Use DNS Filtering Services Almost everything malicious has to make a phone call. A phishing link has to resolve to a web address. Malware has to reach back to its operator for instructions. Ransomware often checks in before it starts encrypting. Every one of those steps begins the same way, by looking up a domain name. DNS filtering sits at that lookup and refuses to connect to destinations known to be dangerous, which means a surprising number of attacks fail at the very first step,...

Trending at Forthright.
CIS IG1 Control 6.2 – Establish an Access Revoking Process
CIS IG1 Control 6.2 – Establish an Access Revoking Process by Heath Gieson If access granting is where intent is established, access revoking...
Access Control Management: Access Should Be Granted Intentionally
Access Should Be Granted Intentionally By Tim Marley As we move into CIS Control 6, Access Control Management, we're going to spend the next...
CIS IG1 5.4: How Everyday Admin Access Turned a Phish Into a Crisis
by Heath Gieson CIS IG1 Safeguard 5.4 states that administrator privileges should be restricted to dedicated administrator accounts, and that...
CIS IG1 5.3 Dormant Accounts Are a Process Failure
by Heath Gieson Years ago, I worked with a client to implement multi‑factor authentication across their organization. As part of the project,...
CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World
CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World By Heath Gieson CIS Safeguard 5.2 is deceptively simple on the...
Security Complexity Is an Operational Risk
Security Complexity Is an Operational Risk by Heath Gieson Most organizations do not set out to create a complex security environment. It usually...
You Can’t Manage What You Can’t See
As we move into CIS Control 5, Account Management, we're going to spend a few weeks working through the individual safeguards. We're starting with...
CIS IG1 Control 4.7: Manage Default Accounts on Enterprise Assets and Software
by Heath Gieson Manage Default Accounts on Enterprise Assets and Software As we continue through the CIS IG1 controls, a consistent pattern keeps...
More Updates Don’t Mean More Risk — They Mean Better Security
Why More Updates Are Coming — and Why That’s a Good Thing Over the next several weeks, organizations are likely to notice something familiar but...












