Ensure Use of Only Fully Supported Browsers and Email Clients Your web browser and your email client are the two applications your people use most, and the two attackers target most, because that’s where the outside world reaches into your business. Control 9.1 asks a simple question about both: is the version you’re running still supported by the vendor? An unsupported browser or mail client isn’t just old. It’s software the vendor has stopped fixing, which means every...

You Cannot Protect What You Have Not Identified
by Tim Marley Last week we talked about data management at a high level. The operating model, the responsibility, the reality that organizations are...
The Financial Risk of Healthcare Non-Compliance: Why “Good Enough” Security Is No Longer Enough
by Heath Gieson For healthcare organizations, cybersecurity and compliance are no longer just IT concerns—they are material financial risks...
CIS IG1 Control 3.1: Data Management is Not a Policy Problem
by Tim Marley Over the course of my career, and particularly in the last five to ten years, the topic of data management comes up frequently....
CIS IG1 Control 2.3 — Why Unauthorized Software Is a Hidden Threat Lurking on “Trusted” Devices
Most organizations assume that corporate devices only run approved software. In reality, that assumption is often wrong. Users are inherently...
CIS IG1 Control 2.2 — Why Running Supported Software Is a Security Requirement, Not an IT Preference
Most security conversations focus on what software exists in an environment. CIS Control 2.2 pushes the conversation one step further by asking a...
CIS IG1 Spotlight: Why a Software Inventory Is More Than a Security Requirement
One of the themes we keep hitting in the CIS IG1 series is simple: you can’t protect what you don’t know you have. That’s true for hardware—and it’s...
CIS IG1 Control 1.2: Why Addressing Unauthorized Assets Matters—and How to Do It Easily
When we kicked off this series with Control 1.1: Establish and Maintain a Detailed Enterprise Asset Inventory, we focused on the Identify security...
CIS IG1 Control 1.1: Establish and Maintain a Detailed Enterprise Asset Inventory
By Heath Gieson If you don’t know what you have, how can you protect it? That simple question is why the very first control in the Center for...
CISOs’ Security Priorities: The Augmented Cyber Agenda—and How Forthright Is Leading the Way
Cybersecurity leaders are facing a rapidly evolving threat landscape. According to CSO Online’s latest Security Priorities Study , CISOs (Chief...













