Blog

Cruciana ISAC 2022-Residual Risk: It's Not Always About the Zero-days

Written by Waits Sharpe | Jul 27, 2022 2:41:02 PM

Lawrence Cruciana, founder and president of Corporate Information Technologies, is set to speak at 2022 ISAC annual meeting in Baltimore, Maryland. His session will be on August 9th from 4:00pm-5:pm and is entitled "Residual Risk: It's not always about the Zero-days". The ISAC annual meetings theme for this year is " Connect, Secure, and Mature. It revolves around creating networks and connections with cybersecurity peers as well as hearing directly from cybersecurity experts and learning about the latest technologies and controls responsible for reducing cyber risk. Join ISAC in hearing from professionals working within the cybersecurity and information technology fields including CorpInfoTech's own Lawrence Cruciana.

Residual Risk: It's Not Always About the Zero-days

The state of cybersecurity often is typified in terms of the latest flashy Zero-Day exploit or the most recent high-profile data breach. While these are characteristic elements of the state of security, they are not representative of the vast majority of successful attacks. Often, smaller organizations focus on implementing increasingly complex. capable and expensive cybersecurity tools rather than securing practical, and often, more opportunistic areas of the information ecosystem. The increasing use of Managed Services Providers (MSP) complicate the accurate calculation of risks within these same organizations.:

This session will review the typical State, Local, Tribal and Territorial (SLTT) informations ecosystem and present practical and directly-implementable methods to implement meaningful security controls across a modern Multi-vendor environment. Using the CIS Controls, we’ll address many of the most commonly attacked areas found in most SLTT information ecosystems using low-cost methods that are easily implemented and understood.”

We at CorpInfoTech provide managed services and premier cybersecurity founded on zero trust principles. Operating on this principle we can better predict and protect against various different cyber risks that may face your business. However, to know how to defend yourself you must know where you stand. This is why CorpInfoTech conducts holistic security assessments in order to diagnose your organizations problem and solution.

More about Lawrence Cruciana

With over 20 years of Information Technology (IT) experience in regulated and manufacturing industries, Lawrence brings unique insight into the fusion of information risk management, third-party supply chain, and the operational IT challenges faced by organizations. He has designed and implemented hundreds of cybersecurity and technology risk management programs incorporating key control frameworks including NIST Cyber Security Framework (CSF), CIS Critical Controls, and NIST 800-171/CMMC.

Contact CorpInfoTech today if you believe your organization is in need of a security assessment!

CorpInfoTech (Corporate Information Technologies) provides small to mid-market organizations with expert I.T. services including compliance assessment, cybersecurity penetration tests, and comprehensive business continuity planning services. CorpInfoTech can help organizations, quantify, create, refine, and mitigate the risks presented by business threatening disasters in whatever form they may be disguised.