read.cash Log in
@M.Rosenquist

@M.Rosenquist in May 2024

@M.Rosenquist

Unlocking SMB Cybersecurity: The Rise of Virtual CISOs in 2024 and Beyond This year, virtual CISOs must begin making a difference in our industry. For the longest time, small and medium businesses (SMBs) have been abandoned by the cybersecurity industry. But, SMBs need security leaders to guide them through the maze of cyber risk and craft practical strategies that align with their unique ever-evolving business objectives. Sadly, SMBs cannot afford an experienced full-time…

@M.Rosenquist

Unlock Your Cybersecurity Career - Exclusive Discounts on Top Training There are tremendous opportunities in cybersecurity and the industry needs many more qualified workers. Training plays an important part. That is why I am partnering with Infosec4TC, an online training provider that offers free courses in addition to affordable classes, to offer huge discounts on cybersecurity training (links below have embedded discount codes). https://school.infosec4tc.com/ I have…

@M.Rosenquist

And Security for All Podcast2024: Cybersecurity's Major Trends & Threat Dynamics I'm excited to be speaking live with Kim Hakim on the And Security For All podcast tomorrow to discuss 2024's Cybersecurity's Major Trends & Threat Dynamics, including the ever-changing role of a CISO and the accelerating risks of Nation State cyberattacks, among other dynamic threats. Join me LIVE tomorrow, Friday May 17th 12pm Pacific…

@M.Rosenquist

SEC Will Require Finance to Notify Breach Victims in 30 Days More SEC rules, this time mandating financial firms inform victims of data breaches within 30 days! Why wasn't this already a requirement? Last year, the SEC instituted requirements for publicly traded companies to inform investors of material cybersecurity events within 4 days. That edict spurred a small wave of misguided protests in the **#cybersecurity** community, who warned of bad omens which never…

@M.Rosenquist

North Korea is Trying to Embed Agents into IT Positions of Western Countries Attention IT departments, the FBI is warning US companies to be wary of inadvertently hiring North Koreans to remotely work in their IT departments, amid fears of data theft and hacking. We are seeing organized activities designed to mask the origins of North Korean people trying to infiltrate IT organizations and then leverage the access of those positions to harvest sensitive data and potentially…

@M.Rosenquist

New Cryptojacking Malware Breakdown New Cryptojacking Malware Breakdown - The GhostEngine cryptocurrency mining malware disables endpoint security protections, deletes logs, modifies the kernel, and digs-in to establish persistence. It all begins with getting the victim machine to launch one .exe file. Cryptojacking malware consumes the compute resources of the victim by running cryptocurrency mining software which then directs any cryptocurrency rewards to accounts that…

@M.Rosenquist

The Rise and Risks of Shadow AI Shadow AI, the internal use of AI tools and services without the enterprise oversight teams expressly knowing about it (ex. IT, legal, cybersecurity, compliance, and privacy teams, just to name a few), is becoming a problem! Workers are flocking to use 3rd party AI services (ex. websites like ChatGPT) but also there are often savvy technologists who are importing models and building internal AI systems (it really is not that difficult) without…