Protecting From Cloud Based Attacks - Webinar https://www.youtube.com/watch?v=1ifsuGtfY5w *Cloud attacks are different. Attackers can strike extremely fast using advanced techniques and automation. Is your team prepared to investigate and respond to cloud threats in less than 10 minutes?* *According to the 555 Benchmark for cloud detection and response (CDR), in the cloud, teams have only:* *➔ 5 seconds to detect* *➔ 5 minutes to investigate* *➔ 5 minutes to respond* *This Tuesday, June 25th, I’m partnering with CloudSecurity experts from Sysdig to discuss why EDR/XDR falls short in the cloud. Tune into our live webinar at 10 am PDT to discover how your security team can investigate cloud threats in 5-minutes or less and meet the 555 Benchmark for CDR.* *Register here:* *https://bit.ly/CDR-Webinar*
@M.Rosenquist
Joined 22 January 2020 · 411 posts
Cybersecuirty strategist and technologist focused on making digital technology trustworthy
120 KT
0 KT · $23.59 received · 0 KT · 8¢ given
Posts
Kraken Hacked by Cybersecurity Researchers When cybersecurity researchers break the law, destroy their reputation, and make the bug-bounty research community look bad. TL:DR Researchers found a vulnerability in a cryptocurrency exchange. They notified the company, but then exploited the bug to steal millions. The irony is that the “security researchers” are claiming bad faith on behalf of Kraken, even though it was them who took millions in assets that did not belong to them. That is not how bug-bounties and ethical cybersecurity research is supposed to work! Full article: https://www.theregister.com/2024/06/20/kraken_certik_crypto_dispute
Modern CISO Network: A directory of board-ready security leaders I never imagined I would see my face in the The New York Times! Yet there I am, thanks to Lacework! I am so very honored to be included in their latest edition of Modern CISO Network: A directory of board-ready security leaders! Board ready CISOs play an important role in assisting C-suites/Boards in directing the cybersecurity capability to be optimized, sustainably effective, and aligning it to serve the shareholder needs. Thanks Lacework and congratulations to everyone recognized!
Reality of Cybersecurity Risks for AI https://www.youtube.com/watch?v=lRnmWMKlQtg The explosive growth of GenAI has serious repercussions for cybersecurity. But is the fear being overplayed in the media? What are the realistic risks and what should security and business leaders be doing to protect their organization. In this week’s Cybersecurity Vault podcast (episode 33), I talk with Ejona Preci, the Principal Manager for Cybersecurity Risk and FREE NOW, to discuss how AI is driving change, leading to new best practices, and how the traditional leader mindset can become a trap when “*when cybersecurity leaders are trying to be the smartest in the room, they are failing to make the room smarter!*” https://www.youtube.com/CybersecurityInsights https://www.linkedin.com/in/ejonapreci/ Ejona’s Cyberstar Talk Podcast https://cyberstartalkspodcast.buzzsprout.com/ Ejona’s LinkedIn profile: https://www.linkedin.com/in/ejonapreci/ Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
CoinGecko Data Breach
Come join the LIVE discussion: Cybersecurity's Major Trends & Threat Dynamics Live tomorrow June 7th 2024 on LinkedIn at noon Pacific/2pm CT — Join a brand new Voice America episode of ***And Security For All!*** Matthew Rosenquist, CISO and Cybersecurity Strategist at Mercury Risk and Compliance, Inc., will be joining Jonathan Kimmitt to explore a variety of major industry trends. This includes giving us insight into the ever-changing role of a CISO and the accelerating risks of Nation State cyberattacks, among other dynamic threats. These two will blow your mind with their never-ending knowledge. Make sure to tune in LIVE to ask Matthew and Jonathan your questions during the show! See you tomorrow. Register: https://www.linkedin.com/events/2024-cybersecurity-smajortrends7204524836725956610/theater/
Microsoft Recall Cybersecurity & Privacy Risks You Need to Know About! https://www.youtube.com/watch?v=ifrgXKnnApA Microsoft created Recall as a tool to benefit the user, but it has far more value to cybercriminals, hackers, data brokers, digital extortionists, and malicious insiders! In today’s video, I discuss the risks and what Microsoft should do to protect users security and privacy, before they release the Recall feature! Follow for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights
The Real Value for Operation Endgame Malware Takedown https://www.youtube.com/watch?v=EyxGRfA135o Operation Endgame has taken down a major cyber criminal infrastructure. This is important, but likely not for the reasons you may think. The multi-national law enforcement effort, led by EUROPOL, seized over 100 servers and 2 thousand domains that hosted dropper malware. Droppers play a key role in malware propagation. They are small programs, often distributed via phishing, trojans or malicious websites, that facilitate the installation of sophisticated malware packages. They are difficult to detect and can even run exclusively in memory, hiding from anti-malware. They essentially open the victim’s door to hackers. Operation Endgame is important, but not because it dismantled the cybercrime infrastructure. Modern criminals often rebuild such services in a matter of days or weeks. The real significance of operations like these is to put pressure and stress on the threat actors, forcing them to spend time and resources protecting and rebuilding their environments. It puts them on the defense and keeps them from rampantly scaling their operations! So, great work Europol! Keep up the pressure! Follow for more Cybersecurity Insights: https://www.youtube.com/CybersecurityInsights
50 CISOs & Cybersecurity Leaders Shaping the Future I am honored and humbled to be listed among such influential luminaries who collectively push our industry to continually adapt to make our digital ecosystem trustworthy! An incredible list of cybersecurity CISOs and leaders that drive innovation for better value, foster industry awareness and collaboration, and optimize the protection of their organization! 50 top CISOs and cybersecurity leaders to know 1. Dmitri Alperovitch is a cybersecurity thought leader, podcast host, and the bestselling author of *World on the Brink*. He is currently the Executive Chairman at Silverado Policy Accelerator, host of the *Geopolitics Decanted* podcast, and Board Member at Automax, Dragos, Inc., Cyber Safety Review Board, Homeland Security Advisory Council, National Security Institute - George Mason University - Antonin Scalia Law School, and The Cipher Brief. https://www.linkedin.com/in/dmitrialperovitch/ 2. Darren Argyle FCIIS is currently the Group Chief Information Security Risk Officer at Standard Chartered Bank, and the former Group Chief Information Security Officer (CISO) at Qantas Airlines, Group CISO at IHS Markit, and has held various senior international cybersecurity leadership roles at Symantec and IBM. Argyle was awarded “Outstanding Cyber Security Professional” by the Cyber OSPAs, the CSO30 ASEAN Award, and “Innovator of the Year” by SANS Institute in 2022. https://www.linkedin.com/in/darrenargyle/ 3. Bret Arsenault is the Corporate Vice President and Chief Cybersecurity Advisor at Microsoft, where he’s spent nearly 35 years as an information security leader. In his current role, he acts as a key advisor to senior and security leadership teams across engineering, products, risk, and resiliency. https://www.linkedin.com/in/bret-arsenault/ 4. Gerald Auger, PhD is the Chief Content Creator at Simply Cyber, which boasts over 4 million views on YouTube. He is also an Adjunct Professor at The Citadel, Conference Director for Simply Cyber Con, Managing Partner at Coastal Information Security Group, and Advisory Board Member at Panoptcy Security. https://www.linkedin.com/in/geraldauger/ https://www.youtube.com/channel/UCG-48Ki-b6W_siaUkukJOSw 5. Jessica Barker, MBE, PhD, is a bestselling author, international keynote speaker, and cybersecurity thought leader. She is Co-founder and Co-CEO at Cygenta. https://www.linkedin.com/in/jessica-barker/ 6. Jerich Beason is a cybersecurity podcast host, keynote speaker, board advisor, and instructor who is currently serving as Chief Information Security Officer at WM. https://www.linkedin.com/in/jerich-beason/ 7. Charlie Bell is Executive Vice President leading the Security, Compliance, Identity, and Management organization at Microsoft. He is a former Senior Vice President at Amazon Web Services, where he spent over 20 years growing the AWS business and leading general management of AWS services. https://www.linkedin.com/in/charlie--bell/ 8. Chuck Brooks is the President of Brooks Consulting International and an Adjunct Professor at Georgetown University. As a thought leader, author, and speaker, Brooks has spoken before the G20, US Embassy to the Holy See and Vatican, and USTRANSCOM as well as served on two National Academy of Science Advisory groups and an industry/government working group for CISA. Brooks has also received presidential appointments for executive service by two U.S. Presidents. https://www.linkedin.com/in/chuckbrooks/ 9. Kip Boyle is a cybersecurity expert, host of the Your Cyber Path Podcast and Cyber Risk Management podcasts, and a course instructor at Udemy. As Fractional Chief Information Security Officer at Cyber Risk Opportunities LLC, Boyle provides cyber risk expertise to companies including the US Federal Reserve Bank, Boeing, Visa, Intuit, Mitsubishi, and DuPont. https://www.linkedin.com/in/kipboyle/ 10. Naomi Buckwalter is an information security leader and the Founder and Executive Director of Cybersecurity Gatebreakers Foundation, which is committed to breaking down barriers of entry and solving the cybersecurity labor shortage. In addition, Buckwalter is also the Sr. Director of Product Security at Contrast Security. https://www.linkedin.com/in/naomi-buckwalter/ 11. Bob Carver, CISM, CISSP, MS is a Principal Cybersecurity Threat Intelligence and Analytics at Verizon with over 25 years of experience in information security, specializing in threat hunting. He also serves on the Advisory Board of LexisNexis Fraud Defense Network and has served on the Advisory Board at Mastercard - Masters Collective. https://www.linkedin.com/in/bobcarver/ 12. Dr. Magda Chelly is a published author, TEDx speaker, and globally recognized cybersecurity leader, recently recognized as a Microsoft Most Valuable Professional in Artificial Intelligence and Cloud Security. Chelly is the co-founder of RiskImmune, Chief Information Security Officer at Responsible Cyber Pte. Ltd., Advisory Board Member at Black Hat, and Sessional Lecturer, Cybersecurity at James Cook University. https://www.linkedin.com/in/magda-chelly-responsible-cyber-immune-x-tprm/ 13. Anton Chuvakin is the Security Advisor at Office of the CISO, Google Cloud and the co-host of Cloud Security Podcast. Formerly a Research VP and Distinguished Analyst at Gartner for Technical Professionals, Security and Risk Management Strategies, he is also the author of *Security Warrior, PCI Compliance, Logging and Log Management*, and the securitywarrior.org blog as well as a contributor to the books *Know Your Enemy II* and *Information Security Management Handbook.* https://www.linkedin.com/in/chuvakin/ http://securitywarrior.org/ 14. Graham Cluley is an award-winning cybersecurity speaker, writer, analyst, and host of the “Smashing Security” podcast, which has over nine million downloads. https://www.linkedin.com/in/grahamcluley/ 15. Steve Cobb is Chief Information Security Officer at SecurityScorecard. With decades of experience leading IT infrastructure, cybersecurity, incident response, and threat intelligence, Cobb was formerly Chief Information Security Officer at One Source Communications and a senior engineer at Microsoft and Verizon Enterprise Solutions. https://www.linkedin.com/in/wscobb/ 16. Edna Conway is a top information security voice, author, executive advisor, board director, and cloud technology executive. She is a Sr. Nonresident Fellow at Carnegie Endowment for International Peace, Advisor at Getz Executive Network, and a board member at Critical Start, Red Queen Dynamics, Inc., NightDragon, Interos Inc., Attabotics Inc., Active Cypher, Long Ridge Equity Partners, YL Ventures, DUST Identity, InfoSec Global, EMC Advisors, and SecurityScorecard. https://www.linkedin.com/in/ednaconway/details/experience/ 17. Sam Curry is Global VP and CISO in Residence at Scaler, as well as a Board Member at Cybersecurity Coalition and CyberTrust Massachusetts and a Fellow at the National Security Institute. With experience at RSA, Arbor Networks, McAfee, and Cybereason, he is also currently serving as an adjunct professor at Nichols College. https://www.linkedin.com/in/currysam/ 18. Rik Ferguson is the VP of Security Intelligence at Forescout Technologies and the Co-Founder of Respect in Security. He is also a Fellow at the RSA, Special Advisor at Europol, and Advisory Board Member at Vaulter. https://www.linkedin.com/in/rikferguson/ 19. Christophe Foulon, CISSP, GSLC, MSIT is a seasoned vCISO and cybersecurity leader, currently serving as Fractional CISO at Nexigen and Executive Cybersecurity Advisor at CPF Coaching. Foulon was formerly a Senior Cybersecurity Advisor at Capital One and Cybersecurity Adjunct Professor at Bellevue University. https://www.linkedin.com/in/christophefoulon/ 20. Jane Frankland is an award-winning author, speaker, coach, advisor, and cybersecurity influencer. She currently serves as an Advisory Board Member Executive Summit at Black Hat, Founder of The Source Platform (for Women in Cyber), Founder of IN Security Movement, StrategicAdvisor for e2e-assure, and Owner and CEO at KnewStart. https://www.linkedin.com/in/janefrankland/ 21. Mari Galloway, MSIS, CISSP, is an Advisor at BestLink Strategies, LLC, bestselling author, and founding board member of the Women’s Society of Cyberjutsu. https://www.linkedin.com/in/themarigalloway/ 22. Carlos Gonzalez is the Chief Information Officer at Epiq. Former President at CEG Tecnology LLC and VP/CIO of Information Services at Mt. Sinai South Nassau Hospital, he’s built secure and scalable operations for healthcare, legal, and financial companies. https://www.linkedin.com/in/carlos-gonzalez-76b9204/ 23. John Hammond is a cybersecurity researcher, educator, speaker, and content creator with over 1.5 million subscribers. He is currently part of the Threat Operations team at Huntress. https://www.linkedin.com/in/johnhammond010/ 24. Tia (Yatia) Hopkins is Chief Cyber Resilience Officer at eSentire, guest lecturer at The Wharton School, and Adjust Professor and Course Author - MS in Cybersecurity at Katz School at Yeshiva University. Hopkins is recognized as The Cyber Equalizer™, a global award-winning cyber exec, best-selling author, and keynote speaker. https://www.linkedin.com/in/yatiahopkins/ 25. Troy Hunt is Founder and CEO of Have I Been Pwned, an organization that helps individuals assess their exposure in major data breaches. He is also an Information Security Author & Instructor at Pluralsight, Partner at Report URI, and Director at Superlative Enterprises, where he conducts professional speaking, training, and writing engagements. https://www.linkedin.com/in/troyhunt/ 26. Diane M. Janosek, PhD, JD, CISSP, LPEC, is an award-winning cybersecurity leader, attorney, author, and speaker. Currently CEO at Janos LLC Practices and former member of the Defense Intelligence Senior Executive Service. Janosek also served as the National Security Agency’s Deputy Chief of Compliance. https://www.linkedin.com/in/diane-janosek-abc/ 27. Zinet Kemal is a noted cloud security engineer, TedX Speaker, and author who’s been recognized as a Top 25 Cybersecurity Leader, Most Inspiring Woman in Cyber, and 40 Under 40. She is the founder of ZNET LLC and an experienced cloud security engineer for Fortune 500 companies. https://www.linkedin.com/in/zinetkemal/ 28. Brian Krebs is an investigative reporter focused on internet security and cybercrime. A former reporter for the *Washington Post* for 15 years, Krebs is also the author of *Spam Nation: The Inside Story of Organized Cybercrime, from Global Epidemic to Your Front Door* and a reporter and publisher at KrebsOnSecurity.com. https://www.linkedin.com/in/bkrebs/ https://krebsonsecurity.com/ 29. Dan Lohrmann is a cybersecurity leader, advisor, mentor, blogger, and keynote speaker who has been named SC Magazine CSO of the Year, Governing Magazine Public Official of the Year, Computerworld Premier 100 Leader, and 2023 Top 30 People to Follow on Cyber. Lohrmann has advised leaders at the White House, National Governor’s Association, National Association of State CIOs, US Department of Homeland Security, and many other federal, state, and local government agencies as well as Fortune 500 companies. He is currently the Field Chief Information Security Officer leading public sector advisory at Presidio. https://www.linkedin.com/in/danlohrmann/ 30. Mark Lynd is a globally recognized thought leader, C-suite strategist, author, and keynote speaker on cybersecurity and AI. He is currently the Head of Executive Advisory & Corporate Strategy - CISSP, ISSAP &ISSMP at NETSYNC and has received several awards and recognitions for his leadership in cybersecurity. https://www.linkedin.com/in/marklynd/ 31. Mic Merritt is the Founder of Merritt Based, a cybersecurity firm specializing in Artificial Intelligence/Machine Learning systems and web/mobile application penetration testing. Merritt is also a Cybersecurity Instructor at Western Governors University https://www.linkedin.com/in/micmerritt/ 32. Daniel Miessler is the Founder of Unsupervised Learning and an Advisor at ProjectDiscovery, JupiterOne, and AKA Identity. Formerly the Head of Vulnerability Management at Robinhood, Miessler is an expert in AI and security infrastructure. https://www.linkedin.com/in/danielmiessler/ 33. Alyssa Miller is an author, international speaker, and experienced security executive. Formerly the Business Information Security Officer at S&P Global Ratings, Miller is currently CISO at Epiq Global and a member of the Technology Advisory Board at Epiphany Solution Group. https://www.linkedin.com/in/alyssam-infosec/ 34. Charlie Miller is a Distinguished Security Engineer, Autonomous Vehicle Security at Cruise. A former hacker for the National Security Agency, Miller has previously worked as a consultant and as a Staff Security Engineer at Twitter. https://www.linkedin.com/in/charliemiller2/ 35. Angelique “Q” Napoleon is Cybersecurity Director, Division Deputy CISO & Cyber Capability Lead at General Dynamics Information Technology and a former Principle Cybersecurity Subject Matter Expert at the US Department of Defense. https://www.linkedin.com/in/angelique-q-napoleon-7b67977/ 36. Henrik Parkkinen is Information Security Officer at WirelessCar and a subject matter expert at ISACA. Parkkinen is recognized as a top cybersecurity voice and a 40 Under 40 in Cybersecurity. https://www.linkedin.com/in/henrikparkkinen/ 37. Chris Roberts is a cybersecurity strategist, researcher, and advisor who is currently Chief Strategist at Nuspire, CISO Advisory Board Member at Onyx Cyber, and Founding Board Member at Security Tinkerers. He also co-hosts the podcast *WTF Did I Just Read*. https://www.linkedin.com/in/sidragon1/ 38. Matthew Rosenquist is a cybersecurity leader, speaker, and advisory board member with over 190k LinkedIn followers. He is currently CISO and Cybersecurity Strategist at Mercury Risk and Compliance, Inc., as well as a Board Member at The Futurum Group, Dominican University of California, United Cybersecurity Alliance, World Business Angels Investment Forum, Private Directors Association, and the University of Phoenix, College of Business and Information Technology, among others. He was formerly Cybersecurity Strategist for the Artificial Intelligence group and Cybersecurity Strategist and Evangelist at Intel. https://www.linkedin.com/in/matthewrosenquist/ 39. Shira Rubinoff is a cybersecurity executive, advisor, keynote speaker, and author who serves on the Boards of Pace University Cybersecurity Program, The Executive Women’s Forum for Information Security, Leading Women in Technology, and others. Her verified YouTube channel has over 172k subscribers, and she has been named a Woman of Influence by CSO Magazine, the “One to Watch” award by CSO and the EWF, and the “Outstanding Woman in Infosec” by the CyberHub Summit. She is currently President - Cybersphere at The Futurum Group. https://www.linkedin.com/in/shirarubinoff/ http://youtube.com/ShiraRubinoffTV 40. Caitlin Sarian is the Founder and Executive Director at Cybersecurity Girl LLC and former Global Lead of Cybersecurity Advocacy and Culture at TikTok. https://www.linkedin.com/in/caitlin-sarian/ 41. Rinki Sethi is VP and CISO at BILL and a Former VP & CISO at Twitter, with experience developing online security infrastructure for companies including IBM, PG&E, Walmart.com, eBay, Intuit Inc., and Palo Alto Networks. She has been recognized by CSO Magazine and SC Magazine as a top information security leader. https://www.linkedin.com/in/rinkisethi/ 42. Richard Stiennon is a research analyst and author of the *Security Yearbook* series. He is Chief Research Analyst at IT-Harvest and a Board Member at sāf.ai, Inc., Quick Heal, Anitian, and Phosphoroous Cybersecurity Inc. https://www.linkedin.com/in/stiennon/ 43. Dean Sysman is CEO/Co-founder at Axonius, a cybersecurity asset management system. As a leading cybersecurity expert, Sysman has spoken at major conferences including Black Hat, Defcon, CCC, and more. https://www.linkedin.com/in/deansysman/ 44. Eric Vanderburg is a noted cybersecurity author and consultant. He is currently Vice President, Cybersecurity at TCDI, where he leads the cybersecurity consulting division. https://www.linkedin.com/in/evanderburg/ 45. Fabian Weber is a vCISO and Head of Compliance at PCG, where he lends his expertise to helping startups and SMBs achieve ISO 27001, SOC 2, and TISAX compliance. He is also CEO & Founder of WHYSEC and a Managing Partner at water IT Security & Defense. https://www.linkedin.com/in/fabian-weber55/ 46. Tyler Cohen Wood, CISSP is a cybersecurity expert, author, and influencer who previously worked at the US Defense Intelligence Agency under the Department of Defense serving as Senior Intelligence Officer, Deputy Cyber Division Chief of the Special Communications Division. Tyler is currently co-founder of Dark Cryptonite and an on-air host at ITSPmagazine Podcasts. https://www.linkedin.com/in/tylercohen78/ 47. Burcu Yarar is Application Security Team Lead at VakifBank, Pentester/Bug Hunter at HackerOne, and Co-Founder at UNIQUESEC, a non-profit organization that brings together cybersecurity professionals in Turkey. https://www.linkedin.com/in/brcyrr/ 48. Heide Young is ranked among the top 10 technology leaders in the Middle East. She is a Cybersecurity Woman of the World finalist 2023, cybersecurity strategist and author, and founding partner of Women in Cyber Security Middle East. https://www.linkedin.com/in/heideyoung/ 49. Helen Yu is Founder & CEO at Tigon Advisory Corp and host of CXO Spice. She’s recognized as a Top 50 Women in Tech and an expert in AI and cybersecurity. She is also Co-Founder and Board Director of Dark Cryptonite, as well as a member of the Board of Directors at Communications Engineering Company (CEC), KEENFOLKS, and Vera Capital LP. https://www.linkedin.com/in/yuhelenyu/ 50. Bob Fabien “BZ” Zinga, CISSP-ISSMP, PMP, MS, MBA is an award-winning cyber executive, CISO, advisor, author, and speaker, recognized as a C|CISO Hall of Fame 2023 Winner by EC-Council. He currently serves at the Information Warfare Commander (CDR/CEO/CISO/CIO/CTO, DoD TS/SCI) at the US Navy Reserve, as well as BCBR AAC Advisor & Co-Chair of The Communications and Technology Committee, Executive Board Advisor at United Cybersecurity Alliance, and Board Director at AZ Cyber Initiative. https://www.linkedin.com/in/bobfabienzinga/
The Rise and Risks of Shadow AI Shadow AI, the internal use of AI tools and services without the enterprise oversight teams expressly knowing about it (ex. IT, legal, cybersecurity, compliance, and privacy teams, just to name a few), is becoming a problem! Workers are flocking to use 3rd party AI services (ex. websites like ChatGPT) but also there are often savvy technologists who are importing models and building internal AI systems (it really is not that difficult) without telling the enterprise ops teams. Both situations are increasing and many organizations are blind to the risks. https://www.linkedin.com/feed/hashtag/?keywords=cybersecurity&highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7199795004838469632 https://www.linkedin.com/feed/hashtag/?keywords=privacy&highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7199795004838469632 According to a recent Cyberhaven report: — AI is Accelerating: Corporate data input into AI tools surged by 485% — Increased Data Risks: Sensitive data submission jumped 156%, led by customer support data — Threats are Hidden: Majority of AI use on personal accounts lacks enterprise safeguards — Security Vulnerabilities: Increased risk of data breaches and exposure through AI tool use. https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk The risks are real and the problem is growing. Now is the time to get ahead of this problem. 1. Establish policies for use and development/deployment 2. Define and communicate an AI Ethics posture 3. Incorporate cybersecurity/privacy/compliance teams early into such programs 4. Drive awareness and compliance by including these AI topics in the employee/vendor training Overall, the goal is to build awareness and collaboration. Leveraging AI can bring tremendous benefits, but should be done in a controlled way that aligns with enterprise oversight requirements. “Do what is great, while it is small” — A little effort now can help avoid serious mishaps in the future!
New Cryptojacking Malware Breakdown New Cryptojacking Malware Breakdown - The GhostEngine cryptocurrency mining malware disables endpoint security protections, deletes logs, modifies the kernel, and digs-in to establish persistence. It all begins with getting the victim machine to launch one .exe file. Cryptojacking malware consumes the compute resources of the victim by running cryptocurrency mining software which then directs any cryptocurrency rewards to accounts that only the attackers can access. It is basically resource theft that impacts systems performance, but because of the access it has, it can also be used as a vehicle for further attacks and to deploy more damaging instructions. It also undermines the protections of the system, which makes it more vulnerable to other attackers! A good writeup: https://arstechnica.com/security/2024/05/researchers-spot-cryptojacking-attack-that-disables-endpoint-protections/
North Korea is Trying to Embed Agents into IT Positions of Western Countries Attention IT departments, the FBI is warning US companies to be wary of inadvertently hiring North Koreans to remotely work in their IT departments, amid fears of data theft and hacking. We are seeing organized activities designed to mask the origins of North Korean people trying to infiltrate IT organizations and then leverage the access of those positions to harvest sensitive data and potentially be a vehicle to conduct cyber-offensive actions! Check out this article which describes two different programs unmasked by the FBI. **https://www.bitdefender.com/blog/hotforsecurity/arrests-made-after-north-koreans-hired-for-remote-tech-jobs-at-us-companies/**
Free Cybersecurity Specialist Workshop A free workshop for students looking to become Cybersecurity Specialists! Also, if you are already a professional and want to explore a career shift to #cybersecurity, check out the live session hosted by InfoSec4TC. Saturday May 25th, register for free! https://www.linkedin.com/company/infosec4tc/ Share to those who might benefit! https://school.infosec4tc.com/p/cyber-security-specialist-webinar2023090221
SEC Will Require Finance to Notify Breach Victims in 30 Days More SEC rules, this time mandating financial firms inform victims of data breaches within 30 days! Why wasn't this already a requirement? Last year, the SEC instituted requirements for publicly traded companies to inform investors of material cybersecurity events within 4 days. That edict spurred a small wave of misguided protests in the **#cybersecurity** community, who warned of bad omens which never materialized. I am anxious to see if this latest regulatory requirement also becomes a hotbed of discussion. <popcorn at the ready> https://www.sec.gov/news/press-release/2024-58
And Security for All Podcast2024: Cybersecurity's Major Trends & Threat Dynamics I'm excited to be speaking live with Kim Hakim on the And Security For All podcast tomorrow to discuss 2024's Cybersecurity's Major Trends & Threat Dynamics, including the ever-changing role of a CISO and the accelerating risks of Nation State cyberattacks, among other dynamic threats. Join me LIVE tomorrow, Friday May 17th 12pm Pacific https://www.linkedin.com/events/2024-cybersecurity-smajortrends7196960575686418432/theater/
Unlock Your Cybersecurity Career - Exclusive Discounts on Top Training There are tremendous opportunities in cybersecurity and the industry needs many more qualified workers. Training plays an important part. That is why I am partnering with Infosec4TC, an online training provider that offers free courses in addition to affordable classes, to offer huge discounts on cybersecurity training (links below have embedded discount codes). https://school.infosec4tc.com/ I have negotiated with the great team at Infosec4TC to reduce the price on select courses by up to 65% off! Many courses include working on real cybersecurity projects, realistic assignments, and prep-work for certifications. They have an impressive TrustPilot score and a 14 Day Money Back Guarantee full refund policy! https://www.trustpilot.com/review/infosec4tc.com Check out these featured classes: Cyber Security Specialist Live Workshop – a total of 64 hours of instruction that cover the breadth of issues for operational specialists. Check out the course curriculum for details. https://school.infosec4tc.com/p/cyber-security-career-from-a-to-z?coupon_code=GFHDGFHDFJ&product_id=4088185&affcode=100167_lzkq3v5y SOC Analyst (Blue Team) Live Workshop – a live, hands-on course designed for front-line tier-1 Security Operations Center analysts. It teaches tools, analysis, event management, threat hunting, and incident response principles. https://school.infosec4tc.com/p/soc-analyst-workshop?coupon_code=HFJSDGFDSJ&product_id=4481591&affcode=100167_lzkq3v5y ISO/IEC 27001:2022 Lead Implementer Live Workshop – an interactive session that covers the standards, methods, and best practices for Information Security Management Systems (ISO 27001) for managers and supervisors. https://school.infosec4tc.com/p/iso-iec-27001-2022-lead-implementer?coupon_code=JHGJDGFDDF&product_id=5522776&affcode=100167_lzkq3v5y Also available is the Gold Membership Access membership that grants access to over 175 training courses, labs, materials, practice exams, and exam simulators. Check out the details. https://school.infosec4tc.com/p/annual-subscription-plan-180?coupon_code=FHGFJGKDFJH&product_id=699660&affcode=100167_lzkq3v5y Be sure to look at the free classes as well! https://school.infosec4tc.com/courses/category/Free Drop me a note if you take one of these courses. Let me know your thoughts and if I should continue to work with them to offer big discounts!


+2 more
Unlocking SMB Cybersecurity: The Rise of Virtual CISOs in 2024 and Beyond This year, virtual CISOs must begin making a difference in our industry. For the longest time, small and medium businesses (SMBs) have been abandoned by the cybersecurity industry. But, SMBs need security leaders to guide them through the maze of cyber risk and craft practical strategies that align with their unique ever-evolving business objectives. Sadly, SMBs cannot afford an experienced full-time CISO. They often either ignore the risks or get lured into purchasing shiny tools that do not meet their overall needs. Before spending money on security solutions, it’s crucial to understand the risks and develop clear objectives that support the overall business goals. This is the role of a CISO: to set the direction and establish cybersecurity program foundations that will meet the expectations of the Board and C-suite. However, there are not enough CISOs to go around which creates a high premium on their time. Hiring a CISO can cost hundreds of thousands of dollars, which is far beyond what most SMBs are willing to commit. But they don’t actually need a full-time CISO. An hour or two may be perfect for guidance, leadership, and strategy development. This is where the fractional/virtual CISOs (vCISO) community can play a role! Experienced CISOs often have a few hours extra per week and yearn to take on new challenges, as long as it does not impact their day job. Many retiring CISOs still have the itch to contribute, but don’t want to commit the long hours of managing all the operations and details. They would rather leverage their experience to provide guidance and help organizations avoid costly pitfalls. It becomes a perfect fit. Experienced leaders offer guidance at a fraction of the cost, with short-term contracts keeping commitments flexible. Everyone wins. vCISOs can provide leadership without being tied to the demanding operational aspects. By dedicating a few hours a week, vCISOs help SMBs benefit from experienced cyber risk leadership with direction, focus, and an understanding of the evolving risks. SMBs can then make informed business decisions that properly account for cybersecurity factors. The practical benefits include effective prioritization and efficient allocation of resources for an optimized cybersecurity posture, based upon their unique needs. There are risks in the vCISO market. Two things to watch out for: First, beware of vCISO services offered by security vendors masquerading as impartial advisors. In many cases, this is just a ploy to get customers to buy the parent company’s products or services. These people are effectively used as a sales channel and incentivized to convince SMBs to purchase their wares. They aren’t necessarily looking out for their clients’ best interests. Instead, seek out vendor-agnostic vCISOs that will work with what you have and align recommendations to your actual needs. Second, many will assert themselves as seasoned cybersecurity leaders, but in actuality, lack the practical experience needed to be a successful vCISO. Let’s be clear, a vCISO is NOT an entry-level job. Rather it is the opposite. An experienced cybersecurity leader can quickly understand the major risks and business needs, develop a customized set of strategic plans for a specific organization, and communicate effectively to executives so they may rapidly understand and make well-informed decisions. vCISOs must be vetted properly to make sure they can deliver quality results in very limited timeframes. Otherwise, it will be money wasted! If you are interested in exploring how vCISOs can help businesses, sectors, or various audiences, reach out to me directly or visit my website. We must purposefully work to support the SMB community. Let’s join forces to make this year a turning point in fortifying SMBs and bolstering their digital security and competitiveness! https://www.cybersecurityinsights.us/
Task Force Gives Terrible Advice About Ransomware https://www.youtube.com/watch?v=SeW3XTAB1gE I couldn’t help myself, I had to rant about this! A ‘security research’ group is recommending against banning ransomware payments, which would eradicate these attacks from occurring, and instead want money to be spent on communications campaigns, gathering metrics, and spending more on insurance. …all of which does not actually stop ransomware. This is crazy and quite sad. Let me know what you think in the comments! Here is a link to their recommendations (.pdf): https://securityandtechnology.org/wp-content/uploads/2024/04/Roadmap-to-Potential-Prohibition-of-Ransomware-Payments.pdf Here are links to two videos about how to actually end ransomware if we were so inclined: Ending Ransomware Plan: https://www.youtube.com/watch?v=7AlMdkaL6II Answer Typical Questions & Concerns: https://www.youtube.com/watch?v=Q33o6Kj0W6E
Guardians of Academia - Battling Cyber Threats in Higher Education https://www.youtube.com/watch?v=k1Olwlqc0CY Donna Kidwell, CISO of Arizona State University, is one of the best and brightest in our community! I am continually amazed at her insights, strategic focus, and ability to creatively tackle some of the biggest problems in cybersecurity. Today, in The Cybersecurity Vault podcast (episode #31), we talked about the incredible challenges and forward-thinking that her team is driving at ASU and across partnerships around the globe. Afghan women and their ARISTA internships — so incredibly proud of them — their story is here! https://tech.asu.edu/features/arista-upksilling-cohort-2023 Donna’s LinkedIn profile: https://www.linkedin.com/in/dkidwell/ Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
Facebook Hacked Users Phones to Snoop on Encrypted Data Media is reporting that documents emerging from a legal case are revealing that in 2016 Facebook created a project to intercept and decrypt traffic on user’s phones to gain a competitive advantage. https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/ I am still wrapping my head around the ethical, criminal, privacy, regulatory, and legal liability of Facebook essentially hijacking user's mobile devices to gain access to data that purposefully was being protected against #privacy invasion. My guess is Facebook built a network shim to monitor traffic patterns from apps to specific domains, but potentially they may have also maneuvered to undermine the protection of the data contents as well. I expect more specific details will emerge with criminal, civil, and regulatory investigations. This type of capability is something that sophisticated cyber hackers strive to achieve. The ability to identify source/destination of encrypted traffic, potentially redirect it, and possibly undermining protective data encryption is hugely powerful! The fact that a major company created and deployed such malicious software (acting in detrimental ways to the user for the benefit of the attacker), showcases the lack of #ethics on the part of Facebook. There needs to be appropriate accountability (ex. criminal, civil punitive, regulatory license revocation, etc.) based upon what full investigations uncover. Read TechCrunch article that describes the man-in-the-middle attack: https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/
Researchers Give Birth to the First GenAI Worm It was bound to happen — researchers have created a 1st generation AI worm that can steal data, propagate malware, and spread via email. Ben Nassi from Cornell Tech, Stav Cohen from the Israel Institute of Technology, and Ron Bitton from Intuit created the self-replicating worm and bestowed the name ‘Morris II’ after the notorious worm that infected systems in the 1980’s. Their creation targets AI apps and AI-enabled email assistants. They published a research paper and video showing methods to steal data and affect others email systems. https://sites.google.com/view/compromptmized This worm basically embeds adversarial type data into malicious email that manipulates victim’s systems to propagate messages, perform malicious activity, and exfiltrates sensitive data. https://www.youtube.com/watch?v=FL3qHH02Yd4&t=204s Strategically, the crux of this evolving problem is based in the fact that the pursuit of more functionality and subsequent value of GenAI and LLM systems, they require more access and permissions to do things in the digital ecosystems they inhabit. So, they become an incredibly powerful tool for both good and also for bad if instructed by malicious parties. So, take a breath! This is just the beginning! We must all understand that we can seize the great benefits of disruptive technologies, like Artificial Intelligence, but we must also be responsible to proactively understand and mitigate the accompanying cybersecurity risks!
Best Practices in Securing 3rd Party Supply-Chain with Cassie Crossley https://www.youtube.com/watch?v=SpZLbW96q1M The Cybersecurity Vault episode 28 Securing the software supply chain, including 3rd party vendors and suppliers, is a difficult problem that the cybersecurity industry is trying to tackle. The threats and risks are growing, which can have catastrophic impacts on companies and their downstream customers. Cassie Crossley, the VP of Supply Chain Security at Schneider Electric and the author of the book “Software Supply Chain Security”, shares her insights and recommendations for cybersecurity leaders. Purchase your copy of the book “Software Supply Chain Security: Securing the End-to-end Supply Chain for Software, Firmware, and Hardware” on Amazon: https://www.amazon.com/Software-Supply-Chain-Security-End/dp/1098133706 Cassie’s LinkedIn profile: https://www.linkedin.com/in/cassiecrossley/ Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
Keynote: Critical Infrastructures Are Under Attack From Aggressive Nation States https://www.youtube.com/watch?v=SNANAfdBtjs Critical Infrastructures are under attack from aggressive nation states! Governments must step forward to help protect these crucial sectors and the services they provide to citizens. My cybersecurity keynote from the InCyber North American conference is now available for the public to watch! InCyber FIC North America, 2023 in Montreal Canada: 3700 participants, 130 partners, and 330 speakers, presentations and discussions on the critical issues of cybersecurity and digital trust. Official website: northamerica.forum-incyber.com
Cybersecurity Panel at CLEA I had a great time speaking today at the CIO/CISO Executive Leadership Alliance (CLEA) meeting with Jesse Bociek and Rocco Grillo (these luminaries are so smart)! Excellent discussions regarding risks of escalating threat actors and the challenges of more regulations. The questions were fearless in asking how cybersecurity can go beyond compliance and protection, to become a competitive advantage value proposition! Thanks HMG Strategy. We need more discussions like this in the #cybersecurity industry!
Incident Materiality and Meeting New SEC Requirements with Malcolm Harkins https://www.youtube.com/watch?v=bNSaj8tE00o The new SEC requirements for public companies includes reporting within 4 days of determining that a cybersecurity incident is ‘material’ to the company. But what is materiality? In this episode, I talk with Malcolm Harkins, the Chief Security and Trust officer at HiddenLayer, former CISO at Intel, and fellow at the Institute for Critical Infrastructure Technology (ICIT). Malcolm’s LinkedIn profile: https://www.linkedin.com/in/malcolmharkins/ Visit Cybersecurity Insights at https://www.cybersecurityinsights.us Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/Cybersecurity
Creating A Sustainable Cybersecurity Industry https://www.youtube.com/watch?v=6Zs5QW2_bW4 The cybersecurity industry is facing many sustainability challenges. I enjoyed a lengthy discussion with Terry Thompson at Top Cyber Pro to highlight the strategic problems and opportunities! Give it a watch.
Online Information Session: MS Cybersecurity at Dominican University of California Dominican University of California offers a fully online, one-year, STEM-designated graduate cybersecurity program starting fall 2024. Join the next online information session with Joanna Grama, JD, VP and Partner at Vantage Technology Consulting Group and Matthew Rosenquist, CISO and Cybersecurity Strategist, on February 22nd at 6 pm Pacific time. RSVP: https://www.dominican.edu/events/online-information-session-ms-cybersecurity-1
Career Advice to Cybersecurity Students – Replay of Live Presentation https://www.youtube.com/watch?v=kub-NBfcBYk I was honored to speak at the recent Cyber Proud event to an audience of students and graduates who were seeking advice on pursuing a career in #cybersecurity. There is a chasm between entry level professionals and organizations needing to hire talent. I discussed the challenges from the perspectives of students, hiring organizations, and academia.
The Unseen Threats: Anticipating Cybersecurity Risks in 2024 Nation-state attacks will be the dominant influence on the capabilities, growth, and impacts seen across the cybersecurity industry in 2024. Years of investment, innovation, and willingness to conduct advanced attacks by nation-states like Russia, China, North Korea, and Iran have accelerated the advancement of malicious capabilities at all levels. Their long-term commitment to developing new tools, techniques, acquiring vulnerabilities, and sponsoring complex cyber operations against other countries empowers threat actors of all types. Critical infrastructure organizations will continue to be prime targets in 2024 as nation-states aggressively go after sectors like healthcare, government, communications, transportation, defense industrial base, utilities, and finance. Both governments and cybercriminals will target these industries due to their importance and ability to inflict widespread harm. Many smaller critical infrastructure firms that underinvested in security will likely get compromised, along with a few larger companies that failed to prioritize cyber defense. The public will see more apparent and impactful critical infrastructure attacks over the next year. Supply chain hacking methods will evolve significantly, fueling a rise in attacks that can infiltrate downstream consumers on a massive scale. Nation-state adversaries are developing new tools and tactics to intensify supply chain compromises against software, cloud services, and hardware vendors in order to gain covert access to large customer networks and industries. The growing technical skills and resources poured into these types of "trojan horse" attacks by state cyber actors will make them a mounting challenge that impacts entire businesses and economic sectors. The insatiable demand for software vulnerabilities and exploits to support nation-state cyber operations has exploded research and tool development efforts. This will lead to a spike in zero-day discoveries being sold privately for millions of dollars. Shortened vendor patching timelines create exploitable windows for sophisticated hacking groups. Open-source software and widely adopted cloud platforms will be favorite hacking targets. The influx of nation-state funded vulnerabilities into cybercriminal hands spreads the technical skills and infrastructure of the most advanced attackers. Generative AI will become a double-edged sword in 2024 as its rapid innovation and adoption is a threat while also providing helpful tools to cyber defenders. AI amplifies both attackers and defenders but is empowering malicious automation at a faster rate. Hackers will leverage AI for more scalable social engineering, disinformation, vulnerability discovery, and attacking automation. Defenders strive to catch up by fielding AI-driven security analytics, incident response aids, and automated patching solutions. The generative AI arms race favors those able to weaponize it first like specialist nation-state hackers. Stringent new cybersecurity regulations are forcing operational changes around risk management and compliance. Recent privacy laws, security mandates, and SEC rules are uncomfortable for many security teams. Regulations are not always clear or consistent but forcing collaboration between diverse business functions. Small compliance investments are expected but not major budget increases. Stricter rules drive increased responsibility for CISOs and boards, who must now communicate regulatory risks internally while externally managing public transparency requirements around cyber incidents. Growing expectations for digital trust along with tighter rules and stronger adversaries will crush organizations reliant on minimalist cybersecurity strategies. Executives, investors, customers and lawmakers now consider cybersecurity a critical concern that directly impacts productivity, customer loyalty, liability and shareholder duties. Companies must take security seriously or face competitive disadvantage and reputational harm from transparent failures. Constrained security budgets will mutate resource constraints from fears into nightmares as the demands dwarf available funding. For the full analysis: https://www.linkedin.com/pulse/2024-cybersecurity-predictions-key-risks-matthew-rosenquist-fzwtf
Embracing Innovation and Managing Cyber Risks https://vimeo.com/899647515 I had a great discussion with Julian, from eChannelNEWS where we discussed the pivotal role of information dissemination and the construction of a fortified cybersecurity ecosystem. Of particular importance is the influence that AI will have on cybersecurity, both as a formidable weapon wielded by attackers and a powerful shield for defenders. CISOs will have an uphill battle in communicating security needs to higher echelons while grappling with scarce resources. The full article and podcast video interview is available https://www.e-channelnews.com/embracing-innovation-and-managing-risks-with-eclipz/