Forthright Technology Partners Logo
  • Solutions
    • Forthright Cyber
    • Forthright Advisory
    • Forthright DigitalNOW
  • Tech Insights
  • About
  • Contact Us
  • Client Hub
CIS IG1 5.4: How Everyday Admin Access Turned a Phish Into a Crisis

CIS IG1 5.4: How Everyday Admin Access Turned a Phish Into a Crisis

by Heath Gieson | Jun 3, 2026 | 2026, Secure IT operations, Tech Insights

by Heath Gieson   CIS IG1 Safeguard 5.4 states that administrator privileges should be restricted to dedicated administrator accounts, and that general computing activities such as email, internet browsing, and productivity work should be performed from a user’s...

Trending at Forthright.

You Can’t Manage What You Can’t See

May 13, 2026 | 2026, Secure IT operations, Tech Insights, Uncategorized

by Tim Marley As we move into CIS Control 5, Account Management, we're going to spend a few weeks working through the individual safeguards. We're starting with 5.1: Establish and Maintain an Inventory of Accounts. This control comes back to a principle we've already...

CIS IG1 5.4: How Everyday Admin Access Turned a Phish Into a Crisis

CIS IG1 Control 4.7: Manage Default Accounts on Enterprise Assets and Software

May 6, 2026 | 2026, Secure IT operations, Tech Insights, Uncategorized

by Heath Gieson Manage Default Accounts on Enterprise Assets and Software As we continue through the CIS IG1 controls, a consistent pattern keeps emerging. Many security incidents don’t begin with advanced techniques or sophisticated tooling. They start with simple,...

More Updates Don’t Mean More Risk — They Mean Better Security

More Updates Don’t Mean More Risk — They Mean Better Security

Apr 28, 2026 | 2026, Secure IT operations, Tech Insights, Uncategorized

Why More Updates Are Coming — and Why That’s a Good Thing Over the next several weeks, organizations are likely to notice something familiar but more pronounced than usual:  an uptick in software updates across devices, operating systems, browsers, and applications....

CIS IG1 Control 4.6: Securely Managing Network Gear

CIS IG1 Control 4.6: Securely Managing Network Gear

Apr 28, 2026 | 2026, Secure IT operations, Tech Insights, Uncategorized

When the Management Plane Becomes the Attack Plane by Heath Gieson A few years ago, I was sitting in a conference room with an executive team after what everyone thought was a routine network outage. We started examining the firewall that had been in place for years....

When It’s Time to Let Data Go

When It’s Time to Let Data Go

by Ceri Sucato | Mar 11, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Tim Marley Over the last few weeks, we have been building the foundation of a responsible data management program. In CIS Control 3.1, we talked...

read more
Just Because You Can Keep It Doesn’t Mean You Should

Just Because You Can Keep It Doesn’t Mean You Should

by Ceri Sucato | Mar 4, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Tim Marley Over the last few weeks, we have talked about knowing what data you have and who has access to it. CIS Control 3.1 – We discussed the...

read more
Not Everyone Needs the Keys to Every Room

Not Everyone Needs the Keys to Every Room

by Tim Marley | Feb 25, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Tim Marley We have spent the last two weeks in the CIS Controls series talking about data management and data inventory. Knowing what you are...

read more
The Cost of Waiting: Why Real-Time Detection and Response Is No Longer Optional

The Cost of Waiting: Why Real-Time Detection and Response Is No Longer Optional

by Heath Gieson | Feb 20, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Heath Gieson It usually starts the same way. An alert comes in overnight. Maybe it is an email from a security vendor. Maybe it lands in a shared...

read more
You Cannot Protect What You Have Not Identified

You Cannot Protect What You Have Not Identified

by Tim Marley | Feb 17, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...

read more
The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough

The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough

by Heath Gieson | Feb 12, 2026 | Healthcare industry, Secure IT operations, Tech Insights

by Heath Gieson   For healthcare organizations, cybersecurity and compliance are no longer just IT concerns—they are material financial risks...

read more
CIS IG1 Control 3.1: Data Management is Not a Policy Problem

CIS IG1 Control 3.1: Data Management is Not a Policy Problem

by Tim Marley | Feb 10, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

by Tim Marley   Over the course of my career, and particularly in the last five to ten years, the topic of data management comes up frequently....

read more
CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices

CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices

by Andrew Scott | Feb 3, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

Most organizations assume that corporate devices only run approved software. In reality, that assumption is often wrong. Users are inherently...

read more
CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference

CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference

by Andrew Scott | Jan 28, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

Most security conversations focus on what software exists in an environment. CIS Control 2.2 pushes the conversation one step further by asking a...

read more
Page 2 of 8«12345...»Last »

Every organization is different.

Your business has unique goals, challenges, and opportunities. Our advisory team takes the time to understand where you are today, where you want to go, and the obstacles standing in the way. From there, we provide the strategic guidance needed to align technology, cybersecurity, and business priorities.

Gain clarity. Build momentum.
Scale with confidence.

Understand Your Priorities | Align Technology and Strategy | Strengthen Operations | Support Growth

Schedule a Call

Let’s discuss your business goals.

  • Follow
  • Follow
  • Follow
  • Follow
  • Follow
  • Follow
  • Follow

Explore

Contact Us
Solutions
About Us
Careers
Events
Blog
Refer a client

Offices

HEADQUARTERS

2893 Executive Park Drive, Suite 204. Weston, FL 33331

(855) 796-3381

Forthright Technology Partners
Certified Minority-owned Business

© 2026 Forthright Technology Partners, Inc.
Sitemap
Privacy Policy
Client Portal
Website Accessibility Statement

Ticket submitted!

Please warm transfer call to (754) 356-1601.