Magazine
Focal Point
Focal Point is dedicated to helping business executives and IT leaders understand the management and security challenges posed by distributed business.

Shadow IT Is ‘Out of Control.’ Here’s How to Manage the Risk
It’s easier than ever for employees to find their own quick IT solutions—which can exponentially expand an organization’s risk landscape. We highlight four critical steps to help ferret out shadow IT – and its newest iteration, “shadow AI” – to limit the threat.

The Essential Guide to Slow Patching: The Reasons, the Risks, the Remedies
A recent survey shows significant delays in patching critical software vulnerabilities. Here’s why it happens, why security teams are sometimes encouraged to let it happen, and the policies that can reverse this (increasingly dangerous) trend.

What Football Coach Bill Belichick Can Teach Us About Cybersecurity
The wisdom and practices of legendary NFL coach Bill Belichick could be the outline for a winning cybersecurity playbook.

As SEC SolarWinds Case Plays Out, CISOs Shift Into Defensive Mode
The SEC is on a tear over cyber risk, with new rules and a SolarWinds lawsuit that have shaken the CISO community. Experts say this is just the start of regulators demanding more cybersecurity transparency. Here’s how CISOs need to adapt.

7 Ways to Defend Your Software Supply Chain
As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

CISO Success Story: Predicting Cyber Risk (Accurately) Is Easier With This Guy’s Formula
Ash Hunt of Apex Group piloted a statistic-driven model for predicting cyber risk events. Here’s why playing the numbers is better than hunches.

The SLCGP Is Another Year Older. Here’s What You Need to Know About Federal Cyber Grants
SLCGP funds might not be around for long, so entities that prepare for its next phase will have the best shot at protecting their networks and constituents.

The 3 Biggest GenAI Threats (Plus 1 Other Risk) and How to Fend Them Off
As enterprises deploy generative AI to boost productivity, they need to be prepared for the associated risks. We checked with experts to outline the ways AI tech is vulnerable. SBOMs and other defense strategies will help, but getting this right this may take some trial and error.

Misinformation / Disinformation, Part 2 – Bringing Old-School Cybersecurity to a New Fight
Deepfakes are harder to spot thanks to AI, making it easier to tarnish your brand. But old-school cybersecurity tactics can thwart these new threats.

CISO Success Story: How LA County Trains (and Retrains) Workers to Fight Phishing
The CISO for LA County, who oversees 100,000 employees, shares tips on cross-agency info-sharing, ongoing audits, and aggressive awareness training.

Misinformation / Disinformation, Part 1 – The Coming Crisis and Enterprises Most at Risk
Bad actors are using inaccuracies, lies, and sophisticated deepfakes to target organizations. Here’s why enterprises—big and small—must take it seriously.

The Chief AI Officer Is Here. It’s Time to Make Room in the C-Suite
As companies rapidly deploy AI technology, they’ll need a dedicated person in the C-suite to oversee those efforts. If that wasn’t clear before Biden’s executive order, it will be now.