Insight #1
"Cybersecurity Awareness month starts on October 1, 2022. One of the themes is enabling MFA. If you haven’t done so, it’s time."
Insight #2
"Security leaders need to stop blaming people for breaches and start examining their risk profile for when someone’s account is compromised. What mitigations or controls are in place to prevent devastation or limit the breach scope?"
Insight #3
"It’s time we move on from using CVSS as the standard for risk management. CVSS has been the cornerstone for many organizations and for CVEs for helping to understand the risk of a specific vulnerability, but it’s not good enough anymore. It’s time we start incorporating EPSS, environmental controls, current attack patterns, library usage, CVE reachability, and more data into our risk-ranking methodologies."