CISOSteve

600 posts

CISOSteve

CISOSteve

@Prot3ctD3f3nd

vCISO | CISO | CIO | Strategic Cyber Security Leader | like to break things....legally

Katılım Mart 2018
230 Takip Edilen111 Takipçiler
CISOSteve retweetledi
SecurityScorecard
SecurityScorecard@security_score·
📣 New SecurityScorecard research powered by our recent acquisition of Driftnet uncovered widespread exposure across a U.S. municipal utility network serving tens of thousands of residents. 🔍 Researchers identified: 🔹 Exposed ICS and OT systems directly reachable from the internet 🔹 30 instances of vulnerable surveillance equipment 🔹 Weak encryption and known exploited vulnerabilities across hundreds of IPs 🔹 More than 140 exposed SMB and NetBIOS services 🔹 Consumer-grade devices operating alongside critical infrastructure systems 🛜 These findings highlight a broader issue: many municipal utility providers operate internet and critical infrastructure systems within the same environment, often with limited segmentation and visibility. 🌐 Driftnet’s internet intelligence capabilities expand SecurityScorecard’s ability to identify hidden exposure across externally facing systems, giving Security Operations, threat hunting, and Third-Party Risk Management teams deeper visibility into infrastructure risk before attackers exploit it. 👉 📖 Read the report and explore the power of Driftnet here: securityscorecard.com/resources/repo… #CISO #cybersecurity #vendorriskmanagement #supplychain #TPRM #driftnet #municipalutilitynetwork #cyberresearch #threatresearch #criticalinfrastructure
English
0
1
1
46
CISOSteve retweetledi
SecurityScorecard
SecurityScorecard@security_score·
📣 Announcement: SecurityScorecard Acquires Driftnet to Power Real-Time, Threat-Informed Third-Party Risk Management 🌐 SecurityScorecard today announced the acquisition of Driftnet, which will bring Driftnet’s high-fidelity internet discovery engine into SecurityScorecard's TITAN AI platform. ⚠️ This will give TPRM, Security Operations, and threat hunting teams the real-time intelligence they need to find and fix third-party risks before attackers exploit them. 💬 “The threat landscape has fundamentally changed. AI agentic automation and connected supply chain tools have exploded across enterprise environments — and most TPRM programs have no visibility into the risk AI poses for their vendors,” said Dr. Aleksandr Yampolskiy, CEO and Co-Founder of SecurityScorecard. ✅ SecurityScorecard announced its new TITAN AI platform earlier this year. SecurityScorecard’s acquisition of Driftnet continues the company’s momentum of transforming TPRM through continuous, threat-informed visibility and global internet intelligence. 👉📘 Read the full press release here: securityscorecard.com/company/press/… #CISO #cybersecurity #vendorriskmanagement #supplychain #TPRM #driftnet #acquisition #pressrelease #MergersAndAcquisitions
English
0
2
3
69
CISOSteve retweetledi
CISOSteve
CISOSteve@Prot3ctD3f3nd·
@HackingDave Congratulations bud! Well deserved and looking forward to watching you crush it!
English
1
0
1
491
Dave Kennedy
Dave Kennedy@HackingDave·
I'm happy to announce that I have officially been promoted to Founder and Chief Executive Officer (CEO) of Binary Defense. With the changes in the industry happening and the shift to artificial intelligence, I have been immersing myself relentlessly on how we innovate and move fast - a complete shift of our entire company. Over the past 12 months we have completely transformed our company to be the most advanced artificial intelligence cyber security company in the world. We have taken MTTD and MTTR to times never thought possible before. Reduced false positives, increased true positives, and completely changed how we operationalize our MDR and product services as a company, and most importantly protect our customers. This journey was one of the fondest memories of my life, doing this with my team and one that is just getting started. With these changes in mind, our board approved me as CEO of the company to drive this company even further during this transformational and historic time in cybersecurity. I want to thank the folks over at Invictus Growth Partners for the trust in me, my partner Mike Valentine, and to all of the amazing folks we have @Binary_Defense . We truly are ahead in this field, innovating everyday, and protecting our customers 24 hours a day, 7 days a week, and 365 days a year. #BinaryDefense
English
87
37
636
41.1K
CISOSteve retweetledi
SecurityScorecard
SecurityScorecard@security_score·
🚢 Cyber-enabled cargo theft is up, and it’s raising concerns as it relates to third-party risk and vendor security. 🕵️‍♂️ The FBI Internet Crime Complaint Center (IC3) alert has reported a 60% increase in cyber-enabled cargo theft since 2024, with losses estimated to be nearly $725 million in 2025 alone. ⛓️‍💥 While the capital loss is substantial, the pivot in criminal groups toward cyber tactics to steal shipments with high resale value and limited traceability reveals a widening security gap in modern supply chains. 💬 Steve Cobb, Chief Information Security Officer at SecurityScorecard is quoted in the story from #Cybernews saying, “the deeper issue is not only stolen cargo, but how easily trust can be manipulated across interconnected third-party relationships.” And scammers aren’t using incredibly sophisticated tactics or schemes unfamiliar to those in the cyber industry. The tactics used are some of the most common, including: ✔️ Criminals posing as trusted carriers ✔️ Social engineering ✔️ Weaknesses in verification practices to steal login credentials ✔️ Phishing emails and malware installation 🗞️ Read the full story here: cybernews.com/cybercrime/fbi… #cybersecurity #cybercrime #supplychains #vendorriskmanagement #thirdpartyrisk #cargotheft #cyberattack
SecurityScorecard tweet media
English
0
1
1
63
CISOSteve
CISOSteve@Prot3ctD3f3nd·
What that looks like operationally: 🛰 Outside-In monitoring of physical supply chain vendors 🤖 AI detection of typosquatted domains and compromised vendor infra 🚨 Multi-channel verification at the point of execution, not just at onboarding Vendor trust has to function as an active security control.
English
1
0
0
12
CISOSteve
CISOSteve@Prot3ctD3f3nd·
Three vendors. All medium impact. All running on the same fourth-party provider. That's concentration risk, and it's the part of TPRM most programs never see. Full conversation on the @SecurityScorecard Weekly Brief: CISO Edition 👇 youtube.com/watch?v=PuLZYd…
YouTube video
YouTube
SecurityScorecard@security_score

⚠️ The risk lies not just in the third-party risk but also in the fourth, fifth, nth party risk. 📊 In this week’s Weekly Brief: The CISO Edition, SecurityScorecard CISO Steve Cobb talks the importance of AI in aiding TPRM teams scale their visibility beyond sole human capabilities. 🔗 With AI, TPRM teams are able to assess not just their immediate third-party vendors but the greater supply chain ecosystem of their third-party suppliers. This is critical for organizations to understand their actual risk and exposure. “ You might have three vendors that you consider medium impact to your organization, but all three of those vendors are using a common vendor to provide them services. That's what we consider concentration risk.” 👉 Subscribe to SecurityScorecard on YouTube for more insights on cyber risk, AI-empowered TPRM programs, supply chain security, and the evolving cyber threat landscape. To learn more about how you can leverage AI from SecurityScorecard in your TPRM program, visit our TITAN platform page: securityscorecard.com/platform/ #CyberSecurity #ArtificialIntelligence #ThirdPartyRisk #VendorManagement #SupplyChainSecurity #CyberRisk #TPRM #CyberAttack

English
0
0
0
29
CISOSteve
CISOSteve@Prot3ctD3f3nd·
Heading to Denver for the @TPRAssociation conference this week. Peaks & Pitfalls: Charting the TPRM Terrain. April 20-23. I'm speaking. Topics I care deeply about: outside-in visibility, AI-assisted TPRM, and building programs that reflect actual risk, not just audit checklists. If you're there, come say hello. DM me and let's find time to connect.
English
0
0
0
7
CISOSteve
CISOSteve@Prot3ctD3f3nd·
Breaches will happen. The organizations that win aren't the ones that stopped every attack. They're the ones that detected fast, contained quickly, recovered, and were straight with stakeholders throughout.
English
1
0
0
2
CISOSteve
CISOSteve@Prot3ctD3f3nd·
The Mythos hype is the security issue. Not the engine itself.
CISOSteve tweet media
English
1
0
0
8