featureHow a digital design firm navigated its SOC 2 auditL+R's pursuit of SOC 2 certification was complicated by hardware inadequacies and its early adoption of AI, but a successful audit has provided security and business benefits.By Alex Levin28 Nov 202311 minsCertificationsCompliance feature Rise of the cyber CPA: What it means for CISOsBy Evan Schuman27 Nov 20237 minsCSO and CISOCompliancenews analysis Ransomware gang files SEC complaint against company that refused to negotiateBy Lucian Constantin17 Nov 20234 minsRansomwareComplianceCybercrime featureHow US SEC legal actions put CISOs at risk and what to do about itBy Evan Schuman 16 Nov 20238 minsCSO and CISOComplianceRisk Management newsGenerative AI could erode customer trust, half of business leaders sayBy Michael Hill 08 Nov 20234 minsCSO and CISOGenerative AICompliance newsUS launches “Shields Ready” campaign to secure critical infrastructureBy Michael Hill 08 Nov 20233 minsGovernmentComplianceCritical Infrastructure newsAuditBoard adds new AI and analytics capabilities for compliance and risk maBy Shweta Sharma 18 Oct 20233 minsGenerative AIComplianceRisk Management newsVanta bakes generative AI into core security and compliance productBy Jon Gold 10 Oct 20233 minsGenerative AIComplianceRisk Management newsCybersecurity experts raise concerns over EU Cyber Resilience Act’s vulnerability disclosure requirementsBy Michael Hill 03 Oct 20234 minsRegulationComplianceVulnerabilities ArticlesnewsTrustCloud adds new tools to automate GRC frameworksThe suite of new capabilities includes framework customization with AI, new APIs, and evidence-collection integrations. By Shweta Sharma 06 Jul 2023 3 minsIT Governance FrameworksIT Governance FrameworksIT Governancenews analysisResilience at the core of the current and future Biden administration cybersecurity plans The Biden administration's cybersecurity initiatives broadly aim to improve cybersecurity resilience, with recent regulations and other actions designed to foster a "defensible, resilient ecosystem."By Cynthia Brumfield 05 Jul 2023 7 minsGovernmentCompliancenews analysisNo consensus on creating a unified US cyber incident reporting frameworkComments submitted to CISA regarding its creation of cyber incident and ransom payment reporting requirements underscore how tough it will be for the agency to create a one-size-fits-all framework.By Cynthia Brumfield 29 Jun 2023 10 minsRegulationRegulationRegulationnewsVanta adds new SaaS capability to address growing concerns over vendor securityVanta’s new offering aims to help customers streamline third-party security with automated workflows for vendor security reviews and compliance. By Shweta Sharma 03 May 2023 3 minsComplianceRisk ManagementVendor Managementnews analysisBattle could be brewing over new FCC data breach reporting rulesAn expanded data breach definition and the telcos’ desire to link notifications to “concrete harm” are among the most controversial aspects of the proposed FCC data breach reporting rules.By Cynthia Brumfield 11 Apr 2023 8 minsRegulationData BreachCompliancenewsObsidian launches new SaaS security and compliance toolsObsidian’s multimodule security posture management offering comes with tools to secure SaaS interactions and ensure associated compliances.By Shweta Sharma 05 Apr 2023 4 minsComplianceRisk ManagementSaaSnewsUK fines TikTok $15.8 million for GDPR violation of children’s privacyChinese-owned social media sensation TikTok has been fined almost $16 million for violating provisions of the UK’s General Data Protection Regulation.By Jon Gold 04 Apr 2023 3 minsRegulationData PrivacyComplianceopinionSoftware liability reform is liable to push us off a cliffRegulatory mandates for software security like those in the Biden Administration's National Cybersecurity Strategy could cause more problems than they solve.By Andy Ellis 02 Mar 2023 6 minsApplication SecurityComplianceOpen SourcenewsAt least one open source vulnerability found in 84% of code bases: ReportAlmost all applications contain at least some open source code, and 48% of all code bases examined by Synopsys researchers contained high-risk vulnerabilities.By Apurva Venkat 23 Feb 2023 4 minsComplianceOpen SourceVulnerabilitiesnewsDNA Diagnostic Center fined $400,000 for 2021 data breachThe DNA testing lab said it was not even aware that the legacy databases existed in its systems at the time of the breach. By Apurva Venkat 21 Feb 2023 4 minsData BreachCompliancenewsEvolving cyberattacks, alert fatigue creating DFIR burnout, regulatory riskDigital forensics and incident response teams face increasing workloads amid evolving cyberattacks, recruiting and hiring challenges, and a lack of effective automation.By Michael Hill 16 Feb 2023 5 minsIncident ResponseInvestigation and ForensicsCompliancenewsEuropean data protection authorities issue record EUR1.65 billion in GDPR finesDLA Piper’s GDPR and Data Breach survey shows a 50% increase in fines in the last 12 months. Data protection authorities turning their focus to artificial intelligence.By Michael Hill 17 Jan 2023 4 minsRegulationData PrivacyCompliance Show more Show less View all Resources whitepaper Test & Learn - The ultimate guide to delivering high quality, high impact products This year, the Progressive Delivery and Experimentation Summit, brought together nearly 1500 professionals. Leaders from Product, Engineering, and Data presented frameworks for adapting software development and delivery practices The post Test & Learn – The ultimate guide to delivering high quality, high impact products appeared first on Whitepaper Repository. By Optimizely 18 Sep 2023Business OperationsFinance and Accounting SystemsMarketing Software whitepaper Modernize and Scale on AWS By Koan 22 Aug 2023Amazon Web ServicesCloud ManagementIT Management whitepaper The Total Economic Impact(TM) Of Optimizely Digital Experience Platform By Optimizely 06 Aug 2023Business OperationsFinance and Accounting SystemsMarketing Software View all Video on demand videoAligning security, compliance and privacy across inventory trackingBrad Wells, Executive Director, Information Security, and Kandice Samuelson, Senior Director, IT Governance at PPD lead a team enhancing PPD’s inventory tracking system that identifies PPD's most valuable assets. Join us to learn how they distribute security resources for appropriate levels of protection, maintain compliance with government regulations and industry standards, and leverage information security controls aligned with client requirements, industry frameworks and privacy regulations. 28 May 2021 20 minsComplianceData and Information SecurityPrivacy See all videos Explore a topic Application Security Business Continuity Business Operations Careers Cloud Security Critical Infrastructure Cybercrime Identity and Access Management Industry IT Leadership Network Security Physical Security Privacy Risk Management Security View all topics All topics Close Application Security Business Continuity Business Operations Careers Cloud Security Critical Infrastructure Cybercrime Identity and Access Management Industry IT Leadership Network Security Physical Security Privacy Risk Management Security Security Infrastructure Software Development Vulnerabilities Generative AI Show me morePopularArticlesPodcastsVideos news UK CSO 30 Awards 2023 winners announced By Romy Tuin 05 Dec 20234 mins CSO and CISO news analysis Deepfakes emerge as a top security threat ahead of the 2024 US election By Cynthia Brumfield 05 Dec 20237 mins Election HackingGovernmentSecurity Practices feature How cybersecurity teams should prepare for geopolitical crisis spillover By Christopher Whyte 05 Dec 202312 mins Advanced Persistent ThreatsThreat and Vulnerability ManagementRisk Management podcast CSO Executive Sessions Australia with Sunil Sale, CISO at MinterEllison 20 Nov 202315 mins CSO and CISO podcast CSO Executive Sessions Australia with Robbie Whittome, CISO at Curtin University 16 Oct 202315 mins CSO and CISO podcast CSO Executive Sessions / ASEAN: Cisco's Anthony Grieco on opportunities in Southeast Asia's cybersecurity landscape 10 Oct 202316 mins CSO and CISO video CSO Executive Sessions Australia with Sunil Sale, CISO at MinterEllison 20 Nov 202315 mins CSO and CISO video AI and Cybersecurity: Speed Bumps, Training, and Communication 06 Nov 202317 mins CyberattacksGenerative AI video CSO Executive Sessions Australia with Robbie Whittome 16 Oct 202315 mins CSO and CISO