Articles

Recent articles

The Volt Typhoon takedown highlights the challenges the world faces in defending against such threats and the private industry/government collaboration that's necessary to succeed.
Operational Technology
Cyber Resilience
Risk Management

Volt Typhoon Takedown Highlights Critical Infrastructure Security Complexities

George V. Hulme
Understanding the nuances of OT cybersecurity vulnerabilities becomes imperative for IT cybersecurity teams to develop comprehensive defense strategies that safeguard both IT and OT environments.
Operational Technology
Operational Resilience
Vulnerability Management
Risk Management

What IT Cybersecurity Teams Need to Know about OT Vulnerabilities (Part 1)

Dan Ricci
With more than a dozen cybersecurity incident notification laws in effect around the world, it’s time for Chief Information Security Officers (CISOs) and incident response teams to think about the consequences of declaring an incident: timing is everything.
Risk Management

Don’t Call it an Incident–Yet: Managing Liability in a New Era of Incident Reporting and Compliance

Cristin Flynn Goodwin
nexus_pipeline.jpg
Risk Management
Vulnerability Management
Zero Trust
Operational Technology

A Strategic Necessity: Compensating Controls in ICS, OT

George V. Hulme
shutterstock_1936992973.jpg
Risk Management

CISO Strategies in a Time of Geopolitical, Kinetic Conflict

ADM. Michael S. Rogers, USN (Ret.)
nexus_solarwinds.jpg
Risk Management

Contentious Debates in Wake of SEC Action Against SolarWinds, CISO

George V. Hulme
nexus_cisos-on-boards.jpg
Risk Management

Do U.S. Boards of Directors Have Adequate CISO Representation?

George V. Hulme
nexus_career-success.jpg
Risk Management

How to Get a Job in Cybersecurity–A Survival Guide

John Frushour
The Securities and Exchange Commission's (SEC) new cybersecurity rules create concern among CISOs and security experts about what will ultimately constitute a material cyber incident.
Risk Management

CISOs Play a Critical Role in Compliance with New SEC Cybersecurity Disclosure Rules

George V. Hulme
NIS2 addresses limitations from NIS1 where some areas of improvement were needed to counter risk introduced by digital transformation and by evolving cyber threats, that exposed a lack of resilience within systems supporting businesses in the EU.
Risk Management
Cyber Resilience

Inside the EU's Toughened NIS2 Cybersecurity Directive

Roberto De Paolis
In part two of Nexus' series on vulnerability remediation and patch management challenges related to industrial automation and control systems, we cover patching challenges, downtime, and the governance and oversight required to reduce risk.
Risk Management
Industrial

IT/OT Convergence Challenges, Part 2: Vulnerability Management Course of Action to Reduce Risk

Juan Piacquadio
Tim Hall
Security leaders newly introduced to OT should have a punch list of things to familiarize themselves with before challenges become overwhelming and insurmountable.
Operational Technology
Risk Management

Cybersecurity Punch List for CISOs Securing Converged IT/OT Environments

ADM. Michael S. Rogers, USN (Ret.)
Latest on Nexus Podcast