Concerned about getting hacked? Where to start for a Small Business.

We get it. You started your business to change the world (or at least your neighborhood). You didn’t sign up to spend your Sunday nights trying to figure out how to unlock your website host account. But in a world where “Hackers” (https://www.imdb.com/title/tt0113243/) have moved from a underappreciated movie from the 90’s to a daily […]

A Case Study in MFA Rollout

A Case Study in MFA Rollout If you ask any cybersecurity professional for the single most effective, low-hanging fruit to secure an organization, Multi-Factor Authentication (MFA) usually tops the list. Adding that extra verification step stops the vast majority of automated credential attacks dead in their tracks. It’s the digital equivalent of adding a second […]

CMMC Paused But Not Forgotten

CMMC Paused But Not Forgotten If you work anywhere near the defense industrial base (or spend your days tracking federal cybersecurity mandates just for fun like I do), the recent headlines around the Cybersecurity Maturity Model Certification (CMMC) probably gave you a sudden case of deadline-induced deja vu. Just as organizations were revving their engines […]

Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride

Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride Everything I know, I’ve learned from The Princess Bride. It’s how I landed my first job, played a key role in my wedding proposal, and inspired me to learn how to swordfight, which led to an Olympic Gold Medal. I’ll let you figure […]

Death, and Disruption of Your Cyber Supply Chain

Two Things Are Certain in Life 1) Death, and 2) Disruption of Your Cyber Supply Chain Benjamin Franklin famously wrote that nothing in this world is certain except death and taxes. If Ben were around today managing an enterprise IT network, he’d almost certainly add a third item to that list: supply chain disruption. We […]

Was Running a Business Always This Hard? Why The Technology Divide Is Real

If you run a business today, cast your mind back ten or fifteen years ago. Back then, starting a business required a solid business plan, a good product or service, a telephone line, a filing cabinet, and maybe a basic website that served as a glorified digital business card. If your computer crashed, you restarted […]

Why Are Cybersecurity Compliance Tools Called GRC?

If you’ve ever shopped around for cybersecurity software or sat through an IT strategy meeting, you’ve almost certainly run into the acronym GRC. And let’s be honest: Governance, Risk, and Compliance is a mouthful of corporate jargon that feels completely disconnected from the actual day-to-day reality of stopping hackers. It sounds like something invented by […]

Why Should I Care About Cyber Threats as a Small Business?

If you run a small-to-medium-sized business, it’s easy to look at major cybersecurity news like breach headlines involving fortune 500 corporations or global infrastructure and think, “That doesn’t apply to me. Why would a hacker target my business when there are bigger fish in the sea?” It’s a natural assumption, but unfortunately, it’s also one […]