A Practical Approach to Cyber Resilience – The five-step process (Part 2 of 3)

This is the second of a 3-blog series on Practical Cyber Resilience. In the first part, I covered the four key characteristics (or guiding principles) of cyber resilience. In this blog we will review the main objectives and 5-step Cyber Resilience Analysis methodology, as defined by the NIST Special Publication 800-160, Developing Cyber Resilient Systems. Within …

Continue reading A Practical Approach to Cyber Resilience – The five-step process (Part 2 of 3)

Three takeaways for a Small Business from the Microsoft Exchange hack

I heard this so many times: “My company is too small to be the target of an advanced attack”. Unfortunately, this is not true and the recent cyber-attacks on Microsoft Exchange servers clearly show it. Compared to the recent SolarWinds Orion security breach that directly affected mostly large organizations, the Exchange vulnerabilities were used to …

Continue reading Three takeaways for a Small Business from the Microsoft Exchange hack

A Practical Approach to Cyber Resilience – Part 1 of a 3 Part Series

In a previous blog, I looked at the key differences between cybersecurity and cyber-resilience, and why cyber-resilience is a better approach for organizations to follow in 2021 because it is holistic. The IT cyber-resilience is a complex objective requiring a solid understanding and a structured approach. NIST Special Publication 800-160, Developing Cyber Resilient Systems, is one …

Continue reading A Practical Approach to Cyber Resilience – Part 1 of a 3 Part Series

Cybersecurity or Cyber-resilience: Which one should be the prime objective for 2021?

Given the increased dependency on digital technologies for daily operations it’s not a surprise that organizations are concerned about cyber threats and the risks these are posing to their operations. But what is the best approach to this problem? Should an organization focus on cybersecurity or on cyber-resilience? Which of the two can be consider …

Continue reading Cybersecurity or Cyber-resilience: Which one should be the prime objective for 2021?

Five defining moments that shaped cybersecurity in 2020

Among the many disruptions brought by 2020, cyber threats ranked in the top concerns. As we had to rely more on digital for work and social life, cyber-attacks became very real threats for most aspects of our lives: health, work, freedom, national security, and even life itself.  Here is a selection of 5 defining moments …

Continue reading Five defining moments that shaped cybersecurity in 2020

Accelerating Safely on the Digital Highway

I wrote this post a couple of months back but it's highly relevant for 2021 and it’s worth being brought up again. You will also find below a reference to an interesting on-demand webinar hosted by InfoSecurity Magazine.. Despite today's harsh medical crisis we are living great times of innovation. For the past years, digital …

Continue reading Accelerating Safely on the Digital Highway

Defeating supply chain attacks together

The recent security incident involving Solarwinds Orion proves that cybersecurity is a team game. We all use software developed by a wide range of providers (and we will continue to do so). Any successful attack on one of these vendors (suppliers) can have negative consequences on all users of their software solutions. Solarwinds was targeted …

Continue reading Defeating supply chain attacks together