Collect Audit Logs There’s a predictable early move in a lot of intrusions: once an attacker is on a machine, they clear its local logs. If the only record of what happened lives on the same computer that was compromised, you’ve effectively handed the person you’re investigating the ability to edit the evidence. Control 8.2 solves that by getting your logs off the individual machines and into a place an attacker can’t quietly reach. If 8.1 was the decision about what to...

Trending at Forthright.
CIS IG1 5.3 Dormant Accounts Are a Process Failure
by Heath Gieson Years ago, I worked with a client to implement multi‑factor authentication across their organization. As part of the project,...
CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World
CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World By Heath Gieson CIS Safeguard 5.2 is deceptively simple on the...
Security Complexity Is an Operational Risk
Security Complexity Is an Operational Risk by Heath Gieson Most organizations do not set out to create a complex security environment. It usually...
You Can’t Manage What You Can’t See
As we move into CIS Control 5, Account Management, we're going to spend a few weeks working through the individual safeguards. We're starting with...
CIS IG1 Control 4.7: Manage Default Accounts on Enterprise Assets and Software
by Heath Gieson Manage Default Accounts on Enterprise Assets and Software As we continue through the CIS IG1 controls, a consistent pattern keeps...
More Updates Don’t Mean More Risk — They Mean Better Security
Why More Updates Are Coming — and Why That’s a Good Thing Over the next several weeks, organizations are likely to notice something familiar but...
CIS IG1 Control 4.6: Securely Managing Network Gear
When the Management Plane Becomes the Attack Plane by Heath Gieson A few years ago, I was sitting in a conference room with an executive team after...
Why “Default Closed” Is a Business Advantage: CIS IG1 Controls 4.4 and 4.5
by Heath Gieson Some attacks are sophisticated. Weeks of reconnaissance, carefully crafted messages, and quiet exploitation in the...
The Unlocked Screen in the Corner Office: What CIS Control 4.3 Requires and Why Biometrics Make It Easier Than You Think
by Heath Gieson Some attacks are sophisticated. Weeks of reconnaissance, carefully crafted phishing emails, vulnerabilities quietly exploited in the...













