Tales From the Road: Physical Penetration Testing Breaches Weak Boundaries

How Secure Are Your Organization’s Premises? When it comes to entry points into an organization, network security gaps and vulnerabilities aren’t the only concern. Bad actors can choose a more traditional way in – physically walking through the doors. You may have locks, ID badges, cameras, and employee protocols, but the best way to know… Read more »

Detecting Hardware Vulnerabilities with IoT Penetration Testing

Welcome to a new series of DirectDefense blog posts about hardware and IoT penetration testing! The goal of this 101 series is to shed light on common hardware I/O interfaces, associated protocols, and the multitude of vulnerabilities that can arise when they are left unprotected. While hardware reconnaissance will be briefly discussed, this particular article… Read more »

Tales From the Road: What An Enterprise Risk Assessment Looks Like

Has your corporation been keeping up-to-date on the latest security practices? An important one to bring into your security repertoire is an enterprise risk assessment. It’s crucial to regularly conduct enterprise assessments to ensure the effectiveness of your corporation’s security measures. An enterprise risk assessment helps your organization continuously update and measure all security protocols,… Read more »

Combat Ransomware: Try Halcyon’s Anti-Ransomware Platform Free for 60 Days

Armor Your Endpoints Free for 60 Days  If you’ve experienced the impact of a ransomware attack, you understand how severely it can disrupt business operations. That is why we’re partnering with Halcyon to offer a 60-day free trial of their anti-ransomware platform.  Halcyon’s next-generation anti-ransomware solution stops attackers at all phases of a breach using… Read more »

Tales From the Road: A Cybersecurity Breach is Only A Phone Call Away

How DirectDefense Compromised a Banking Institution’s Help Desk and Member Services Using a Phone Social Engineering Attack + 5 Common Vishing Pitfalls to Avoid Cyber criminals will stop at nothing to steal personal and confidential information from their target. In recent years, many high-profile attacks have leveraged targeted phone social engineering attacks, known as vishing.… Read more »

Tales From the Road: When it comes to your SCADA Network: Segment. Segment. Segment.

How DirectDefense uncovered weaknesses in a municipality’s SCADA systems and a need for SCADA network segmentation A large municipality enlisted the services of DirectDefense to perform a Critical Infrastructure Assessment of the SCADA network controlling their water and electric services. During the SCADA assessments, our team identified several weaknesses that demonstrated the need for SCADA… Read more »

The Rise of Remote Work and Cybersecurity: What You Need to Know to Stay Safe

The COVID-19 pandemic caused a massive shift towards remote work, which remains today. Remote work has become the new norm, and it has brought about many changes in the workplace. While remote work offers many benefits, it also increases cybersecurity risks. In this article, DirectDefense will discuss the rise of remote work and cybersecurity, and… Read more »

Tales From the Road: Minimize Third-Party Software Security Risks

How to Prevent Credential Stuffing with IPv6 Protocol Security Third-party software security risks are created when third-party vendor products lack security, giving attackers wide open access to your organization’s networks and databases. When a vendor has access to your network, including customer and corporate information, your own company’s security doesn’t cover all the gaps, so… Read more »

WATCH: Why Should CISOs Consider a MSSP and How Do You Choose the Right One?

Discover the Benefits of Partnering with an MSSP and Tips for Selecting the Right One for Your Organization A resilient cybersecurity strategy is essential to running your business while protecting against security threats and preventing data breaches. For CISOs, partnering with a managed service security provider (MSSP) means you can be in control of your… Read more »

What’s New in PCI DSS 4.0?

Get Ready for the 2024 PCI Compliance Update The new, stringent, PCI DSS 4.0 will replace PCI DSS version 3.2.1 on March 31, 2024. At that time, you will be required to be compliant with the new specifications. (Do not become confused by the March 31, 2025, date which is when the requirements labeled “best… Read more »