Skip to main content

Author

David Rand

preemptive-cybersecurity-real-protection-or-minority-report-fantasy
Feb 12, 2026

Stopping attacks before they happen is every defenders dream and it could be heading toward reality as AI-driven predictive cyber insights takes shape.

An abstract painting in bright primary colors of one figure whispering into the ear of another.
Jan 21, 2026

Unbridled AI can leave a company exposed to regulatory fines, stalled operations, and brand-damaging headlines. Enter the CISO who shifts from defender in the background to AI risk whisperer at the decision-making table.

A white billiard ball with a wide red band and marked with the number 11 sits on a pool table.
Jan 7, 2026

Focal Point gathered guidance from leading cybersecurity experts to identify what CISOs should watch for in the new year—from hijacked AI agents to shifting boardroom accountability—and the best steps to take now to deal with the coming challenges.

A bright red plastic disc in the shape of a cloud sits atop a computer console.
Dec 11, 2025

The data deluge from GenAI has cyber teams struggling to manage their hybrid infrastructures, but experts have identified a range of effective responses that can help companies regain control.

A row of traffic lights, all lit red, trail off into the distance.
Nov 11, 2025

Like the meteoric rise of ChatGPT, vibe coding is all anybody can talk about this year. In fact, it just became a word in the dictionary. But beware the boom: Here’s what enterprise and security leaders need to know to keep their orgs safe.

An old rusted wrench, hammer, plyers and other tools lay on a dirty metal surface.
Oct 14, 2025

Odds are your employee security training just isn’t cutting it. With staffers still falling for phishing scams and AI amping up attacks, researchers advise replacing or supplementing the usual methods with skills-based approaches that allow workers to practice, get feedback, and retain what they learn on a regular basis. Follow these tips to make training part of your culture.

A weather vane stands against a bright blue sky with puffy white clouds.
Sep 24, 2025

After penetrating the perimeter, hackers can execute lateral movement—and survey network structure, map devices, identify targets, seize data—in just 27 minutes. Old-school defense tactics (and, yes, AI and automation) can stop intruders in their tracks.

A photo of a laptop consumed by flames.
Sep 18, 2025

Social engineering, upgraded: Hackers use AI and advanced tech to exploit kind employees, breach networks, and devastate data—fast.

A polished wooden gavel with gold trim rests on a sound block against a crimson background.
Sep 10, 2025

In a rare interview, SolarWinds CISO Tim Brown recounts the legal fallout from one of the biggest cybersecurity breaches in history, the personal impact (“The doctors confirmed a heart attack”), and why being a CISO is still a great job.

A supermarket shopping cart sits in silhouette before a bright blue swirling storm.
Aug 21, 2025

A recent wave of cyberattacks on cold chain companies—most recently in Germany and the UK—have experts worried about the delivery of food, medicine and other perishables. We offer practical cyber strategies for logistics vendors and consider whether these attacks will ramp up in the U.S.

Fingers seen in silhouette touch a computer screen filled with ones and zeros.
Aug 6, 2025

Data tampering is a stealthy, often underestimated tactic in a hacker’s toolkit that can distort audits, mislead regulators, and erode customer trust. Arm your teams with these five expert-endorsed strategies.

An image of a hypodermic needle sitting atop a spread of neon-bright ones and zeros.
May 22, 2025

With the increasing deployment of artificial intelligence comes the danger of attackers manipulating AI commands. It’s remarkably easy to do – you don’t have to be a member of a sophisticated cyber gang to pull this off – and can wreak havoc on operations and assets.

Closeup image of a foosball table, with plastic figures on metal rods facing off in blue and red jerseys.
Feb 1, 2024

The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

Photo of a hand passing a wad of cash to another hand.
Jan 10, 2024

SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.

Photo of a row of palm trees, with the downtown Los Angeles skyline in the distance.
Dec 8, 2023

The CISO for LA County, who oversees 100,000 employees, shares tips on cross-agency info-sharing, ongoing audits, and aggressive awareness training.

Photo of a medieval white stone sculpture of a young man's head, with black tape covering the mouth.
Nov 7, 2023

To establish common ground with business leaders, this healthcare pro and Honest Medical Group CISO Dennis Leber listens first, then aligns his cybersecurity strategy to business needs.

A photo of blue classroom desks seen at a diagonal.
Oct 26, 2023

Despite high-profile takedowns of notorious ransomware-as-a-service (RaaS) gangs, attacks like the Vegas casino hacks are on the rise. Here’s how businesses need to adapt.

Image for What is Risk Management blog post
Oct 4, 2023

In the second of an ongoing series of one-on-one interviews with security leaders, Focal Point sits down with Stephen Held of architectural engineering firm Leo A Daly to discuss his not-so-typical take on third party risk.

The MOVEit Breach Is Still Going Strong: Here’s How to Keep Your Data Safe
Aug 23, 2023

Is the MOVEit breach this year’s Log4j? Well, we sure haven’t heard the last of it. Here are seven steps enterprise leaders must take to safeguard their data.

Make Friends with Your Cyber Insurance Agent, Part 2—The Steps to Take Now
Jul 20, 2023

In an era of rising rates and denied claims, it’s easy to see insurance companies as adversaries. Previously, we looked at the benefits of partnering with your insurer. Here, we show how to succeed at that, step by step.

Make Friends with Your Cyber Insurance Agent, Part 1—Why It Matters
Jul 16, 2023

In an era of rising rates and denied claims, it’s easy to see insurance companies as adversaries. Part 1 of this two-part series looks at why it’s better to see your insurers as partners and leverage their tools and expertise. Later this week, we cover how to do it.

Banks vs. Ransomware: The Battle Is on Again in 2023
Jun 29, 2023

After ransomware attacks plunged last year, hackers are back to wreaking havoc on finserv companies. But there are plenty of ways banks and other financial institutions can fend off the damage.

What Cybersecurity Layoffs Mean for Risk—and How to Be Ready
Jun 28, 2023

Cybersecurity teams have been spared the pain of layoffs. but don’t sigh with relief just yet. Change is afoot and enterprise leaders need to be prepared.

3 Ways Banks Can Prep for Quantum Computing Threats to Cybersecurity
Jun 8, 2023

The full potential of quantum computing is still several years away, but banks need to start countering this ‘“existential” cybersecurity threat now.

5 Ways Boards Can Improve Their Cybersecurity Governance
Jun 1, 2023

Experts advise these key practices for boards of directors to meet rising cybersecurity threats—and intensifying pressure from regulators.

What Many Get Wrong About Persistent Engagement and Why It Matters to Business
May 8, 2023

We talked to Richard J. Harknett, the pioneering professor who’s advising U.S. military and intelligence on persistent engagement, a more active approach to national cybersecurity.

What Businesses Need to Know About Biden’s National Cybersecurity Strategy
May 4, 2023

Biden’s new cybersecurity strategy offers an innovative 24/7 approach to cyber vigilance and a two-word mantra for Big Tech: Do more.

RSA 2023 Preview: What CISOs (Need to) Know About Board Accountability
Apr 19, 2023

In the first of our three-part sneak-peek at RSA Conference 2023, Focal Point sits down with Tanium CISO Chris Hallenbeck to discuss board awareness of cybersecurity and what CISOs can do to help. Here’s a tip: Don’t talk too much.

Blog image for What is Active Directory security
Apr 5, 2023

There’s mounting evidence that multifactor authentication (MFA) isn’t exactly the panacea that will fix everyone’s hacking problems. Yes, it’s super effective for user-verification, but hackers are using three sneaky tactics to get around it.

Yes, ChatGPT Will Turbocharge Hacking—and Help Fight It, Too
Feb 17, 2023

While amateurs can now use ChatGPT to create malware and phishing emails, security pros can also enlist the bot to fight cyberattacks.

Layoffs Could Hatch a New Generation of Data Thieves and Hackers
Feb 10, 2023

As corporate layoffs keep coming, cybersecurity experts predict an uptick in insider risks. How you fire—and hire—can make all the difference when it comes to combating data thieves and hackers.

How CISOs Can Fight Burnout and Extend Their Careers
Jan 26, 2023

There is no question that security is a tough field. Figuring out how to get through each day effectively, and unscathed, is a bit murkier. The following advice can help execs thrive under pressure.

It Pays to Know How Your Cybersecurity Stacks Up
Jan 18, 2023

Cybersecurity benchmarking compares your IT risk metrics to industry competitors, a key upgrade that adds business value—and reduces risk.

5 Myths—and Realities—About Cyber Insurance
Jan 6, 2023

Companies often choose to forgo cyber insurance—at their peril. Here’s why executives must learn the truth about coverage.

The Legal Danger Lurking in Cyber Insurance Policies
Nov 15, 2022

Experts advise companies to understand the fine print in their cyber coverage—and be ready for more insurers to contest claims or rescind policies over alleged misrepresentations.

Why Bug Bounty Hunters Are Earning Huge Payouts
Oct 17, 2022

Here’s what security executives need to know about working with ethical hackers on emerging technologies like blockchains.

Why the Bridges Between Blockchains Are Under Assault
Oct 5, 2022

Connections between blockchains are the weak links in the security armor of the “unhackable” technology underpinning the next generation of the internet.

The Rise of the Cybersavvy Corporate Treasurer
Aug 26, 2022

Treasurers hold the purse strings. That makes them attractive targets for cyberthieves. Here’s how to outsmart the bad guys.

Will the Feds Backstop Cyber Insurance?
Aug 11, 2022

Critical infrastructure providers may soon get federal protection against the crippling costs of cyberattacks. Here’s why.

Surprise! It's Another Zero-Day Vulnerability
Jul 14, 2022

Security experts are debating the cause of a growing number of zero-day software flaws, but there is consensus about one thing: how to prepare for the next attack.

Ransomware Is Battering the Cyber Insurance Industry
Jul 6, 2022

It’s usually up to corporate treasurers to shop for cyber insurance. Here’s how to navigate that costly shifting market.

Why Corporate Leaders Must Secure the Wild West of the Metaverse
Jun 23, 2022

As more businesses enter the metaverse, security leaders must ensure this emerging virtual marketplace is safe for customers and employees.

Image for Strengthening Cloud Security blog post
Jun 17, 2022

To stay ahead of hackers, enterprises must improve visibility and security across the many cloud environments that underpin IT operations.

State CISOs to Feds: Show Us the Money
May 26, 2022

States are waiting for $1 billion in federal cybersecurity grants. Here’s what they need to know to act fast when those infrastructure funds start to flow.

Cryptojacking: How to Stop Coin Miners From Hitting Your Network
Apr 19, 2022

Coin mining attacks are increasing in frequency and severity, threatening enterprises. Here’s how to fight back.

The Future Is Passwordless
Mar 29, 2022

Enterprises are (finally) trading passwords for biometrics, multifactor authentication and single-sign-on tools. Here’s why.

Are Metaverse Meetings the Answer to Better Employee Engagement?
Feb 17, 2022

Your workers may be remote but need not feel alone: Here’s how metaverse meetings and virtual reality can enhance the employee experience.

Universal Broadband Must Include Cyber Hygiene Practices
Dec 21, 2021

As state and local governments allocate ARPA funds to boost digital services, experts plead for an investment in cybersecurity.

Big Enough to Hack
Oct 5, 2021

Cyberattacks on small and medium-size businesses are surging. We asked experts and criminal hacking targets what steps must be taken—before it's too late.

How NPower Creates Pathways to Prosperity
Sep 15, 2021

Too many people don’t know how to get into high tech, especially in underserved communities. Tech training from NPower helps develop that workforce.

The Art of Ransomware Negotiation
Sep 7, 2021

Ransomware negotiation is part tennis match, part art form—which is why most enterprises hire experts to handle deals. Here’s how the best resolve conflict.

More E-commerce, More Cybersecurity Problems
Aug 13, 2021

As e-commerce continues to boom, a patchwork of legacy technology is leading to corporate cybersecurity vulnerabilities and hindering resilience.

Bodies Electric: The Promise of 6G Wireless Technology
Jul 9, 2021

In the wake of massive ransomware attacks, researchers, governments, and businesses are looking past the roll out of 5G wireless technology to create a more secure future with 6G.

The Pandemic Made CISOs Mission-Critical. Here’s How They Can Maintain Their Status
May 17, 2021

Lauded as heroes during the pandemic crisis, CISO's must build a secure foundation to enable possibilities rather than having to defend against threats.

Tool Sprawl Threatens Post-Pandemic Security
Apr 9, 2021

Tool sprawl and the use of rogue software by remote workers has become a major concern for security teams. CISOs have devised ways to improve IT visibility.

Supply Chain Risks to the Vaccine Rollout
Mar 18, 2021

Ransomware attacks have hit the healthcare industry networks hard with the spread of COVID-19, and the risks have increased with the global vaccine rollout.

What is performance monitoring?
Feb 11, 2021

Learn about performance monitoring and tools that enable organizations to monitor, manage, secure, and optimize their computers and devices' health.

What Is configuration management?
Feb 11, 2021

Learn about IT configuration management and the tools that define, apply, and enforce a system’s desired state across computer systems, servers, and software.

Software management
Feb 11, 2021

Learn more about software management and how modern solutions improve the IT team's control and support over the organization's application landscape.

How Endpoint Security Can Mesh with Rapid Digital Transformation
Jan 11, 2021

Enterprise endpoints are a major weak link in cybersecurity during the pandemic. Greater alignment between digital transformation & security is needed.

How To Turn Your Remote Workers Into Security Advocates
Nov 18, 2020

Cyberattacks are up in the WFH era, meaning employees need extra security training to raise their awareness of potential threats.

Four Use Cases for How 5G Will Transform Enterprises
Nov 18, 2020

As 5G adoption and rollout gets closer to realization, we look at use cases that highlight just how transformative this technology is expected to be.