Author
David Rand

Preemptive cybersecurity: Real protection or ‘Minority Report’ fantasy?
Stopping attacks before they happen is every defenders dream and it could be heading toward reality as AI-driven predictive cyber insights takes shape.

How CISOs can become AI ‘risk advisers’
Unbridled AI can leave a company exposed to regulatory fines, stalled operations, and brand-damaging headlines. Enter the CISO who shifts from defender in the background to AI risk whisperer at the decision-making table.

11 cybersecurity predictions (and how to prepare) for 2026
Focal Point gathered guidance from leading cybersecurity experts to identify what CISOs should watch for in the new year—from hijacked AI agents to shifting boardroom accountability—and the best steps to take now to deal with the coming challenges.

AI is disrupting hybrid cloud security. These 4 steps restore it
The data deluge from GenAI has cyber teams struggling to manage their hybrid infrastructures, but experts have identified a range of effective responses that can help companies regain control.

Vibe coding may be unstoppable—but here’s how to rein in the risks
Like the meteoric rise of ChatGPT, vibe coding is all anybody can talk about this year. In fact, it just became a word in the dictionary. But beware the boom: Here’s what enterprise and security leaders need to know to keep their orgs safe.

Employee security training is way overdue for a shake-up. Here’s the fix
Odds are your employee security training just isn’t cutting it. With staffers still falling for phishing scams and AI amping up attacks, researchers advise replacing or supplementing the usual methods with skills-based approaches that allow workers to practice, get feedback, and retain what they learn on a regular basis. Follow these tips to make training part of your culture.

Lateral Movement Update: 3 Ways to Stop the Sideways Steal of Data Across Your Network
After penetrating the perimeter, hackers can execute lateral movement—and survey network structure, map devices, identify targets, seize data—in just 27 minutes. Old-school defense tactics (and, yes, AI and automation) can stop intruders in their tracks.

Help Desk Hell: The Targeted Attacks That Fool Your IT Workers and Steal Your Data
Social engineering, upgraded: Hackers use AI and advanced tech to exploit kind employees, breach networks, and devastate data—fast.

SolarWinds CISO Tim Brown Speaks Out Ahead of Final SEC Settlement
In a rare interview, SolarWinds CISO Tim Brown recounts the legal fallout from one of the biggest cybersecurity breaches in history, the personal impact (“The doctors confirmed a heart attack”), and why being a CISO is still a great job.

Spoilage Alert: Cyberattacks Are Disrupting Europe’s Supermarket ‘Cold Chain’
A recent wave of cyberattacks on cold chain companies—most recently in Germany and the UK—have experts worried about the delivery of food, medicine and other perishables. We offer practical cyber strategies for logistics vendors and consider whether these attacks will ramp up in the U.S.

Subtle Sabotage: The Rise of Data Tampering, the Next Cyber Battleground
Data tampering is a stealthy, often underestimated tactic in a hacker’s toolkit that can distort audits, mislead regulators, and erode customer trust. Arm your teams with these five expert-endorsed strategies.

Protect Your Prompts: Injection Threats Are Coming for Your AI Tools
With the increasing deployment of artificial intelligence comes the danger of attackers manipulating AI commands. It’s remarkably easy to do – you don’t have to be a member of a sophisticated cyber gang to pull this off – and can wreak havoc on operations and assets.

As SEC SolarWinds Case Plays Out, CISOs Shift Into Defensive Mode
The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

The SLCGP Is Another Year Older. Here’s What You Need to Know About Federal Cyber Grants
SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.

CISO Success Story: How LA County Trains (and Retrains) Workers to Fight Phishing
The CISO for LA County, who oversees 100,000 employees, shares tips on cross-agency info-sharing, ongoing audits, and aggressive awareness training.

CISO Success Story: How to Build Trust With the Board? Don't Talk Cybersecurity (Much)
To establish common ground with business leaders, this healthcare pro and Honest Medical Group CISO Dennis Leber listens first, then aligns his cybersecurity strategy to business needs.

RaaS Class: A Defensive Guide to Ransomware-as-a-Service Attacks
Despite high-profile takedowns of notorious ransomware-as-a-service (RaaS) gangs, attacks like the Vegas casino hacks are on the rise. Here’s how businesses need to adapt.

CIO Success Story: Looking At the Flip Side of Third-Party Risk
In the second of an ongoing series of one-on-one interviews with security leaders, Focal Point sits down with Stephen Held of architectural engineering firm Leo A Daly to discuss his not-so-typical take on third party risk.

The MOVEit Breach Is Still Going Strong: Here’s How to Keep Your Data Safe
Is the MOVEit breach this year’s Log4j? Well, we sure haven’t heard the last of it. Here are seven steps enterprise leaders must take to safeguard their data.

Make Friends with Your Cyber Insurance Agent, Part 2—The Steps to Take Now
In an era of rising rates and denied claims, it’s easy to see insurance companies as adversaries. Previously, we looked at the benefits of partnering with your insurer. Here, we show how to succeed at that, step by step.

Make Friends with Your Cyber Insurance Agent, Part 1—Why It Matters
In an era of rising rates and denied claims, it’s easy to see insurance companies as adversaries. Part 1 of this two-part series looks at why it’s better to see your insurers as partners and leverage their tools and expertise. Later this week, we cover how to do it.

Banks vs. Ransomware: The Battle Is on Again in 2023
After ransomware attacks plunged last year, hackers are back to wreaking havoc on finserv companies. But there are plenty of ways banks and other financial institutions can fend off the damage.

What Cybersecurity Layoffs Mean for Risk—and How to Be Ready
Cybersecurity teams have been spared the pain of layoffs. but don’t sigh with relief just yet. Change is afoot and enterprise leaders need to be prepared.

3 Ways Banks Can Prep for Quantum Computing Threats to Cybersecurity
The full potential of quantum computing is still several years away, but banks need to start countering this ‘“existential” cybersecurity threat now.

5 Ways Boards Can Improve Their Cybersecurity Governance
Experts advise these key practices for boards of directors to meet rising cybersecurity threats—and intensifying pressure from regulators.

What Many Get Wrong About Persistent Engagement and Why It Matters to Business
We talked to Richard J. Harknett, the pioneering professor who’s advising U.S. military and intelligence on persistent engagement, a more active approach to national cybersecurity.

What Businesses Need to Know About Biden’s National Cybersecurity Strategy
Biden’s new cybersecurity strategy offers an innovative 24/7 approach to cyber vigilance and a two-word mantra for Big Tech: Do more.

RSA 2023 Preview: What CISOs (Need to) Know About Board Accountability
In the first of our three-part sneak-peek at RSA Conference 2023, Focal Point sits down with Tanium CISO Chris Hallenbeck to discuss board awareness of cybersecurity and what CISOs can do to help. Here’s a tip: Don’t talk too much.

Is Multifactor Authentication (MFA) Living Up to Its Hype?
There’s mounting evidence that multifactor authentication (MFA) isn’t exactly the panacea that will fix everyone’s hacking problems. Yes, it’s super effective for user-verification, but hackers are using three sneaky tactics to get around it.

Yes, ChatGPT Will Turbocharge Hacking—and Help Fight It, Too
While amateurs can now use ChatGPT to create malware and phishing emails, security pros can also enlist the bot to fight cyberattacks.

Layoffs Could Hatch a New Generation of Data Thieves and Hackers
As corporate layoffs keep coming, cybersecurity experts predict an uptick in insider risks. How you fire—and hire—can make all the difference when it comes to combating data thieves and hackers.

How CISOs Can Fight Burnout and Extend Their Careers
There is no question that security is a tough field. Figuring out how to get through each day effectively, and unscathed, is a bit murkier. The following advice can help execs thrive under pressure.

It Pays to Know How Your Cybersecurity Stacks Up
Cybersecurity benchmarking compares your IT risk metrics to industry competitors, a key upgrade that adds business value—and reduces risk.

5 Myths—and Realities—About Cyber Insurance
Companies often choose to forgo cyber insurance—at their peril. Here’s why executives must learn the truth about coverage.

The Legal Danger Lurking in Cyber Insurance Policies
Experts advise companies to understand the fine print in their cyber coverage—and be ready for more insurers to contest claims or rescind policies over alleged misrepresentations.

Why Bug Bounty Hunters Are Earning Huge Payouts
Here’s what security executives need to know about working with ethical hackers on emerging technologies like blockchains.

Why the Bridges Between Blockchains Are Under Assault
Connections between blockchains are the weak links in the security armor of the “unhackable” technology underpinning the next generation of the internet.

The Rise of the Cybersavvy Corporate Treasurer
Treasurers hold the purse strings. That makes them attractive targets for cyberthieves. Here’s how to outsmart the bad guys.

Will the Feds Backstop Cyber Insurance?
Critical infrastructure providers may soon get federal protection against the crippling costs of cyberattacks. Here’s why.

Surprise! It's Another Zero-Day Vulnerability
Security experts are debating the cause of a growing number of zero-day software flaws, but there is consensus about one thing: how to prepare for the next attack.

Ransomware Is Battering the Cyber Insurance Industry
It’s usually up to corporate treasurers to shop for cyber insurance. Here’s how to navigate that costly shifting market.

Why Corporate Leaders Must Secure the Wild West of the Metaverse
As more businesses enter the metaverse, security leaders must ensure this emerging virtual marketplace is safe for customers and employees.

Why Multicloud Security Never Sleeps
To stay ahead of hackers, enterprises must improve visibility and security across the many cloud environments that underpin IT operations.

State CISOs to Feds: Show Us the Money
States are waiting for $1 billion in federal cybersecurity grants. Here’s what they need to know to act fast when those infrastructure funds start to flow.

Cryptojacking: How to Stop Coin Miners From Hitting Your Network
Coin mining attacks are increasing in frequency and severity, threatening enterprises. Here’s how to fight back.

The Future Is Passwordless
Enterprises are (finally) trading passwords for biometrics, multifactor authentication and single-sign-on tools. Here’s why.

Are Metaverse Meetings the Answer to Better Employee Engagement?
Your workers may be remote but need not feel alone: Here’s how metaverse meetings and virtual reality can enhance the employee experience.

Universal Broadband Must Include Cyber Hygiene Practices
As state and local governments allocate ARPA funds to boost digital services, experts plead for an investment in cybersecurity.

Big Enough to Hack
Cyberattacks on small and medium-size businesses are surging. We asked experts and criminal hacking targets what steps must be taken—before it's too late.

How NPower Creates Pathways to Prosperity
Too many people don’t know how to get into high tech, especially in underserved communities. Tech training from NPower helps develop that workforce.

The Art of Ransomware Negotiation
Ransomware negotiation is part tennis match, part art form—which is why most enterprises hire experts to handle deals. Here’s how the best resolve conflict.

More E-commerce, More Cybersecurity Problems
As e-commerce continues to boom, a patchwork of legacy technology is leading to corporate cybersecurity vulnerabilities and hindering resilience.

Bodies Electric: The Promise of 6G Wireless Technology
In the wake of massive ransomware attacks, researchers, governments, and businesses are looking past the roll out of 5G wireless technology to create a more secure future with 6G.

The Pandemic Made CISOs Mission-Critical. Here’s How They Can Maintain Their Status
Lauded as heroes during the pandemic crisis, CISO's must build a secure foundation to enable possibilities rather than having to defend against threats.

Tool Sprawl Threatens Post-Pandemic Security
Tool sprawl and the use of rogue software by remote workers has become a major concern for security teams. CISOs have devised ways to improve IT visibility.

Supply Chain Risks to the Vaccine Rollout
Ransomware attacks have hit the healthcare industry networks hard with the spread of COVID-19, and the risks have increased with the global vaccine rollout.

What is performance monitoring?
Learn about performance monitoring and tools that enable organizations to monitor, manage, secure, and optimize their computers and devices' health.

What Is configuration management?
Learn about IT configuration management and the tools that define, apply, and enforce a system’s desired state across computer systems, servers, and software.

What is software management?
Learn more about software management and how modern solutions improve the IT team's control and support over the organization's application landscape.

How Endpoint Security Can Mesh with Rapid Digital Transformation
Enterprise endpoints are a major weak link in cybersecurity during the pandemic. Greater alignment between digital transformation & security is needed.

How To Turn Your Remote Workers Into Security Advocates
Cyberattacks are up in the WFH era, meaning employees need extra security training to raise their awareness of potential threats.

Four Use Cases for How 5G Will Transform Enterprises
As 5G adoption and rollout gets closer to realization, we look at use cases that highlight just how transformative this technology is expected to be.