Reviewing Your Information Security Program for 2023

by Tori Thurmond / June 15, 2023

2023 may feel like it’s flying by already but there’s still time to make sure your information security program can overcome the current threat landscape. Each year, we often hear a lot of confusion and frustration about frameworks modifying their requirements, the cost of audits rising, the cost of pen tests rising, scopes getting larger, and testing being more difficult. There’s a reason for this – the threats are advancing.…

5 Questions to Ask When Choosing Your Audit Partner

by Tori Thurmond / June 13, 2023

How do you choose the right audit partner for your compliance journey?   In order to successfully protect your data and your reputation through an information security audit, you must first choose an audit firm. This firm is the entity that will have access to your people, your assets, your data, and your risks. This can be an overwhelming task, but it’s extremely important. Hiring a firm to provide information security…

What CISOs Have to Know about Data Governance 

by Tori Thurmond / June 15, 2023

With the amount of data organizations possess today, is true data governance possible anymore? CISOs’ jobs are becoming more challenging with the influx of data—not to mention the risk that goes along with that data.  As a reminder, data governance is defined as –   “An organization’s internal process of ensuring data integrity, confidentiality, availability, quality, transparency, minimization of collection, access and use, defined legal bases for the use of data,…

Man working on computer

5 Ways to Prevent Zero Day Attacks 

by Tori Thurmond / October 4, 2023

Hackers get better at their jobs every day.   It can be overwhelming to try to stay ahead and keep your organization as secure as possible. New ways to capitalize on vulnerabilities within an organization’s security landscape pop up frequently putting your data at risk. One of the methods threat actors use to gain control of your environment is through zero-day attacks.   A zero-day attack, or Day Zero, is a software-related…

What You Need to Know about Data Governance from Chief Data Officers 

by Tori Thurmond / June 15, 2023

Data is a hot topic right now. It seems like everywhere we turn, there’s a data breach or new data privacy law rolling out, and it can be hard to keep track of everything. At the 2022 Information Systems Audit and Control Association (ISACA) Chicago conference, a group of Chief Data Officers gathered to talk about data priorities and what the future of data will look like. Before we dive…