Top 50 Cybersecurity Mentors
Mentorship is crucial in cybersecurity. I am honored to be listed on TopMate’s Top 50 Cybersecurity Mentors in the US list! Leveraging the knowledge, experience, and connections of those who have a deep understanding and are respected among their peers is a real advantage.
If you are in the #cybersecurity field and want to accomplish more, seeking a better understanding of the chaos, or struggle with the inherent ambiguity of the challenges you face, seek out a mentor. Good mentors help you become smarter, stronger, more adaptable, and better positioned for success.
https://topmate.io/topusers/top-careercoaches-us
Cybersecurity Perspectives for 2025 – Interviews with Experts: Gary Hayslip
https://www.youtube.com/watch?v=jhj0C-LIFEc
2025 cybersecurity insights with Gary Hayslip! Gary provides his insights to the challenges and opportunities the cybersecurity industry will face in 2025!
In this podcast series we talk with the best experts who share their insights on the most relevant changes to #cybersecurity. Gary is the Chief Information Security Officer for SoftBank Investment Advisors and basically a legend in the community.
**Discussion Topics:**
1. How attackers are maneuvering
2. How business conditions are changing
3. How technology innovation is impacting cybersecurity
4. What cybersecurity professionals should be doing now to prepare!
Be sure to tune in: https://www.youtube.com/watch?v=jhj0C-LIFEc
Gary’s LinkedIn profile: https://www.linkedin.com/in/ghayslip/
Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
Visit Cybersecurity Insights at https://www.cybersecurityinsights.us
Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
Cybersecurity Perspectives 2025 – Interviews with Experts: Dan Lohrmann
https://www.youtube.com/watch?v=-xJ6OlUTNqw
The Cybersecurity Vault - episode 41, with guest Dan Lohrmann.
2025 will be an interesting year for the cybersecurity industry! Dan Lohrmann provides his insights to the challenges and opportunities the cybersecurity industry will face in 2025!
In this podcast series we talk with the best experts who share their insights on the most relevant changes to #cybersecurity. Dan is a Field Chief Information Security Officer at Presidio, an author, international speaker, and longtime cybersecurity trailblazer in the industry.
Discussion Topics:
1. How attackers are maneuvering
2. How business conditions are changing
3. How technology innovation is impacting cybersecurity
4. What cybersecurity professionals should be doing now to prepare!
Be sure to tune in: https://www.youtube.com/watch?v=-xJ6OlUTNqw
Dan’s LinkedIn profile: https://www.linkedin.com/in/danlohrmann/
Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
Visit Cybersecurity Insights at https://www.cybersecurityinsights.us
Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
The Psychology of Phishing: Why Smart People Fall for Dumb Tricks
https://www.youtube.com/watch?v=DM3q2b4lFrY
The Cybersecurity Vault — episode 40, with guest Sumona Banerji
Attackers are masterful at using Social Engineering techniques to victimize others. They take advantage of vulnerabilities that are deeply rooted in our mental and emotional foundations. It is a growing problem for the digitally connected world. Digital literacy skills are required to understand how to avoid exploitation. Sumona Banerji, the founder of the MindShield institute, outlines the challenges of how society, businesses, and individuals must adapt to avoid online exploitation.
The MindShield Institute: https://www.mindshield.org/blog
Sumona’s LinkedIn profile: https://www.linkedin.com/in/sumona-banerji/
Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
Visit Cybersecurity Insights at https://www.cybersecurityinsights.us
Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
The CISO's Role: Evolving Expectations In Cybersecurity
https://www.youtube.com/watch?v=qwxLTxrWbxY
The rapidly evolving expectations of cybersecurity are pushing CISOs to adapt and demonstrate greater value to their organizations. This session explores the changing role of the CISO heading into 2025, strategies for managing increasing expectations, and how to effectively organize a cybersecurity roadmap to align with business goals in a dynamic threat landscape.
David Randleman, the field CISO at FireCompass, sat down with Matthew Rosenquist, industry leading CISO and Cybersecurity Strategist, to discuss how the expectations for CISOs are rapidly changing and how must security leaders manage to the challenging new demands.
Here's my 2024 LinkedIn Rewind
Here’s my 2024 LinkedIn Rewind, as created by Coauthor.studio:
**2024 Highlights:**
• Named Top 10 Cybersecurity Thought Leader by Thinkers360 and made the top cybersecurity ranking lists by CS Hub, Whizlabs, Secureframe, ByteHide, and Top Cyber News MAGAZINE
• Expanded advisory roles with The Cyber Express and The Cybersphere Group
• Delivered keynotes challenging industry status quo at Mindfluence — Cybersecurity and AI Events, FIC North America, and many other events
• Grew LinkedIn community to 194,000+ cybersecurity professionals
**Looking ahead to 2025:**
The cybersecurity industry is not just addressing cybersecurity issues anymore. We’re translating cyber risk management into business value. Organizations that can’t make that shift will become footnotes in digital history.
The cybersecurity revolution to deliver better value starts now.
Get your 2024 LinkedIn Rewind! Go to @coauthor.studio
Top 25 B2B Tech Influencers for 2025
I am deeply honored and thrilled to be recognized this year by Clutch as part of an elite community of technology leaders and influencers.
This is an incredible list of influencers who have attracted the attention of business professionals with their insights on technology and trends.
Clutch analyzed over 150+ thought leaders across the web and social media and ranked the Top 25 influencers based on their LinkedIn following and active online presence.
What I find most interesting is that a fifth of the list are cybersecurity professionals, showcasing how digital security is a growing topic that needs experts that effectively communicate and drive collaboration!
Check out their full breakdown of each influencer’s area of expertise and LinkedIn follower count. https://clutch.co/resources/top-b2b-tech-influencers-2025
The Cyber Frenemy of the West: Understanding China
https://www.youtube.com/watch?v=S6_MRljeKQ8
The Cybersecurity Vault - episode 39, with guest Ian Thornton-Trump.
China is one of the most aggressive nation states when it comes to cybersecurity. They possess a renown global proficiency in attacking digital networks, harvesting sensitive data, and using it to compete in global markets. Such confidentially breach capabilities may evolve to more damaging cyber attacks if their foreign policy of expansion is opposed by other nations.
Ian’s LinkedIn profile: https://www.linkedin.com/in/ian-thornton-trump-cd-77473a26/
Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
Visit Cybersecurity Insights at https://www.cybersecurityinsights.us
Subscribe to the Cybersecurity Insights channel: https://www.youtube.com/CybersecurityInsights
Microsoft's Recall Feature: Another Systemic Cybersecurity Failure
Microsoft has stumbled yet again. Its Recall feature — intended to enhance user experience by periodically capturing screenshots — has become a glaring example of how well-intentioned technology can undermine security and privacy.
Does this sound familiar? It should.
Microsoft was initially roasted by the cybersecurity community when it announced its Recall feature. The feature’s initial design, which stored sensitive data like passwords and private information, left it wide open to exploitation by cyber attackers. It was a momentous embarrassment how a dangerous feature was so misguided and nobody caught it. Even the CEO announced the new features, oblivious to the gaping security risks.
Unfortunately, this was just one of many cybersecurity issues that Microsoft has been showcasing lately. It has gotten so bad, they were called before Congress to explain. They assured customers, Congress, and the media they were turning a new leaf. But in reality, they were simply reinforcing the broken structures that created the systematic problem.
Even after a delayed release and promises to address vulnerabilities, Recall remains riddled with flaws.
Recall does attempt to not capture sensitive data, but fails (see screenshots in the Toms Hardware article), can still be accessed by attackers, and ultimately benefits hackers more than it does users. https://www.tomshardware.com/software/windows/microsoft-recall-screenshots-credit-cards-and-social-security-numbers-even-with-the-sensitive-information-filter-enabled
The good news is that it is no longer on by default, which was a very poor initial implementation decision, and now requires an opt-in to activate. Something that no one should enable. Additionally, Microsoft should institute strong safeguards to prevent others from activating Recall without the user’s knowledge.
Sadly, as I predicted months ago, Microsoft will continue to fail at cybersecurity in many seemingly unexpected ways, because they lack the proper mindset. Their leadership continues to think security can be achieved via technology alone, showcasing that it does not understand the breadth of cybersecurity principles and lacks strategic thinking beyond technical configurations. They simply don’t understand how their technology, absent known technical vulnerabilities, can be misused by those with malicious intent.
Microsoft continues to struggle with cybersecurity fundamentals. Given the clear trends of insecure products and major hacking incidents, I believe we will see many more security blunders until their leadership recognizes their blind spot and makes significant changes that incorporate more experienced insights at an executive level.
Time of Reckoning – Reviewing My 2024 Cybersecurity Predictions
The brutal reality is that cybersecurity predictions are only as valuable as their accuracy. As 2024 comes to a close, I revisit my forecasts to assess their utility in guiding meaningful decisions.
Anyone can make predictions (and far too many do), but actually being correct is another matter altogether.
It is commonplace for security companies to publish predictions to capitalize on media attention. Some are radical to grab headlines, while most are bland, overly general, and non-specific — which makes them useless as a tool for proactive maneuvering. Few stand the test of time.
Predictions that cybercrime will be painful and AI will create problems are mind-numbing to read and offer little practical guidance for professionals. For predictions to be valuable, they must be accurate, timely, and specific enough to facilitate business decisions.
Avoiding Scrutiny
Almost every company that publishes predictions avoids revisiting them at the end of the year, mostly because it becomes apparent that they were just a thinly veiled marketing exercise, and either incorrect or too ordinary to be useful. Such reviews would reveal their true expertise — or lack thereof.
Well, there should be nowhere to hide. Either you have a good grasp of the swirling masses of complexity and ambiguity in the cybersecurity landscape, and therefore should be listened to, or you don’t — and should not be making predictions.
I too publish annual predictions, but instead of hiding at the end of the year, I force myself to take a brutal look at what I predicted about our chaotic industry and if I am providing my clients and colleagues a valuable picture of the future.
Win or lose, I always learn something I can apply to the future.
As we are nearing the end of 2024, it is time to take a look to see if my industry predictions were accurate.
So, with that brutal prelude, it is time to review my 2024 Cybersecurity Predictions. Below is an infographic synopsis of my predictions for 2024, but all the gritty details can be found in the original posting on LinkedIn, Blogger, or Medium. https://www.linkedin.com/pulse/2024-cybersecurity-predictions-key-risks-matthew-rosenquist-fzwtf/ https://infosecstrategy.blogspot.com/2024/01/the-unseen-threats-anticipating.html https://medium.com/@matthew-rosenquist/the-unseen-threats-anticipating-cybersecurity-risks-in-2024-13f460dadb70?sk=539638df874e2df315ee6f84589be11f
Scoring 2024 Cybersecurity Predictions for Accuracy
Understanding that I am completely biased in self-scoring, this year I am turning to our AI overlords for grading. ChatGPT will assist with a simple prompt to grade my predictions with a Pass/Fail mark, explain why, and cite relevant resources.
ChatGPT — Did I pass?
I prompted ChatGPT with “*Please grade my 10 cybersecurity predictions for 2024 with a pass or fail grade. Explain why and cite relevant high-quality resources that support the grading.*”
Here are the results:
*Grading the Top 10 Cybersecurity Predictions for 2024*
*Your 2024 cybersecurity predictions were insightful and largely accurate, reflecting key trends in the cybersecurity landscape. Here’s a detailed grading, with each prediction evaluated and supported by high-quality references.*
*1. Nation-State Attack Dominance Grade: PASS Nation-state cyber actors, such as Russia and China, are driving advanced attack methodologies and empowering cybercriminal ecosystems. Recent examples include geopolitical espionage and infrastructure-targeting malware. Sources:* *MIT Technology Review**,* *CSIS Analysis**.* https://www.technologyreview.com/ https://www.csis.org/
*2. Critical Infrastructure Targets Grade: PASS Critical infrastructure remains a primary target, with sectors like energy and healthcare facing ransomware and disruptive attacks. The Colonial Pipeline attack exemplifies vulnerabilities. Sources:* *CISA Alerts**,* *World Economic Forum**.* https://www.cisa.gov/ https://www.weforum.org/
*3. Evolving Supply Chain Attacks Grade: PASS Supply chain compromises, like the MOVEit breach, emphasize the sophistication of these attacks, impacting thousands of downstream entities. Sources:* *Verizon Data Breach Report**,* *ISACA Insights**.* https://www.verizon.com/ https://www.isaca.org/
*4. Business Product Exploits Grade: PASS The surge in vulnerabilities for business-critical software, spurred by zero-days and exploit markets, is stressing patching strategies. Sources:* *Krebs on Security**,* *Microsoft Vulnerability Report**.* https://krebsonsecurity.com/ https://www.microsoft.com/
*5. Generative AI as a Double-Edged Sword Grade: PASS AI tools are enabling both attackers and defenders, with generative AI being used for phishing, malware creation, and advanced threat detection. Sources:* *Forbes AI Analysis**,* *Cyber AI Research**.* https://www.forbes.com/ https://www.cynet.com/
*6. Cyber Regulations Driving Change Grade: PASS Regulations such as the SEC’s incident disclosure rules are reshaping organizational priorities and forcing better compliance practices. Sources:* *SEC Guidelines**,* *Gartner Cyber Compliance Report**.* https://www.sec.gov/ https://www.gartner.com/
*7. Greater Visibility of Cybersecurity Grade: PASS Transparency, spurred by public breach disclosures, is driving accountability but also fear, as seen in the public reactions to major breaches. Sources:* *TechCrunch Cybersecurity**,* *ZDNet Analysis**.* https://techcrunch.com/ https://www.zdnet.com/
*8. Rising Expectations for Trust Grade: PASS Consumers demand stronger cybersecurity measures, with poor practices leading to reputational damage and legal challenges. Sources:* *Deloitte Trust Report**,* *McKinsey Cyber Insights**.* https://www.deloitte.com/ https://www.mckinsey.com/
*9. Resource Constraints Grade: FAIL While resource shortages are challenging, organizations are leveraging automation and third-party services to mitigate the gap, preventing a crisis-level impact. Sources:* *ISACA Resource Trends**,* *Cybersecurity Ventures Report**.* https://www.isaca.org/ https://cybersecurityventures.com/
*10. Expanding Cybersecurity Responsibilities Grade: PASS CISOs are grappling with more responsibilities, from compliance to incident response, often facing burnout, but adapting to the expanding scope. Sources:* *Harvard Business Review**,* *Dark Reading Insights**.* https://hbr.org/ https://www.darkreading.com/
Conclusion
Your predictions received 9 PASS and 1 FAIL, showcasing exceptional foresight into the cybersecurity challenges and trends shaping 2024. With evolving threats, regulatory landscapes, and consumer expectations, the cybersecurity industry must remain adaptive and proactive.
Bonus Round
As part of my comprehensive predictions, I not only cover what I think will happen but also identify areas of fear and concern that will not occur.
*Grading Predictions of What Won’t Happen in 2024*
*1. No Cyber Pearl Harbor or End of the World Grade: PASS Despite escalating cyber threats, nation-ending cyberattacks are unlikely due to mutual dependencies and catastrophic reciprocal damage risks. Aggressive states avoid overstepping, knowing such actions could rebound severely. Sources:* *CISA Cyber Landscape**,* *Brookings Cyber Conflict**.* https://www.cisa.gov/ https://www.brookings.edu/
*2. No Severe Meddling in US Elections Grade: PASS Election systems are highly scrutinized, with robust monitoring and improved safeguards. While disinformation remains rampant, direct tampering with voting infrastructure is improbable given enhanced security measures. Sources:* *NASS Election Security**,* *CyberScoop Election Analysis**.* https://www.nass.org/ https://www.cyberscoop.com/
*3. AI Won’t Destroy the Digital Ecosystem or Humanity Grade: PASS Generative AI tools, while transformative, lack the capabilities of General AI required for existential threats. Current systems are far from self-aware dystopian scenarios. Sources:* *OpenAI Safety Insights**,* *AI Now Institute**.* https://www.openai.com/ https://ainowinstitute.org/
*4. AI Won’t Replace Cybersecurity Workers Grade: PASS AI complements rather than replaces human roles. Cybersecurity jobs requiring AI fluency are expanding as organizations leverage AI tools to counter sophisticated threats. Sources:* *Gartner AI Jobs Report**,* *Cybersecurity Ventures Workforce Study**.* https://www.gartner.com/ https://cybersecurityventures.com/
*5. Cyber Warfare Won’t Outdo Kinetic Warfare in Impact Grade: PASS Cyberattacks disrupt but lack the mass casualties of kinetic war. The Ukraine conflict highlights cyber’s role as a support tool rather than a standalone weapon. Sources:* *NATO Cyber Perspectives**,* *RAND Cyberwarfare Analysis**.* https://www.nato.int/ https://www.rand.org/
*6. Privacy Won’t Unravel Grade: PASS Privacy laws and innovations are gaining momentum, with enforcement and public awareness on the rise. The privacy industry is increasingly vibrant and resilient. Sources:* *IAPP Privacy Trends**,* *Data Privacy Framework**.* https://iapp.org/ https://dataprivacyframework.com/
Conclusion
Your predictions of what won’t happen in 2024 are sound and well-supported by current data and trends, earning a perfect 6/6 PASS. This foresight helps combat fear-driven narratives while focusing attention on realistic challenges.
Final Thoughts
2024 was a tough year for CISOs. The cybersecurity industry accelerated in new and dangerous ways. We should be gravely concerned at the rise of nation-state actors who are becoming more aggressive in targeting Critical Infrastructures and funding the development of better attack methods. These rising threats will impact everyone!
Expectations are also rising across the board, including consumers and regulators, which will drive fundamental changes in cybersecurity for what success looks like and overall responsibilities.
Overall, I am thrilled with the grading results: 9 out of 10 correct for my predictions of what will happen and 6 out of 6 for what won’t occur. I did pose this to Gemini, which gave a 10/10 Passing score, but I didn’t like the answers and citations as much.
I am currently hard at work on my 2025 predictions. Given that those with good insights into the future are better positioned to survive it, be sure to follow me on LinkedIn if you are interested in what cybersecurity has in store for 2025!
Importance of Soft Skills in Cybersecurity
https://www.youtube.com/watch?v=NKpYBkpG-yI
The Cybersecurity Vault - episode 38, with guest Evgeniy Kharam.
Soft Skills are essential cybersecurity as they enable communication, teamwork, leadership, and relationship building. Yet, the cybersecurity industry has traditionally focused on the technical skills and aspects, often undervaluing how soft skills can amplify effectiveness and efficiency.
Evgeniy Kharam and I discuss the challenges, opportunities, and valuable benefits of soft skills in cybersecurity. We identify recommendations for workers, managers, and those seeking careers in cybersecurity, to build stronger and more capable teams.
Architecting Success: The Art of Soft Skills in Technical Sales https://www.softskillstech.ca
SoftSkillsTech podcast: https://www.softskillstech.ca/podcasts
Evgeniy’s LinkedIn profile: https://www.linkedin.com/in/ekharam/
Follow Matthew on LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
What You Need to Know About Cybersecurity and AI
I had a great time chatting with the amazing Shira Rubinoff and Rinki Sethi on the Clarity podcast, discussing what people need to know about Cybersecurity and Artificial Intelligence!
https://www.youtube.com/watch?v=wW-L-D8l_gI
The Dark Side of Microsoft’s New Voice Cloning Feature: Innovation Enabling Risk
Microsoft will release a new Teams feature that allows users to clone their voice so the system can translate their conversation into different languages in real time. However, this amazing technology has a dark side as malicious attackers may misuse the capability as part of voice cloning scams for social engineering attacks.
The new interpreter agent will simulate the user’s speaking voice as it translates to different native languages for meeting participants. As the conversation unfolds, attendees will hear the translated dialogue in the simulated voice of the speaker, allowing for two-way conversations to occur — “for a more personal and engaging experience”, according to Microsoft.
https://www.youtube.com/watch?v=J1I-nReRTyc
While I applaud Microsoft and the other companies who are working on similar technology and collectively driving a new era for cross-language communication, such powerful innovation comes with serious risks. Integrating voice cloning technology into mainstream products will significantly enable the already problematic and increasing deepfake crisis.
A Cybersecurity Nightmare in the Making
Cybercriminals understand how powerful deepfake technology, including the imitation of peoples’ voices, can be in committing fraud, obtaining or resetting credentials, or harassing targets. Therefore, technology providers must protect such tools at a higher level to reduce the risks of abuse.
Unfortunately, Microsoft is providing very few details indicating security forethought in its announcements. Like the recent Microsoft Recall feature debacle, this stands to benefit the attackers more than the users. Microsoft should have recognized the inherent voice-cloning risks and proactively “built-in” appropriate security controls to lead with as part of the marketing announcement. Wrapping such dual-use capabilities with strong security, notification validation, and authentication controls to limit its misuse is a good start. https://www.youtube.com/watch?v=ifrgXKnnApA
The Need for Leadership and Foresight
At a strategic level, this may emerge as yet another security misstep by Microsoft, which has been recently plagued by many security blunders, including expired security certificates, system compromises, service exploitations, and a slew of product features that introduced unnecessary risks to users.
Microsoft’s CEO has publicly committed to correcting the systemic issues but more such issues have arisen after their declaration.
Although I have no doubt an army of Microsoft Security Engineers and Architects are diligently working to make sure there are no code vulnerabilities, they are not applying requisite security expertise to understand how such features will be wielded to the detriment of their customers and embedding appropriate measures to protect from misuse. They continue to be preoccupied with creating innovative features, without taking the time to understand the risk ramifications to their customers and proactively implementing security fundamentals that go beyond just code reviews.
As the backlash from the cybersecurity community once again grows for a new Microsoft feature, I expect security will be ”bolted-on” to help abate the concerns. Such post-actions are less than optimal and showcase the continuing shortsightedness in Microsoft’s cybersecurity strategic leadership.
I have been critical of the systemic lack of Microsoft’s security leadership in the past, even going as far as writing an open letter to CEO Satya Nadella and predicting continued blunders that will befuddle their leadership. If the strategic leadership concerns are not addressed, issues will continue to surprise Microsoft’s top executives and board members in seemingly unrelated ways across projects, products, and services in the future. https://www.helpnetsecurity.com/2024/07/09/microsoft-cybersecurity-dilemma/
As Microsoft continues to push the boundaries of technological innovation, it must pair these advancements with strategic foresight and a commitment to cybersecurity.
Is Cyber Threat Intelligence Worthless?
I was recently asked “*What do intelligence reports do? They appear worthless!*”
I found the question both funny and ironic. Unfortunately, I had to gently deliver some uncomfortable news.
There is a fundamental difference between *intelligence* and the ability to *apply* it effectively to make better decisions. Intelligence is the distillation and organization of data that is analyzed and assessed to draw meaningful conclusions. These insights often highlight risks and opportunities, serving as a foundation for better decisions.
However, intelligence alone doesn’t guarantee action or success. It takes someone with knowledge and experience to interpret these insights within a specific context, align them with goals, and uncover actionable strategies to address potential risks or opportunities. This process enables smarter decisions and often provides a competitive edge advantage.
Simply put: “***Intelligence is useless without the wisdom to meaningfully apply it.***”
In this case, the person dismissing threat intelligence as “*worthless*” failed to understand how to use it. Intelligence reports don’t necessarily dictate actions — they empower decision-makers with the information they need to act. The value lies not in the report itself, but in the expertise to leverage it.
2024 Top 50 Thought Leaders on Risk Management
Congrats to the Top 50 Global Thought Leaders and Influencers on Risk Management 2024!
Thanks ***Thinkers360*** for the recognition to myself and so many of the hard working colleagues in the cybersecurity industry! http://www.thinkers360.com/
See the full list of profiles here: https://www.thinkers360.com/top-50-global-thought-leaders-and-influencers-on-risk-management-2024/
Fraudsters Abuse DocuSign API for Legit-Looking Invoices
I didn’t see much visibility on this DocuSign hack. This is a situation where the product features were not vetted to understand if they could be misused by malicious fraudsters. There is not a technical vulnerability, it comes down to a design weakness in the product.
According to the security team at Wallarm, “*An attacker creates a legitimate, paid DocuSign account that allows them to change templates and use the API directly.*” They then employ a special template that masquerades as a well-known brand to send the billing invoice. Because the fraudulent invoice is directly sent from the DocuSign platform, it appears legitimate and won’t be stopped by email filters. https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/
The entire process can be automated and sent out on a massive scale, spraying large numbers of unsuspecting victims.
It is the old story of well-intentioned developers asking if they “***can***” develop something without questioning if they “***should***” develop something.
It often takes security-minded experts, savvy in the ways of how attackers think, to evaluate such situations. These are often missed by even experienced developers because there is no technical vulnerability per se. But that does not mean a creative adversary can’t use it in destructive ways. Often, additional controls, oversight, or accountability must be included to dissuade, prevent, or quickly alert of misuse.
The sustainable solution for all software and service vendors is to have cybersecurity experts, not just security-minded developers, as part of the initial feature design teams, keep them in the loop during development, and make sure they vet the final capabilities before going live.
Joining The Cyber Express Advisory Board
I’m thrilled to join the incredible team at The Cyber Express as a member of their Editorial Advisory Board! It’s an honor to collaborate with an esteemed group of cybersecurity experts, all dedicated to delivering accurate, timely, and valuable insights for the cyber defense community.
Together, we aim to empower our readers with relevant knowledge in the fight against evolving digital threats!
Check out all the members here: https://thecyberexpress.com/editorial-advisory-board-international/
Perfect Vulnerability for CISO Ultra Reliable Systems
A “Perfect” 10 vulnerability score is not what users of Cisco Ultra-Reliable Wireless Backhaul (URWB) systems were expecting. The recently discovered cybersecurity vulnerability CVE-2024–20418 is remote, easy, and gives full Admin rights to the device. That is potentially a devastating combination (hence the CVSS score of 10)!
Probably some overtime hours are in store for those patching these systems:
- Catalyst IW9165D Heavy Duty Access Points
- Catalyst IW9165E Rugged Access Points and Wireless Clients
- Catalyst IW9167E Heavy Duty Access Points.
The more strategic concern is that these devices are the type of systems that would be purchased and installed to protect either very sensitive systems or environments that cannot be easily patched — like Operational Technology (OT).
Given that a large portion of our Critical Infrastructure uses OT environments, this vulnerability represents a risk to crucial services we all rely upon, including telecommunications, power, water, transportation, and healthcare systems.
Have a good weekend!
Highlights from the InCyber Montreal Forum
I had a tremendous time at the InCyber Montreal forum. The speakers, panels, fellow practitioners, and events were outstanding!
I bumped into Dan Lohrmann and Nancy Rainosek before their panel with Sue McCauley on CISO challenges. We had some very interesting discussions throughout the day. Always great to hang out with Dan and Nancy.
Then it was my turn on a panel, led by Nataliya Khylenko, discussing how to strike a balance when protecting data in the age of AI. Fellow panelists Sandra Estok, Tania Tanic, and Brandon Pugh were brilliant in providing diverse and relevant perspectives.
By the end of the day, I was able to spend some quality time with Diane M Janosek, Christophe Foulon, and Evgeniy Kharam.
One of my favorite talks was from the passionate Sumona Banerji, who discussed the evolving risks of child online grooming and victimization.
I also caught glimpses of Alexa Charles who leads the coordination of this massive event and keeps all us speakers happy! She is a true superstar!
The Gala Cocktail was spectacular. A local mariachi band, not what I expected in Montreal Canada, played lively tunes and the discussions were flowing among the cybersecurity professionals!
Last but not least Vincent Riou and Shigeru Kitamura, former National Security Advisor of Japan, announced an expansion of the InCyber events to include San Antonio and Japan for 2025!
I am looking forward to both next year!

Malware Can Hide From Email Scanners in Virtual Hard Drives
This is an interesting tactic by cyber attackers – using virtual machine hard drive files to bypass email malware filters!
Never underestimate the creativity and resourcefulness of intelligent adversaries in finding ways to leverage technology for their advantage and to deftly get around security controls.
The use of virtual machine hard drive files like .vhd and .vhdx can be opened in windows and function like a physical drive. They are perfect to hide malware from email gateways and network perimeter filters looking for dangerous files and compressed volumes.
The natural response should be for security filters to access and scan the contents of virtual drives before allowing them to be delivered to potential victims. Sounds simple, but there are some interesting nuances that need to be considered, and of course the attackers would also respond in kind.
This kind of maneuvering warfare is typical and is part of the never-ending game of cybersecurity!
Article: https://www.csoonline.com/article/3575345/threat-actors-increasingly-using-malicious-virtual-hard-drives-in-phishing-attacks.html
SEC is Not Accepting Half-Truths
The SEC has fined four major companies for materially misleading investors regarding cyberattacks.
Tech in Trouble
Regulatory actions have been brought against Unisys, Avaya, Check Point, and Mimecast for their purposeful decisions to not clearly inform customers and shareholders of the attacks and breaches they suffered as part of the SolarWinds cyberattack.
The SEC concluded that these companies were purposely vague by framing their cybersecurity risk factors hypothetically or discussing them in generic terms, even after knowing the issues were present and material.
Reporting material issues to shareholders is a requirement for public companies, so investors will have the same information to make decisions as the insiders of the company.
Jorge G. Tenreiro, acting chief of the Crypto Assets and Cyber Unit, warned that “downplaying the extent of a material cybersecurity breach is a bad strategy”.
The result of this investigation is that Unisys Corporation is fined $4 million as a civil penalty for misleading disclosures and a failure to maintain proper controls over its public statements. Check Point, Avaya, and Mimecast were fined close to $1 million each for similar reasons.
Message to CISOs
The message to boards, C-suites, and especially Chief Information Security Officers (CISOs) is clear — report material breaches as required by the governing regulations. Misleading or false statements are not acceptable.
Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement, stated “…while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered”
Security must be seen as a center of trust. Ethical representations of risks and impacts are the foundation. This includes messages and formal notifications to shareholders and customers. CISOs must recognize their new responsibilities and actively navigate conflicts of interest they experience, and honor their duties.
SEC Press Release: https://www.sec.gov/newsroom/press-releases/2024-174
Are Leaders Ready to Break the Ransomware Cycle
It is good to see US government leaders realize that ransomware is a growing existential threat to our country, at the hands of our adversaries.
A top US national cybersecurity advisor **stated in a recent op-ed**, “This is a troubling practice that must end.” The government is looking at ways to disrupt ransomware attacks. One tactic is to get cyber insurance companies to stop reimbursements for ransoms. https://www.cnbc.com/2024/10/18/that-must-end-government-urges-new-thinking-on-ransomware-payments.html
Undermining ransomware is possible, but the only path is to outlaw digital extortion payments. This targets the root of the problem by undermining the motivation of the attacker.
For decades, cybersecurity and insurance companies have taken advantage of growing attacks and fears to sell their products, which have not provided a meaningful solution to stop the widespread surge of ransomware. It has become a self-serving profit center to motivate customers to purchase more tools and policies for a problem they are not solving.
Security controls are a costly tactic where the attacker maintains a significant overall advantage because they can quickly adapt, thereby requiring more tools to be purchased by the potential victims who are caught in an endless spending cycle. Insurance does nothing to reduce attacks, as it is a mechanism to transfer risk. In fact, paying the attacker simply motivates them more, thereby precipitating even more attacks!
There are **feasible and practical plans** that would work. However, security and insurance companies are the first to cast doubt on any plans that may disrupt their revenue streams. Their narratives are foreboding, but when closely examined, the fears of outlawing payments are **largely unfounded**. https://www.youtube.com/watch?v=7AlMdkaL6II https://www.youtube.com/watch?v=Q33o6Kj0W6E
As a nation, we are beginning to see how digital extortion is effectively being used by international adversaries and cybercriminals. The trend will continue, rapidly causing more extensive harm. Traditional measures, like continually adding more security tools, continue to fail in fundamental ways, and we must take a different approach.
It is time for the US government to take a serious step forward to undermine ransomware, without creating an unnecessary financial burden on the potential victims, by outlawing digital extortion payments.
The Latest Cybersecurity Vault Interviews
The most influential cybersecurity experts discuss adversaries, risks, cyber warfare, and supply chain outages on the Cybersecurity Insights podcast!
Reality of Cybersecurity Risks for AI — **Ejona Preci** https://youtu.be/lRnmWMKlQtg https://www.linkedin.com/in/ejonapreci/
Cybersecurity is Adversarial — Our Failures are Attackers Opportunities — **Dr. Chase Cunningham** https://youtu.be/C4L26qjO0G4 https://www.linkedin.com/in/dr-chase-cunningham/
Rising Threat of Russia’s Cyber Warfare — **Mikko Hypponen** https://youtu.be/E6OvLbAHM6s https://www.linkedin.com/in/hypponen/
CrowdStrike Global Outage: Unpacking the Fallout and Future — **Ira Winkler** https://youtu.be/AqWLQswrAyg https://www.linkedin.com/in/irawinkler/
Be sure to follow the Cybersecurity Insights channel to catch all the podcasts and other strategic discussions about our challenging industry! https://www.youtube.com/CybersecurityInsights
Fraudulent Worker Schemes Lead to Cyberattacks
Secureworks released a report detailing how North Korean attackers are targeting western countries with a new tactic. Attackers are fraudulently obtaining positions so they can victimize the employer! https://www.secureworks.com/blog/fraudulent-north-korean-it-worker-schemes
I predict we will see more of these types of attacks where stolen or fabricated data is used to obtain a trusted position at the targeted organization. Once permissions are granted to the new employee, they use that access to steal information, upload malware, facilitate ransomware attacks, and eventually plant logic bombs & backdoors in products and infrastructure. Depending upon the role the fraudster is able to obtain, they may be able to use their position to infect partners, vendors, and even customers!
Be wary and act now to implement basic insider risk programs to prevent/minimize, detect, and respond to these attacks
The best mitigation is to thoroughly vet applicants, apply the principles of least access to new hires, and train existing employees to watch for signs of unusual activity.
Rising Cyber Aggression from Nation States
There are big predators in our digital world. In recent keynotes I have been talking about the big 4 aggressive nation states and how they are heavily investing in offensive cyber capabilities that trickles down to everyday cybercriminals.
Cybersecurity and Infrastructure Security Agency (CISA) just published an advisory warning regarding the latest activities of Iranian cyber threats. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-290a
CISA warns that Iranian cyber actors are using brute force and credential access activity compromises on critical infrastructure targets, which can impact everyone!
I will be talking about this and other emerging threats next week, at the Mindfluence - Cybersecurity and AI Event - CISO/Executive Leadership Forum in Napa CA, when I deliver the opening keynote discussing how cybersecurity is at a crossroads and we must transition from a cost center to competitive advantage!
I am looking forward to seeing many CISO colleagues - https://mind-fluence.com/napa-2024/
Explaining Cybersecurity - Vizitek Interface Overview
https://www.youtube.com/watch?v=eqcr5Gs0FMY
Explaining cybersecurity is challenging, but with the right visual interface, it is easier to understand the behavioral, technical, and process aspects of cyberattacks.
For the full video Explaining Ransomware: https://www.youtube.com/watch?v=njXi-NoLZiQ
Check out the Vizitek interface and explore different attacks: https://rb.gy/33u6pb
Follow Matthew Rosenquist on LinkedIn https://www.linkedin.com/in/matthewrosenquist/ And for more Cybersecurity Insights, be sure to Like and Follow: https://www.youtube.com/CybersecurityInsights
InCyber Forum Canada 2024
The InCyber Forum Canada 2024 conference is an outstanding event, packed with multiple stages, many thought-leadership panels, and an expansive array of vendors showcasing their latest innovation.
Come join me in Montreal Canada, Oct 29th-30th, and check out our panel *Protect your Data, Thrive in Business: Strike a Balance* on the Trust & Safety stage (Oct 30th, from 2:40pm to 3:40pm).
Registration is open now and here is a bonus: an exclusive 50% discount code on registration, so you can enjoy all the sessions!
**Registration link:** https://2024.northamerica.forum-incyber.com/en/pe1/pe1-home.htm
**Discount code is:** ININ59XU2CF3
***Panel Abstract:*** Protecting data while thriving in business is a delicate but much needed balance in today’s digital landscape. Companies are faced with the need to ensure the privacy and security of their customers’ data while continuing to innovate and grow. What are the best practices for striking the right balance?
**Esteemed Panel:**
**Luc Gagnon** — Chief Technology Officer of the Canada Treasury Board
**Sandra Estok** — Founder & CEO of Way2Protect
**Brandon Pugh** — Director of Cybersecurity and Emerging Threats Policy at R Street Institute
**Tania Tanic** — Founder & CEO of Brainstorm CyberRisque
**Matthew Rosenquist** — CISO and Cybersecurity Strategist at Mercury Risk
**Nataliya Khylenko** (moderator) — President & Founder of KhylenCo Consulting and AdaptAble Academy
Empowering the Modern CISO: Leading the C-Suite & Boardroom
I had a fantastic time moderating an expert panel at the HMG Strategy 16h Annual Silicon Valley C-Level Technology Leadership Summit!
The panel, “Empowering the Modern CISO: Leading the C-Suite & Boardroom with a Bold Digital Agenda” brought an incredible group of cybersecurity leaders to share their insights and recommendations!
Huge thanks to my panelists:
o Alex Bessonov, Security Lead, Amazon
o Jonathan Chan, Head of IT & Security, Episource
o Dhawal Thakker — Cyber Risk, RSM US LLP
o Dušan Vuksanovic, CEO, Swisscom Outpost Silicon Valley
Leading a Panel for CISOs
I am looking forward to moderating an expert panel at the **HMG Strategy** 16th Annual Silicon Valley C-Level Technology Leadership Summit, tomorrow on Tues Oct 8th 2024! https://www.linkedin.com/feed/
The panel will discuss: Empowering the Modern CISO: Leading the C-Suite & Boardroom with a Bold Digital Agenda
**Abstract:** In today's digital landscape, the Chief Information Security Officer (CISO) has evolved into a strategic leader within the C-Suite and boardroom. This session explores how modern CISOs can drive their organizations forward with a robust digital agenda that aligns with business goals.
**Key topics include:**
**Leveraging Advanced Technologies:** Enhancing security with cutting-edge solutions like AI.
**Balancing Innovation and Risk:** Staying ahead of threats while fostering innovation.
**Securing the Supply Chain:** Managing third-party risks in a globally connected world.
**I have 4 superb panelists:**
o **Alex Bessonov**, Security Lead, Amazon https://www.linkedin.com/in/abessonov/
o **Jonathan Chan**, Head of IT & Security, Episource https://www.linkedin.com/feed/
o **Dhawal Thakker**, Principal - Cyber Risk, RSM US LLP https://www.linkedin.com/feed/
o **Dušan Vuksanovic**, CEO, Swisscom Outpost Silicon Valley https://www.linkedin.com/feed/
More event details can be found here: **https://web.cvent.com/event/bfb93642-8c59-4f4b-9803-2e0429da2c82/summary**
US Takes Down 2 Exchanges Laundering Russian Cryptocurrency
Video: https://youtube.com/shorts/wvRelrVSOcE
This is important for two reasons:
1. It disrupts illegal money laundering, in this case, hundreds of millions of dollars that were heading to Russia. These two crypto exchanges were on track to move money in excess of a billion dollars to criminal organizations.
2. It showcases how tools to detect and track illicit cryptocurrency activity are becoming more sophisticated!
Chainalysis is a leader in this space and they are getting better at tracking illicit crypto transactions, which helps global law enforcement partners target offending services.
Overall, this is improving the legitimacy and reputation of the cryptocurrency industry and it keeps the pressure on global criminal activities.
Congratulations to the US Secret Service and its partners for this major takedown!
For interesting cybersecurity insights, be sure to like and follow!
Dept of Justice press release: https://www.justice.gov/opa/pr/two-russian-nationals-charged-connection-operating-billion-dollar-money-laundering-1
Chainalysis Report: https://www.chainalysis.com/blog/ofac-sanctions-russian-exchange-cryptex-uaps-fraud-shop-2024/
If you like insights about cybersecurity, be sure to like subscribe: https://www.youtube.com/CybersecurityInsights