Enterprise Risk Management
Top Stories
-
Tip
16 Jul 2026
How mapping security controls can ease the compliance burden
Being able to map cybersecurity controls to applicable standards and regulations can make compliance work less complicated – especially when automation and AI come into play. Continue Reading
By -
Feature
13 Jul 2026
Why conversational AI is redefining your security perimeter
As employees become more accustomed to using AI, they might be getting a little too comfortable. Learn how strong AI governance helps manage this new human risk. Continue Reading
By- Richard Livingston, Site Editor
-
News
26 Jun 2026
NO FAKES Act advances: What CISOs need to know
As the NO FAKES Act moves to the Senate, the country is closer to real protections against unauthorized AI replica use -- a move that also has enterprise implications. Continue Reading
By- Richard Livingston, Site Editor
-
Tip
25 Jun 2026
What CISOs should know about AI runtime security
With AI, security at runtime means protecting access, vetting inputs, checking outputs and detecting anomalous behaviors. It is challenging to get right. Continue Reading
By- John Burke, Nemertes Research
-
News
24 Jun 2026
As Q-Day looms, 90% of systems are unprepared for PQC
Quantum computing could break encryption in the next several years, and research suggests that few organizations are ready. Experts say CISOs must act now. Continue Reading
By- Craig Galbraith, Galbraith Multimedia
-
News
18 Jun 2026
Most security pros say their culture is 'just average'
'The Life and Times of Cybersecurity Professionals' survey assessed how workers feel about defending against constant threats, as well as what's getting better and what is not. Continue Reading
By- Phil Sweeney, Industry Editor
-
News
05 Jun 2026
Researchers build autonomous AI worm that can reason and adapt
University of Toronto researchers created a proof-of-concept AI worm that dynamically identifies vulnerabilities and adapts its attack strategies. Here's what it means for enterprises. Continue Reading
By- Alissa Irei, Senior Site Editor
-
Tip
03 Jun 2026
How to find cyber-risk data sources for a FAIR analysis
Cyber-risk quantification with FAIR can change the game for CISOs -- but sourcing enough accurate data for analysis can feel impossible. Learn how and where to find it. Continue Reading
By- Alissa Irei, Senior Site Editor
- Paul Kirvan
-
News
27 May 2026
OT attacks shift from recon to physical control, raising stakes
Malicious hackers are no longer just snooping around OT systems, researchers warn. They're preparing to cause real-world damage. Continue Reading
By- Alissa Irei, Senior Site Editor
-
Feature
27 May 2026
How to operationalize a strong cyber-resilience plan
Attackers are becoming increasingly powerful, and regulators are demanding proof of cyber-resilience. In this threat landscape, cyber-resilience plans need to change, too. Continue Reading
-
Tip
19 May 2026
What CISOs need to know about AI audit logs
AI audit logs are rapidly becoming essential tools for enterprise CISOs. Here's what cybersecurity leaders need to track to mitigate risks. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
-
News
15 May 2026
Instructure cyberattack reignites ransom payment debate
Instructure struck a deal to recover its stolen data -- likely paying a hefty ransom. For CISOs, deciding whether to negotiate with cybercriminals should come down to business risk. Continue Reading
By- Alissa Irei, Senior Site Editor
-
Tip
05 May 2026
6 things to check in your cyber insurance policy fine print
Cyber insurance premiums are stabilizing, but coverage is narrowing. From AI risks to nation-state attacks, here's what your policy might no longer cover. Continue Reading
By- John Burke, Nemertes Research
-
Feature
04 May 2026
How cyber insurance helped with breach recovery -- or not
Four organizations, each with cyber insurance policies, responded differently to data breaches. Read the real-world examples of what went right and wrong. Continue Reading
By- Richard Livingston, Site Editor
-
Tip
28 Apr 2026
Shadow code: The hidden threat for enterprise IT
The shadow code running in your web apps could be a ticking time bomb. Learn more about the cybersecurity risks of shadow code and how to protect your enterprise. Continue Reading
By- Karen Kent, Trusted Cyber Annex
-
Feature
23 Apr 2026
Deepfake era demands proof-based security, not just awareness
Deepfakes are reshaping social engineering attacks, and traditional security awareness training is falling short. Some experts say it's time for proof-based verification policies. Continue Reading
-
Feature
23 Apr 2026
The push for digital sovereignty: What CISOs need to know
Digital sovereignty is reshaping global IT strategies and governments are prioritizing local tech to reduce foreign dependencies. Find out what this means for your organization. Continue Reading
-
Feature
21 Apr 2026
Beyond awareness: Human risk management metrics for CISOs
Traditional security training isn't keeping threat actors out. As employee awareness programs fall short, Forrester Research suggests a better approach. Continue Reading
By- Richard Livingston, Site Editor
-
Feature
06 Apr 2026
What to know about red team testing and the law
Red teaming isn't just about finding flaws in cyberdefenses. There are important legal implications that deserve careful consideration. Continue Reading
By- Phil Sweeney, Industry Editor
-
Tip
02 Mar 2026
How to perform a data risk assessment, step by step
Data risk assessments review how an organization protects its sensitive data and identify necessary improvements by revealing potential vulnerabilities, threats and other risks. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Karen Kent, Trusted Cyber Annex
-
Tip
24 Feb 2026
Top threat modeling tools, plus features to look for
Automated threat modeling tools make identifying threats simpler, but the tools themselves can be fairly complex. Understanding where risks exist is only one part of the process. Continue Reading
By -
Feature
30 Jan 2026
Quantifying cyber-risk at Netflix, Highmark Health: Case studies
Show me the money: In these case studies, learn how the FAIR model helped a nonprofit healthcare company and a streaming giant quantify cyber-risk in financial terms. Continue Reading
-
Tip
13 Jan 2026
Deepfake phishing is here, but many enterprises are unprepared
Deepfake phishing attacks are on the rise, as attackers use AI to deceive and defraud end users and their employers. Learn what CISOs can do to protect their organizations. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
-
News
24 Oct 2025
Cybersecurity awareness news brief: What works, what doesn't
Check out the latest security news from the Informa TechTarget team. Continue Reading
By -
Quiz
23 Oct 2025
Cybersecurity awareness quiz: Questions and answers
From phishing to patching, file sharing to MFA, find out how much you know about preventing cybersecurity incidents in this security awareness training quiz. Continue Reading
By -
Tip
22 Aug 2025
Red vs. blue vs. purple team: What are the differences?
Red teams attack, blue teams defend and purple teams facilitate collaboration. Together, they strengthen cybersecurity through simulated exercises and knowledge sharing. Continue Reading
By- Sharon Shea, Executive Editor
-
News
22 Aug 2025
News brief: Safeguards emerge to address security for AI
Check out the latest security news from the Informa TechTarget team. Continue Reading
By -
Definition
07 Aug 2025
What is integrated risk management (IRM)?
Integrated risk management (IRM) is a set of proactive, businesswide practices that contribute to an organization's security, risk tolerance profile and strategic decisions. Continue Reading
By- Nick Barney, Technology Writer
- Wesley Chai
-
Video
24 Jul 2025
An explanation of risk management for businesses
Risk management transforms uncertainty into opportunity by identifying threats, evaluating impacts and implementing strategic controls to protect and enhance business value. Continue Reading
By- Sabrina Polin, Managing Editor
- Tommy Everson, Assistant Editor
-
Answer
24 Jul 2025
How extortionware, cyberextortion and ransomware differ
Prevention is the only line of defense against an extortionware attack. Learn how extortionware works and why it can be more damaging than ransomware. Continue Reading
By- Andrew Froehlich, West Gate Networks
-
Tip
15 Jul 2025
AI in risk management: Top benefits and challenges explained
AI can improve the speed and effectiveness of risk management efforts. Here are the potential benefits, use cases and challenges your organization needs to know about. Continue Reading
By- Donald Farmer, TreeHive Strategy
-
Definition
15 Jul 2025
What is cloud infrastructure entitlement management (CIEM)?
Cloud infrastructure entitlement management (CIEM) is a modern cloud security discipline for managing identities and privileges in cloud environments. Continue Reading
By- Mary K. Pratt
- Kinza Yasar, Technical Writer
-
Tip
09 Jul 2025
How to perform a cybersecurity risk assessment in 5 steps
When assessing cybersecurity risk, be sure to consider the scope of the project, your organization's specific assets and leadership's tolerance for risk. Continue Reading
By- Char Sample, ICF International
-
Definition
02 Jul 2025
What is SIEM (security information and event management)?
SIEM (security information and event management) is software that helps organizations detect, analyze, and respond to security threats by collecting and correlating security event data from across the IT environment in real time. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Linda Rosencrance
-
Definition
01 Jul 2025
What is risk analysis?
Risk analysis is the process of identifying and analyzing potential issues that could negatively affect key business initiatives or projects. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Kinza Yasar, Technical Writer
- Linda Rosencrance
-
Tip
01 Jul 2025
How to implement a risk-based security strategy: 5 steps
Making the move from compliance-based to risk-based security helps organizations prioritize threats using systematic assessment and strategic planning. Continue Reading
By- Ed Moyle, SecurityCurve
-
Definition
01 Jul 2025
What is risk management? Importance, benefits and guide
Risk management is the process of identifying, assessing and controlling threats to an organization's capital, operations and financial performance. Continue Reading
By- Linda Tucci, Industry Editor -- CIO/IT Strategy
- Craig Stedman, Industry Editor
-
Definition
30 Jun 2025
What is the ISO 31000 Risk Management standard?
The ISO 31000 Risk Management framework is an international standard that provides organizations with guidelines and principles for risk management. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Brien Posey
-
Tip
30 Jun 2025
What is attack surface management? Guide for organizations
Attack surface management can help CISOs and other cybersecurity managers address the growth in the number of potential entry points threat actors might exploit. Continue Reading
By -
Definition
30 Jun 2025
What is vulnerability management? Definition, process and strategy
Vulnerability management is the process of identifying, assessing, remediating and mitigating security vulnerabilities in software and computer systems. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
- Sean Michael Kerner
-
Tip
27 Jun 2025
SBOM formats explained: Guide for enterprises
SBOMs inventory software components to help enhance security by tracking vulnerabilities. Teams have three standard SBOM formats to choose from: CycloneDX, SPDX and SWID tags. Continue Reading
By- Ravi Das, ML Tech Inc.
-
Tip
25 Jun 2025
Ransomware threat actors today and how to thwart them
Top experts convened on BrightTALK's 'CISO Insights' to discuss 'Ransomware 3.0' -- the current threat and what organizations, large and small, must do to thwart these bad actors. Continue Reading
By -
Definition
24 Jun 2025
What is risk avoidance?
Risk avoidance is the elimination of hazards, activities and exposures that can negatively affect an organization and its assets. Continue Reading
-
Definition
23 Jun 2025
What is residual risk? How is it different from inherent risk?
Residual risk is the risk that remains after efforts to identify and eliminate some or all types of risk have been made. Continue Reading
By- Dave Shackleford, Voodoo Security
- Francesca Sales
-
Definition
23 Jun 2025
What is pure risk?
Pure risk refers to risks that are beyond human control and result in a loss or no loss, with no possibility of financial gain. Continue Reading
By- Linda Tucci, Industry Editor -- CIO/IT Strategy
- Ben Cole, Executive Editor
-
Definition
20 Jun 2025
What is risk assessment?
Risk assessment is the process of identifying hazards that could negatively affect an organization's ability to conduct business. Continue Reading
By- Kinza Yasar, Technical Writer
- Alexander S. Gillis, Technical Writer and Editor
-
Definition
16 Jun 2025
What is operational risk?
Operational risk is the risk of losses caused by flawed or failed processes, policies, systems, people or events that disrupt business operations. Continue Reading
By- Kinza Yasar, Technical Writer
- Lisa Morgan
-
News
13 Jun 2025
News brief: Gartner Security and Risk Management Summit recap
Check out the latest security news from the Informa TechTarget team. Continue Reading
By -
Tip
13 Jun 2025
What is cyber risk quantification (CRQ)? How to get it right
Cyber risk quantification translates security threats into financial terms, so executives can prioritize risks, justify investments and allocate resources to protect the business. Continue Reading
By- Stephen J. Bigelow, Senior Technology Editor
-
Tip
13 Jun 2025
What a smart contract audit is, and how to conduct one
Smart contracts ensure the integrity of transactions, such as those that initiate key services. A smart contract audit is one way to ensure the programs work as designed. Continue Reading
By -
Feature
12 Jun 2025
Cybersecurity risk management: Best practices and frameworks
This proactive approach protects business operations, ensures compliance and preserves reputation through comprehensive security practices. Continue Reading
By- Stephen J. Bigelow, Senior Technology Editor
-
Definition
03 Jun 2025
What is a chief risk officer (CRO)? A detailed CRO job description
The chief risk officer (CRO) is a senior executive tasked with assessing, overseeing and mitigating an organization's risks. Continue Reading
By- Kinza Yasar, Technical Writer
- Mary K. Pratt
- Ben Cole, Executive Editor
-
Definition
30 May 2025
What is security?
Security for information technology (IT) refers to the methods, tools and personnel used to defend an organization's digital assets. Continue Reading
By- Nick Barney, Technology Writer
- Madelyn Bacon, TechTarget
-
Definition
16 May 2025
What is risk appetite?
Risk appetite is the amount of risk an organization or investor is willing to take in pursuit of objectives it deems have value. Continue Reading
By- Alexander S. Gillis, Technical Writer and Editor
-
Definition
09 May 2025
What is a risk profile? Definition, examples and types
A risk profile is a quantitative analysis of the types of threats an organization, asset, project or individual faces. Continue Reading
-
Definition
09 May 2025
What is risk reporting?
Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes. Continue Reading
By -
Feature
08 May 2025
How to spot and expose fraudulent North Korean IT workers
North Koreans have infiltrated countless U.S. companies as remote IT workers. That means your top developer could also work for one of the world's most notorious dictators. Continue Reading
By- Alissa Irei, Senior Site Editor
-
Definition
28 Apr 2025
What is a risk map (risk heat map)?
A risk map, or risk heat map, is a data visualization tool for communicating specific risks an organization faces. Continue Reading
-
Tip
28 Apr 2025
7 stages of the ransomware lifecycle
It can be nearly impossible to predict if or how a ransomware group will target an organization, but there are knowable stages of a ransomware attack. Continue Reading
By- Char Sample, ICF International
- Andrew Froehlich, West Gate Networks
-
Definition
24 Apr 2025
What is risk exposure in business?
Risk exposure is the quantified potential loss from currently underway or planned business activities. Continue Reading
By- Dave Shackleford, Voodoo Security
- Ben Cole, Executive Editor
-
Tip
17 Apr 2025
Tips to find cyber insurance coverage in 2025
Most businesses have a form of cyber insurance, either through cyber liability and data breach endorsements in traditional business policies or through standalone cyber policies. Continue Reading
-
Tip
14 Apr 2025
How to conduct ransomware awareness training for employees
As your organization's first line of defense, hold regular employee training on how to prevent, detect and respond to ransomware attacks. Continue Reading
By- Sharon Shea, Executive Editor
-
Tip
09 Apr 2025
How to prevent and protect against ransomware
Organizations sometimes learn difficult lessons about gaps in their cybersecurity defenses. Here's what to know about ransomware preparation, detection, response and recovery. Continue Reading
By- Dave Shackleford, Voodoo Security
-
Feature
07 Apr 2025
Explaining AI's impact on ransomware attacks and security
Experts say AI and LLMs will make ransomware attacks more dangerous, but those same tools could be turned against criminals by bolstering ransomware protections. Continue Reading
-
Tip
17 Mar 2025
How to avoid and prevent social engineering attacks
Organizations and employees must both do their part to prevent and avoid social engineering attacks. A combination of security controls, policies, procedures and training is necessary. Continue Reading
By -
Tip
07 Mar 2025
Top 14 open source penetration testing tools
From Aircrack-ng to ZAP, these open source penetration testing tools are essential additions to any security pro's toolbox. Continue Reading
By- Ed Moyle, SecurityCurve
-
Definition
18 Feb 2025
What is defense in depth?
Defense in depth is a cybersecurity strategy that uses multiple security measures to protect an organization's networks, systems and data. Continue Reading
By- Kyle Johnson, Technology Editor
-
Tip
05 Feb 2025
How to create a third-party risk management policy
NIST's Cybersecurity Framework offers some helpful tips for organizations to fortify their third-party risk management strategies. Here's how to implement them. Continue Reading
By- Matthew Smith, Seemless Transition LLC
-
Definition
23 Jan 2025
What is threat modeling?
Threat modeling is the systematic process of identifying threats to and vulnerabilities in software applications, and then defining countermeasures to mitigate those threats and vulnerabilities to better protect business processes, networks, systems and data. Continue Reading
-
Tip
04 Dec 2024
How to protect against malware as a service
Malware operators are further monetizing their malicious software by selling it to other attackers on a subscription basis. Learn how to detect and mitigate the threat. Continue Reading
By- Ashwin Krishnan, StandOutin90Sec
-
Tip
27 Nov 2024
How to build an effective third-party risk assessment framework
Don't overlook the threats associated with connecting vendors and partners to internal systems. Do your due diligence and use third-party risk assessments to prevent supply chain attacks. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
-
Tip
27 Nov 2024
How AI is reshaping threat intelligence
As promising as AI technology is for threat intelligence, organizations grapple with a long learning curve and other challenges that could impede successful adoption. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
- Sharon Shea, Executive Editor
-
Feature
16 Oct 2024
How to define cyber-risk appetite as a security leader
In this excerpt from 'The CISO Evolution: Business Knowledge for Cybersecurity Executives,' learn how to define and communicate an enterprise's true cyber-risk appetite. Continue Reading
By- Alissa Irei, Senior Site Editor
- Wiley Publishing
-
Tip
26 Sep 2024
5 online payment security best practices for enterprises
Ensuring the security of your company's online payment systems is key to preventing costly attacks, meeting compliance requirements and maintaining customer trust. Continue Reading
-
Opinion
18 Sep 2024
Top vulnerability management challenges for organizations
Organizations understand vulnerability management is essential to identifying cyber-risks, but coordinating teams, tools and handling CVEs keeps the pressure on. Continue Reading
By- Jon Oltsik, Analyst Emeritus
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Opinion
11 Sep 2024
6 steps toward proactive attack surface management
With organizations' attack surfaces growing, new research shows better asset management, tighter access policies like zero trust and consistent configuration standards can help. Continue Reading
By- Jon Oltsik, Analyst Emeritus
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Tip
10 Sep 2024
Cyber-risk quantification challenges and tools that can help
While cybersecurity risk should inform budget and strategy decisions, quantifying risk and the ROI of mitigation efforts isn't easy. Cyber-risk quantification tools can help. Continue Reading
By- John Burke, Nemertes Research
-
Opinion
09 Sep 2024
Cyber-risk management remains challenging
Strong cyber-risk management demands collaboration and coordination across business management, IT operations, security and software development in an ever-changing environment. Continue Reading
By- Jon Oltsik, Analyst Emeritus
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Tip
26 Aug 2024
How to use the NIST CSF and AI RMF to address AI risks
Companies are increasingly focused on how they can use AI but are also worried about their exposure to AI-fueled cybersecurity risks. Two NIST frameworks can help. Continue Reading
By- Matthew Smith, Seemless Transition LLC
-
Tip
26 Aug 2024
5 open source Mitre ATT&CK tools
Security teams that use the Mitre ATT&CK framework should consider using these open source tools to help map attacker techniques to the knowledge base. Continue Reading
By- Ashwin Krishnan, StandOutin90Sec
-
Opinion
16 Aug 2024
Cyber-risk management: Key takeaways from Black Hat 2024
Product updates announced at Black Hat USA 2024 can help security teams better manage constantly changing attack surfaces and ensure new AI projects won't pose security risks. Continue Reading
By- David Vance
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
News
09 Aug 2024
Evolving threat landscape influencing cyber insurance market
Many aspects of cyber insurance were addressed throughout Black Hat USA 2024, including changes in the threat landscape that affect policies and coverage. Continue Reading
By- Arielle Waldman, Features Writer, Dark Reading
-
News
06 Aug 2024
Security framework to determine whether defenders are winning
Columbia University researcher and longtime security practitioner Jason Healey will present at Black Hat USA a new framework to determine defensive advantage. Continue Reading
By- Alexander Culafi, Senior News Writer, Dark Reading
-
Opinion
29 Jul 2024
5 key capabilities for effective cyber-risk management
Faced with relentless cyberattacks, organizations need to shore up their cyber-risk management programs by updating legacy tools and checking out new vendor options. Continue Reading
By- David Vance
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Feature
29 Jul 2024
How the Change Healthcare attack may affect cyber insurance
UnitedHealth's Change Healthcare attack continued to show the devastating aftermath of supply chain attacks. Experts say it could change contingent language for future policies. Continue Reading
By- Arielle Waldman, Features Writer, Dark Reading
-
Tip
24 Jul 2024
How to implement an attack surface management program
Keeping attackers away from corporate assets means keeping constant vigilance over the organization's attack surface. An attack surface management program can help. Continue Reading
By -
Definition
22 Jul 2024
What is exposure management?
Exposure management is a cybersecurity approach to protecting exploitable IT assets. Continue Reading
By- Kyle Johnson, Technology Editor
-
Tip
18 Jul 2024
How to conduct a cloud security assessment
Cloud computing presents organizations of all types with a nearly endless array of security challenges. Is your security team keeping up – and how do you know? Continue Reading
By- Dave Shackleford, Voodoo Security
-
News
24 Jun 2024
Corvus: Cyber insurance premiums see 'stabilization'
Corvus Insurance's Peter Hedberg provided insight into the cyber insurance landscape after a tumultuous 2023 and what enterprises can expect moving forward. Continue Reading
By- Arielle Waldman, Features Writer, Dark Reading
-
Answer
12 Jun 2024
Zero trust vs. defense in depth: What are the differences?
Security administrators don't have to choose between zero-trust and defense-in-depth cybersecurity methodologies. Learn how the two frameworks complement each other. Continue Reading
By- Andrew Froehlich, West Gate Networks
-
Tip
05 Jun 2024
What is a cloud security framework? A complete guide
With so many apps and data residing in cloud, employing a security framework to help protect cloud infrastructure is an essential move for an organization. Continue Reading
By- Ed Moyle, SecurityCurve
-
Opinion
22 May 2024
10 risk-related security updates you might have missed at RSAC
AI was a prominent theme at RSA Conference, but many security vendors also delivered risk-focused capabilities to help infosec pros better manage their risk posture. Continue Reading
By- David Vance
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Tip
21 May 2024
5 Mitre ATT&CK framework use cases
The Mitre ATT&CK framework helps security teams better protect their organizations. Read up on five Mitre ATT&CK use cases to consider adopting, from red teaming to SOC maturity. Continue Reading
By- Amy Larsen DeCarlo, GlobalData
-
Definition
15 May 2024
Common Vulnerability Scoring System (CVSS)
The Common Vulnerability Scoring System (CVSS) is a public framework for rating the severity and characteristics of security vulnerabilities in information systems. Continue Reading
By- Kinza Yasar, Technical Writer
- Alexander S. Gillis, Technical Writer and Editor
- Madelyn Bacon, TechTarget
-
Tip
14 May 2024
Cloud vulnerability management: A complete guide
Your security strategy might not grapple directly with cloud vulnerability management. Is it time to consider the possible benefits and challenges of this emerging product class? Continue Reading
By- Ed Scannell, Freelancer
-
Tip
13 May 2024
How to create a cloud security policy, step by step
What are the necessary components of a cloud security policy, and why should an organization go to the trouble to create one? Download a template to get the process started. Continue Reading
By -
Definition
08 May 2024
risk-based patch management (RBPM)
Risk-based patch management (RBPM) is an approach to implementing patches to fix software code that prioritizes patches that address security issues posing the highest risk to the organization. Continue Reading
-
Definition
06 May 2024
risk-based vulnerability management (RBVM)
Risk-based vulnerability management (RBVM) is an approach to identifying and addressing security vulnerabilities in an organization's IT environment that prioritizes remediating vulnerabilities that pose the greatest risk. Continue Reading
-
News
24 Apr 2024
Coalition: Insurance claims for Cisco ASA users spiked in 2023
Coalition urged enterprises to be cautious when using Cisco and Fortinet network boundary devices as attackers can leverage the attack vectors to gain initial access. Continue Reading
By- Arielle Waldman, Features Writer, Dark Reading
-
Opinion
28 Mar 2024
5 areas to help secure your cyber-risk management program
To meet the challenges of managing cyber-risk, organizations need to have a cyber-risk management plan in place. Look at five areas to better secure your organization's assets. Continue Reading
By- David Vance
-
Omdia
Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.
-
Tip
20 Mar 2024
How to defend against phishing as a service and phishing kits
Phishing is a perennial thorn in the side of enterprise security. Thanks to phishing-as-a-service offerings and phishing kits, the problem will only get worse. Continue Reading
By- Ashwin Krishnan, StandOutin90Sec
-
Tip
19 Mar 2024
How to manage third-party risk in the cloud
Third parties, including CSPs, remain a weak point in the supply chain. Adding CSPs into your organization's third-party risk management processes is crucial. Continue Reading
By- Dave Shackleford, Voodoo Security