTNA to avoid exposing private servers to the Internet. •Reducing the complexity of remote access to hybrid cloud. •Combining NG SWG with ZTNA to deliver SASE for remote workers.

2020/10/21
阅读更多

Session #1 - SASE at-the-Core - Content and Context with Next Gen SWGs

Digital transformation is driving the need to review cloud and web use in our organizations. Secure web gateways (SWGs) are now the core of SASE architecture to provide content and context for granular policy controls for apps and web. Here are five areas to consider for your SASE blueprint. Over half of SWG sessions are now cloud apps and services. •Web filtering needs to advance to decoding cloud app traffic inline. •The allow/block model no longer works for cloud, you need to manage risk. •Appliance limitations are being replaced with cloud native platforms. •Performance matters to avoid security trade-offs.

2020/10/21
阅读更多

Ransomware: New Variants & Better Tactics to Defend & Defeat These Threats

Ransomware continues to be an ongoing threat to organizations of all sizes that must defend against. Successful attacks have caused a large increase in overall ransomware incidents. Join Infoblox and (ISC)2 for the latest research on the emergence of Qakbot InfoStealer, the Return of Emotet, Vidar InfoStealer, and much more. We’ll also examine how Ransomware as a service continues to grow, the tactics threat actors are using to be successful and what can you do differently to better defend against them. Key takeaways will include: · New and recently emerged malware variants and trends · How these differ from other variants we have seen in the past · What defensive tactics work, and what has failed in the past · What the state of ransomware looks like

2020/10/20
阅读更多

Swimlane #1: Five SOAR Use Cases to Address Analyst Burnout

A recent study revealed how security orchestration, automation and response (SOAR) can deliver impressive gains in your security operations center's (SOC) efficiency, productivity, and consistency within a relatively short time-frame—11 months or less on average. But, how do you get there, and what SOAR use cases can lead to these remarkable gains? Join Swimlane and (ISC)2 on October 8, 2020 at 1:00 p.m. Eastern for a pragmatic approach to automation and orchestration as we dig into the use cases where organizations are seeing significant impacts in their SOCs. We’ll also examine: •Typical challenges that SOAR platforms address. •Five SOAR use cases that can be used immediately to alleviate analyst burnout and provide more effective use of existing tools. •How to further increase the ROI of a SOAR platform with robust reporting and metrics.

2020/10/8
阅读更多

Chronicle #2: From EDR to XDR: Evolving Security Analytics to Keep Pace

The XDR technology ecosystem promises a new level of cyber security visibility, improved detection and active protection against modern threats. The full telemetric value of XDR platforms, however, may not be realized without rethinking security analytics. Join the Google Cloud Security team for this webcast to learn more about the dimensions of modern security analytics that will enable you to fully unleash your XDR investment.

2020/10/1
阅读更多

Ransomware Deep Dive: Examining Disturbing Ransomware Trends

Successful ransomware attacks are at an all-time high. And so is the number of organizations paying ransoms to recover their data. But why? And what can smart IT security teams do to mitigate the risks of falling victim? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he reviews key findings from CyberEdge’s 2020 Cyberthreat Defense Report. In this webinar, we’ll: - Examine disturbing ransomware trends, by country and by industry - Postulate why more organizations are paying ransoms - Underscore the importance of investing in your company’s “human firewall” - Review technologies to help give security teams the upper hand

2020/9/29
阅读更多

Chronicle 3:Detect Everything: Bringing Google Scale Threat Detection to the SOC

Skillful threat detection and investigation starts with a diverse hub of security telemetry to draw from. The Chronicle platform allows security teams to cost effectively store and analyze petabytes of security data in one place and perform investigations in seconds. Now, Chronicle brings Google-scale threat analysis to your SOC with the debut of its detection engine, Chronicle Detect, fully equipped with ATT&CK reference rules, an integrated detection-based rules language, and intelligence from Chronicle’s elite threat research team. In this webcast, we’ll examine what’s new in Chronicle and see the detection engine in action with a live demo.

2020/9/28
阅读更多

Blackberry #3: Preparing for the Future of Work

Part three will examine how a Zero Trust security strategy built on AI-based security technologies could better prepare you to face the modern threat landscape. We will walk through some current, pervasive threats to gain a better understanding of why and how the unique features of AI-driven technologies are better suited to prevent, detect, and respond to them.

2020/9/25
阅读更多

Blackberry #2: Combating Cyber Chaos with Unified Endpoint Security

In Part two, we’ll discuss strategies for securing remote workers using Zero Trust. As millions of us have grown accustomed to and continue working from home, the delineation between work and home has become increasingly porous. Devices – no matter the environment in which they are situated – must be secure without any performance trade-offs. We will explore how emerging solutions like continuous authentication and unified endpoint security that leverage AI, machine learning, and automation could play a critical role in deploying a robust Zero Trust security framework to secure all devices – anytime, anywhere.

2020/9/25
阅读更多

Blackberry #1: Zero Trust Framework: What’s the Best Approach to Implement It?

In this first part, we’ll explore the important preliminary questions about whether Zero Trust should be a priority for your organization and provides guidance on defining trusted users and devices, and how to integrate identity and network. It will address how to build a business case for Zero Trust, addressing business drivers such as cloud environments and business continuity needs.

2020/9/25
阅读更多

Darktrace #1: Securing the New Normal: Cyber AI for Email

The future of work remains unpredictable and uncertain. More than ever before, business leaders need to remain confident that their operations can continue securely. However, 94% of cyber-threats still originate in the inbox, and ‘Impersonation attacks’ that expertly mimic the writing style of trusted contacts and colleagues are on the rise. Humans can no longer distinguish real from fake on their own – businesses are increasingly turning to AI to distinguish friend from foe and fight back with autonomous response. . Join Darktrace and (ISC)² on September 24, 2020, at 1:00 p.m. Eastern for expert insight into how cyber AI is the only tool that can keep pace with the rapidly evolving threat landscape facing organization’s inboxes every day. The webcast will examine: · Exploration of the most recent email threat trends and statistics · Overview of Darktrace’s latest developments to secure the email environments of the dynamic workforce · Case studies and use cases from industry leading customers

2020/9/24
阅读更多

Gigamon #3: Network Visibility in Today’s Complex World

Having visibility into your network, what’s on it and how it’s preforming, is critical to any sized organization. The use of network monitoring tools like SPAN and TAP can certainly help, as can Network Aggregation and Packet Brokers. Join Gigamon and (ISC)2 on September 15, 2020 at 1:00 p.m. Eastern as we dive into visibility topics such as Data Deduplication, Slicing, Masking, TLS Decryption, Inline and Out of band… and more. We’ll even include Virtual Environments and Cloud to make it even more interesting.

2020/9/15
阅读更多

How to Build and Govern a Multi-cloud Strategy that Accelerates Innovation

More than 70% of enterprises today are multi-cloud, either through organic growth, through mergers and acquisitions, or as a corporate strategy. While cloud is a powerful opportunity to unleash innovation within the enterprise, IT and security teams must then devise governance strategies to support that innovation. Join DivvyCloud and (ISC)2 to hear about some real-world experiences, a top 10 list of governance starting points and key takeaways that include: · Top 3 mistakes made in multi-cloud governance · A set of related resources, including industry reports on the state of cloud, cloud misconfiguration security and more

2020/9/4
阅读更多

Chronicle #1 Modernizing Threat Investigation & Decreasing Infrastructure Spend

SOC operations are impaired by security tools that are ineffective in detecting and triaging modern threats and also carry a high TCO burden. Most of these products, including legacy SIEMs, were built to analyze terabytes rather than exabytes of telemetry. However, a new generation of security analytics solutions is emerging to solve exactly these problems, bringing together the scale, performance, economic model and analytical capabilities needed to protect against today’s threats. Join Google Cloud Security and (ISC) 2 for an examination of threat investigation and how to cut costs associated with this critical operation.

2020/9/1
阅读更多

Imperva #3: How to Protect Your Data in the Cloud

The cloud is a popular destination for companies of all sizes. As companies plan their migration to the cloud, there is pressure to use database services from public cloud vendors. What are the compliance and visibility requirements and what does a secure cloud data deployment looks like. Join Imperva and (ISC)2 on August 27, 2020 at 1:00PM Eastern for a discussion on protecting data in the cloud and how to deploy securely and quickly.

2020/8/27
阅读更多

Think Outside the Box: Mitigating the IT Security Skills Shortage

Nearly nine in 10 organizations are experiencing a shortfall of skilled IT security personnel, according to CyberEdge’s 2020 Cyberthreat Defense Report. That’s up from eight in 10 organizations just two years ago. This weighs heavily on the minds of IT security professionals as ‘lack of skilled personnel’ is rated as the #1 inhibitor to successfully defending against cyberthreats. So, what can organizations do to mitigate the effects of this crisis? Well, if you’re willing to ‘think outside the box,’ there is hope. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Examines the shortage of IT security personnel by job role - Proposes creative ways for recruiting new security talent - Suggests clever ways for retaining the talent you already have - Identifies technologies that enable security teams to do more with less

2020/8/25
阅读更多

Gigamon #2: What Zero Trust Networking Means for Network Visibility

There is much talk in the Industry with regards to Zero Trust Networking (ZTN) - but what does it involve and what does this mean for Network Visibility? In this Webinar we will explore the reason for ZTN, some of the current ideas surrounding the implementations of ZTN and where Network Visibility plays a key role in securing such environments. With one of the key concepts of ZTN being the encryption and authentication of data in motion, we will also discuss the need for Metadata and why this can be an advantage over traditional methods of monitoring. Join Gigamon and (ISC)2 on August 13, 2020 at 1:00PM Eastern for an examination of: - Understanding the ZTN trust model at a high level - See which components are important within ZTN and why - Understand why the perimeter is changing and why the need for segementation goes beyond physical devices - How Metadata can play a key role in understanding the activity of applications on your network

2020/8/13
阅读更多

Gigamon #1 - Here Be Dragons: The Double-Edged Sword That is TLS

TLS is becoming ubiquitous, but it’s a double-edged sword. On the one side, organizations can mitigate risk vectors using this protocol. On the flipside is the misuse of TLS by threat actors trying to hide their activities and prevent your security monitoring infrastructure from detecting their activities. How do you benefit from TLS, but avoid the risks? Is decrypting everything the right approach? And if so, where? What about non-decrypting approaches to threat detection, like JA3? TLS 1.3 was a significant change, what do I need to know about it? Join Gigamon and (ISC)2 on Thursday, July 30, 2020 at 1:00PM Eastern to get answers to these questions and more.

2020/7/30
阅读更多

The 'Hottest' IT Security Technologies in 2020

Want to know which IT security technologies are hot and which ones are not? 2020 has thrown many purchasing and deployment plans into a state of flux and your organization has probably been caught up in this. Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP) and (ISC)2 on Tuesday, July 28, 2020 at 1:00PM Eastern as Steve reviews key purchase insights from the 2020 Cyberthreat Defense Report. Specifically, this webcast will examine which security technologies are most widely deployed and most planned for acquisition in 2020 so you can benchmark your company’s current and planned investments against your peers. Purchase intent across five key security technology categories will be focused on including: •Network security •Endpoint security •Application and data security •Security management and operations •Identity and access management

2020/7/28
阅读更多

Imperva #2: Application Security as the Business Transforms

As transformations continue at breakneck speeds, how are these changes impacting security? Specifically, applications are being written in new ways and deployed across clouds. How do you maintain consistent app security in a way that enables agility and speed of deployment? Join Imperva and (ISC)2 on July 9, 2020 at 1:00PM Eastern for a discussion on applications and their addition to the computing infrastructure is impacting organizations both small and large.

2020/7/9
阅读更多

Do's and Don’ts for Business Email Compromise (BEC) & Email Account Compromise

The financial losses associated with Business Email Compromise (BEC) and Email Account Compromise (EAC) continue to rise. The FBI reported losses of almost $1.7B in 2019 alone. While BEC and EAC start to become one of CISO’s top concerns, there are still a lot of confusion regarding the terms. In addition, many organizations are struggling to identify the scope of the problem regarding BEC/EAC. So how can you better manage this billion-dollar problem in your organization? Join Proofpoint and (ISC)2 for a deep dive into how best manage the BEC and EAC issues and problems they can bring. We’ll discuss: - What is BEC and EAC - What do they have in common and how are they different - Why is it difficult to prevent BEC/EAC - What are the best practices to help you mitigate BEC/EAC risks

2020/6/30
阅读更多

Approaching Application Security in the Enterprise

A significant percentage of data breaches in the last year came as a result of the targeting of web applications. ‘Software’ continues to eat the world, but not all of the code behind it is being constructed in conditions that ensure security. DevSecOps is oft talked about, but what does implementation mean from a practical standpoint? What’s really meant by ‘shift left’? Join Daniel Kennedy, Senior Analyst for 451 Alliance and (ISC)² on June 30, 2020 at 1:00PM Eastern for a discussion drawing on multiple years of peer market intelligence around application security, including tool usage within enterprises. We’ll examine what challenges emerge as security and development share responsibility for ensuring application security, and how can the needs of each be met.

2020/6/30
阅读更多

Imperva #1: How Automated Attacks Can Derail Your Company’s Business

You are a security professional. The world is changing - there are transformation initiatives being accelerated across your company - What are they, what is the impact on security and how can you ensure that a consistent security profile is maintained as your business transforms? Transformation is driving your company to engage with customers and partners in new ways, but automated attacks can steal your revenue and kill your business. How can the security team stop that happening? Join Imperva and (ISC)2 on June 18, 2020 at 1:00PM Eastern for a discussion on the processes and tools which will help to enable key transformation initiatives while protecting the integrity and security of your company.

2020/6/18
阅读更多

PerimeterX #3: Limiting the Damages Resulting from Carding Bots

Stolen payment card information usually needs to be validated before they can be used to run larger fraudulent transactions or be sold on the black market. Typically, automated bots run these tests or validation through smaller websites that lack anti-bot defenses. Join PerimeterX and (ISC)2 on June 4, 2020 at 1:00PM Eastern as we discuss how to detect and stop fraudulent transactions originating from carding bots and save thousands of dollars in payment processing charges. We’ll also cover : ● Carding attacks from the wild ● How carding attacks evade detection ● Trends leading into the holiday season

2020/6/4
阅读更多

Axonius #3: Navigating the Coming IoT Asset Visibility Gap

As IT complexity increases at organizations, gaining visibility into a comprehensive asset inventory becomes progressively difficult for information security teams. The convergence of three trends account for this new era of complexity: the increase in the number and types of devices, rapid public cloud adoption, and the looming IoT explosion. Axonius commissioned a research survey with Enterprise Strategy Group (ESG) to uncover what kinds of visibility gaps, challenges, and strategies are top of mind for information security professionals. Join Axonius and (ISC)2 on May 21, 2020 at 1:00PM Eastern for the third of three webinars focusing on the looming and inevitable IoT explosion. By some reports, there will be 500 billion connected devices by 2030 (Cisco). Organizations are most concerned about visibility into the volume and diversity of devices. Webinar attendees will learn: • Detailed research findings on the looming IoT explosion, visibility challenges, and security implications • An understanding of the key asset inventory challenges and how organizations are addressing these issues • Best practices when implementing and improving an asset inventory process • Emerging innovations and approaches to continuous asset discovery and automation

2020/5/21
阅读更多

Keysight 3: SD-WAN & CDN – Performance & Security of Highly Distributed Networks

The beauty of the internet is that when users access content, they don’t actually care about the exact physical location of the “hardware” that is ultimately fetching the information. Users primarily care about how quickly they can get the information and how secure they are while doing it. To ensure business continuity, organizations deploy highly distributed but interconnected networks to ensure faster and efficient internet delivery. This webinar highlights some of the challenges you face while deploying distributed infrastructure and validation solutions to ensure high performance and security. - Overview of technologies like software-defined wide area network (SD-WAN) and contend delivery network (CDN) that leverage distributed topologies - Common challenges of deploying such technologies - Performance and security issues during deployment and post deployment of distributed networks

2020/5/20
阅读更多

Key Insights from CyberEdge’s 2020 Cyberthreat Defense Report

Did you know that 81% of organizations reported that they suffered a successful cyber-attack in 2019? CyberEdge’s 2020 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. The 2020 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 12, 2020 at 1:00PM Eastern for highlights of the results and get key insights including: A record 62% of organizations were compromised by ransomware last year 58% of ransomware victims paid ransoms last year, but a third failed to recover their encrypted data Malware, spear-phishing, and ransomware cause the most headaches while zero-day attacks are of least concern Lack of skilled personnel and low employee awareness inhibit IT security’s success 85% of organizations are experiencing a shortfall of skilled IT security personnel

2020/5/12
阅读更多

Keysight #2: Increase Protection and Performance of Web Applications

Organizations across the world rely heavily on customer-facing and enterprise web applications to conduct their day-to-day business operations. It is mission-critical to ensure legitimate users are able to access these applications unhindered while malicious actors are kept at bay. This has become even more complicated since web apps have grown from just a few business apps to a multitude of backend web apps, mobile apps, SaaS apps, and other cloud-delivered solutions — all while the number and diversity of threats targeted at web applications continues to increase. Web application firewalls (WAFs) are generally tasked to protect modern websites and applications, but many times policies are based on performance rather than a known risk level. In this webinar we will discuss the following: 1) Techniques to discover security loopholes in existing WAFs that hackers may exploit 2) Continuous validation and remediations that not just help close existing loopholes, but also identify new ones as they arise 3) Performance benchmarking that ensures the WAF continues to deliver expected performance while increasing its security efficacies

2020/5/7
阅读更多

PerimeterX #2: Protecting Your Brand from Rising ATO Attacks

Account Takeover (ATO) attacks are on the rise. Not only are they hard to detect, they have consequences far beyond compromised PII and stolen goods. Stopping such ATO attacks is critical for any company engaged in online commerce. Join PerimeterX and (ISC)2 on May 7, 2020 at 1:00PM Eastern time as we highlight the top five ways to identify automated bot attacks to your website. We’ll cover: ● Real use cases - attacks that happened in the real world ● Practical strategies for identifying automated attacks ● Best practices for addressing and blocking bot attacks ● ATO attack trends during COVID19 pandemic

2020/5/7
阅读更多

Keysight #1: Going on the Offensive: Protecting Your Network w/ Threat Intell.

When you hear the words "Threat Intelligence", what's the first thing that comes to mind? Back end research? Threat Hunting? It's easy to categorize threat intelligence as a reactive tool - best suited for things like root-cause analysis - but it's so much more than that. In the first part of a three part series presented by Keysight, we'll explore an array of practical applications for threat intelligence, including traditional defensive strategies and new offensive strategies that will help you maximize your SecOps team. •Join us to discover how applying threat intelligence can help you: •Answer the question "Am I more secure today than I was yesterday?" •Improve the efficiency and effectiveness of Breach and Attack Simulation tools •Reduce your attack surface by blocking the latest threats •Prevent DDoS attacks and improve performance with pre-deployment testing •Maximize your threat hunting capability with real-time insights into botnets, phishing, etc. •Stay ahead of attackers by researching the latest attack signatures

2020/4/27
阅读更多

Axonius #2: Navigating the Cloud Asset Visibility Gap

As IT complexity increases at organizations, gaining visibility into a comprehensive asset inventory becomes progressively difficult for information security teams. The convergence of three trends account for this new era of complexity: the increase in the number and types of devices, rapid public cloud adoption, and the looming IoT explosion. Axonius commissioned a research survey with Enterprise Strategy Group (ESG) to uncover what kinds of visibility gaps, challenges, and strategies are top of mind for information security professionals. Join Axonius and (ISC)2 on April 23, 2020 at 1:00PM Eastern for the second of three webinars that will focus on rapid cloud adoption. We have surpassed the Cloud Tipping Point with more than half of all virtual machines (VMs) residing in the cloud and container usage becoming mainstream. Organizations are struggling to solve cloud asset visibility challenges and the resulting security incidents as expected growth adds further complexity. We’ll examine · Detailed research findings on cloud adoption, visibility challenges, and security implications · An understanding of the key asset inventory challenges and how organizations are addressing these issues · Best practices when implementing and improving an asset inventory process · Emerging innovations and approaches to continuous asset discovery and automation

2020/4/23
阅读更多

PerimeterX #1: Magecart Attacks and How to Defend Against Them

Targeting online shopping cart systems, Magecart attacks steal customer payment information via insertion of a malicious piece of Javascript code. This code-injection exploit can leave businesses exposed to digital skimming, data theft, compliance penalties, and brand damage. But how do these attacks actually happen and how does one mitigate them? Join PerimeterX and (ISC)² on April 9, 2020 at 1:00PM Eastern for a discussion on Magecart attacks and see a live simulation of a Magecart attack. You will also learn about: ● Methods and tricks used to compromise websites ● Data exfiltration mechanisms used by malicious scripts ● Detection techniques and their limitations

2020/4/9
阅读更多

Axonius #1: Navigating the Asset Inventory Visibility Gap

As IT complexity increases at organizations, gaining visibility into a comprehensive asset inventory becomes progressively difficult for information security teams. The convergence of three trends have resulted in a new era of complexity: the increase in the number and types of devices, rapid public cloud adoption, and the looming IoT explosion. Axonius commissioned a research survey with Enterprise Strategy Group (ESG) to uncover what kinds of visibility gaps, challenges, and strategies are top of mind for information security professionals. Join Axonius and (ISC)² March 26, 2020 at 1:00PM Eastern for a discussion on the explosion of the number devices in an enterprise and how to keep them accounted for and secure. Areas to be covered include: -Detailed research findings on device adoption, solution deployment, and time to inventory -An understanding of the key asset inventory challenges and how organizations are addressing these issues -Best practices when implementing and improving an asset inventory process -Emerging innovations and approaches to continuous asset discovery and automation

2020/3/26
阅读更多

Using AI to Improve Detection, Prevention & Response

Legacy, signature-based AV isn’t working. It is ineffective in stopping ransomware and zero-day attacks and creates a burden on your staff between patching, updating, reimaging systems, and overall impact to endpoint performance. As former NSA Director Admiral Michael Rogers said, “Without Artificial Intelligence, Cyber ‘is a losing strategy.” AI is all around us, and everyone is claiming to use it, but not all AI is created equal. With 70% of all attacks beginning on the endpoint, with the right AI in place organizations can move to a prevention first approach to end point security. Join BlackBerry Cylance and (ISC)2 on Thursday, January 9, 2020 for our first Security Briefing of the year where we will discuss AI-tools that can provide powerful detection, prevention and response capabilities.

2020/1/9
阅读更多

Netskope #3: Anatomy of a Cloud Data Breach

Cloud adoption is exploding with nearly 1,300 cloud apps in use in an average enterprise. From suites like Office 365 to collaboration tools like Slack, the cloud has enabled new levels of productivity resulting in enterprises gaining strategic advantages. Enterprises are not the only ones benefitting from cloud adoption. Bad actors are using the cloud to bypass legacy defense mechanisms and harvest credentials, deliver malicious payloads, and steal data. In this webcast, we’ll examine a few recent cloud data breaches and dissect how these breaches occurred and best practices to reduce the chance it will happen to your organization. We will dive into new attack scenarios that involve using the cloud to bypass traditional security tools, how the cloud-enabled kill chain forces a rethinking of how to defend against threats such as phishing and data exfiltration and 5 steps to protect against cloud threats.

2019/12/20
阅读更多

Infoblox #3: Stop Attacks Faster - Using the MITRE ATT&CK Framework

The MITRE ATT&CK Framework is a comprehensive, up-to-date knowledge base of cyberattacker tactics and techniques gathered from actual observation of attacker behavior. The framework can help anticipate what an attacker will do and how to respond. Join Infoblox and (ISC)2 on December 12, 2019 at 1:00PM Eastern for an examination of how the MITRE ATT&CK can help you make better, faster decisions about assessing risks, deploying new security controls and stopping attacks faster and more efficiently.

2019/12/12
阅读更多

Netskope #1: A Blueprint for Designing a New Security Perimeter

Recent research shows that more than 85% of web traffic is comprised of cloud services. The rapid adoption of cloud and mobile is fundamentally changing network traffic patterns and the movement of data, rendering existing network and security models obsolete. This shift is resulting in enterprise security teams supplementing next-gen firewalls (NGFWs), secure web gateways (SWGs), and VPNs with cloud access security brokers (CASBs). While CASBs address a key set of cloud-specific use cases tied to visibility, data security, compliance, and threat protection, your dissolving corporate perimeter is also forcing security teams to rethink their entire legacy security stack. After all, if most of your web traffic is comprised of cloud services, why does most of your security spend on security tools that are not effective in this new world? Join Netskope for Part 1 of this 3-part series to discover new blind spots that exist with legacy security tools, why simply moving legacy security tools to the cloud is not enough, top cloud security use cases driving the need for a new perimeter and the essential requirements for a new, more effective perimeter.

2019/12/10
阅读更多

Netskope #2: State of Cloud and Threats

The many stages of cyber kill chains are leveraging cloud services in new ways to evade legacy web and email defenses. These trusted domains with valid certificates are a quick path using implicit trust for success. Inline defenses need to understand cloud service account instances, activity, and data to prevent these cloud-enabled threats while enabling business unit and user freedom to adopt cloud services for digital transformation. In Part 2 of this series from Netskope, we’ll examine the average use of cloud services per company, why so few cloud services are managed by IT, what the key indicators are signaling this change, examples of cloud-enabled threats and kill chain stages and what defense updates you should consider to prevent and detect.

2019/12/5
阅读更多

Keysight #3 - Don’t be a Victim of the Breach: Embrace the Hacker Within & Win!

The hackers have automated their attacks, which gives them quite an upper hand. You, on the other hand, work at the pace and capability of your team and have to trust the products you’ve installed to defend your network. It’s time you utilize Breach and Attack Simulation and the emerging method of safely automating example attacks being used by the hackers to assess your deployed products, processes, and people. In this webcast you’ll learn how to hack yourself now and gain a new level of insight that will prepare you unlike ever before. We will examine what breach and attack simulation is, how automation and continuous assessment can show the current state of your defenses and how to find existing gaps in your security posture.

2019/11/22
阅读更多

Bitsight #3 - Experiences in Optimizing Third-Party Risk Management Programs

When it comes to managing third-party risk, there are different stages on the road to maturity. Many organizations today have a good program in place, but often run into issues with growing and optimizing their program in a scalable way. True optimization requires a confluence of process, policy, automation and cross-functional collaboration with other business leaders. With so many areas to focus on, it can be difficult to know where to even start. Fortunately, there are plenty of examples of companies that have successfully scaled their TPRM programs and offer valuable lessons for those looking to take their program to the next level. Join this discussion on managing third-party risk management to hear about these approaches and lessons learned.

2019/11/18
阅读更多

Keysight #2 - Six Steps to Optimize Defensive Security

The number of exposed consumer records more than doubled in 2018 from 2017, according to the Identity Theft Resource Center, but enterprises don’t have to be a victim. Most attacks can be prevented by deploying the right mixture of products and processes. The primary goal is to coordinate and optimize your security defenses. A simple, but coordinated, security defense strategy allows you to: • Validate equipment readiness • Prevent access from bad IP addresses • Decrypt malicious traffic • Analyze traffic in real-time • Perform advanced data analytics • Enable DPI In this webcast, Keysight and (ISC)2 will explore an overview of defensive security, a six step approach to defensive security and examples of visibility and security solutions that make this approach work.

2019/11/15
阅读更多

Infoblox #2: Threat Intelligence Update - Ransomware Tools Continue to Increase

Ransomware continues to be a widespread problem for organizations. Defending against such attacks are paramount for security teams at businesses small and large. Join Infoblox and (ISC)² on November 7, 2019 at 1:00PM Eastern and hear about the latest information concerning many of the leading ransomware threats, as well as updates on the state of the global ransomware assault and overall trends in developing and designing ransomware malware tools. Additionally, there will be details of original research on malware variants to include Shade, Sodinokibi, Megacortex, Cryptomix, Ryuk, Keypass, Hermes and Grandcrab.

2019/11/7
阅读更多

Keysight #1 - Best Practices for Security Resilience

It’s not a question of IF your network will be breached, but WHEN. News broadcasts for the last several years have shown that most enterprise networks will be hacked at some point. In addition, the time it takes for most IT departments to notice the intrusion usually takes months—over six months according to the Ponemon Institute. This gives hackers plenty of time to find what they want and exfiltrate whatever information they want. There are some clear things that you can do to minimize your corporate risk and the potential costs of a breach. One new approach is to create a resilient security architecture model. The intent of this model is to create a solution that gets the network back up and running after a breach has occurred, as fast as possible. While prevention should always be a key security architecture goal, a resilient architecture goal focusses on recognizing the breach, investigating the breach, and then remediating the damage as quickly as possible. Join Keysight and (ISC)2 for an examination of what network security resilience is, the benefits of such and examples of the visibility and security solutions that can be implemented to reduce the time to remediation.

2019/11/5
阅读更多

Infoblox #1 - Get Encrypted! Examining Emerging DNS Privacy Standard

DNS has always seemed to have a “last mile” security issue. Communications from a local DNS served to a client are typically unencrypted and not secure, leaving this traffic vulnerable to spoofing, hijacking and more. But privacy standards and protocols are emerging which are helping to encrypt this traffic. Join Infoblox and (ISC)2 on October 3, 2019 at 1:00PM Eastern for an examination of DNS over TLS (DoT) and DNS over HTTPS (DoH). The discussion will include the pros and cons of the two protocols, what option might make sense for your security & risk requirements and simple ways to secure your network and DNS.

2019/10/3
阅读更多

Un día en la vida de un CISSP

Más de 130.000 profesionales de la seguridad de la información han invertido tiempo, determinación y recursos para lograr la certificación CISSP. Únase a (ISC)² miembros de diferentes regiones de América Latina para saber cómo la certificación CISSP les ha ayudado con su trabajo y carrera y quales los puntos de dolor, problemas y desafíos que encuentran en su vida laboral diaria, así como soluciones, consejos y mejores prácticas que han desarrollado a lo largo del camino.

2019/9/27
阅读更多

2019 Security Congress Preview – Security Automation

(ISC)² will hold its 2019 Security Congress in Orlando, Fl Oct 28th – 30th. This conference will bring together a global community of cybersecurity professionals and more than 180 educational sessions. One of the 18 tracks at the conference will focus on Security Automation and the role that Machine Learning and Artificial Intelligence is playing in securing organizations of all sizes. On September 24, 2019 at 1 p.m. Eastern, join (ISC)² and several speakers who’ll be presenting in the Security Automation track on the Impact of Machine Learning on Cyber Security and Ethical Bias in AI-Based Security Systems as they preview their sessions and discuss why security automation is a leading concern for cyber security practitioners to understand.

2019/9/24
阅读更多

(ISC)²’s Digital Transformation Journey – Part 3

(ISC)² recently completed our multi-year Digital End-to-End Transformation (DETE) project, which positions us to deliver a more a seamless and user-friendly experience to all members. In addition to revamping our online presence, we launched a new Learning Management Systems where members can access all the courses developed by our Professional Development Institute. In Part 3 of the (ISC)² Digital End-to-End Transformation (DETE) webcast, we will examine the “new world” of what the project has provided to internal (how we serve the members and visitors), the members (what you as members see and experience) and what’s to come. Join Wes Simpson, COO and Bruce Beam, CIO on September 17, 2019 at 1:00PM Eastern for a discussion on these items and a Q&A with our COO and CIO.

2019/9/17
阅读更多

Gigamon #3: Network Traffic Decryption: Keeping Secure in a Private World

Today’s network environment can feel like a Cold War-era novel, full of who’s watching whom scenarios and heavily protected intelligence communications. Visibility is critical to an organization’s security posture, and encrypted channel communications can become an obstacle to it when gets to the wrong eyes. Decryption can illuminate what is hidden and restores the advantage you need to see what’s lurking in the shadows. Join Gigamon and (ISC)2 on September 5, 2019 at 1PM Eastern for an examination of decryption best practices, a review of encryption methodologies, the obstacles that impact security, resources and regulatory compliance and what’s changed with TLS 1.3 and how this newer protocol impacts visibility.

2019/9/5
阅读更多

Bitsight #1: How to Set a Solid Foundation for Your Third-Party Risk Management

As companies grow, so do their third-party digital ecosystems. This is hardly a new phenomenon, but the dynamic changes and rapid growth often experienced today have made it increasingly difficult for companies to stay on top of their multiplying business relationships. Today, organizations are looking for best practices on how to handle this from a cybersecurity perspective. Given that there are multiple frameworks, approaches, and guidelines, it is hard to figure out which best practices will meet the needs of your organization. In Part 1 of this series, we’ll discuss frameworks, policies, and process to build a successful third-party risk management program; typical roles and responsibilities found in programs across companies of all sizes and best practices for third-party governance and program sponsorship.

2019/8/27
阅读更多

Bitsight #2: Best Practices to Grow Your Third-Party Risk Management Program

So you’ve established the foundation of your third-party risk management (TPRM) program...now what? For many organizations, growing their TPRM program to scale at the speed of their business can be extremely challenging. This challenge is exacerbated because, in many cases, third-party ecosystem growth occurs with little coordination or oversight. Furthermore, once they establish third-party relationships, companies may not implement centralized processes to continuously monitor and evaluate those relationships, including the cyber risks they may pose. In the second installment of this webinar series, we discuss tips on how to “go beyond” the foundation of third-party risk assessments and drill down further into your vendors’ security posture, best practices for TPRM process improvement, reporting, and dashboard use and how to leverage continuous monitoring to scale your TPRM program at the speed and growth of your business.

2019/8/22
阅读更多

Gigamon #2 - Unleash the Power of True Application Visibility

You know that metadata helps you separate signal from noise, reduce time-to-threat-detection and improve overall security efficacy. But did you know that application metadata helps you monitor user experience, troubleshoot problematic apps, understand “Shadow IT” usage and improve security posture within your organization? Join Gigamon and (ISC)² on August 22, 2019 at 1:00 PM Eastern as we discuss the growing need for application-aware network operations and how Gigamon Application Metadata Intelligence provides the deep application visibility needed to rapidly pinpoint performance bottlenecks and potential network security risks. You’ll see how next-gen network packet brokers enhance metadata with intelligence and insights from traffic flows and discover how to understand the performance and control of hundreds of critical apps.

2019/8/22
阅读更多

(ISC)²’s Digital Transformation Journey - Part 2

(ISC)² recently completed our multi-year Digital End-to-End Transformation (DETE) project, which positions us to deliver a more a seamless and user-friendly experience to all members. In addition to revamping our online presence, we launched a new Learning Management Systems where members can access all the courses developed by our Professional Development Institute. In Part 2 of the (ISC)² Digital End-to-End Transformation (DETE) will examine how (ISC)² executed the plan for the project, following the AGILE Project Management framework and the buy-in and support from other departments and stake holders within the organization. Additionally, there was board governance and oversight to contend with. Join Bruce Beam, CIO; Beth Paredes, Sr. Corporate Member Services Manager; and Sommer Hess, Director PMO, Quality and Training on August 20, 2019 at 1:00PM Eastern for a discussion on these items and the speed bumps that were run into on this project.

2019/8/20
阅读更多

2019 Security Congress Preview - Privacy

(ISC)² will hold its 2019 Security Congress in Orlando, Fl Oct 28th – 30th. This conference will bring together a global community of cybersecurity professionals and more than 180 educational sessions. One of the 18 tracks at the conference will focus on Privacy and the challenges organizations and practitioners face in this area. On Aug. 13, 2019 at 1 p.m. Eastern, join (ISC)² and several speakers who’ll be presenting in the Privacy track on GDPR, the role of AI in Privacy and the upcoming California Consumer Privacy Act (CCPA)  at Security Congress as they preview their sessions and discuss why privacy has coming a critical area for cyber security practitioners to understand.

2019/8/13
阅读更多

2019 Security Congress Preview – Cloud Security

(ISC)² will hold its Security Congress 2019 in Orlando, FL October 28th – 30th. This conference will bring together 3000+ attendees and over 180 educational sessions. One of the 18 tracks that are being offered with focus on Cloud Security and the challenges practitioners face when dealing with all things cloud related. On July 23, 2019 at 1:00PM Eastern, join (ISC)² and several of the speakers who’ll be presenting in the Cloud track as we preview their sessions, get an idea of what will be discussed and discuss the state of cloud security today.

2019/7/23
阅读更多

(ISC)²’s Digital Transformation Journey – Part 1

(ISC)² recently completed our multi-year Digital End-to-End Transformation (DETE) project, which positions us to deliver a more a seamless and user-friendly experience to all members. In addition to revamping our online presence, we launched a new Learning Management Systems where members can access all the courses developed by our Professional Development Institute. The road to DETE, however, took years of planning and execution as our team modernized our infrastructure and back-end systems, including migrating the majority of key systems to the cloud. In Part One of this series examining the journey the organization undertook, Bruce Beam, CIO, will discuss the rationale behind the initiative and steps taken to gain approval from the board of directors. Join us on July 16, 2019 at 1 p.m. Eastern as we begin this three-part, in-depth case study of how (ISC)² accomplished this ambitious project.

2019/7/16
阅读更多

Gigamon #1: Network Data Capture for Incident Response

Information security and incident response teams are often hampered by an inability to see what is happening on the network. That lack of visibility mean they cannot confidently detect threats or respond quickly and effectively. A new approach that consolidates fundamental network detection and response capabilities using enriched metadata collected from sensors in physical, virtual and cloud environments is helping security teams minimize mean-time-to-detection and response. How can you achieve accelerated threat detection and response through broad situational awareness fueled by real-time access to historical metadata? Join Gigamon and (ISC)2 on July 11, 2019 at 1PM Eastern as we dive into metadata’s critical role in incident detection and response strategies and how to best use metadata to focus incident response efforts through data correlation and enrichment.

2019/7/11
阅读更多

Chronicle #3: Backstory + VirusTotal: Scale, Speed & Intelligence Multiplied

Having access to new technology and intelligence to allow proactive response to the threats will change the way teams protect their environments. Harness the massive computing power of Backstory integrated with the powerful insights from VirusTotal to process petabytes worth of data in almost real-time. Watch a step-by-step demo of how Chronicle's security solutions, working with partners like Tenable, can help your organization be better prepared and connected for what comes onto your network.

2019/6/19
阅读更多

Gigamon #3 - Why Should I Care About SSL/TLS Decryption?

The August 2018 GAO Report on the Equifax breach disclosed that while they used a tool for network layer decryption, their certificates were nine months out of date. This lapse gave the threat actors the time they needed to break in and exfiltrate reams of personal data. Once the certs were updated on their decryption tools, they realized what happened. A lesson learned from this is the importance of efficient decryption for effective threat detection. Join Gigamon and (ISC)2 on June 6, 2019 at 1PM Eastern for a discussion about how SSL/TLS encryption has become a threat vector, why decryption is essential to security and how to effectively perform detection and how to make sure your detection tools are working at their greatest capacity without the latency introduced by decryption.

2019/6/6
阅读更多

Chronicle #2: Better Threat Hunting and Investigation with VirusTotal

Get a deeper look into malware campaigns using VirusTotal's newest tools. Learn from the expert how to use the platform and how best to leverage the data available to you and your security team. By better understanding the breadth and depth of malicious campaigns, researchers can better investigate and mitigate impact. Recently introduced improved relational metadata as well as expanded retroactive and proactive hunting capabilities allow investigators to dive deep into malware within a global data source.

2019/5/24
阅读更多

Migrating to the Cloud Safely & Securely - Imperva Part 3

Data capture, storage, and usage continues to grow at exponential rates. As a result, and in an effort to obtain operational efficiencies, many new organizations are “born in the cloud”, while for others, the migration of data and data driven business processes to cloud environments continues to escalate rapidly. The use of third party database and related cloud service offerings to support cloud and hybrid environments is also growing and evolving. However, security teams consistently report concerns with respect to the lack visibility and oversight of their data in the cloud. Typical questions being asked by CISOs are complex and not easy to answer. Join Imperva and (ISC)2 on May, 23, 2019 at 1:00PM Eastern for an examination of these questions and how to address them effectively.

2019/5/23
阅读更多

Gigamon #2: Application Visibility for Better Security Operations

Securing your infrastructure can sometimes feel like navigating a ship at night in a storm, with pirates attacking. An occasional flash of lightning allows a quick glimpse of the intruders, but you never really know when or from where the next attack is coming. What if you could illuminate the best path forward? A centralized platform gives you a single window with pervasive visibility into all network traffic – both north-south and east-west which allows improvement to the effectiveness and efficiency of all your security tools and better manage SSL decryption as well as NetFlow generation. Join Gigamon and (ISC)2 on May 2, 2019 at 1:00PM for a discussion on how to discover applications on your network you didn’t know where there, spotting potential security vulnerabilities before they become a problem and see a live demo of how you can optimize security and network performance.

2019/5/2
阅读更多

Buying Down Risk in the New World of App Development - Imperva Part 2

In this era of rapid modern application development, organizations often deploy code into production with critical vulnerabilities that often lead to exploitation by cybercriminals. These bad actors are on the look-out, scanning for vulnerabilities that will allow them to establish a silent foothold into your environment. Join Imperva and (ISC)2 on April 25, 2019 at 1:00PM Eastern and discover a defense in depth security strategy to protect your most valuable web applications and your business from damaging cyber-attacks.

2019/4/25
阅读更多

Chronicle #1: How Backstory Can Help Organizations Rethink Enterprise Security

Today, most security teams struggle to identify and locate threats in their networks. Without the ability to find the bad actors in the network, security teams are unable to be effective in their roles. Organizations need tools to link intelligence about threats in the wild, threats in your network, and understand unique signals from both. In this webcast, we’ll examine the latest trends and downfalls in this space, and how Chronicle, an Alphabet company, is looking to solve them at a global scale with a focus on speed and efficacy. We’ll also have a demo of the Chronicle security platform, Backstory and how it can help streamline your security.

2019/4/16
阅读更多

Gigamon #1: Network Upgrades Giving You Security Headaches?

As the insatiable demand for bandwidth drives the need for faster networks, organizations still need to inspect and enforce network security policies at wire speed. And that is particularly challenging when you are upgrading networks from 10GB to 40GB or from 40GB to 100GB. Join Gigamon and (ISC)2 on April 4, 2019 at 1:00PM Eastern as we discuss how to solve the security headaches that go with these network upgrades and new architectures that strengthen your security posture, simplify IT and reduce costs. We’ll also discuss how to increase your security ROI, reduce your security risk and improve threat response.

2019/4/4
阅读更多

Best Practices for Mitigating Data Breach Risk - Imperva Part 1

Data breach(es) remains atop the list of any CISO’s main concern. With the exponential growth of users, apps, and data, that leads to more and more legitimate data access, the attack surface expands making it harder to determine whether a data access is appropriate. Many organizations rely on traditional perimeter-based security approach, but they’re still getting breached. Additionally, trying to constrain and control the interactions between users and data by locking down usage can not only slow down business, but also frustrate users. Due to this, they may decide to work around you, creating an even bigger risk for your company. Join Imperva and (ISC)2 on March 28, 2019 at 1:00PM Eastern to learn about some best practices to mitigate data breach risk without decelerating your business growth.

2019/3/28
阅读更多

Infoblox #3: DNS….. One of the Best Weapons for Securing Networks?

Today’s sophisticated cybersecurity attacks often unfold in the blink of an eye. To respond quickly, your security teams need to see security incidents as they happen to ensure that attempts to hack your server environment are thwarted before entry into your machines. Whether detecting malware, helping to prevent and disrupt command and control communication, ransomware and phishing attacks – DNS can help with this and much more. But are you leveraging it as part of your cyber strategy? Nearly all threats use the DNS system therefore threats in your network can easily be seen in your DNS data. Join Infoblox and (ISC)2 on March 21, 2019 at 1:00PM Eastern as we bring in experts from IDC and ELEVI for a discussion on how leveraging DNS can help identify attacks as they happen or even prevent them before they happen, remediate attacks faster, and help detect and stop malware from spreading.

2019/3/21
阅读更多

Infoblox #2 - How to Integrate and Automate Your Security Response at Scale

Your enterprise network relies on a vast assortment of security devices and solutions, each generating their own alerts. More often than not, security teams don’t have the resources to address every one of them in a timely manner. According to a 2017 EGS report, keeping up with the enormous volume of security alerts and a lack of integration are the biggest network security challenges enterprise's face. Join Infoblox, their special guest Optiv and (ISC)2 on February 7, 2019 at 1:00PM Eastern , for a live discussion on how organizations can leverage ecosystem integrations to bridge islands of security, while automating incident response through automation and orchestration.

2019/2/7
阅读更多

Psychographics of the CISO – New Infosecurity Survey Results from 451 Research

Security budgets continue to tick upward, but underneath the hood, increasingly hybrid architectures in enterprise IT are driving shifts in where that money is applied. GDPR has driven compliance to the forefront of security project decision making, while other pain points including user behavior and lack of qualified personnel drive specific security product deployments. Security resistance to cloud continues to decrease, while the endpoint security space remains both relevant and increasingly crowded. Join Daniel Kennedy, Research Director for 451 Research on January 29, 2019 at 1:00PM Eastern as he walks through highlights of 451's 2018 surveys and interviews of information security professionals.

2019/1/29
阅读更多

Infoblox #1: Remediating Threats by Bridging Islands of Security

Most organizations have multiple products and services, from multiple vendors and suppliers to address their cybersecurity needs. The lack of integration and inability to share critical information results in silos of technology that cause inefficiency, lack of agility, limited visibility and a poor security posture. How can an organization solve and streamline this improve their cybersecurity operations? Join Infoblox and (ISC)2 on January 10, 2019 at 1:00PM Eastern for an examination of how Infoblox and Fortinet have joined together to assist organizations in improving their security operations and reducing time to containment.

2019/1/10
阅读更多

RSA #3 - Transforming Secure Access to be Intelligent

When it comes to making access decisions, it’s all about being smart. In the speed of today’s business agility requirements, we cannot stop users at the door all the time and ask for their ID. We need to know them. Intelligent Authentication provides the benefit of reducing friction AND adding security to protect applications and data that are critical to the business. It provides security and convenience, considering the needs of the modern workforce. In this session we will discuss a simple process to gain visibility into the right listening posts, derive actionable insights and then drive action to protect the organization’s most valuable assets from rogue access and drive Identity Assurance.

2018/12/7
阅读更多

RSA #2 - Transforming Secure Access to be Pervasive - 5 Ways to Transform Access

Ever heard the expression, “you can’t hit what you can’t see?” Well that sentiment rings true when it comes to protecting access to critical resources. You can only secure what you actually take steps to protect. .As such, secure access needs to be pervasive and cover all access user cases, regardless of whether applications and resources live on-premises or in the cloud. And because it’s likely have both, you need a solution that works equally well across these hybrid environments. In this session we will explore five critical secure access use cases, and how you can achieve a high-level of identity assurance that users are who that claim to be so that you can avoid falling victim to the next wave of credential-based attacks.

2018/11/30
阅读更多

PAM: The Critical Missing Piece in Your Security Strategy

Industry thought leaders have stated that if you can only tackle one project to improve the security of your organisation it should be Privileged Access Management (PAM). Our own research backs this up with the 2018 Privileged Access Threat Report revealing organizations using automated PAM technology experience far fewer serious breaches than those that did not. Karl Lankford, Lead Solutions Engineer EMEA at Bomgar will discuss what ‘privilege’ means to your business and how implementing a PAM solution can drive significant improvements across the organisation. You will learn: •Why organisations should make PAM their top 2019 investment •Why quickly controlling and automating key PAM capabilities is critical to your organisation’s success •Help you to prepare the business case for your PAM project and to get Executive Leadership buy in

2018/11/22
阅读更多

The Workforce Gap Widens: The Need to Focus on Skills Development

The 2018 (ISC)² Cybersecurity Workforce Study finds the cybersecurity skills shortage continues to grow. But the news isn’t all doom and gloom. Our latest deep dive into the issues and challenges facing cybersecurity professionals adopts a new approach to more broadly define the cybersecurity workforce. The study reveals a relatively satisfied, younger and more diverse field of practitioners focused on developing their skills and advancing their careers. Join (ISC)² Director of Cybersecurity Advocacy, North America, John McCumber On November 20, 2018 at 1:00PM Eastern as we examine how practitioners are dealing with the workforce gap while balancing skills development, hiring priorities and everyday threats they face.

2018/11/20
阅读更多

RSA #1 - Transforming Secure Access to be Convenient

The market demands for the modern approach to authentication is more like “Have it your way!” That’s why many of the approaches and offerings can only do one thing. Those apps will become obsolete or acquired as Access Management vendors will face the complex reality that enterprises who want modern authentication will also want access that’s convenient, intelligent and pervasive – not just 2FA or SSO. In this webinar, RSA will examine how to leverage a trusted, secure access platform that provides access to all users, to all apps from anywhere at any time in a smart, secure and noninvasive way.

2018/11/16
阅读更多

Gigamon 3 - Threat Hunting: Objectively Measuring Value

Someone in leadership always seems to ask the question “How can I tie my threat hunting activities to real impacts for the organization?” Threat hunting programs are encouraged as part of a mature and successful incident response capability and teams invest significant time and effort in the development and maintenance of that program. However, management is always looking for metrics to demonstrate the value of threat hunting in real terms due to the number of hours consumed by such highly skilled professionals. It’s a big investment. Join Gigamon on November 1, 2018 at 1:00PM Eastern for an examination of how to demonstrate value from threat hunting operations with practical methods and examples for tracking hunting operations, reporting and attributing outcomes to industry-leading frameworks and plot hunting goals and coverage across the MITRE ATT&CK framework.

2018/11/1
阅读更多

Has Your Network Packet Broker Evolved with Your Infrastructure?

As your infrastructure has grown to include a mix of physical, virtual and cloud environments with increased network speeds and volume of data, so have the threats increased to your attack surface with more vectors to breach your organization. This challenges your network and security operation teams and tour traditional network packet broker needs to evolve from providing network visibility to also helping strengthen your security posture. Join Gigamon and (ISC)2 on October 18, 2018 at 1:00PM Eastern where we will examine the acquisition and aggregation of data from your physical, virtual and cloud infrastructure, filtering of traffic to provide the right data to the right tools, transforming your data with masking, header stripping and SSL decryption (TLS1.3) to ensure compliance, threat prioritization by providing context and bridging the gap between NetOps and SecOps.

2018/10/18
阅读更多

Gemalto Part 3: Preparing for Quantum

We’ve all heard that quantum computers are coming; beyond being a boon for materials science they’re going to wreak havoc for cybersecurity. Part 3 of this series from Gemlato will outline the scope of the problem (it’s more than just algorithms) as well as the work required and being done to protect data through the upcoming transition.

2018/9/18
阅读更多

KnowBe4 #3: Secrets to a Successful Security Awareness Training Program

With 91% of data breaches being the result of human error, security leaders, auditors, and regulators increasingly recognize that a more intentional focus on the human side of security is critical to the protection of organizations. However, organizations have been struggling with and debating the effectiveness of traditional security awareness and training. KnowBe4 shares results-focused strategies and practical insights on how to build a world-class program

2018/9/7
阅读更多

KnowBe4 #2: How To Phish Like the Bad Guys

In spite of all the spectacular news stories about advanced persistent threats and targeted hacks from nation-states, the most common security challenge facing enterprises today continues to be social engineering. Successful hackers know the user is the weakest link in the security chain. Email phishing campaigns have proven to be the path of least resistance to get unsuspecting individuals to download and install their malicious software. Getting users to identify phishing attacks and training them not to click on links in email messages is not a trivial task. Join KnowBe4 as we discuss the strategies and techniques that social engineers are finding success with, how to implement these techniques and to create real-world simulated phishing email to test your employees and see how phish-prone they really are.

2018/9/6
阅读更多

Security Briefing: What’s So Hard About Securing Virtual Workloads?

As organizations build out their infrastructure across public, private and hybrid platforms, security architects need to extend their enterprise security policies and protocols to all workloads, no matter where they reside. Still, security operations teams are challenged with proactively detecting threats, deviations from organizational policies and violations of industry and organizational compliance for mission-critical applications in the cloud. Why is that? Join Gigamon and (ISC)2 on September 6, 2018 at 1:00PM Eastern where we’ll explore ways to assure compliance and decrease time to detect threats in mission-critical applications, reduce risk by leveraging a common platform across your entire IT environment and ensuring SLAs are met by tightly integrating the public cloud provider’s APIs and critical cloud provider services to automatically detect changes in virtual private clouds and virtual networks.

2018/9/6
阅读更多

KnowBe4 - Levers of Human Deception: Science & Methodology of Social Engineering

No matter how much security technology we purchase, we still face a fundamental security problem: people. People can be manipulated every day and in many ways; from the tactics used by car dealers, to sophisticated social engineering and online scams. Part 1 of KnowBe4’s 3 part series will This webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding and how to ethically use these same levers when educating users.

2018/9/4
阅读更多

Gemalto 2 - The EU’s General Data Protection Regulation (GDPR) - Myth to Action

The General Data Protection Regulation (GDPR) is the biggest overhaul of EU data protection law in more than 20 years. It’s not simply another regulation. It’s about accountability and it’s reshaping how organizations view and interpret privacy. Join us as we uncover the regulation, define a new lens and perspective to address not only the GDPR, but other regulations which are sure to follow. Understand the ecosystem and seamless integrated security solutions necessary to address these key privacy challenges. Whether you are looking for insight, guidance, or solutions to privacy, join in on this journey with GDPR as a guide to understanding and addressing privacy in today’s organizations.

2018/8/7
阅读更多

2018 Security Congress Preview – Cloud Security

(ISC)2 will hold its Security Congress 2018 in New Orleans, LA, October 8th – 10th. This conference will bring together 2000+ attendees and over 100 educational sessions. One of the 13 tracks that are being offered with focus on Cloud Security and challenges practitioners face when dealing with all things cloud. On July 24, 2018 at 1:00PM Eastern, join (ISC)2 and several of the speakers who’ll be presenting in the Cloud track as we preview their sessions, get an idea of what will be discussed and discuss the state of cloud security today.

2018/7/24
阅读更多

Gigamon Briefing Part 3 - Improving Security Using Metadata

Imagine what a security analyst could deduce if they had visibility into all the common applications flowing through their network. They could optimize the data being sent to security tools, correlate information across the various protocols to determine who is talking to whom and get visibility into malware and bad actors that may be hiding on the network. Many enterprises aggregate information from various sources, such as events and logs from DNS servers, web servers and security tools, to hunt for threat events and indicators of compromise. But these are not reliable sources; logging can be turned off inadvertently or for performance reasons. Raw network data is the ultimate source of truth – but sending it all to a SIEM can become very expensive. Join Gigamon and (ISC)2 on Thursday, June 28, 2018 at 1:00PM Eastern for a discussion on how visibility into your application traffic is elemental to security, how application metadata can provide context of potential threat events and to more easily enforce corporate compliance.

2018/6/28
阅读更多

Before You Choose Microsoft - 5 Things to Consider in an Access Mgmt Solution

Organizations with Microsoft environments, such as Azure or Office 365, are inclined to implement Microsoft’s native access management solutions (namely, Azure AD and AD FS). Defaulting to Microsoft’s cloud SSO solutions may appear to be the best choice, a closer examination of these solutions reveals critical downsides, as well. This Security Briefing will examine the five things to consider before implementing Microsoft’s access management solutions. You will also see a demo of how you can centrally define access management policies (including cloud SSO and step-up authentication) for Microsoft and 3rd party apps with a vendor agnostic-solution.

2018/6/13
阅读更多

Taming the Cloud Together – CCSP & CCSK Cloud Certification Synergy

Certain things go together to make the sum of their parts that much better. Peanut Butter and Jelly. Lennon and McCartney. Batman and Robin. In the ever-changing world of the cloud, cyber security professionals need continuous training and certifications to stay up-to-speed and pairing (ISC)2’s CCSP (Certified Cloud Security Professional) with CSA’s CCSK (Certificate of Cloud Security Knowledge) can put any cyber security practitioner ahead in terms of knowledge, skills and job opportunities. On June 12, 2018 at 1:00PM Eastern, join David Shearer, (ISC)2’s CEO and Jim Reavis, CSA’s CEO, along with other subject matter expects as we explore the differences between each program, the training options available for each, and how these programs are synergistic in nature and together were designed to build on one another.

2018/6/12
阅读更多

Organizational Dynamics of Information Security

Positioning Information Security within the enterprise presents its own set of challenges. Our recent survey data from hundreds of senior security and IT leaders like you uncovered a number of systemic security challenges – from skills shortages to retention strategies; not to mention responding to new challenges around cloud and IoT, and other organizational and operational issues. Join 451 Research and (ISC)2 on June 5, 2018 at 1:00PM Eastern as Research Director and former CISO Daniel Kennedy discusses this survey data and takes questions from the audience.

2018/6/5
阅读更多

Gigamon Part 2 - Threat Detection in TLS: The Good, Bad & Ugly

While TLS (formerly known as SSL) has become the de facto way of encrypting data in motion on networks, it can also hide threats from your InfoSec team. As the volume of encrypted traffic continues to grow, organizations become even more vulnerable to encrypted attacks, hidden command and control threats and data exfiltration exploits that go undetected. Making this situation even more complex, the TLS 1.3 draft 28 proposal, ratified at the IETF 101 conference in London and now moving toward official RFC status, has actually removed the visibility which was widely deployed for threat identification in TLS 1.2. On one hand, encryption is moving toward ubiquity but on the other, we need to detect when threat actors use it too. Join Gigamon and (ISC)2 on May 31, 2018 at 1PM Eastern where we’ll discuss the necessity of deploying TLS decryption in the core of networks and will explore innovative architectures that deliver that capability while maintaining availability and reliability.

2018/5/31
阅读更多

Gigamon Part 1: Using Inline Security Tools to Achieve Your Security Goals

Inline security tools operate by actively preventing threats in your network, but deploying and optimizing these tools presents several challenges to both network and security engineers. The downsides can include a potential point of failure, degradation of network and application performance, difficulty to scale and upgrade. The use of a next-generation packet broker and its inline bypass functionality can mitigate these challenges. Join Gigamon and (ISC)2 on April 26, 2018 at 1:00PM Eastern for Part One of a Security Briefings series where we will examine how inline bypass can overcome physical deployment obstacles, maximize network availability, increase the scale of inspection and reduce the impact to network performance.

2018/4/26
阅读更多

Imperva Part 3 - Hybrid Cloud – What it is & How Do You Secure It?

The advantages offered by a cloud-based environment makes it an easy decision for most companies to have apps and data both on-premises and in the cloud. Still, there are numerous critical choices to be made that can transform the complexities of the migration process into a relatively smooth transition—especially regarding application and data security. Join Imperva and (ISC)2 on April 5, 2018 at 1:00PM Eastern as we define the hybrid cloud and talk about best practices to secure your company assets as you start managing and securing them both on-premises and in the cloud.

2018/4/5
阅读更多

F5 (Pt. 3): The Rise of Bots: Top 5 Bot Driven Threats & How to Stop Them

Bots are now teetering on the edge of being the majority of traffic on the internet. It’s not all bad news, as there are plenty of useful bots that make both our work and personal lives more productive. However, malicious bot and botnet creators have introduced more sophistication into their bots, making them harder to detect, and the resulting threats are becoming more common place. Join F5 and (ISC)2 on March 29, 2018 at 1:00PM Eastern as data gathered from internal threat research teams is presented that explains how bots are being created, the top application threats driven by bots, and how to detect and better protect to your business.

2018/3/29
阅读更多

(ISC)2 Part 2 – Time’s Up! Ready or Not, Here Comes GDPR

In Part 1, we examined what GDPR is, what the requirements are and how organizations will be impacted. In Part 2, our panel will discuss more on the potential impacts of GDPR across a typical organization (including assessments, encryption, audit & controls and the impact to each department, from finance to marketing) and what the organization should be doing to plan for GDPR. Join (ISC)² on March 27, 2018 at 1:00PM Eastern, as (ISC)² discusses these topics and answers questions from the audience about this important and looming regulation.

2018/3/27
阅读更多

(ISC)2 Part 1 - Time’s Up! Ready or Not, Here Comes GDPR

May 25, 2018 is coming like a freight train. The General Data Protection Regulation (GDPR) goes into effect on that date, and organizations of all sizes (that collect data from EU residents) need to be ready for this new regulation. With the new regulation, the definition of personal data has been expanded and it applies to wherever data is sent, processed or stored. On March 13, 2018 at 1:00PM Eastern, (ISC)² kicks off the 1st part of the 2-part webcast where we will focus on what is GDPR, what the requirements are and how organizations will be impacted. Part 2 will expand on potential impacts and examine what organizations should be putting into their planning for GDPR.

2018/3/13
阅读更多

Imperva Part 2: Top Three Ways To Tackle API Security

Security is an essential element of any application and increasingly critical for API-driven architectures in hybrid and public cloud environments. New threats and vulnerabilities emerge constantly, and enterprises find themselves struggling to protect these APIs from attacks. Join Imperva and (ISC)2 for Part 2 of our Security Briefings series on March 8, 2018 at 1:00PM Eastern where we will discuss proven approaches to making API security a priority through understanding how common types of attacks such as distributed denial of service (DDoS) can target APIs, what are the steps to proactively secure development frameworks, and how to enforce identity across enterprise environments.

2018/3/8
阅读更多

IBM 2- Make Faster, Smarter Decisions about Insider Threats

Every second counts in the fight to prevent, detect and respond to an Insider Threat. You need to be able to make smarter, faster decisions when it comes to detecting suspicious behavior and preventing further damage. Join this webinar to learn about how you can properly secure access to your critical crown jewel data, automate the process of identifying risky users through user behavior analytics, and shutting down their access with identity governance. See how integration between security analytics and identity and access management tools provide automated, user-centric threat mitigation.

2018/3/2
阅读更多

IBM Security > Convenience? What 4K Users Taught Us about the Future of Identity

In a world powered by consumer choice, our authentication programs are only as effective as their adoption rates – by real, living-breathing, error-prone human beings. IBM recently conducted a research study of 4,000 adults called The Future of Identity, designed to examine what people around the world really think about various old and new methods of signing on (passwords/biometrics/multifactor authentication), what they’re using today, and what they plan to use in the future. Insights from the Future of Identity report have been covered around the world by publications like Politico, TechRepublic, and Engadget, and even featured on NBC's Today Show. Join IBM Security's authentication experts as we cover some never-before-seen data on the 'authentication adoption curve' and discuss practical guidance to put those insights into action.

2018/3/2
阅读更多

F5 (Pt. 2): The Hunt for IoT and it’s Threat to Modern Life

Our modern world depends on healthy, functioning, IoT devices. Unfortunately many of them are terribly insecure. Cyber attackers know this and have been aggressively compromising IoT devices for years. For the past two years, F5 Labs has been tracking cyber attackers as they hunt, infect, and build “Thingbots” - botnets made from IoT devices. This hunt has developed sizable thingbots like the infamous Mirai, and many others that have the capability to launch globally destructive attacks. These attacks can significantly impact modern life because of IoT’s presence within power systems, transportation systems, airport monitors, emergency warning systems, and security cameras. Join F5 and (ISC)2 on March 1, 2018 at 1:00PM Eastern for the 2nd Part of our three part Security Briefings series where we’ll explore the threat actors behind these attacks, the geographical targets of their attacks, how they are evolving their attack methods, and the types of devices impacted. We’ll include tips on how to start protecting yourself personally, and what you should be doing to protect your businesses.

2018/3/1
阅读更多

IBM Part 1: Demystifying Decentralized Identity

Today, the average internet user has lost control over their personal information, the result of endless requests to create accounts validated with personal data like SSN/home address/date of birth; and the persistence of hackers and ne’er-do-wells to compromise that data. Users are demanding simpler and more portable ways to manage their identities online, and organizations are joining the charge, as they look to reduce the cost, risk and liability of managing their own identity stores in siloes. A leader in blockchain and cybersecurity, IBM is one of many technology providers leading the movement toward Decentralized Identity systems that aim to put people back in control of their data. Join tech luminary and IBM CTO Dr. Sridhar Muppidi as we move past the buzzwords, exploring the basic terminology and adoption patterns of Decentralized Identity. Listeners will gain a deeper understanding of what it will take to make this vision a reality, and walk away with best practices to get started.

2018/2/23
阅读更多

Imperva Part 1 - March of the Bots: How to Deal with the Onslaught

Bots. They generate over half of the internet traffic and over half of the bots are malicious (or of questionable value). Bots can make your systems vulnerable to scraping bots, account takeover bots, impersonators, spammers and hackers. On February 8, 2018 at 1:00PM Eastern, Impreva will share data gathered from their security research team about the most recent bot trends, how bot traffic is changing, where it’s coming from, and the top actions you should be taking to mitigate the effects of bad bots on your websites. Join us for Part 1 of a 3 Part Security Briefings series and understand how commercial services take a multi-layer approach to bot mitigation and management and whether one of these services may be appropriate for you.

2018/2/8
阅读更多

F5 (Pt. 1): Don't Get Stung! Examining the OWASP Top 10 & Advanced WAF

Web application security is complex, difficult, and costly. These issues are well known, but remain prevalent out in the real world. Most development teams do not have the time or resources to sufficiently protect against the myriad of attacks that are relevant to each vector, while the level of expertise required to address these issues are difficult to come by even if your project has the time and budget for it. The good news is that advanced WAF technology is more accessible and affordable than ever before. With the right tools, comprehensive WAF coverage can not only reduce your exposures and give you better control over your applications but also help optimize your resources and reduce overall operating costs. Join F5 and (ISC)2 for Part 1 of a 3 part Security Briefings Series on February 1, 2018 at 1PM Eastern where we’ll discuss the OWASP Top 10, defenses for everything it addresses and how to use WAF to optimize and filter unwanted traffic to cut costs in the cloud.

2018/2/1
阅读更多

Briefings Part 2: Email at the root of problems? Cyber Resilience is the answer

Do you have a minute? 1 minute 40 seconds to be exact? That’s the median time-to-first-click in most phishing expeditions. While we celebrate all that humans can accomplish with the help of technology, we must also be cognizant of the dangers affiliated with humans and technology. How can you as a leader educate your people? How can you encourage them to take a minute to THINK before clicking? Join Mimecast and (ISC)2 as we explore how email is being used as entry point for multiple types of attacks, the negative impact these attacks have on organizations and how to enhance your email security and overall cyber resilience.

2017/12/1
阅读更多

Briefings Part 2: Effectively Exposing Hidden Threats and Malware

As the volume and variety of network data increases, security tools in high-speed networks are unable to keep pace with the explosion of encrypted threats, from malware incursion to data exfiltration. The standard approach of decryption of traffic by each security tool no longer works. Additionally, this approach can result in performance degradation, massive inefficiencies and unnecessary expenditures by security teams. In this webcast, we’ll examine how to eliminate tool overload and high latency as well as how a “decrypt once and inspect many” approach to managing SSL traffic effectively detects hidden threats and provides greater security infrastructure resiliency.

2017/11/28
阅读更多

Briefings Part 1 Using Metadata Generation to Supercharge your Incident Response

Managing the increasing volumes of network data across expanding physical, virtual and cloud networks is a growing challenge for Enterprise IT organizations. Likewise, the increase in malware, data breaches and ransomware challenges SecOps teams to build a stronger, scalable security posture while mitigating risk. This effort overloads network security, monitoring and analysis tools, as well as the Infosecurity staff. How can an organization access and utilize critical network information and use the metadata generated to turbo charge incident detection and response? In this webcast, we’ll examine how to reduce time-to-threat detection by analyzing metadata traffic, using proactive, real-time traffic monitoring vs. reactive forensics, to protect increasingly complex networks.

2017/11/27
阅读更多

Briefings Part 3: Extending Your Security Posture to the Public Cloud

Organizations continue to move to the public cloud in large numbers, but they often do not understand the implications of the shared responsibility model. The question is: “who is responsible for security of the cloud versus security in the cloud”? This webcast will address this question, look at SLAs for mission-critical workflows to the cloud, as well as how to assure compliance and accelerate the on-boarding of critical applications.

2017/11/21
阅读更多

IBM Part 2 - How Government Agencies Can Harness the power of A. I.

With the eruption of connected devices and the Internet of Things, cybersecurity professionals have a lot on their plates. More connected devices equates to more traffic, more attack routes, more attempts at cybersecurity breaches, and a lot more data that needs to be analyzed. As the volume of intrusions and breaches multiple, Artificial Intelligence (A.I.) may be able to provide a tool to gain defensive advantage for government agencies. Join John McCumber, (ISC)2’s Director of Cybersecurity Advocacy and Ian Doyle, IBM’s Executive Security Advisor for the U.S. Government as they discuss how to leverage these collaborative and cognitive solutions to help prevent, detect, and respond to today’s cybersecurity threats impacting your agency.

2017/11/17
阅读更多

IBM Part 1 - Using A.I. to Find the Needle in the Federal Haystack

A recent research study conducted by Meritalk on the use of Artificial Intelligence (A.I.) asked federal cybersecurity professionals to share their views on the use of AI to enhance a cybersecurity analyst’s ability to identify and understand sophisticated threats, by tapping into unstructured data and correlating it with local cybersecurity offenses. What are the cybersecurity implications within the Federal Government for the rise of A.I.? What role can A.I. play in incident response? Can it help prepare agencies for real-world cyber attack scenarios? Join John McCumber, (ISC)2’s Director of Cybersecurity Advocacy and Ian Doyle, IBM’s Executive Security Advisor for the U.S. Government for an examination of the recent study and results.

2017/11/17
阅读更多

Briefings Part 1: Anatomy of a Large Scale Email-borne Attack

Your organization and people are being targeted by cyber criminals, hackers and even state-sponsored threat actors and learn how email is a key vector at the heart of this new threat. Join Mimecast and (ISC)2 for an intriguing presentation when you’ll discover and view examples of the various tools attackers leverage to expose your organization with a combination of technology, psychology, and the simplest of methods to "Hack a Human." We’ll also examine the current threat landscape using email attacks and how social engineering has become “malware-less”.

2017/11/16
阅读更多

Security Briefing On Demand - Redefining Security: Data Protection On Demand

Faced with more stringent compliance requirements, driven by GDPR and other regulations, coupled with the difficulties to maintain an effective security profile in dynamic threat environment, many organizations are looking for a new way to manage their data protection. Guided by the ease of use and affordability of as-a-service offerings, organizations are looking to the cloud for answers. Proven efficient for a range of solutions from authentication to networking, the next cloud-based security frontier is revolutionizing the way companies and their service providers manage complex key management and encryption solutions. Simpler, more cost-effective, on-demand options that allow the organization to focus on its business, knowing that their data is securely under control, and only they have the keys to their kingdom, is set to redefine the way organizations do data protection today.

2017/10/26
阅读更多

Briefing on Demand Part 3 - Talking to Your Developer about Security

More and more enterprises are moving their applications into public and private cloud infrastructure. The cloud is becoming more appealing for enterprises as it facilitates business growth due its agility, resiliency and scalability. The advent of a variety of technologies and processes such as containers, micro-services, and DevOps has made rolling out new applications into the cloud very quick and desirable for development teams. Join Imperva and (ISC)2 for an examination of how enterprises move applications to the cloud without forgetting to put security first.

2017/10/18
阅读更多

Briefings On Demand Part 2 - Security Across Cloud Platforms

With the proliferation of cloud deployment options and platforms, management of application security across platforms has become a major problem for security teams. In this webinar, we address challenges posed by cloud proliferation, and how to approach development of a consistent security posture across platforms to better manage risks.

2017/10/18
阅读更多

Briefing On Demand Part 1 - Rethinking Security for Hybrid Environments

As more workloads are moved to cloud infrastructure, unique security challenges arise. Join Imperva and (ISC)2 for this webinar where we'll discuss some of the tradeoffs for on-prem and cloud app security, strategies for approaching security in hybrid environments, and the importance of flexible deployment models.

2017/10/17
阅读更多

Prepping for May 2018: A Guide to Complying with GDPR’s Data Security Regs

With less than a year to go before it takes effect, GDPR is everywhere in security and privacy news. Much of that coverage treats GDPR at a high-level, addressing topics such as implementation timeline, potential fines and catchy articles like the ‘right to be forgotten’. While important, these topics just scratch the surface of a mandate that is so broad in scope it affects everything from corporate governance to consent rights. Those that fall under GDPR’s scope, find it can be daunting to know where to start and what is really of concern. And, with so much high-level information out there, administrators and compliance teams may find it hard to get the more detailed guidance they need to map their path forward. We aim to fix that. This webcast will examine the privacy legislations’ security mandates, the core themes that span articles, and offer constructive, practical ways to comply using encryption and key management. Right now, organizations are spread widely across the readiness spectrum from basic awareness to the advanced stages of meeting their compliance obligations. Wherever you are on your compliance journey, we’ll help you understand GDPR’s security themes as they relate to you, and we’ll lay out solutions to put you in full control of your data and your compliance destiny. Join us to learn more about how encryption and key management can get you ready for May 2018 when GDPR takes effect.

2017/8/28
阅读更多

Part 3: Future of SIEM—Remediate Malware & Spear Phishing w/Automated Playbooks

It’s not uncommon for security teams to see upwards of 17,000 malware alerts per week and only investigate a third of them. Each incident detected requires investigation and eventually remediation before it can be laid to rest. Unfortunately, the security talent capable of performing these tasks is scarce, which leaves most security operations teams spread thin, a symptom of sparse coverage compounded by the drain of low fidelity security alerts and false positives. Join Exabeam and (ISC)² on August 3, 2017 at 1:00PM Eastern to learn how SIEM technologies must evolve to include automated playbooks and orchestration for common attacks such as malware and spear-phishing.

2017/8/3
阅读更多

Part 2: Future of SIEM—Sniff Out Malware & Spear-Phishing w/Behavioral Analytics

Malware and spear-phishing continue to cause the most headaches for IT security teams. Over the years, attackers have become more sophisticated and SIEM systems have failed to keep up. Key indicators of emerging threats include lateral movement, where the attacker silently attempts to access multiple servers on the network, and account management, where the attacker escalates privilege or creates new privileged accounts. Detection of advanced threats like these require real time analytics and the ability to find signals within the very noisy security environment. Join Exabeam and (ISC)² on June 29, 2017 at 1:00PM Eastern to learn how user behavior analytics automatically analyzes and scores activity for escalated risk allowing for quick attack detection.

2017/6/29
阅读更多

Data Security Briefings Part 2: Securing Innovation - Big Data, Cloud and IoT

Big data, Hadoop, Cloud and Internet of Things (IoT), promise to revolutionize the business of governments and enterprises alike. But they not only create opportunity, but also more data flows to be attacked and surface area for attacks, including more devices, connections, and networks. Government and enterprises must protect the data that flows across new initiatives and innovations while preserving business processes and protecting business-critical legacy systems. This presentation will cover how data-centric security and Format-Preserving Encryption can enable safe innovation and business transformation. Come along with HPE and (ISC)2 as we explore Big Data, Cloud and IoT.

2017/6/6
阅读更多

Data Security Briefings Part 3: Protecting Sensitive Data-at-Rest

In the final part of this Security Briefings series, we’ll examine why protecting data-at-rest is so important. We’ll discuss problems of the “perform storm”, what analysts have concluded, and discuss how Enterprise Secure Key Manager technology helps protect data, eliminate risk, and reduce your operational and capital costs.

2017/6/2
阅读更多

Part 1: Future of SIEM–Why Static Correlation Fails Insider Threat Detection

Hackers stealing credentials and operating in your corporate network…disgruntled employees collecting customer lists and design materials for a competitor…malware sending identity information back to random domains…these common threats have been with us for years and are only getting worse. Most organizations have invested large amounts in security intelligence, yet these solutions have fallen short. Simply put, security intelligence and management, in the form of legacy SIEM technologies, has failed to keep up with complex threats. Join Exabeam and (ISC)² on June 1, 2017 at 1:00PM Eastern to gain a better understanding of why static correlation rules are no longer a match for today’s threats.

2017/6/1
阅读更多

Briefing On Demand - Authentication in Healthcare - Six Ways to Improve Security

Healthcare organizations are entrusted with securing sensitive patient records, which also happen to be high-worth targets for hackers and fraudsters. Suffering the highest cost per-breached-record across industries, the healthcare sector also contends with maintaining compliance with mandates such as HIPAA, EPCS, eIDAS, and HITECH (aka EHR Incentive programs). How can strong authentication help comply with these mandates, and what use cases does it address? Join Gemalto and (ISC)2 to learn: · Why electronic healthcare records are a prime target for both compliance fines and fraudsters · How do healthcare organizations comply with mandates such as HIPAA, HITECH, EPCS and eIDAS? · Who in the healthcare business chain has to comply with these mandates? · Six strong authentication use cases for improving security and compliance in healthcare organizations and their business associates

2017/5/22
阅读更多

Data Security Briefings Part 1: Neutralizing Data Breach and Insider Threat

Governments and enterprises are more challenged than ever to protect their most valuable data, from a citizen’s social security number to highly classified data. But endpoint or network security can’t stop attackers, and much less a malevolent insider. The solution lies in protecting the data itself. Recent NIST and FIPS validations make groundbreaking Format-Preserving Encryption (FPE) technology available to government and enterprises. FPE “de-identifies” sensitive data, rendering it useless to attackers, while maintaining its usability and referential integrity for data processes and applications, and easily layering protection into decades-old legacy systems. Join HPE and (ISC)2 for an exploration of this topic in the 1st part of a three part series.

2017/5/11
阅读更多

Better Vulnerability Awareness for IT and Development

The increasing rate of vulnerability reporting, combined with the number of sources producing those reports has made it more difficult than ever to monitor critical issues affecting your organization. While monitoring vulnerabilities has traditionally been most important for IT teams, it is becoming rapidly more relevant for software development teams as well, especially as the use of open source / third-party libraries increases. Join Cytenna and (ISC)2 on November 22, 2016 at 1:00PM Eastern as we discuss solutions to this problem at both the IT and development level. Among other things, we'll cover Vulnerability Central, a free member benefit for all (ISC)2 members that can help you stay more aware of recent vulnerabilities, especially with its new e-mail notification feature.

2016/11/22
阅读更多

Solution Summit - Shadow Data Part 2 - Exploits Leveraging Cloud Apps & Services

As valuable company data increasingly migrates to cloud apps and services, the risk and expense of data theft and leakage has risen dramatically. Malicious actors are less likely to attack the well-fortified back-end infrastructure of cloud app vendors, preferring to exploit the weakest link – the human element – to get in through the "front door". Compromised credentials via phishing attacks or other means or malware that hijacks a valid user session are some of the key threats that must be addressed in this new cloud landscape. This session will examine recent exploits leveraging cloud apps and services.

2016/10/6
阅读更多

Solution Summit - Part 4: Roundtable Discussion

A discussion with the presenters of the first 3 parts of the Solution Summit series.

2016/10/6
阅读更多

Solution Summit Part 3: Threat Protection & Incident Response

It is said that the bad guys follow the money (why do thief's rob banks? . . .). As valuable assets increasingly migrate to cloud infrastructure, there is a need for diligent protection of these assets. Malicious actors are less likely to attack the well-fortified back-end infrastructure of cloud app vendors, but rather pray on the human element to get in through the "front door". Compromised credentials via phishing attacks or other means or malware that highjacks a valid user session are some of the key threats that must be addressed in this new cloud landscape. This session will examine these and other threats, along with new approaches to address these at scale.

2016/10/6
阅读更多

Solution Summit - Part 2: Data Governance & Protection

Even when applications are "sanctioned", there is still a need to ensure they are being used in a safe manner. Ease of collaboration is a double-edged sword, as employees may inadvertently share sensitive content leading to liability for the company. Furthermore, compliance regulations often have strict requirements on how data is managed in the cloud. This session will explore data governance and protection of sensitive data as it migrates to cloud apps and services.

2016/10/6
阅读更多

Solution Summit - Part 1: Cloud App Discovery & Analysis

You can't secure what you can't see. While many organizations are actively embracing cloud apps as a strategic part of their IT infrastructure, many employees or lines of business are adopting additional ad hoc cloud services to aid business productivity or for personal applications. Known as "Shadow IT", these additional cloud apps and services bypass the oversight of IT, and may introduce risk or cost inefficiencies. This session will explore this issue, along with approaches.

2016/10/6
阅读更多

Briefings Part 2: The Evolving Nature of Ransomware Attacks

Like all cyber threats, ransomware continues to evolve and its effects will cause significantly greater impact to corporate organizations and networks. Just as computer viruses caused more damage as they grew in sophistication, ransomware is increasing its way to enter networks and wreak more havoc. Newer strains now know to look for networked file shares as encryption targets. Do you know what signals to look for to detect ransomware as it begins to attack? Exabeam researchers have analyzed nearly 100 strains of malware and have categorized some of the more aggressive techniques being used. Join Exabeam and (ISC)2 on August 18, 2016 at 1:00PM Eastern and gain a better understanding of the mechanisms ransomware might use to propagate and how to detect signs of these mechanisms in use.

2016/8/18
阅读更多

Briefings Part 3: Secure in the Cloud - Securing Email Migration to Office 365

The cloud's promise of on-demand functionality for a lower cost has arrived to business applications. The use of Microsoft Office 365 across the globe is growing rapidly, with a clear value proposition to re-invent productivity for organizations of all sizes. But the transition to the cloud is not without challenges. Office 365 offers concerns in terms of privacy, compliance and security which can be addressed through the use of end-to-end encryption for all e-mails and files sent to Office 365. Join HPE and (ISC)2 on August 4, 2016 at 1:00PM Eastern for an examination of the steps for an Office 365 migration, security and privacy concerns for the cloud environment and how to achieve end-to-end encryption.

2016/8/4
阅读更多

Briefings Part 1: Anatomy of a Ransomware Attack

Ransomware is currently one of the most disruptive security challenges for enterprises. As it moves from an individual employee's PC to the corporate network, the impact can be significant. Despite research and analysis by security firms and analysts, most don't have a good idea of how a piece of ransomware actually operates, i.e. what is affected and when, what signals to look for, etc. Exabeam researchers have detonated nearly 100 strains of ransomware in the labs and produced a detailed analysis of how a ransomware attack actually unfolds, and how an organization might respond to shut it down. Join Exabeam and (ISC)2 on July 21, 2016 at 1:00PM Eastern and gain a better understanding of the mechanisms of ransomware, how to detect it and shut down an attack.

2016/7/21
阅读更多

Briefings Part 2: Integrate Data Security with Your Big Data Platform

A global telecoms company ingests 300 million customer records in < 1.5 minutes today. A mid-size firm handles 3.7 billion transactions annually. With Big Data analytics at the heart of all these systems-driving transformation, innovation and new customer insights-these projects include massive quantities of sensitive data that flow across multiple systems. Adding to the complexity of securing your data, these systems are spread across multiple data centers, on premise, and in the cloud. Join HPe Security - Data Security and (ISC)2 on July 19, 2016 at 1:00PM Eastern to understand how enterprises can leverage end-to-end data-centric protection in conjunction with their Big Data systems and view a technical deep dive into how enterprises can gain Big Data Insights - without the risk.

2016/7/19
阅读更多

Security Briefing: Translating Cyber Risk to Financial Risk

Incident rate. Mean time to discovery. Patch management coverage. These are terms that infosecurity professionals use on a daily basis, but have little to no meaning to those who measure performance in terms of dollars and cents. It's important for infosecurity practitioners to be able to communicate effectively with other departments, particularly the C-Suite and board level. CyVaR allows for the ability to quantify an organization's financial risk exposure to cyber attacks. Join PivotPoint Risk Analytics and (ISC)2 on July 12, 2016 at 1:00PM Eastern for a discussion and demonstration of the CyVaR service and how to reduce financial risk, as well as build a security budget based on ROI.

2016/7/12
阅读更多

Briefings Part 1: Proven Strategies to Calm Cloud Security Fears

In the borderless world of Cloud computing, everything changes from anywhere access to anything as-a-service. While organizations are keen to reap the benefits the cloud offers, many fall shy of adoption for two reasons: security and control. Cloud computing imposes significant security risks on the corporation, network, IT and the day to day activities of the business. How do organizations maintain compliance, control and ownership of sensitive data as they move from the physical environment to a cloud world when the distribution of data may not be completely controlled by the data owner, and there is liability confusion as cloud service providers take on a larger role? Join HPE Security - Data Security and (ISC)2 on June 28, 2016 at 1:00PM Eastern for Part 1 of a 3 part Security Briefings series examining the key security challenges faced when moving to the Cloud.

2016/6/28
阅读更多

Using Actionable Intelligence to Find & Prioritize Vulnerability & Access Risk

In the world of increasing security risks, do you know which threats are most critical to your network? Using actionable intelligence, you can not only identify but resolve immediate threats by applying proactive analytics to your enterprise and create in-depth views of areas of access. This intelligence allows the application of custom analytics to massive amounts of data and provides a comprehensive, real-time view of the multi-dimensional relationships between identities, access rights, policies, resources, vulnerabilities, and more across enterprise systems. Join Core Security and (ISC)2 on June 9, 2016 at 1:00PM Eastern for a Security Briefings that will examine the opportunities for using actionable insight with your data to deter, detect, and remediate vulnerability and access risk.

2016/6/9
阅读更多

Briefings Part 3: The Rise of Automated Attacks – Dissecting the Event

The volume, size, and sophistication of DDoS attacks have increased rapidly over the years. Is your organization prepared for today’s modern, multi-vector DDoS offensives? Join Imperva and (ISC)2 on May 19, 2016, at 1:00 PM Eastern for the final part of a three-part Security Briefing series where we’ll specifically explore the anatomy and timeline of a complex DDoS attack, as well as the steps used to mitigate each phase of the assault.

2016/5/19
阅读更多

Rock the CASB Part 3: Enabling Secure BYOD w/Cloud Access Security Brokers

As organizations migrate to services like Google Apps and Office 365, there is a growing need to secure data both in the cloud and across mobile devices. With CASB, IT administrators can distinguish between managed and unmanaged mobile devices without invasive agents, yet are able to limit access to sensitive data using granular policy controls. CASBs even enable control over data once downloaded to an end-user's device. Join Bitglass and (ISC)2 on May 5, 2016 at 1:00PM Eastern for the final part of our three-part webinar series, where we discuss the drawbacks of existing mobile security solutions and the ease of deploying a CASB to secure BYOD without hassles.

2016/5/5
阅读更多

Part 2: The Rise of Automated Attacks – Take Back Control of Your Web Accounts

During every hour of every day, cyber criminals launch web application attacks that silently bypass traditional perimeter controls. They use millions of stolen user credentials to take over web application accounts, access sensitive applications, steal confidential data, and conduct fraudulent transactions. Stop account takeover attacks, right in their tracks. Join Imperva and (ISC)2 on April 21, 2016, at 1:00 PM Eastern for the second part of a three-part Security Briefing series where we’ll examine the types of automated attacks that impact business operations today and the importance of globally, crowd-sourced threat intelligence to defend against such threats.

2016/4/21
阅读更多

A New Vision for CISOs – Unprecedented Visibility of Your Attack Surface

In today’s complex security landscape, networks are getting larger and more complicated, creating myriad holes in defenses, while cyberattacks are increasing in sophistication and persistence. CISOs are challenged to centralize security and gain visibility over the attack surface, the ways in which their IT systems are vulnerable to threats, including potential attack vectors. According to a 2015 Gartner report1, enterprises are shifting security budgets to security management platforms that integrate existing technologies, unify data from multiple vendors, provide greater insight through advanced analytics and enable security operations teams to automate and prioritize activities. Register today to learn how to: * Visualize and analyze your attack surface with an interactive model that links network topology, network connections, business units and organizational hierarchy * Categorize Indicators of Exposure (IOEs), rank the severity of those IOEs and display the data in a format understandable to both technical and business-oriented viewers * Drill down with interactive tools to get quick summaries of actionable intelligence; pinpoint and protect the systems most vulnerable to threats * Systematically manage and reduce the attack surface by allocating security resources to where they are most needed 1 Gartner Innovation Tech Insight for Security Operations, Analytics and Reporting, Oliver Rochford and Paul E. Proctor. November 11, 2015. Join Skybox Security and (ISC)2 on April 12, 2016 at 1PM (GMT+8; Hong Kong, Singapore, Beijing) for a discussion on this topic.

2016/4/12
阅读更多

Rock the CASB Part 2: Real World Use-Cases for Cloud Access Security Brokers

Thousands of organizations across all verticals are leveraging CASBs to secure data in public cloud apps like Office 365, Google Apps, and Box. Join us for Part 2 of our Security Briefings Series April 7, 2016 at 1:00PM Eastern where we'll detail the use cases for complete control and visibility provided by CASBs across both managed and unmanaged devices. We'll also discuss how access control functionality is used in regulated industries for compliance. Learn how your peers are leveraging CASBs to secure data beyond the firewall.

2016/4/7
阅读更多

Briefings Part 1 - The Rise of Automated Attacks - Stop Botnets at the Gate

The elimination of bots may seem more difficult than the eradication of Polio. When one botnet gets taken down, another botnet with more sophistication takes over and does not miss a beat. As long as there are profit-driven organized cyber-crime rings, then there will be malicious activity that threatens business-critical applications. Join Imperva and (ISC)2 on March 24, 2016 at 1:00PM for the first part of a three-part Security Briefing where we'll examine the types of automated attacks that impact business operations today and the importance of globally, crowd-sourced threat intelligence in the defense against such threats.

2016/3/24
阅读更多

Architecting an Endpoint Strategy to Respond & Protect Against Today's Threats

It's now widely recognized that traditional security solutions are insufficient to protect organizations from advanced threats and targeted attacks. To fight back you need your own unified plan of attack so that you can better sense malicious activity and take preventive action that will crush attackers and keep your environment safe Join Brett Williams, Senior Security Engineer for Carbon Black on March 23, 2016 at 1PM (GMT+8; Hong Kong, Singapore, Beijing) for an overview of how organizations are moving from a passive to proactive defense on the end point. This webinar will cover: * End point security challenges organizations face today * Why using a trusted security model on the endpoint is essential * The importance of choosing the right solution and integration with your existing security investments * Example of Ransomware detection and protection using proactive defense. * Best practices learned from successful deployments

2016/3/23
阅读更多

Rock the CASB Part 1: Critical Capabilities for Cloud Access Security Brokers

As organizations move from on-premise infrastructure and device-level security to public cloud applications like Google Apps and Office 365, the need for a data-centric solution that can protect data in the cloud, on device, at access, and on the network becomes critical. Cloud apps now feature robust functionality but lack the level of granular control and deep visibility many organizations need for compliance purposes. On March 10, 2016 at 1:00PM Eastern, join us for the first part of a new Security Briefings series and learn how Cloud Access Security Brokers can help protect data in the cloud by providing visibility and control. We'll also discuss how API integration and a hybrid architecture can be used to control data on both managed and unmanaged devices, enabling secure SaaS and BYOD.

2016/3/10
阅读更多