Archive

All entries

Petro and Vargas explain numerous attacks that leverage weaknesses in the protocol itself that may not be easily rectified, in addition to implementation and configuration errors, and vulnerabilities, that may be effectively mitigated with some work by vendors of readers and controllers.
Risk Management
Federal

Nexus Podcast: Bishop Fox on OSDP Vulnerabilities and Physical Security

Michael Mimoso
nexus_extortion.jpg
Ransomware

Resilience, Recovery Strategies to Combat Ransomware and Extortion

ADM. Michael S. Rogers, USN (Ret.)
nexus_ics-vulns-matter.jpg
Operational Technology
Vulnerability Management

Why ICS Vulnerabilities Do Matter

Dan Ricci
Jennifer Lyn Walker, Director of Infrastructure Cyber Defense for the WaterISAC, discusses the current state of cybersecurity within the water sector, and explores the disparity in security talent, technology, and funding available across the sector.
Risk Management

Nexus Podcast: Jennifer Lyn Walker on Cybersecurity Risks in the Water Sector

Michael Mimoso
The Securities and Exchange Commission's (SEC) new cybersecurity rules create concern among CISOs and security experts about what will ultimately constitute a material cyber incident.
Risk Management

CISOs Play a Critical Role in Compliance with New SEC Cybersecurity Disclosure Rules

George V. Hulme
The inherent security of new devices and software associated with managing the grid is shipping natively with better code and design quality, cutting down on commodity vulnerabilities.
Industrial
Operational Technology

Bulk Power System Risks Span Complexity, Vulnerabilities, Advanced Actors

George V. Hulme
Center for Internet Security CTO Kathleen Moriarty joins the Nexus podcast to discuss CIS' new IoT Embedded Security Guidance document, which provides IoT developers and DevOps pros with security guidance as they choose their protocol stack.
Internet of Things

Nexus Podcast: Kathleen Moriarty on CIS’ IoT Cybersecurity Guidance

Michael Mimoso
An accurate medical device asset inventory enables security teams to ensure that devices are adequately secured and monitored. Asset visibility also helps to improve overall operations and ensure patient safety.
Healthcare
Operational Resilience

Medical Device Visibility: Tracking What Must Be Secured

George V. Hulme
Walter Risi, the Global OT Lead and the Technology and Cyber Security Consulting leader at KPMG in Argentina, discusses the CISO’s journey from IT to OT and brings his extensive experience to the conversation.
Cyber Resilience
Operational Resilience

Nexus Podcast: Walter Risi on the CISO’s Journey from IT to OT

Michael Mimoso
NIS2 addresses limitations from NIS1 where some areas of improvement were needed to counter risk introduced by digital transformation and by evolving cyber threats, that exposed a lack of resilience within systems supporting businesses in the EU.
Risk Management
Cyber Resilience

Inside the EU's Toughened NIS2 Cybersecurity Directive

Roberto De Paolis
Cyber-informed engineering ensures the design, manufacture, and deployment of new OT and critical infrastructure assets — enough that these assets are reasonably secure from cyberattacks and remain reliable and resilient.
Cyber Resilience
Operational Technology

Cyber-Informed Engineering: A Way Toward More Resilient OT Systems

George V. Hulme
Ransomware may be past its hey-day, and it is a malware threat that will not fade away. But are attackers ready to move past it to more human attack vectors?
Cyber Resilience
Ransomware

Is Ransomware Still Sexy?

John Frushour
Latest on Nexus Podcast