Which NIST Standard Is Most Important for Small Businesses?
by Andrew Paull on July 19, 2024 at 2:53 PM
Navigating the complexities of cybersecurity can be challenging for small businesses, but the National Institute of Standards and Technology (NIST) offers robust frameworks to help. This blog analyzes the various NIST initiatives and guidelines designed to enhance cybersecurity for sm …
CCPA vs. GDPR: A Comprehensive Comparison
by Andrew Paull on April 11, 2024 at 2:15 PM
Compliance laws such as the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) were established to safeguard user data from unauthorized access and breaches. These laws are applicable to businesses involved in the collection, usage, or sharing of …
ProxyNotShell – Microsoft Exchange Exploit Explained
by Andrew Paull on March 23, 2023 at 1:15 PM
ProxyNotShell – What is it? Cyberattacks have become increasingly sophisticated and widespread in recent years, with hackers constantly finding new ways to infiltrate networks and steal sensitive information. One such vulnerability that has recently come to light is ProxyNotShell, ide …
The Online Shopping Scam That Almost Duped a Security Professional
by Andrew Paull on December 10, 2020 at 3:15 PM
A great many things have changed in our daily lives since the COVID-19 pandemic began rampaging across the world at the beginning of this year. We have been collectively forced to adapt to working from home, schooling from home, shopping from home, and even receiving healthcare from h …
Vendor Risk Management: Third-Party Risk Analysis / Annual Review
by Andrew Paull on October 8, 2020 at 2:00 PM
We live in a world where our interactions with each other are generally benign, observed to be candid at face value, making it easy to take the assurances of success, functionality, and capability of our colleagues and acquaintances as they are meant. Unfortunately, business interacti …
Vendor Risk Management: Information Security Responsibilities
by Andrew Paull on January 29, 2020 at 3:30 PM
Welcome back! This article serves as part two in my Vendor Risk Management blog series, continuing the discussion on some important factors of creating and renewing third-party contracts.