With greater SaaS-app deployment comes greater SaaS-app risk. Here are some insights on how you can better understand the risks you face.
Policymakers imposing TikTok bans have something to teach us about app security. But there are also more tools for app sec than the ban hammer.
Google Chrome will soon be requiring 90-day SSL/TLS expirations. Here's what that means.
IT infrastructure has evolved over the years. Meanwhile, ransomware runs wild. The 3-2-1 rule of data backups is out. The 4-3-2-1 rule is in.
RSAC 2023's theme was "Stronger Together." Now that the conference is over, Rik Ferguson shares his takeaways.
ISO 27701 can guide organizations in designing more effective personal information management systems.
With the cloud, identities are the new perimeter. Here's how to understand—and stop—privilege escalation and lateral movement in the cloud.
When criminals hold your data for ransom, should it be illegal for you pay it?
Data-protection regulations are fine—unless they contribute to security blind spots. Go beyond compliance and take an everything-everywhere approach.
Penetration testing can be overwhelming to reactive-thinking CISOs. Here's an overview of initial considerations in getting started with pen testing.