Applying a Cybersecurity Threat Agent Risk Assessment to Healthcare There are many approaches to conduct a strategic cybersecurity risks assessment. This is one of my favorite ways, using a Threat Agent Risk Assessment (TARA) methodology. This paper was authored by Tim Casey, David Houlding, and I while we were at Intel. It showcases how to understand the origins of cybersecurity threats to an organization. The resulting knowledge can greatly improve the management of cyber…
@M.Rosenquist in July 2023
Cybersecurity Meetup – 2023 Cybersecurity Predictions https://www.youtube.com/watch?v=pxcTzzr47pM Check the calendar as Richard Stiennon and I discuss the forward-looking cybersecurity predictions for 2023 and beyond! With several decades of knowledge and experience between us, we take a pragmatic look into the crystal ball. Those who have an understanding of what is coming will have an advantage to deal with the risks and seize the opportunities.
Delayed Reporting of HCA Healthcare Data Breach The recent HCA Healthcare data breach of 11 million patients’ data is shaping up to be another ugly incident where a company did not promptly communicate with its customers. HCA Healthcare is a large American healthcare services organization that covers 180 hospitals and over two thousand care centers across 20 states. The loss of data is bad, as it includes 27 million rows and contains identity, contact, birthdate, and email…
National Cybersecurity Plan Fails to Address Ransomware https://www.youtube.com/watch?v=4oSr-3dbHDg The US National Cybersecurity Strategy Implementation Plan fails to address ransomware. There is a real opportunity for the government to make significant progress in crushing the growing scourge of ransomware attacks which threaten businesses, individuals, and the range of Critical Infrastructures that all citizens rely upon. Although the 2023 National Cybersecurity Strategy…
New SEC Rules Mandate Cybersecurity Transparency and Oversight The new SEC Rules establish a framework that requires rapid disclosure of material cybersecurity incidents (4 days), companies will need to be able to explain their cybersecurity posture to manage risks, and for boards to describe their oversight and expertise for cybersecurity. This is a major leap forward for securing US public companies! The new regulation drives transparency of incidents, risk management…