Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest Posts

PCI 4.0: Your Next Audit May Take Longer, But it's for a Good Cause

2024 is almost here, and that means PCI DSS 4.0 will soon go into effect. The newest version will have some mandatory controls on March 31, 2024, for those who store, process, or transmit card payment data. While its predecessor weighed in at 190 pages, PCI DSS 4.0 is 486 pages and includes 63 new security controls.

Understanding DNS-Based Threats and How They Impact Your Business

Cybersecurity, DNS (Domain Name System), and your company are interconnected topics in the field of network security. Protecting a company’s cybersecurity, including its DNS infrastructure, is of utmost importance in today’s digital landscape. DNS is responsible for translating user-friendly domain names into machine-readable IP addresses, allowing devices to communicate with each other over the internet.

MSSP Alert Names CISO Global to 2023 Top 250 Managed Security Services Providers List

CISO Global has been designated a Top 25 Managed Security Services Provider by cybersecurity business intelligence company CyberRisk Alliance and MSSP Alert, the authoritative news and research channel for managed security services providers (MSSPs).

Becoming FedRAMP and StateRAMP Authorized Part 4: Can Continuous Monitoring Actually Give You a Leg Up?

Validating the security of your organization’s sensitive information at a single point in time with an annual risk assessment can be helpful, but what about the other 364 days of the year? If you have a cloud application and hope to sell your services to federal agencies, point-in-time assessments won’t be enough.

CISO Global Participates in Microsoft Security Copilot Partner Private Preview

CISO Global announces its participation in the Microsoft Security Copilot Partner Private Preview. CISO Global was selected based on their proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and their close relationship with Microsoft.

Move to the Cloud with Confidence: 6 Key Risks & Mitigation Techniques, Part 3

Cloud application, platform, and infrastructure vendors (cloud service providers, or CSPs) do a great job of advertising online. They offer seemingly painless ways to sign up for their services through “freemiums” and two-week trials, advertisements that follow you from Google to LinkedIn, and what appear to be straight-forward sales processes.

CMMC 2.0 Preparation: Top Four Strategic Actions to Take Now

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a compliance requirement that all Department of Defense (DoD) Contractors (aka, the Defense Industrial Base) will soon have to meet. See my blog Why is CMMC a Big Deal? for more information about the legal implications of CMMC. The CMMC official mandate is expected to be released from rulemaking in the first quarter of 2024 and be in full implementation in the first quarter of 2026.

Creating a Culture of Cybersecurity Part I: The 8 Benefits of Insourcing Your IT Help Desk

What is the culture of cybersecurity, anyway? When most people hear the phrase “Cybersecurity is a Culture,” their minds jump immediately to cybersecurity awareness training videos that help employees avoid phishing scams. Certainly, that is an important part of driving security awareness in your organization, but the true culture of cybersecurity is so much more. To quote our CTO, Jerald Dawkins, Ph.D., “Cybersecurity is a team sport.