Deploy and Maintain Anti-Malware Software Anti-malware is the one security control almost every business already believes it has. So the question worth asking isn't whether you have it. It's whether what you have can catch what actually shows up today, and whether it's running on everything, not just the obvious computers. A lot of organizations are protected on paper and quietly exposed in practice. Control 10.1 is deliberately foundational. It doesn't ask for anything exotic. It asks...

Trending at Forthright.
Secure by Design, Not by Accident: CIS Controls 4.1 & 4.2
by Heath Gieson Every device you deploy and every application you install arrives configured for ease of use, not security. When was the last time...
CIS IG1 Control 3.6: Encrypt Data on End User Devices—Because Lost Doesn’t Have to Mean Exposed
by Heath Gieson As we continue our weekly journey through the CIS IG1 controls, each safeguard builds on the operational foundations we’ve been...
Global Conflicts Escalate: 4 Critical Cybersecurity Changes For Businesses
When geopolitical tensions rise, widespread cyber activity follows. Recent attacks connected to events involving Israel, the Gulf States, and India...
When It’s Time to Let Data Go
by Tim Marley Over the last few weeks, we have been building the foundation of a responsible data management program. In CIS Control 3.1, we talked...
Just Because You Can Keep It Doesn’t Mean You Should
by Tim Marley Over the last few weeks, we have talked about knowing what data you have and who has access to it. CIS Control 3.1 – We discussed the...
Not Everyone Needs the Keys to Every Room
by Tim Marley We have spent the last two weeks in the CIS Controls series talking about data management and data inventory. Knowing what you are...
The Cost of Waiting: Why Real-Time Detection and Response Is No Longer Optional
by Heath Gieson It usually starts the same way. An alert comes in overnight. Maybe it is an email from a security vendor. Maybe it lands in a shared...
You Cannot Protect What You Have Not Identified
by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...
The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough
by Heath Gieson For healthcare organizations, cybersecurity and compliance are no longer just IT concerns—they are material financial risks...













