Compliance

Data Breach Laws: A State-by-State Framework as of September 2021

What you need to know for compliance coast-to-coast. Back in 2020 we posted an article containing links to data breach laws from each state, and it has proven to be one of our more popular posts.  Because laws surrounding the use (and abuse) of technology are always evo...

An Overview of the FFIEC Architecture, Infrastructure, and Operations Booklet

Our Lead Non-Technical Auditor takes a look at the new AIO Guidance… Architecture, Infrastructure, and Operations (AIO) is the latest booklet released by the Federal Financial Institutions Examination Council (FFIEC) in their line of  IT Examination Handbooks. It i...

A Cloud Security Reminder

Many organizations still fail to consider the unique risks posed by cloud computing… An article review. Last month thousands of Western Digital MyCloud device owners learned about the risks of cloud-based solutions the hard way: their data had been wiped remotely...

‘Disrupted’ Employees: The New Insider Threat?

Employees working from home may find it more difficult to follow security policies… An article review. The surge in employees working from home during the pandemic created many headaches for IT departments around the world, many of whom had no telecommuting polic...

What To Expect from an infotex Incident Response Tabletop Test Movie

A Webinar-Movie infotex presents the 2021 update of a previously released webinar presented by our Lead Non-Technical Auditor, Adam Reynolds. This movie-short is intended for those who are planning to participate in an infotex Incident Response Test. Not sure about the i...

Sometimes Say Sometimes

Another Manifesto A supply-chain manifesto by the author of Never Say Never: A Password Manifesto! Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . [Sssshh.  Turn out the lights.  Let’s lower our inner voices,...

The Problem with Cybersecurity Insurance

The cybersecurity industry faces challenges, and some of them may involve your business… An article review. In a world where threats to your organization’s electronic assets are constantly emerging and evolving a cybersecurity insurance policy can help miti...

Are You Ready to Discuss the GLBA?

A long overdue update, but an update nonetheless. . . Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . “To respond to heightened cybersecurity threat,” as they said, in fourth quarter of 2021, the Federal Trade Commi...

Incident Response on Steroids!

Turning Letters into Lemonade . . . Could Marketing Messages be Pre-Planned Into Response? Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Something I just noticed: I now know what Yandex is. And I would not have k...