Offense + Defense

DirectDefense Blog

Successful mitigation of today’s security threats requires an approach that is both on the offensive and on the defensive. Here, we give our take on how to approach and handle specific security challenges, as well as our reaction to some of the latest industry topics.

  • Experienced a breach?
  • Blog
  • Partners
  • 1-888-720-4633
Talk With an Expert
  • Services
    • Overview
    • Managed Services
      • Overview
      • Customized MDR + MSSP
    • Connected Systems
      • ICS / SCADA Real-Time Monitoring
      • Technical Assessment
      • Architecture Review & Assessment
      • Smart Device Testing
      • IoT / IIoT
      • Smart Cities
      • Embedded Systems
      • Enterprise Security Program
    • Professional Services
      • Overview
      • Security Testing
      • Risk Assessment & Compliance
      • Talent Acquisition
      • Strategy & Planning
    • ThreatAdvisor
    • Services
  • Solutions
    • Overview
    • Security Need
      • Overview
      • Application Security
      • Network Security
      • Cloud / Mobility Security
      • Malware
      • Mergers & Acquisitions
      • Peace of Mind / E-Discovery
      • Privacy
      • Protection From Advanced Threats
      • Research, Technology & Validation
      • Skill Set Deficiency
      • Threat Mitigation
    • Security Vertical
      • Overview
      • Aerospace / IFE
      • Automotive / IUE
      • Energy & Utilities
      • Financial Services & Insurance
      • Gaming & Entertainment
      • Healthcare
      • Educational Institutions
      • Retail & Hospitality
      • Technology & Manufacturing
      • Government
    • Security Compliance
      • Overview
      • PCI Compliance
      • CMMC
      • HIPAA / HITECH
      • ISO 27001 / 27002
      • Data Privacy
      • GDPR
      • FCA
      • NCUA / FFIEC
      • NERC CIP
      • FISMA/FedRAMP
      • Enterprise Risk Assessment
  • Why DirectDefense?
    • Our Approach
    • Industry Recognition
    • Leadership
    • Careers
    • Our History
    • Partners
  • Resources
    • Be Protected Even on a Tight Cyber Budget.
    • TRENDING
      • Exfiltration Defense Report
      • Oh Sh!t Guide
      • 2025 Threat Report
      • Rising Vulnerabilities Guide
      • Asset Visibility Roadmap
    • RESOURCE CENTER
      • Blog Articles
      • Security Documentation
      • Press Releases
      • News Articles
      • All Resources >
    • UPCOMING EVENTS
      • All Events >
  • Services
    • Overview
    • Managed Services
      • Overview
      • Customized MDR + MSSP
    • Connected Systems
      • ICS / SCADA Real-Time Monitoring
      • Technical Assessment
      • Architecture Review & Assessment
      • Smart Device Testing
      • IoT / IIoT
      • Smart Cities
      • Embedded Systems
      • Enterprise Security Program
    • Professional Services
      • Overview
      • Security Testing
      • Risk Assessment & Compliance
      • Talent Acquisition
      • Strategy & Planning
    • ThreatAdvisor
    • Services
  • Solutions
    • Overview
    • Security Need
      • Overview
      • Application Security
      • Network Security
      • Cloud / Mobility Security
      • Malware
      • Mergers & Acquisitions
      • Peace of Mind / E-Discovery
      • Privacy
      • Protection From Advanced Threats
      • Research, Technology & Validation
      • Skill Set Deficiency
      • Threat Mitigation
    • Security Vertical
      • Overview
      • Aerospace / IFE
      • Automotive / IUE
      • Energy & Utilities
      • Financial Services & Insurance
      • Gaming & Entertainment
      • Healthcare
      • Educational Institutions
      • Retail & Hospitality
      • Technology & Manufacturing
      • Government
    • Security Compliance
      • Overview
      • PCI Compliance
      • CMMC
      • HIPAA / HITECH
      • ISO 27001 / 27002
      • Data Privacy
      • GDPR
      • FCA
      • NCUA / FFIEC
      • NERC CIP
      • FISMA/FedRAMP
      • Enterprise Risk Assessment
  • Why DirectDefense?
    • Our Approach
    • Industry Recognition
    • Leadership
    • Careers
    • Our History
    • Partners
  • Resources
    • Be Protected Even on a Tight Cyber Budget.
    • TRENDING
      • Exfiltration Defense Report
      • Oh Sh!t Guide
      • 2025 Threat Report
      • Rising Vulnerabilities Guide
      • Asset Visibility Roadmap
    • RESOURCE CENTER
      • Blog Articles
      • Security Documentation
      • Press Releases
      • News Articles
      • All Resources >
    • UPCOMING EVENTS
      • All Events >
  • Experienced a breach?
  • Blog
  • Partners
  • 1-888-720-4633
DirectDefenseDirectDefense
Cyber Attacks & Threat Trends

The Colonial Pipeline Shutdown Demonstrates How Precarious Our Critical Infrastructure Security Really Is

   By: Jonathon Grant   05.13.21

The Colonial Pipeline shutdown should be seen as a serious incident pointing to the precariousness of critical infrastructure security.

Asset Visibility & Risk Management

Tales From The Road: Gone Phishin’!

   By: Bethany Kozal   05.11.21

How DirectDefense leveraged the pandemic to exploit remote access security for a large corporate network through an email phishing campaign While most of the world was busy adapting to the Work from Anywhere #WFA movement that the pandemic suddenly brought on, a certain segment of the population saw a unique opportunity to get into an… Read more »

Cyber Attacks & Threat Trends

Your Detailed Out-of-Office Autoresponder Could be Putting Your Organization’s Email Security at Risk

   By: Bethany Kozal   05.10.21

When it comes to email security, did you know your out-of-office autoresponder could be making your organization more vulnerable to attack?

Security Assessments & Testing

Tales from the Road: Taking Control of Access Controls to Protect Sensitive Data from Unauthorized Users

   By: Bethany Kozal   04.29.21

How a recent DirectDefense security assessment revealed a common application vulnerability through commandeering access controls.

Security Assessments & Testing

Tales from the Road: Last Year the Landscaper Conducted a Successful Data Breach…How’d it go This Year?

   By: Bethany Kozal   03.23.21

Take two of our team attempting to conduct a data breach at a company that previously let us in as landscaping job candidates. How’d it go this year?

Security Assessments & Testing

Tales from the Road: Think Your Web Application is Attacker-Proof? Think again.

   By: Bethany Kozal   02.16.21

Our information security and managed security services firm found vulnerabilities in our client’s web application security.

IoT, OT, & SCADA Security

Tales from the Road: Water Utilities, Take Warning!

   By: Bethany Kozal   02.09.21

If you don’t want to issue the dreaded boil-water advisory then make sure your wireless network is hacker-proof. How our team was able to drive up to a municipal water utility, join the wireless SCADA network and gain the access needed to do some major damage to the water supply – all in 10 minutes… Read more »

Vulnerability Management

Why a Cybersecurity Operations Center Isn’t a Nice-to-Have, but a Must-Have

   By: Bethany Kozal   01.12.21

Keep Your Organization Safe Around the Clock with a Cybersecurity Operations Center from an MSSP Here’s a projection that’s hard to ignore: the cost of cybercrime is expected to exceed $8 billion by 2022. The reality of that amount of financial fallout from cyber attacks is staggering. Driving up the cost of cybercrime is the… Read more »

Security Assessments & Testing

Tales from the Road: Y2K Called, It Wants Its Passwords Back

   By: Jesse Rodriguez   12.16.20

Part 1: Get Inside the Heads of the DirectDefense Team as We Launched an Attack on a Client’s System to Bypass Passwords and Gain Access to “Protected” Critical Data This post is the first in a 2-part series addressing the need for strong passwords across all industries to adequately protect important company and user data.… Read more »

Security Assessments & Testing

Tales from the Road: It’s 2020 and Your Passwords Still Suck

   By: Jesse Rodriguez   12.16.20

Part 2: Get Rid of Weak Passwords like Winter2020 and Password1 Our Attack into One Company’s Database Highlights the Risk of Poor Passwords This post is the second in our 2-part series addressing the need for strong passwords across all industries to adequately protect critical information. In a recent client engagement, we set out to… Read more »

  • First
  • Previous
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • Next
  • Last

Categories

  • All Categories
    • AI & Cybersecurity
    • Asset Visibility & Risk Management
    • Cyber Attacks & Threat Trends
    • Cybersecurity Compliance
    • Events & Community Engagement
    • IoT, OT, & SCADA Security
    • Security
    • Security Assessments & Testing
    • Technical
    • Vulnerability Management

Sign up for the latesest security threat news.

Sign up for the latest security threat news.

Like what you’re seeing? Contact us today.

Get Started
  • Home
  • Careers
  • Contact Us
© 2026 DirectDefense - All Rights Reserved    Privacy  //  Site Map     Website by: Fishnet MediaFishnet Media
Privacy Notice

To provide a better experience and analyze web traffic, we use technologies like cookies to store and/or access user information. Withdrawing consent may adversely affect certain functions.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}