New Tools for Today’s Modern Cybersecurity

The New York Department of Financial Services (DFS) Cybersecurity Symposium on March 29, included a presentation entitled “Modernizing Cybersecurity Supervision,” presented by Assistant Deputy Superintendent William Peterson. The presentation outlined new efforts by DFS to revamp its supervision process to address modern cybersecurity challenges and to better evaluate how companies can prepare for and respond to attacks. Mr. Peterson identified several new tools to provide DFS with a more informative starting point, as well as create a more collaborative environment with covered entities. Security ratings are useful in settings like the DFS evaluations because they measure large pools of data. This data also gives an outside-in viewpoint, which will combine with an inside-out viewpoint collected via a questionnaire process called the Cybersecurity and Information Technology Baseline Risk Questionnaire (CIBRQ). DFS regulated entities will be required to periodically complete the new CIBRQ questionnaire tool. By combining traditional exam data and incorporating…

0 Comments

CRISP Spring Workshop – Gaining Insight with Zeek – May 10 & 11, 2022

AgendaEvent Location: Discovery Hall at PNNL650 Horn Rapids RoadRichland, WA 99354Format: In-person (registered attendees only); remote dial-in not available Course SyllabusInstructor: Patrick KelleyCourse Web: https://www.criticalpathsecurity.comCourse DescriptionZeek is a great open-source tool that allows you to monitor your network and analyze events within it. Thiscourse will teach you about this tool, and how to configure and use it within your network to suit your needs.More Information

0 Comments

CTO, Rick Hudson, speaks at Alabama Rural Electric Association 2022 IT Conference

On Wednesday, April 6th we spoke at the Alabama Rural Electric Association of Cooperatives (AREA) conference to the IT leadership in attendance. Our topic was how to leverage Zeek to prevent a catastrophic event. In the talk we started with a bit of history and how malware, ransomware, and threat actors have evolved over the years; and how their tactics have transformed and become all but invisible to the naked eye. We also spoke about how the problems of our audience were vastly different from most other companies in that they were both supporting the Nation's Critical Infrastructure as well as they are also supporting technologies in their SCADA systems, of which many were developed with a 20-year lifecycle.   Today threats and threat actors are changing their mode of operations by the minute and many of today's tools cannot or should not be used on the IC networks. By…

0 Comments

Founder, Patrick Kelley, interviewed by NBC/11Alive

"My initial reaction was: 'they're doomed,'" cybersecurity expert Patrick Kelley, founder of Critical Path Security, said. Kelley said he was surprised to see funding for Atlanta Information Management drop since the 2018 ransomware attack, based on a report shared with the city's finance committee on March 30. "Most cybersecurity plans are built on a five-year maturity model," Kelley said. "We're not even four years after the recovery of the ransomware event that cost the city millions of dollars." Given limited resources, Kelley said local governments are already at a disadvantage compared to large corporations when it comes to technology funding. "They have to operate with the lowest amount of money that they can possibly get," Kelley said of the challenges, "And have to do the most that they can with it." Yet, he said resources and response time are critical. According to Kelley, it only takes five to six minutes…

Comments Off on Founder, Patrick Kelley, interviewed by NBC/11Alive