Use DNS Filtering Services Almost everything malicious has to make a phone call. A phishing link has to resolve to a web address. Malware has to reach back to its operator for instructions. Ransomware often checks in before it starts encrypting. Every one of those steps begins the same way, by looking up a domain name. DNS filtering sits at that lookup and refuses to connect to destinations known to be dangerous, which means a surprising number of attacks fail at the very first step,...

When It’s Time to Let Data Go
by Tim Marley Over the last few weeks, we have been building the foundation of a responsible data management program. In CIS Control 3.1, we talked...
Just Because You Can Keep It Doesn’t Mean You Should
by Tim Marley Over the last few weeks, we have talked about knowing what data you have and who has access to it. CIS Control 3.1 – We discussed the...
Not Everyone Needs the Keys to Every Room
by Tim Marley We have spent the last two weeks in the CIS Controls series talking about data management and data inventory. Knowing what you are...
The Cost of Waiting: Why Real-Time Detection and Response Is No Longer Optional
by Heath Gieson It usually starts the same way. An alert comes in overnight. Maybe it is an email from a security vendor. Maybe it lands in a shared...
You Cannot Protect What You Have Not Identified
by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...
The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough
by Heath Gieson For healthcare organizations, cybersecurity and compliance are no longer just IT concerns—they are material financial risks...
CIS IG1 Control 3.1: Data Management is Not a Policy Problem
by Tim Marley Over the course of my career, and particularly in the last five to ten years, the topic of data management comes up frequently....
CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices
Most organizations assume that corporate devices only run approved software. In reality, that assumption is often wrong. Users are inherently...
CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference
Most security conversations focus on what software exists in an environment. CIS Control 2.2 pushes the conversation one step further by asking a...













