Recent Posts

In Granite State: Industry Groups Paint Dark Picture of Right to Repair

The battle lines were drawn at a hearing in New Hampshire last week for a proposed right to repair law, with supporters calling for economic justice for consumers and opponents warning of crime and injury should the law pass.

Four Signs You’re Ready for a Virtual CISO

A virtual Chief Information Security Officer (or vCISO) can be a great resource to a company. But how do you know when your company is ready for one? Rob Black of Fractional CISO shares four telltale signs to watch for.

Government, Private Sector Unprepared for 21st Century Cyber Warfare

U.S. government agencies and businesses are largely unprepared for a major cyber attack from state-sponsored actors, and must prepare now, according to a report by key governmental-focused think tanks.

ExileRAT Malware Targets Tibetan Exile Government

Researchers have discovered a new cyber-espionage campaign targeting the organization representing the exiled Tibetan government.

Podcast Episode 132: NERC issues a Big Fine – does it matter?

In this week’s episode of the podcast (#132): in the wake of news of the biggest fine yet for violations of the NERC Critical Infrastructure Protection (CIP) standard, we talk with Willy Leichter and Saurabh Sharma of the firm Virsec about whether the industry’s main security standard even matters in an age of sophisticated, nation-backed hackers. As we reported last week, NERC – the North American Electric Reliability Corporation – issued a $10 million fine and a 250 page report (PDF) detailing the failure by one of its member companies to abide by the organization’s main cyber security regulation the Critical Infrastructure Protection or CIP standards. Thirteen of the violations listed were rated as a “serious risk” to the operation of the Bulk Power System and 62 were rated a “moderate risk.” Together, the “collective risk of the 127 violations posed a serious risk to the reliability of the (Bulk […]