Require MFA for Externally‑Exposed Applications This article is part of our ongoing CIS IG1 series focused on practical, high‑impact security controls. In this section of the framework, identity takes center stage. Rather than focusing on new tools or complex...
Trending at Forthright.
CIS IG1 Control 6.2 – Establish an Access Revoking Process
by Heath Gieson If access granting is where intent is established, access revoking is where discipline is revealed. Most organizations do not struggle with revoking access because they disagree with the idea. They struggle because no one clearly owns the moment...
You Can’t Manage What You Can’t See
by Tim Marley As we move into CIS Control 5, Account Management, we're going to spend a few weeks working through the individual safeguards. We're starting with 5.1: Establish and Maintain an Inventory of Accounts. This control comes back to a principle we've already...
CIS IG1 Control 4.7: Manage Default Accounts on Enterprise Assets and Software
by Heath Gieson Manage Default Accounts on Enterprise Assets and Software As we continue through the CIS IG1 controls, a consistent pattern keeps emerging. Many security incidents don’t begin with advanced techniques or sophisticated tooling. They start with simple,...
More Updates Don’t Mean More Risk — They Mean Better Security
Why More Updates Are Coming — and Why That’s a Good Thing Over the next several weeks, organizations are likely to notice something familiar but more pronounced than usual: an uptick in software updates across devices, operating systems, browsers, and applications....
CIS IG1 Control 4.6: Securely Managing Network Gear
When the Management Plane Becomes the Attack Plane by Heath Gieson A few years ago, I was sitting in a conference room with an executive team after...
The Unlocked Screen in the Corner Office: What CIS Control 4.3 Requires and Why Biometrics Make It Easier Than You Think
by Heath Gieson Some attacks are sophisticated. Weeks of reconnaissance, carefully crafted phishing emails, vulnerabilities quietly exploited in the...
CIS IG1 Control 3.6: Encrypt Data on End User Devices—Because Lost Doesn’t Have to Mean Exposed
by Heath Gieson As we continue our weekly journey through the CIS IG1 controls, each safeguard builds on the operational foundations we’ve been...
You Cannot Protect What You Have Not Identified
by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...
CIS IG1 Control 3.1: Data Management is Not a Policy Problem
by Tim Marley Over the course of my career, and particularly in the last five to ten years, the topic of data management comes up frequently....
CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices
Most organizations assume that corporate devices only run approved software. In reality, that assumption is often wrong. Users are inherently...
CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference
Most security conversations focus on what software exists in an environment. CIS Control 2.2 pushes the conversation one step further by asking a...
CIS IG1 Spotlight: Why a Software Inventory Is More Than a Security Requirement
One of the themes we keep hitting in the CIS IG1 series is simple: you can’t protect what you don’t know you have. That’s true for hardware—and it’s...
🚨 Why Companies & Users Should Avoid the OneStart Browser 🚨
As security leaders, we’re constantly pitched tools that promise productivity gains. OneStart, an AI-powered browser, claims to integrate ChatGPT,...









