• Solutions
    • Forthright DigitalNOW
    • Forthright Advisory
    • Forthright Cybersecurity
  • Tech Insights
  • About
  • Contact Us
  • Client Hub
CIS Safeguard 7.2: Finding the Problem Is Only the Beginning

CIS Safeguard 7.2: Finding the Problem Is Only the Beginning

by Tim Marley | Jul 22, 2026

In Safeguard 7.1, we discussed the difference between running a vulnerability scanner and operating a vulnerability management program. A scan may identify weaknesses, but the organization still needs a documented process that explains what happens next. That brings us to CIS Safeguard 7.2: Establish and Maintain a Remediation Process. The safeguard calls for a documented, risk-based remediation strategy that is reviewed at least monthly. The phrase “risk-based” matters. Most organizations...

Trending at Forthright.

CIS IG1 5.3 Dormant Accounts Are a Process Failure

CIS IG1 5.3 Dormant Accounts Are a Process Failure

CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World

CIS IG1 Safeguard 5.2: Why Unique Passwords Still Matter in a Multi-Factor World

Security Complexity Is an Operational Risk

Security Complexity Is an Operational Risk

You Can’t Manage What You Can’t See

You Can’t Manage What You Can’t See

Not Everyone Needs the Keys to Every Room

Not Everyone Needs the Keys to Every Room

by Tim Marley | Feb 25, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Tim Marley We have spent the last two weeks in the CIS Controls series talking about data management and data inventory. Knowing what you are...

read more...
2025 known exploited vulnerabilities

The Cost of Waiting: Why Real-Time Detection and Response Is No Longer Optional

by Heath Gieson | Feb 20, 2026 | Cybersecurity, Secure IT operations, Tech Insights

by Heath Gieson It usually starts the same way. An alert comes in overnight. Maybe it is an email from a security vendor. Maybe it lands in a shared...

read more...
cybersecurity

You Cannot Protect What You Have Not Identified

by Tim Marley | Feb 17, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...

read more...
doctor with laptop

The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough

by Heath Gieson | Feb 12, 2026 | Healthcare industry, Secure IT operations, Tech Insights

by Heath Gieson   For healthcare organizations, cybersecurity and compliance are no longer just IT concerns—they are material financial risks...

read more...
data management

CIS IG1 Control 3.1: Data Management is Not a Policy Problem

by Tim Marley | Feb 10, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

by Tim Marley   Over the course of my career, and particularly in the last five to ten years, the topic of data management comes up frequently....

read more...
CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices

CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices

by Andrew Scott | Feb 3, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

Most organizations assume that corporate devices only run approved software. In reality, that assumption is often wrong. Users are inherently...

read more...
supported software

CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference

by Andrew Scott | Jan 28, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

Most security conversations focus on what software exists in an environment. CIS Control 2.2 pushes the conversation one step further by asking a...

read more...
CIS IG1 Spotlight: Why a Software Inventory Is More Than a Security Requirement

CIS IG1 Spotlight: Why a Software Inventory Is More Than a Security Requirement

by Heath Gieson | Jan 22, 2026 | Cybersecurity, Secure IT operations, Tech Insights, Uncategorized

One of the themes we keep hitting in the CIS IG1 series is simple: you can’t protect what you don’t know you have. That’s true for hardware—and it’s...

read more...
CIS IG1 Control 1.2: Why Addressing Unauthorized Assets Matters—and How to Do It Easily

CIS IG1 Control 1.2: Why Addressing Unauthorized Assets Matters—and How to Do It Easily

by Heath Gieson | Jan 15, 2026 | Cybersecurity, Secure IT operations, Tech Insights

When we kicked off this series with Control 1.1: Establish and Maintain a Detailed Enterprise Asset Inventory, we focused on the Identify security...

read more...
Page 1 of 3112345...102030...»Last »

Every organization has technology goals.

Your business has unique goals, challenges, and opportunities. Our advisory team takes the time to understand where you are today, where you want to go, and the obstacles standing in the way. From there, we provide the strategic guidance needed to align technology, cybersecurity, and business priorities.

Gain clarity. Build momentum.
Scale with confidence.

Understand Your IT Priorities | Align Technology and Strategy | Strengthen Operations | Support Growth

Schedule a Call

Let's discuss your business and technology goals.

  • Follow
  • Follow
  • Follow
  • Follow
  • Follow
  • Follow
  • Follow

Explore

Contact Us
About Us
Careers
Events
Blog
Refer a client

Offices

HEADQUARTERS

2893 Executive Park Drive, Suite 204. Weston, FL 33331

(855) 796-3381

Forthright Technology Partners
Certified Minority-owned Business

© 2026 Forthright Technology Partners, Inc.

Sitemap
Privacy Policy
Client Portal
Website Accessibility Statement

Ticket submitted!

Please warm transfer call to (754) 356-1601.