<p> <!– CONTENT COMPONENT :74294–></p> <p>Business impact analysis is key to developing an effective and comprehensive business continuity and disaster recovery plan.</p> <p>The business impact analysis (<a href=”https://www.techtarget.com/searchstorage/definition/business-impact-analysis”>BIA</a>) process involves identifying all potential threats and vulnerabilities to the business in…
Tag: Search Security Resources and Information from TechTarget
Taking care of business: The CISO’s role in a cyber crisis
<p>The role of the chief information security officer is pivotal — and constantly evolving. Today’s CISOs are responsible for all aspects of cybersecurity planning, prevention and management, and must also be attuned to the needs of the business.</p> <p>Increasingly, the…
What CISOs need to know about AI audit logs
<p>AI is reshaping the application landscape, seemingly overnight. A recent Google Cloud <a target=”_blank” href=”https://services.google.com/fh/files/misc/google_cloud_roi_of_ai_2025.pdf” rel=”noopener”>survey</a> of 3,466 senior business leaders found 77% of organizations are increasing spending on generative AI, with the vast majority already reporting ROI on at…
SOC vs. MDR: What CISOs need to consider
<p>Every modern organization must monitor its networks continuously and respond to suspicious or malicious activity quickly and effectively. Two basic options exist: an in-house security operations center or a managed detection and response service. Some organizations use both.</p> <p>Let’s examine…
Instructure cyberattack reignites ransom payment debate
<p>Following a massive cyberattack on its popular Canvas learning management system, education software provider Instructure said it had struck a deal with malicious hackers to recover its stolen data. Instructure did not disclose the terms of the deal, but experts…
Transform SIEM rules with behavior-based threat detection
<p>Modern organizations invest heavily in SIEM systems to centralize security data across disparate platforms. They are an important cybersecurity component, yet still miss critical threats, often leaving organizations unaware and exposed. That leads to breaches, prolonged attacker dwell times and…
CISO’s guide: How to test an incident response plan
<p>An incident response plan helps mitigate unexpected and potentially disruptive cybersecurity events. Testing that plan is very much like test-driving a new car. It’s how a potential buyer confirms the experience lives up to the hype. Do all the features…
How to implement zero trust for AI
<p>AI environments involve complex data pipelines, model-training infrastructure, APIs and third-party components, all of which introduce new security risks.</p> <p>Modern security techniques– with and without AI — recognize that traditional trusted-network approaches are inadequate. AI systems ingest new data, interact…
Data after the breach: Economics of the dark web
<p>When sensitive data is stolen in high-profile data breaches, the information doesn’t simply vanish into a digital void. Data extraction is just the beginning of a calculated journey through a sophisticated criminal economy where files are tested, packaged, priced and…
The breakup: Why CISOs are decoupling data from their SIEMs
<p>The traditional enterprise SIEM pulls security log data from sources across the IT environment, then normalizes it, analyzes it and retains it. But because SIEM providers typically charge more to hold more data, organizations generally must retain less data than…
News brief: Security worries and warnings as AI use expands
<p>”We live in a world that could become fraught with day-to-day hazards from the misuse of AI and we need to take ownership of the problems — because the risks are real,” warned Dr. Seán Ó hÉigeartaigh, executive director of…
How to construct an effective security controls evaluation
<p>I once received an ad from a company that promised to lower home energy costs by conducting a free energy audit. The audit, it said, could be done over the phone — no home visit — and would require absolutely…
5 leading enterprise password managers to consider
<p>Enterprise password managers are must-have tools for organizations of all shapes and sizes. While consumer-based password managers are good for users’ personal lives, enterprise security and desktop administrators require more comprehensive password managers that offer greater security, control and visibility…
Claude Mythos changes the AI security threat matrix
<p>When Anthropic announced its latest large language model, Claude Mythos, the news hit with a jolt. Anthropic wasn’t putting out word that it was about to release Mythos — it wanted the world to know that it would <i>not</i> release…
Buyer’s guide for CISOs: Cloud security posture management
<p>Cloud security posture management has become a core layer of modern cloud defense because it addresses a basic but persistent problem: many cloud security incidents begin with misconfigurations, excessive privileges, unmanaged assets, weak network exposure decisions and drift from approved…
6 things to check in your cyber insurance policy fine print
<p>Cybersecurity insurance has never been a “must-have” purchase for enterprises, with many still forgoing any form of coverage. Others, however, have found it attractive as a way to hedge against the failure of their cybersecurity investments.</p> <p>Cyber insurance can help…
How cyber insurance helped with breach recovery — or not
<p>Since its emergence in the 1990s, cyber insurance has become a critical part of enterprise risk management. Initially an offshoot of errors and omissions insurance, cyber insurance coverage, which was limited in scope, swiftly matured as companies became more reliant…
News brief: Critical infrastructure, OT cybersecurity attacks
<p>The Stuxnet worm is widely recognized as the first confirmed cyberattack designed to damage critical infrastructure. Discovered in 2010 but used as early as 2009, it targeted uranium enrichment systems at Iran’s Natanz Nuclear Facility, causing physical destruction of centrifuges.</p>…
Top zero-trust use cases in the enterprise
<p>Most organizations have embraced zero trust, but many are early in their adoption journey. Yet with the rising volume, velocity and sophistication of attacks, security teams are under pressure to accelerate those journeys.</p> <p>”We’re definitely seeing higher rates of adoption…
Tape’s strategic role in modern data protection
<p>The necessity of data backup has been clear since the early days of computing. And the oldest backup method — tape — is still a viable option.</p> <p>In the past decade, tape use declined in favor of the cloud due…
