INTERPOL Takes Down a Infostealers Operation Congrats to INTERPOL for taking down a major cyber information-theft infrastructure! Over 20 thousand Ips/domains were shuttered and 41 servers that contained more than 100GB of sensitive data was seized. It is estimated this group, 32 of which were arrested, victimized over two-hundred thousand people by stealing their login credentials, credit card information, and cryptocurrency wallet keys. Such takedowns are a showcase of…
Cycles That Drive Cybersecurity The cybersecurity industry moves fast! The attackers are constantly adapting and relentless in their pursuits that victimize others. New users are being added to the global online ecosystem. Services are hungry for data, which is rising in total value. The result is more attacks and greater impacts. These detrimental effects shift consumers’ expectations which in turn drive the slow gears of regulation. With greater public concern comes a…
Why Threat Agents Must be Included in Cybersecurity Risk Assessments https://www.youtube.com/watch?v=MCof-cko2iI In the ever-evolving landscape of cybersecurity, organizations face a constant struggle: how to best allocate limited resources to maximize their defensive posture. No one has enough budget, personnel, or tools to defend against every conceivable threat. When effort is misapplied to low-risk areas, higher-risk areas are left exposed. This inefficiency can prove…
Bankers Association’s attack on cybersecurity transparency Myarticle on Help Net Securityhighlighting how the banking industry is leveraging their powerful lobbying groups to try and undermine the U.S. Securities and Exchange Commission 4-day cybersecurity reporting rule, which has been in place for over a year. https://www.helpnetsecurity.com/2025/06/03/bankers-association-attack-on-cybersecurity-transparency/ Their cited reasons are absurd and I fear the hidden reasoning…
Shameful Lobbying: Bankers Association’s Attack on Cybersecurity Transparency https://www.youtube.com/watch?v=zkWj0UqzoK0 Banking industry lobbyists are pressuring the SEC to gut the four-day breach disclosure rule — an essential safeguard for shareholders and potential victims. Their arguments are misleading, self-serving, and designed to protect profits over public trust. This video breaks down their claims and exposes the real motivations behind this disgraceful effort to…
War & Cyber: 3 Years of Struggle and Lessons for Global Security Russia is one of the most aggressive nations when it comes to state coordinated cyberattacks — and Ukraine has been at the center of their crosshairs for 3 years. This report, provided the State Service of Special Communications and Information Protection of Ukraine contains an incredible amount of cybersecurity insights, showcasing the coordinated aggressive cyberwarfare campaigns of Russia against Ukraine. It…
Serviceaide Data Breach is Part of a Larger Healthcare Trend https://www.youtube.com/watch?v=4Iqmgv3JXkQ Another big healthcare sector data breach, impacting 480 thousand Catholic Health patients. Their 3rd party vendor Serviceaide is the root cause of this exposure. This is the latest in many healthcare data breaches this year! Year-to-Date we are at a 25% increase in incidents as compared to the 2024 average! U.S. Department of Health and Human Services (HHS) @Office for…
Coinbase Hacked and Turns the Tables on the Cybercriminals! This is how you handle cybercrime digital extortion! Cybercriminals attempted to extort $20 million from Coinbase, but Coinbase refused and will instead fund a $20 million bounty for those that provide information that leads to the attacker’s arrest! This is AWESOME and should be the playbook for every company out there that is at risk of ransomware or other digital extortion! Never fund your enemy or make yourself…
Cybersecurity Leadership Coaching Very excited to share that I’m now offering cyber security leadership coaching! With over 35 years of experience, I have become an outspoken advocate, mentor, and respected authority in the field of cybersecurity. I can work with you on… ✅ Understanding emerging threats, opportunities, and the fundamental factors that drive the industry, in pursuit of optimal security levels ✅ Strengthening expertise in risk management leadership and career…
OneDrive’s New Sync May be a Privacy and Security Nightmare https://youtu.be/hZVjJNPrWIM There are many cybersecurity and privacy risks to consider, both from the user and the enterprise, when it comes to Microsoft's new OneDrive feature that will connect their personal OneDrive with their work device! LinkedIn:https://www.linkedin.com/in/matthewrosenquist/ YouTube:https://www.youtube.com/CybersecurityInsights Follow me on Substack:https://substack.com/@matthewrosenquist For…
PowerSchool Data Breach – Round 2 Extortions The PowerSchool data breachnightmare of 2024 doesn’t end. Here is a quick rundown to catch up, before I call out some key learnings: https://www.theregister.com/2025/05/08/powerschool_data_extortionist/ In December 2024, PowerSchool was breached by ransomware attackers who claimed to have copied 62 million records, a figure that PowerSchool has declined to specify. Forensic assessments indicated the company failed to apply basic…
Microsoft Listens to Security Concerns and Delays New OneDrive Sync Misuse of the newly announced Microsoft OneDrive synchronization feature puts corporate security and personal privacy at serious risk in ways not likely understood by the users. Microsoft wants people to connect their personal OneDrive file share with their work systems, synchronizing potentially private files onto their enterprise managed PCs. The problem is having these files copied to enterprise machines…
Cyberwarfare Funding Accelerates and Everyone is at Risk Nations are investing heavily in offensive cyber capabilities. The proposed 2026 US defense budget earmarks an additional $1 billion in funding for offensive cyber operations, specifically to the US Indo-Pacific Command (USINDOPACOM). In 2025, the Department of Defense spent over $14 billion on cyber, with $6.4 billion allocated to offensive operations. An extra billion dollars buys a significant boost in attack…
Practical Cybersecurity Leadership for IT Teams – Live Webinar! Join me on Thursday May 1st, 11am PT as a guest with Defendify on a live webinar where I’ll discuss practical cybersecurity leadership for IT teams! Communicating cyber risk in business terms to secure support and resources Importance of planning and preparedness to reduce risks Being an enabler versus a barrier to the business Selecting the right tools and services to maximize effectiveness and efficiency…
Simplifying Cyber Safety for Everyone with Sandra Estok https://www.youtube.com/watch?v=F_qC8n71y44 Cybersecurity is not just a technical endeavor. Attackers often pursue people to either gain access to valuable systems or to directly victimize them. This includes companies, adults, and even children. In this episode of the Cybersecurity Vault I talk with Sandra Estok, founder of Way2Protect, about social engineering and online fraud. The industry is realizing that people…
Breaking Down Risks in Cybersecurity https://youtu.be/Y60C5u6lzdI?si=XVq2oM9WJzxsn8OY Cyber Crime Junkies podcast Breaking Down Risks in Cybersecurity — A great conversation on the Cyber Crime Junkies podcast with David Mauro! We covered so many different topics that the CISOs are struggling with: · Generative vs Agentic AI risks and opportunities · How cyber attackers leverage powerful tools like AI · Why defenders are slower than attackers in using AI · How attackers adapt…
Boards Challenged to Embrace Cybersecurity Oversight Cybersecurity failures are now business risks that CEOs and Boards must own. The world of business owners, investors, and their representatives are collectively realizing the potentially catastrophic impacts of cybersecurity incidents if not incorporated into the strategic management of the most senior business leadership. Many regulatory bodies, insurance providers, business partners, and customers take cybersecurity very…
Are They Vulnerabilities or Undocumented Debug Features The recent undocumented code in the ESP32 microchip, made by Chinese manufacturer Espressif Systems, is used in over 1 billion devices and could represent a cybersecurity risk. Its reveal by security researchers has kicked off an interesting discussion regarding undocumented features in firmware devices - are they security vulnerabilities or just debug tools?…
Ransomware Attack Ends a 150 Year Company Knights of Old, a 150-year-old UK company, is gone – due to a cyberattack! This terribly unfortunate event is a good example of how cybersecurity matters to every company that depends on digital technology - even if it is to run your books or manage your logistics. Failures in cybersecurity can cause catastrophic impacts, up to and including the total loss of a business. The other point is that cybersecurity is not binary. It is not…
The CISO Transformation – A Path to Business Leadership The Chief Information Security Officer (CISO) position is on the precipice of transformation! The CISO role has dramatically changed over the years as the demands have significantly grown and expanded, elevating what was once a support function buried in IT to a high-profile role that regularly provides reports and updates to the Board of Directors. The Traditional CISO is becoming outdated and not on a trajectory for…
Cryptocurrency Hack of $1.5 Billion This may turn out to be the biggest #cryptocurrency hack in history! $1.5 BILLION. The details are sparse, but I am interested in the origins of this attack, especially if it was from a nation-state level attacker. Apparently, it was the cold wallet that was compromised, which is impressive. Cold wallets are specifically designed to protect against such attacks! In my 2025 Cybersecurity Predictions, I predicted that cryptocurrency would be…
Cybersecurity Perspectives for 2025 – Rinki Sethi https://www.youtube.com/watch?v=U3BQxZroX9k The Cybersecurity Vault - episode 44, with guest Rinki Sethi. 2025 will be an interesting year for the cybersecurity industry! Cybersecurity Insights interviews experts for their take on the most relevant changes. Rinki Sethi discusses how attackers are maneuvering, how business conditions are changing, and how technology innovation is impacting cybersecurity. Rinki’s LinkedIn…
Strategic Insights of Cybersecurity – Career, Threats, AI, and Advice https://www.youtube.com/watch?v=mnzaphZ6GOE A fantastic discussion covering: Career Lessons & Leadership – Pursuing Impossible Problems Strategic Insights of Cybersecurity – Applying “The Art of War” AI in Cybersecurity – Both Real and Fake Fears! Cyber Insurance and the Challenges of Risk Metrics Advice for Cybersecurity Professionals – Being a Trusted Manager Risks in the Face of Chaos Much thanks to…
Healthcare Crisis Emerges: Cybersecurity Vulnerabilities in Patient Monitors Confirmed by FDA For over a decade, we warned the healthcare industry this was coming. They ignored us. Their sole focus was HIPAA compliance — checking regulatory boxes rather than securing critical systems. We told them that system and service availability attacks were coming too. They didn’t care — until they were hit, and hospitals could no longer process new patients or handle billing. The…
Top 100 B2B Thought Leaders, Analysts & Influencers I am honored to be recognized by **Thinkers360** as one of the "Top 100 B2B Thought Leaders, Analysts & Influencers You Should Work With In 2025 (North America)"! https://www.linkedin.com/company/thinkers360/ Full List: **https://www.thinkers360.com/top-100-b2b-thought-leaders-analysts-influencers-you-should-work-with-in-2025-north-america/**
The Data Diva Talks Privacy Podcast https://www.youtube.com/watch?v=2u6E8r1OUo4&list=PLHWfb3mQ5tvpw1urr-MZHWvCCoXVbBS_I I had such a wonderful conversation with Debbie Reynolds on here podcast "The Data Diva Talks Privacy". Cybersecurity and Data Privacy are conjoined. We will succeed or fail together! We all must work closer to protect the data and systems of our digital ecosystem! Audio and transcript: https://www.debbiereynoldsconsulting.com/podcast/e221-matthew-rosenquist
A Top Cybersecurity Career Coach Who is this cybersecurity guy on a New York Times Square billboard? Thanks topmate.io for the recognition of being one of the Top Career Coaches in the US! **Cyber threats are evolving, and cybersecurity leaders must stay ahead.** I help executives and security leaders understand emerging risks, optimize limited resources, and transform cybersecurity programs to deliver more meaningful business value. By proactively addressing threats and…
The Cybersecurity Vault Podcast 2024 Recap My deepest appreciation to all the incredible cybersecurity luminaries who joined *The Cybersecurity Vault* podcast last year! Your insights, expertise, and thought-provoking discussions made each episode invaluable for the audience and myself. I appreciate your time and dedication to advancing the industry! **The Cybersecurity Vault Podcast 2024 Recap:** **Ian Thornton Trump**, CISO at Cyjax Limited - Loops and Angles of…
Cybersecurity Perspectives for 2025 – Insights from David Hahn https://www.youtube.com/watch?v=BCToMyW0u-M The Cybersecurity Vault — episode 43, with guest David Hahn. 2025 will be an interesting year for the cybersecurity industry! Cybersecurity Insights is interviewing experts for their take on the most relevant changes. Experts discuss how attackers are maneuvering, how business conditions are changing, and how technology innovation is impacting cybersecurity. David is…
10 Cybersecurity Predictions for 2025 The cybersecurity landscape is poised for transformation in 2025. The rapid evolution of technology, coupled with the increasing sophistication of threat actors, presents a future that is both exciting and daunting. In this era of digital interconnectedness, understanding the potential cybersecurity challenges that lie ahead is a crucial requirement to protect it from rapidly evolving threats. The following predictions and…