Most of our IT infrastructures were built to trust. From the time users sign on in the morning until they log off at the end of the day, the network trusts them as well as the computer that they are...
Brian Petzold
Recent Posts
What is "Best Practice"?
by Brian Petzold | Mar 5, 2021
Over the years, I have become wary of the term “best practice” when it is applied to technology and cybersecurity. The term “best practice” is supposed to mean that what is being described aligns...
Guidance on Obsolete Encryption Protocols
by Brian Petzold | Jan 22, 2021
Networks rely on encryption to ensure that data is kept private and cannot be changed while at rest or in transit. In most cases this encryption utilizes certificates, and these certificates in turn...
Mitigating Supply Chain Attacks
by Brian Petzold | Dec 30, 2020
The worst fears of security experts became a reality recently when threat actors maliciously hid malware inside legitimate updates of SolarWinds network monitoring software. When the malware...
The Powerful GLBA Board Report
by Brian Petzold | Dec 11, 2020
When the Gramm-Leach-Bliley Act was implemented, each regulatory agency adopted a set of interagency guidelines and regulations required for compliance with the provisions of the Act. Within each of...
Inherent and Residual Risk
by Brian Petzold | Nov 13, 2020
When we start working with financial institutions, we often find that there is a lot of confusion around how cybersecurity inherent risk and residual risk should be defined. The assessments seem to...
Asset Management Lessons Learned from Morgan Stanley
by Brian Petzold | Oct 16, 2020
Asset Management is one of the foundations of a sound Information Security Program, but it is also often neglected in the rush to replace or decommission systems. Every IT Manager has been through...
Typ0squatting
by Brian Petzold | Sep 25, 2020
We recently have seen an increase in “typosquatting” activity targeting financial institutions. Typosquatting is when someone registers a domain with a name that is very similar to the legitimate...
National Insider Threat Awareness Month
by Brian Petzold | Sep 4, 2020
A group of US security agencies has once again designated September as “National Insider Threat Awareness Month” (NITAM). While insider threats are always a concern, the agencies point out that...
Herding CATs
by Brian Petzold | Aug 7, 2020
After helping many financial institutions complete their Cybersecurity Assessment Toolkit (“CAT”), we have found that there are a small number of CAT statements that commonly get institutions...