Ensure Use of Only Fully Supported Browsers and Email Clients Your web browser and your email client are the two applications your people use most, and the two attackers target most, because that’s where the outside world reaches into your business. Control 9.1 asks a simple question about both: is the version you’re running still supported by the vendor? An unsupported browser or mail client isn’t just old. It’s software the vendor has stopped fixing, which means every...

Trending at Forthright.
CIS IG1 Control 7.4: Perform Automated Application Patch Management
Updates You’re Probably Not Catching Your operating system is probably the best-patched software on your computers. Modern Windows and macOS...
CIS IG1 Control 7.3: Perform Automated Operating System Patch Management
Why Patching Should Be a System, Not a Habit Almost no one argues against patching. Every leader I talk to already knows that unpatched systems are...
CIS Safeguard 7.2: Finding the Problem Is Only the Beginning
In Safeguard 7.1, we discussed the difference between running a vulnerability scanner and operating a vulnerability management program. A scan may...
CIS Safeguard 7.1: Why a Vulnerability Scanner Is Not a Vulnerability Management Program
A Vulnerability Scanner Is Not a Vulnerability Management Program As we move into CIS Control 7, Continuous Vulnerability Management, we're going to...
CIS IG1 Safeguard 6.5: Require MFA for Administrative Access
CIS IG1 Safeguard 6.5: Require MFA for Administrative Access by Heath Gieson This final article in the MFA mini‑series focuses on the...
Why 84% of Companies Fail at Digital Transformation. And Why That Number Hasn’t Moved.
Why 84% of Companies Fail at Digital Transformation. And Why That Number Hasn't Moved. By: Frank Merino Nearly a decade ago, Forbes published a...
CIS IG1 Safeguard 6.4: Require MFA for Remote Network Access
CIS IG1 Safeguard 6.4: Require MFA for Remote Network Access by Heath Gieson This article continues our CIS IG1 identity series by extending...
CIS IG1 Safeguard 6.3
Require MFA for Externally‑Exposed Applications This article is part of our ongoing CIS IG1 series focused on practical, high‑impact security...
CIS IG1 Control 6.2 – Establish an Access Revoking Process
CIS IG1 Control 6.2 – Establish an Access Revoking Process by Heath Gieson If access granting is where intent is established, access revoking...










