cyberdefense
Europe’s Sovereign Search Plan is Really a Security Strategy
Alan Shimel | | access to information, adversarial manipulation, AI retrieval, auditability, censorship risk, centralized control, crawling infrastructure, cyberdefense, Data Governance, data provenance, digital policy, digital sovereignty, economic strategy, fragmentation, GDPR, hidden dependencies, information dependency, knowledge bases, legal clarity, Log4j, multi-cloud, national critical infrastructure, operational intelligence, parallel ecosystems, ranking algorithms, Resilience, search infrastructure, security strategy, software supply chain, sovereign search, Threat intelligence sharing, trusted data, vendor lock-in
Europe’s plan to build sovereign search infrastructure highlights a growing security concern: dependence on foreign platforms for access to information and AI knowledge may represent a systemic vulnerability ...
Security Boulevard
Iranian Cyber Threat Escalation: Preparing for Asymmetric Response through Adversarial Validation Emulation
Paul Reid | | cyberattacks, cyberdefense, Cyberdefense Operations, cyberespionage, Cybersecurity, Iran
Amid rising tensions after Israeli and U.S. strikes on Iranian nuclear sites, experts warn of increased Iranian cyber retaliation. With limited conventional options, Iran is expected to rely on cyberattacks against U.S ...
Leveraging Wargaming Principles for Cyberdefense Exercises
Wargames are an excellent way to ensure your cyberdefense plans are solid and your processes are current ...
Security Boulevard
US Disrupted Russian GRU’s Hydra and Sandworm
The United States has been largely mum on its offensive capabilities when it comes to cybersecurity operations. But recently, the Director of the National Security Agency and Cyber Command, General Nakasone, referenced ...
Security Boulevard
Prioritize and streamline vulnerability management through a threat-informed defense, with new research from the Center for Threat-Informed Defense and the MITRE ATT&CK framework as a foundation.
Jonathan Reiber | | Blog, Center for Threat-Informed Defense, CVE, cyberdefense, Cybersecurity, MITRE ATT&CK, Vulnerability Management
In today’s information age, where almost every transaction is digitized, organizations face hundreds–and in some cases thousands–of vulnerabilities. The U.S. Department of Defense even kept a running list of all of its ...
How purple team operations helped defend the Pentagon — and can help your security team today.
Jonathan Reiber | | Blog, blue team, cyberdefense, Cybersecurity, Innovation, national security, operations, purple team operations, Red Team
The purple team construct is changing cybersecurity for the better. Here is how you build, lead, and manage effective purple team operations. The post How purple team operations helped defend the Pentagon ...
GAO Finds Gaps in DoD Cyberdefenses, Highlights Importance of Breach and Attack Simulation Tools
Stacey Meyer | | Accountability, Blog, Congress, cyberdefense, Cybersecurity, defense department, GAO, government, national security
AttackIQ’s Security Optimization Platform gives an agency a proactive—rather than a reactive—security posture. It enables continuous validation of security controls to definitively establish the effectiveness of key initiatives, to include zero-trust controls ...
If You Don’t Hire Robots to Attack Your Networks, You’re Not Doing Security Right
Jonathan Reiber | | Automated Testing, Blog, Blue Teams, CMMC, cyberdefense, Cybersecurity Maturity Model Certification, DoD, effectiveness, Red Teams, SBN News, security control validation, white teams
Complying with DoD’s new cybersecurity regulations requires hard data, the kind that pretty much requires automation to compile. The post If You Don’t Hire Robots to Attack Your Networks, You’re Not Doing ...

