Quantum Incident Response

When the first cryptographically relevant quantum computer (CRQC) arrives, it won’t come with a press release. One day in the not too distant future, a nation-state, organized crime group or unhinged megalomaniac billionaire will quietly spin up the capability, and in eight hours or less, your TLS (Transport Layer Security) RSA-2048 encryption is gone. Like a hot knife through butter.

Endpoint Data Loss Prevention: Everything You Need to Know

Endpoint data loss prevention (DLP) is a critical compliance service designed to ensure that an organization's sensitive or confidential information remains secure by implementing robust security controls and continuously monitoring devices to protect data from unauthorized access or transmission and prevent potential data breaches.

This is how you stop drowning in noise and start preventing breaches.

Security teams are drowning in a sea of noise. The good news? The solution isn't to work harder, but to work smarter. Breach Risk's threat monitoring capabilities use source-aware Transforms to automatically fan out and detect exposures across the open, deep, and dark web, including platforms notoriously difficult to monitor, such as GitHub and Telegram, and ransomware blogs, forums, and illicit marketplaces.

What is Insider Risk Management?

In this video, we explain the basics of insider risk management — the practice of identifying, assessing, and reducing the risks that come from employees, contractors, or partners who have access to sensitive data. Insider risk management goes beyond traditional data loss prevention by addressing both malicious and accidental insider threats. From protecting intellectual property to preventing data leaks, insider risk management helps organizations secure their most valuable information.

Warning: New Spear Phishing Campaign Targets Executives

Researchers at Stripe warn of a wave of spear phishing attacks targeting C-suite employees and senior leadership across a wide range of industries. The emails pose as OneDrive document-sharing notifications with subject lines like “Salary amendment” or “FIN_SALARY.” If a user clicks the link, they’ll be taken to a spoofed Microsoft Office/OneDrive login page designed to steal their credentials.

The Hidden Costs of Remote Support Security Incidents-And How to Mitigate Them With Tanium + ScreenMeet

Remote support is essential for modern IT operations, but legacy tools have become a growing liability. In 2024, a series of high-profile breaches revealed how attackers exploited remote access platforms to infiltrate critical systems. These incidents exposed not only technical vulnerabilities but also the broader financial, operational, and reputational risks tied to outdated support architectures.

KnowBe4: The Most Advanced Human Risk Management Platform

Strengthen your organization's security with the KnowBe4 human risk management platform! KnowBe4 helps you manage and reduce cyber risk by focusing on the human layer of security. Traditional security measures often overlook the fact that people are the biggest variable in your defense. KnowBe4's comprehensive platform goes beyond simple training, providing a full suite of tools to build a strong security culture and transform your employees from a potential vulnerability into your strongest line of defense.

What is Data Lineage?

In this video, we break down the concept of data lineage — a way to track how data moves, changes, and is used across your organization. Data lineage provides visibility into the lifecycle of sensitive information, from where it originates to where it flows, and who interacts with it. Understanding data lineage helps organizations improve security, ensure compliance, and reduce insider risk. Watch now to learn what data lineage is, why it matters, and how it helps protect your most valuable data.

Advanced Educational Competition - Ask Your Employees To Submit Their Best Phishing

I occasionally get human risk management (HRM) administrators asking me to help them with ideas of “contests” to better educate their end-users. They have usually done the traditional recommendations, which means at least monthly-to-weekly security awareness training (SAT) and simulated phishing. They are working to educate their end-users about social engineering and phishing attacks as best as they can without being overly annoying.