Blog
Third-Party Risk Management: A Comprehensive Framework for Modern Organizations
In 2024 almost a third of data breaches were the result of third-party access to corporate data (2024 Verizon Data Breach Investigation Report – DBIR) third-party risk management (TPRM) has emerged as a critical component of organizational cybersecurity strategy in...
The Hidden Cost of Cybersecurity Inaction: Why Financial Services CEOs Can’t Afford to Wait
In boardrooms across the financial services sector, the cybersecurity conversation has shifted from "Can we afford it?" to "Can we afford not to?" With 64% of financial institutions experiencing cyber incidents in 2024 alone(1) and the average breach cost reaching...
Navigating the New SEC Regulation S-P: Why Financial Services Need a vCISO to Bridge Compliance and Framework Integration
The updated SEC Regulation S-P, adopted in May 2024, represents the most significant overhaul of customer data protection requirements for financial institutions since the rule's original introduction in 20001. With compliance deadlines fast approaching—December 3,...
Why I Chose a Cybersecurity Masters in Science Degree Over the CISSP Certification
After spending ~8 years actively managing and learning about cybersecurity — I chose to pursue a MS in Cybersecurity degree over pursuit of a slew of professional certifications. I initially struggled with that decision and my rationale was primarily driven by 4...
I use 3 steps to create Third-Party Cybersecurity Risk Assessments for Small Business
Third Party (vendor) cybersecurity risks are critical for small businesses to understand and mitigate. Fortunately, third party risk assessments are a cottage industry for laws firms and compliance companies.
NIST CSF and 800-53 For The Win!
One of a vCISO’s first tasks should be to pick or affirm an industry cybersecurity framework to use for building and evaluating a cybersecurity program. The NIST Cybersecurity Framework should be considered – but it is too high level to effectively audit and implement without further guidance.






