<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title><![CDATA[SMB Tech & Cyber Newsletter | CPF Coaching]]></title><description><![CDATA[I empower Chief Information Security Officers (CISOs) and Small to Medium-sized Businesses (SMBs) to elevate their cybersecurity strategies, guiding them past stagnation to achieve tangible outcomes. <br/><br/><a href="https://substack.cpf-coaching.com?utm_medium=podcast">substack.cpf-coaching.com</a>]]></description><link>https://substack.cpf-coaching.com/podcast</link><generator>Substack</generator><lastBuildDate>Mon, 11 May 2026 10:51:47 GMT</lastBuildDate><atom:link href="https://api.substack.com/feed/podcast/1338707.rss" rel="self" type="application/rss+xml"/><author><![CDATA[CPF Coaching | Christophe Foulon]]></author><copyright><![CDATA[Christophe Foulon]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[info@cpf-coaching.com]]></webMaster><itunes:new-feed-url>https://api.substack.com/feed/podcast/1338707.rss</itunes:new-feed-url><itunes:author>CPF Coaching | Christophe Foulon</itunes:author><itunes:subtitle>I empower Chief Information Security Officers (CISOs) and Small to Medium-sized Businesses (SMBs) to elevate their cybersecurity strategies, guiding them past stagnation to achieve tangible outcomes.</itunes:subtitle><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>CPF Coaching | Christophe Foulon</itunes:name><itunes:email>info@cpf-coaching.com</itunes:email></itunes:owner><itunes:explicit>No</itunes:explicit><itunes:category text="Business"><itunes:category text="Careers"/></itunes:category><itunes:category text="Technology"/><itunes:image href="https://substackcdn.com/feed/podcast/1338707/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/><item><title><![CDATA[5 Critical Security Alerts from Last Week: Copilot Bugs, Bluetooth Hacks, and New Privacy Laws]]></title><description><![CDATA[<p>January 2026 Alert: Critical Microsoft Copilot vulnerability (Reprompt), Bluetooth "WhisperPair" exploit affecting Sony/Google devices, and new privacy laws in IN, KY, & RI. Get the executive summary and 30-day mitigation plan for SMBs.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-smb-leaders-guide-to-surviving</link><guid isPermaLink="false">substack:post:186297873</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 31 Jan 2026 17:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/186297873/25b94b6e7b2b151ace074769a9879b48.mp3" length="4517897" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>376</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/186297873/aa04dc26f7f4c36ce2b42b2ba15d7ce5.jpg"/></item><item><title><![CDATA[AI, Identity, and Breaking Into Cyber: CEO Jasson Casey’s Blueprint for Success]]></title><description><![CDATA[<p>From building software to defending it: Jason Casey (CEO, Beyond Identity) shares his journey from Software Engineer to Cybersecurity Expert. Discover why mastering network protocols and engineering fundamentals is the secret to a successful cyber career. Listen now on Breaking into Cybersecurity.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/ai-identity-and-breaking-into-cyber</link><guid isPermaLink="false">substack:post:184021355</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 09 Jan 2026 18:47:23 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/184021355/9d18b6db974f26aa1dc00d68d457ab6d.mp3" length="4622532" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>385</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/184021355/f4b277f6daa42a0fe999203cba1c23be.jpg"/></item><item><title><![CDATA[The Glass House: Why 2026 is the Year We Must Audit Our "Agents" and "Avatars"]]></title><description><![CDATA[<p>CES 2026 changed the threat landscape. From "Superuser" AI agents to "cute" surveillance robots like Mirumi, we outline the top 4 trends SMB tech leaders must address immediately to secure their organizations.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-glass-house-why-2026-is-the-year</link><guid isPermaLink="false">substack:post:183792744</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 09 Jan 2026 14:41:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/183792744/18d99dfe4c5ec974c13914eaa5b5ff35.mp3" length="8126506" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>677</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/183792744/bd1a3845f85ddb5c488e17ab8e4c2b51.jpg"/></item><item><title><![CDATA[3 Urgent Cyber Threats Costing SMBs Millions (2025 Update)]]></title><description><![CDATA[<p>Urgent briefing for US SMBs: Critical patches needed for WatchGuard, Fortinet, & Cisco. Discover how to stop AI attacks and avoid $3M breach costs. Read the Urgent briefing for US SMBs: Critical patches needed for WatchGuard, Fortinet, & Cisco. Discover how to stop AI attacks and avoid $3M breach costs. Read the plan.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/us-smb-cyber-alert-critical-device</link><guid isPermaLink="false">substack:post:182504051</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 26 Dec 2025 16:39:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/182504051/c2bd4f14a20a3403b1bc43b1be2943fc.mp3" length="7599734" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>633</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/182504051/0e3f5c6c485e151598baefa05fbb82e9.jpg"/></item><item><title><![CDATA[Don't Boil the Ocean: A Cost-Effective Architecture for CMMC Level 2]]></title><description><![CDATA[<p>CMMC Phase 1 is effective as of Nov 2025. DIB leaders: Get the strategic guide to CUI, VDI, and NIST 800-171 compliance before the 2026 deadline.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-era-of-self-attestation-is-over</link><guid isPermaLink="false">substack:post:181887715</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 22 Dec 2025 14:20:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/181887715/329d7a2e0b0b63e80481b273184d44eb.mp3" length="8096874" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>675</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/181887715/c6e6b97998d5e473e4270d8f0f6c63a3.jpg"/></item><item><title><![CDATA[The Silent Kill Switch: Why Your Business Needs a "Human" Disaster Recovery Plan]]></title><description><![CDATA[<p></p><p>Is your business one tragedy away from collapse? Learn how to mitigate "Key Person Risk" and the "Bus Factor" with our 2025 guide to IT succession planning.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-silent-kill-switch-why-your-business</link><guid isPermaLink="false">substack:post:180343558</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 30 Nov 2025 20:10:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/180343558/b6012722977ec7efaa242b40233c6e59.mp3" length="11106000" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>925</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/180343558/fb8f9879b9b1ac628afa120cf5ec4c47.jpg"/></item><item><title><![CDATA[Your CEO and Your Sales Team Don't Face the Same Threats.]]></title><description><![CDATA[<p><strong>The “One-Size-Fits-All” Problem</strong></p><p>We’ve all been there. A mandatory, hour-long cybersecurity training video that covers everything from phishing to physical security in a bland, generic way. Your marketing team is half-listening while thinking about their next campaign, and your finance department is wondering how any of this applies to their daily invoice processing.</p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/beyond-the-basics-a-framework-for</link><guid isPermaLink="false">substack:post:176407450</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 22 Oct 2025 14:18:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/176407450/e50d812ed3920e7ec1aad4018656353f.mp3" length="11817857" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>985</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/176407450/3acf7f9a0c776f41b5a27673c55efd5f.jpg"/></item><item><title><![CDATA[Breaking into Cybersecurity: An In-Depth Conversation with Eric Stride]]></title><description><![CDATA[<p>In the latest episode of “Breaking into Cybersecurity,” host Chris Foulon sits down with Eric Stride, the Chief Security Officer at Huntress. Eric’s journey into cybersecurity is not only inspiring but also enlightening for anyone looking to enter this ever-evolving field. With over two decades of experience in the military and private sectors, Eric shares his insights on career development, leadership, and the future of cybersecurity.</p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/breaking-into-cybersecurity-an-in</link><guid isPermaLink="false">substack:post:176419258</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 17 Oct 2025 17:02:11 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/176419258/2554ca314266572853c101b52893f244.mp3" length="19119136" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1593</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/176419258/51cbd0583be9f5cc2fd849b9f45f5ae7.jpg"/></item><item><title><![CDATA[Quantum Computing: Your Next Great Opportunity]]></title><description><![CDATA[<p>Quantum Computing: The Future of Innovation and Security In this episode, we explore the revolutionary impact of quantum computing on the future of technology, innovation, and security. Learn about the key differences between classical bits and quantum qubits, and how superposition and entanglement enable unprecedented computational capabilities. Discover the strategic opportunities quantum computing presents for industries such as pharmaceuticals, logistics, and artificial intelligence, as well as the urgent cybersecurity threats it poses. Finally, gain actionable insights on how to prepare your organization for the quantum age by conducting risk assessments, exploring post-quantum cryptography, and ensuring crypto-agility. Don't be left behind—embrace this transformative technology and secure your place in the future.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/a-leaders-guide-to-quantum-computing</link><guid isPermaLink="false">substack:post:175521574</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 08 Oct 2025 12:43:51 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/175521574/a469336a8dce595a67a207799e268b79.mp3" length="5259911" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>438</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/175521574/53e23b340b42f2b70c2313272cf4d7f2.jpg"/></item><item><title><![CDATA[Beyond the Cloud: Mastering the Shared Responsibility Model for Comprehensive Risk Management]]></title><description><![CDATA[<p>Don't assume your cloud provider has you covered. Master the Shared Responsibility Model, build a comprehensive SRM, and align your strategy with frameworks like NIST and CMMC. Read our guide to achieve total accountability.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/beyond-the-cloud-mastering-the-shared</link><guid isPermaLink="false">substack:post:174760179</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 30 Sep 2025 16:46:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/174760179/941cecd2bd92004bda76cd4ef2c83e12.mp3" length="3217144" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>268</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/174760179/74a939c12a3e83c7764e9cb9a3aed95c.jpg"/></item><item><title><![CDATA[Navigating the Future of Cybersecurity: Insights from William (Bill) Welser IV]]></title><description><![CDATA[<p>Discover what lies ahead in cybersecurity with technology expert Bill Welser IV. Gain insights into AI's influence, key skills needed, and ways to prepare for the future. From his experience in the Air Force to AI startups, Bill Welser IV discusses his distinctive cybersecurity career path. Explore topics like systems thinking, new technologies, and advancing your career.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-the-future-of-cybersecurity</link><guid isPermaLink="false">substack:post:172871169</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 05 Sep 2025 17:24:29 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/172871169/03a75bcca6318bd36da8c601847893fb.mp3" length="36524324" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>2283</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/172871169/5f37894b0389a139c894f1eac38f6443.jpg"/></item><item><title><![CDATA[Cybersecurity Entrepreneurship: Real-World Advice from Serial Founder Sinan Eren]]></title><description><![CDATA[<p></p><p><em>By Chris Foulon & Sinan Eren</em></p><p><strong>Introduction</strong></p><p>In this episode of "Breaking into Cybersecurity," we sat down with Sinan Eren, a seasoned cybersecurity professional, entrepreneur, and founder. Sinan’s journey from a curious hobbyist in Istanbul to a serial founder in Silicon Valley offers a wealth of insights for anyone interested in cybersecurity, entrepreneurship, or both. Here are the highlights and lessons from our conversation.</p><p><strong>From Hobbyist to Professional: The Early Days</strong></p><p>Sinan’s entry into cybersecurity wasn’t a deliberate career choice. In the late 1990s, cybersecurity wasn’t even a defined field—just a function of IT. Resources were scarce, and much of the learning happened in underground communities like IRC and through publications like FRAC magazine. For Sinan, curiosity and a desire to experiment led him to discover vulnerabilities and share his findings on platforms like Bug Track, which eventually opened doors to job opportunities.</p><p><strong>Key Takeaway:</strong> Sometimes, passion and curiosity can be more important than formal education in breaking into a new field.</p><p><strong>Signature-Based vs. Heuristic Security: A Technical Evolution</strong></p><p>Sinan explained the shift from signature-based antivirus solutions to heuristic and behavioral approaches. Early security tools relied on known patterns to detect threats, but as malware evolved—like the infamous Code Red worm—this reactive approach proved insufficient. The industry began to focus on detecting abnormal behaviors, setting the stage for modern endpoint security.</p><p><strong>Key Takeaway:</strong> The cybersecurity landscape is always evolving. Staying ahead means understanding both the history and the latest trends in threat detection.</p><p><strong>Entrepreneurship in Cybersecurity: Two Playbooks</strong></p><p>Sinan’s entrepreneurial journey followed two main playbooks:</p><p>* <strong>The Hype Playbook:</strong> Attach security to the latest technology trend (e.g., AI + Security).</p><p>* <strong>The Next-Gen Playbook:</strong> Take an existing solution and make it better, faster, or more secure (e.g., reinventing VPNs with Zero Trust Network Access).</p><p>His first company focused on mobile security, capitalizing on the rise of mobile apps and their security flaws. Later ventures addressed remote access and automation, always driven by real-world needs and feedback from users.</p><p><strong>Key Takeaway:</strong> Successful startups often solve existing problems in new ways or improve on what’s already out there. Listen to the market and adapt.</p><p><strong>Lessons Learned: Growth, Pivots, and Exits</strong></p><p>Sinan shared candid stories about the challenges of scaling a startup, including the risks of over-reliance on a single partner and the importance of diversifying your customer base. He emphasized the value of learning from mistakes and knowing when to pivot or sell.</p><p><strong>Key Takeaway:</strong> Flexibility and self-awareness are crucial in entrepreneurship. Sometimes, the best move is to exit and apply your lessons to the next venture.</p><p><strong>Automation and the Future: Beyond Cybersecurity</strong></p><p>Sinan’s latest venture emerged from listening to managed service providers who struggled with operating and automating a growing stack of security tools. By leveraging process mining, UI automation, and AI, his team built solutions that automate repetitive tasks—not just in cybersecurity, but also in finance and other fields.</p><p><strong>Key Takeaway:</strong> The skills and solutions developed in cybersecurity can often be applied to other industries. Don’t limit your vision to a single domain.</p><p><strong>Advice for Aspiring Professionals and Leaders</strong></p><p>* <strong>For Beginners:</strong> The field is more exciting than ever, especially with the rise of AI and LLMs (Large Language Models). Red teaming and offensive security remain fertile ground for creative minds, regardless of background.</p><p>* <strong>For Experienced Pros:</strong> Embrace the challenge of integrating AI responsibly. Focus on building guardrails and understanding business processes, not just deploying tools.</p><p>* <strong>For Entrepreneurs:</strong> Understand your customers’ workflows and pain points. Document processes, model workflows, and always be ready to adapt your product or business model.</p><p><strong>Conclusion</strong></p><p>Sinan Eren’s story is a testament to the power of curiosity, adaptability, and listening—both to technology and to people. Whether you’re just starting out or leading a team, the lessons from his journey can help guide your own path in cybersecurity and beyond.</p><p>To hear the full conversation, listen to the episode of <a target="_blank" href="https://youtu.be/JjbLl0cgQmY"><em>Breaking Into Cybersecurity</em></a> (and uploaded as the video in this post ;-) The YouTube channel has years of previous conversations)</p><p></p><p></p><p><strong>Some security tools you can consider for improving your business security posture:</strong></p><p>CrowdStrike Falcon: An AI-driven platform for securing your infrastructure at scale and keeping up with AI advancements. <a target="_blank" href="https://crowdstrike2001.partnerlinks.io/Cpf-coaching">https://crowdstrike2001.partnerlinks.io/Cpf-coaching</a></p><p>INE Security Awareness and Training is essential for your team to stay updated with the evolving threat landscape, enhancing the effectiveness of the teams supporting your organization. <a target="_blank" href="https://get.ine.com/cpf-coaching">https://get.ine.com/cpf-coaching</a></p><p>Tenable helps identify weaknesses in your infrastructure, whether on-premises, in the cloud, or in your software, providing your vulnerability management with the visibility it needs. <a target="_blank" href="https://shop.tenable.com/cpf-coaching">https://shop.tenable.com/cpf-coaching</a></p><p>Cyvatar.AI Managed endpoint protection solution for SMBs and digital cloud environment <a target="_blank" href="https://cyvataraif5706.referralrock.com/l/CHRISTOPHE77/">https://cyvataraif5706.referralrock.com/l/CHRISTOPHE77/</a></p><p>Omnistruct helps you with privacy, GRC, and security programs. They can serve as your BISO to help scale your team and security program. <a target="_blank" href="https://omnistruct.com/partners/influencers-meet-omnistruct/">https://omnistruct.com/partners/influencers-meet-omnistruct/</a></p><p>Guidde helps you turn your tribal, undocumented processes into easy-to-follow documented videos and instructions. <a target="_blank" href="https://affiliate.guidde.com/cpf-coaching">https://affiliate.guidde.com/cpf-coaching</a></p><p>Cyberupgrade simplifies the process of enhancing your cyber and digital risk management, allowing you to grow your business without having to be a compliance expert. We take care of the complexities associated with frameworks like DORA, ISO 27001, and NIS2, enabling your team to concentrate on building, scaling, and serving your customers. <a target="_blank" href="https://join.cyberupgrade.net/cpf-coaching">https://join.cyberupgrade.net/cpf-coaching</a></p><p>1Password secures your secrets, tokens, passwords, documents, and more, whether you're at home, work, or school. They offer programs suited for everyone. <a target="_blank" href="https://1password.partnerlinks.io/cpf-coaching">https://1password.partnerlinks.io/cpf-coaching</a></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/breaking-into-cybersecurity-lessons</link><guid isPermaLink="false">substack:post:172674909</guid><dc:creator><![CDATA[Christophe Foulon 📓 and Sinan Eren]]></dc:creator><pubDate>Wed, 03 Sep 2025 13:12:55 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/172674909/78074486a61527f89a4e627fc3dfeeb6.mp3" length="48689884" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and Sinan Eren</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>3043</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/172674909/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[How to Build a Security Culture with Data-Driven Reporting]]></title><description><![CDATA[<p>Foster a true security-first culture by mastering effective cloud security reporting. Learn to translate technical risk into business impact for leadership and technical teams using tools like Microsoft Power BI. Move security from a cost center to a strategic business enabler.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/building-a-security-first-culture</link><guid isPermaLink="false">substack:post:172481104</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 01 Sep 2025 14:43:05 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/172481104/a9e74b3f7b098ff955e96eeba8290a8f.mp3" length="10132599" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>844</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/172481104/3c41781935e0fb00c9beb8babaed19c1.jpg"/></item><item><title><![CDATA[Vulnerability Management Metrics: 15 KPIs to Measure & Mature Your Program]]></title><description><![CDATA[<p>Supercharge your vulnerability management with a data-driven approach! Discover the 15 essential key performance indicators (KPIs) that will help you track your progress, highlight the value of your efforts, and elevate your security program. Embrace actionable metrics to continuously measure, monitor, and enhance your strategy—it's a journey towards a more secure future!</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/vulnerability-management-metrics</link><guid isPermaLink="false">substack:post:171700349</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 25 Aug 2025 13:30:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/171700349/25800df4557a3c29822d65bffc2a775b.mp3" length="6887869" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>574</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/171700349/880d2182eacd9b584ebf460f7d41e80a.jpg"/></item><item><title><![CDATA[The Ghost in Your Cloud: How Hackers Use Social Engineering to Infiltrate and Attack]]></title><description><![CDATA[<p><strong>The Ghost in Your Cloud: How Hackers Use Social Engineering to Infiltrate and Attack</strong></p><p>Unmasking the "low and slow" identity attacks where threat actors lie in wait within your cloud accounts, and how to fight back before they strike.</p><p>Discover the new wave of silent cyber threats. Learn how hackers use social engineering to compromise cloud accounts, stay dormant to evade detection, and launch devastating attacks later. Protect your organization now.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-ghost-in-your-cloud-how-hackers</link><guid isPermaLink="false">substack:post:171276068</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 20 Aug 2025 16:15:03 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/171276068/82cafaa3b0c34f2b629e8112ab3c9c33.mp3" length="17526270" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1460</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/171276068/a8ff482b7cfceec1891e4a7e48c8e3ba.jpg"/></item><item><title><![CDATA[Data-Centric Security: Protect Your Cloud Data with Microsoft Defender]]></title><description><![CDATA[<p>Stop chasing every vulnerability. Learn how a Data-Centric Security approach using Microsoft Defender for Cloud helps you discover, classify, and protect your most sensitive cloud data. Prioritize real business risks and prevent impactful breaches.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/data-centric-security-protect-your</link><guid isPermaLink="false">substack:post:171167680</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 18 Aug 2025 13:26:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/171167680/ec8581144b9a3e8043ae0e743d77e5d2.mp3" length="8295459" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>446</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/171167680/0296c47de1c6a612a751bd2500f64c9e.jpg"/></item><item><title><![CDATA[The Phantom Workforce: A Guide to Combating State-Sponsored IT Infiltration]]></title><description><![CDATA[<p>🚀 Transform Your Cybersecurity Approach! 🚀 Join me on a journey through "The Phantom Workforce," where I delve into combating state-sponsored IT infiltration. Equip yourself with knowledge and strategies to protect your organization's sensitive information from modern threats. Let's enhance our cyber defenses together! #cyberawareness #protectyourdata #ITinfiltration</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-phantom-workforce-a-guide-to</link><guid isPermaLink="false">substack:post:170503857</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 13 Aug 2025 13:48:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170503857/6ed958e00b1c17ccb7d8376f77b34204.mp3" length="6187724" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>516</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170503857/fb6f5bf74124a0d728afd0cefeabf383.jpg"/></item><item><title><![CDATA[Develop and Enforce Robust Remediation Policies and SLAs]]></title><description><![CDATA[<p>Strengthen your organization's security response with robust Remediation Policies and SLAs! Discover how to transform your vulnerability management program into a mature, auditable business function that ensures accountability and timely risk reduction. Learn more about the essential components of a successful policy in our latest discussion. </p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/develop-and-enforce-robust-remediation</link><guid isPermaLink="false">substack:post:170440180</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 11 Aug 2025 13:04:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170440180/4553db5d20c6a0e304412c1c5f1d8fed.mp3" length="4375490" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>364</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170440180/ccf8c6731ca0811f9895842d00064faf.jpg"/></item><item><title><![CDATA[From Psychology to Cybersecurity: Craig Taylor's Impact]]></title><description><![CDATA[<p>In this episode of Breaking into Cybersecurity, host Chris welcomes Craig Taylor, CEO of Cyber Hoot, as he shares his inspiring journey into the cybersecurity industry. Known for his role as a virtual CISO and cybersecurity awareness advisor, Craig discusses how he began his career with a psychology degree and eventually transitioned into cybersecurity. He delves into the importance of positive reinforcement over punishment in cybersecurity training and the evolving role of AI in detecting and mitigating threats. Craig also offers valuable advice for those looking to enter the field and emphasizes the need for organizations to understand and manage AI-related risks. Tune in for insights on cybersecurity, AI advancements, and practical tips to enhance cybersecurity awareness.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/from-psychology-to-cybersecurity</link><guid isPermaLink="false">substack:post:170437012</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 08 Aug 2025 17:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170437012/df8cfa1809780e4f3e33d397e22605ff.mp3" length="33737042" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>2108</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170437012/273cab09c14fe5d254651a5a5b40a3a7.jpg"/></item><item><title><![CDATA[Navigating the Cybersecurity Career Path: Insights from CISO Tradecraft with Guest Christophe Foulon]]></title><description><![CDATA[<p></p><p>In a recent episode of CISO Tradecraft, host G Mark Hardy sat down with cybersecurity expert Christophe Foulon to explore the intricacies of entering and thriving in the cybersecurity industry. Christophe, a seasoned professional and podcast host, shared his wealth of experience and offered valuable insights for anyone considering a career in cybersecurity or looking to advance within the field. </p><p>Breaking into Cybersecurity </p><p>The episode began with a discussion about the challenges and rewards of breaking into cybersecurity. Christophe highlighted his own journey, starting from a help desk role and eventually transitioning into cybersecurity. He emphasized the importance of staying current with certifications and the ever-evolving nature of the industry. "Technology moves along with or without us," Christophe noted, emphasizing the necessity of continuous learning. </p><p>Understanding the CISO Role</p><p>A key focus of the conversation was the allure of the CISO (Chief Information Security Officer) title and its associated responsibilities. Christophe pointed out that while the title and paycheck might seem attractive, the reality involves continuous learning, long hours, and high-pressure situations. He stressed the importance of understanding these demands before aspiring to such a position. </p><p>The Importance of Leadership and Ownership</p><p>Christophe shared that becoming a successful CISO requires more than just technical expertise. It involves political and management skills, and the ability to communicate effectively with the board and other executives. He also emphasized the need for CISO candidates to have political awareness and the capacity to work with stakeholders to own and manage risk. </p><p>Building a Strong Cybersecurity Team </p><p>Leadership was another crucial topic discussed. Christophe underscored the importance of understanding personal motivations and career aspirations within a team. By aligning roles with individual strengths and desires, leaders can foster productivity and satisfaction. He advocated for methods like personality assessments and one-on-one conversations to optimize team dynamics. </p><p>Leveraging Neurodiversity</p><p>A particularly insightful part of the discussion revolved around the role of neurodiversity in cybersecurity. G Mark Hardy and Christophe agreed that cybersecurity often attracts neurodiverse individuals, whose unique skills can become superpowers within the field. Ensuring these individuals find roles that align with their strengths not only enhances organizational productivity but also boosts individual fulfillment. </p><p>Advice for Aspiring CISOs and New Entrants</p><p>Christophe provided guidance for those considering a career as a fractional or virtual CISO, emphasizing the importance of understanding legal responsibilities and setting clear scope and expectations with clients. He also advised on staying true to one’s passions to prevent burnout. </p><p><strong>Conclusion and Contact Information</strong></p><p> The episode wrapped up with Christophe encouraging strategic thinking in both career development and cybersecurity program planning. For those interested in learning more from Christophe, his resources, including his podcast "Breaking into Cybersecurity" and books, are available on platforms like YouTube, Apple Podcasts, and Amazon. Additional information can be found on his website at christophefoulon.com. </p><p><a target="_blank" href="https://substack.com/profile/145702488-ciso-tradecraft">CISO Tradecraft</a>  continues to provide invaluable content for cybersecurity professionals seeking to elevate their careers and leadership skills. As the industry evolves, the lessons from thought leaders like Christophe Foulon remain crucial for both personal and professional development.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-the-cybersecurity-career</link><guid isPermaLink="false">substack:post:170173657</guid><dc:creator><![CDATA[Christophe Foulon 📓 and CISO Tradecraft]]></dc:creator><pubDate>Tue, 05 Aug 2025 14:04:21 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170173657/1c71498a69659290f209bb7ba86f0b13.mp3" length="42797913" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and CISO Tradecraft</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>2675</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170173657/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Embed Security into the DevOps Lifecycle (DevSecOps)]]></title><description><![CDATA[<p>Learn to "shift left" with DevSecOps. Discover how to integrate security into your development lifecycle, from Infrastructure as Code (IaC) scanning to container analysis, using Microsoft Defender for Cloud to build a proactive, code-to-cloud security posture.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/embed-security-into-the-devops-lifecycle</link><guid isPermaLink="false">substack:post:170041582</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 08 Aug 2025 01:26:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170041582/90f0bfcb8e71c7f9b600ec0dbc152789.mp3" length="5664619" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>472</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170041582/86a25ec00aa00586446f08ed6548b1c4.jpg"/></item><item><title><![CDATA[CISO Trade Craft Podcast with Guest Christophe Foulon]]></title><description><![CDATA[<p>In this episode of CISO Tradecraft, host G Mar welcomes Christophe Foulon, founder of CPF Coaching LLC. Christophe shares insights on enabling businesses to use technology safely through strategic planning, risk management, and tailored cybersecurity measures. He emphasizes the importance of a holistic approach to security, addressing people, processes, and technology to enhance business resilience. Christophe also discusses his efforts in developing leaders within organizations and his support for the community through his podcast and involvement with various non-profits.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/ciso-trade-craft-podcast-with-guest</link><guid isPermaLink="false">substack:post:170018951</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 04 Aug 2025 13:01:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/170018951/11341f75fb244635b3f16b6da1fff3a1.mp3" length="32342483" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>2675</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/170018951/d1308f32782798689f713bc2af3d9ea9.jpg"/></item><item><title><![CDATA[Automate Remediation and Response with Security Orchestration]]></title><description><![CDATA[<p>Ditch slow manual processes. Discover how security automation and SOAR reduce human error, accelerate threat containment, and free up your security analysts.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/automate-remediation-and-response</link><guid isPermaLink="false">substack:post:169326788</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 30 Jul 2025 14:18:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/169326788/f033b8c7d098799a6230fe4a8c842ec3.mp3" length="8190021" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>682</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/169326788/0047ac2d357614a52f583442f82a9b71.jpg"/></item><item><title><![CDATA[Cloud Security: Identity as the New Perimeter | JIT & Adaptive Access]]></title><description><![CDATA[<p>Discover how a robust Identity and Access Management (IAM) strategy, with JIT access and adaptive controls, can transform your cloud security and virtually patch vulnerabilities.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/cloud-security-identity-as-the-new</link><guid isPermaLink="false">substack:post:168647507</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 19 Jul 2025 21:27:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/168647507/8800dc0d4032578ec27e60689f9339d1.mp3" length="6011433" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>501</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/168647507/6c947f807ece7c40912ce36a4376fad2.jpg"/></item><item><title><![CDATA[Overwhelmed by Alerts? A Guide to Risk-Based Prioritization Over CVS]]></title><description><![CDATA[<p>Discover how to mature your vulnerability management from a reactive chore to a continuous, risk-based program. This guide helps leaders protect their multi-cloud enterprise, prevent data breaches, and measurably reduce business risk.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/overwhelmed-by-alerts-a-guide-to</link><guid isPermaLink="false">substack:post:168102080</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 14 Jul 2025 16:37:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/168102080/aa01f13c0cbb088deb2f8e52f9089e12.mp3" length="6210953" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>517</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/168102080/e97d64a871dabc0e25802ac82f3792db.jpg"/></item><item><title><![CDATA[10 Best Practices for the Modern Enterprise: Achieve Complete Attack Surface Visibility]]></title><description><![CDATA[<p>Discover how to mature your vulnerability management from a reactive chore to a continuous, risk-based program. This guide helps leaders protect their multi-cloud enterprise, prevent data breaches, and measurably reduce business risk.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/10-best-practices-for-the-modern</link><guid isPermaLink="false">substack:post:167643600</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 07 Jul 2025 13:57:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/167643600/05c4834bab25f54c56e49e1599e44f00.mp3" length="10028678" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>836</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/167643600/5c602570b12f28b425d0861db1c1c4ea.jpg"/></item><item><title><![CDATA[Strengthening Your Digital Defense: Practical Cybersecurity Approaches for SMB Tech Executives in 2025]]></title><description><![CDATA[<p>The cyber environment presents ongoing challenges with increasing cyber threats, and Small to Medium Businesses (SMBs) often find themselves particularly at risk. Although high-profile breaches frequently make the news, SMBs are sometimes targeted because they are viewed as more vulnerable and have limited resources, making them what some might call "low-hanging fruit" for cybercriminals.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/strengthening-your-digital-defense</link><guid isPermaLink="false">substack:post:164046150</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 21 May 2025 14:37:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/164046150/125ced4705557f9631e4ce0718c37e5b.mp3" length="7469080" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>622</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/164046150/a3d4a41bd9c5009c1c5dbafe57bc4a3c.jpg"/></item><item><title><![CDATA[Review of the 2025 Verizon DBIR]]></title><description><![CDATA[<p>The 2025 Verizon DBIR is out! Learn the critical cybersecurity shifts impacting SMBs: soaring third-party risks, rising espionage, persistent ransomware, and the continued threat of credential abuse. Get actionable insights for stronger defenses.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/review-of-the-2025-verizon-dbir</link><guid isPermaLink="false">substack:post:162719547</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 05 May 2025 14:22:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/162719547/46dc1e26287f4e8ce8b2898e9e67a8f4.mp3" length="6554689" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>546</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/162719547/98b1f8432dbb68c0b7aa1d1f659648ed.jpg"/></item><item><title><![CDATA[Navigating CMMC 2.0: A Strategic Imperative for Tech Leaders Protecting CUI]]></title><description><![CDATA[<p>Navigate CMMC 2.0 compliance for government contractors protecting CUI. Understand the 3 levels, key requirements, and how it compares to FedRAMP and DoD Impact Levels. Learn about Microsoft GCC High for CMMC readiness.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-cmmc-20-a-strategic-imperative</link><guid isPermaLink="false">substack:post:162710465</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 02 May 2025 18:22:41 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/162710465/83ef22040713b990cc44c08b22b35715.mp3" length="6799509" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>567</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/162710465/aeb4c409d94a525a26ca42ca33997baa.jpg"/></item><item><title><![CDATA[Crafting an Effective Overall Risk Management Plan for SMBs from Scratch]]></title><description><![CDATA[<p>Small and medium-sized enterprises (SMBs) increasingly rely on digital presence, facing IT and business challenges. Tech leaders launching initiatives need a robust risk management strategy that is careful yet efficient. This report provides SMBs with a comprehensive template that combines industry insights, risk management best practices, and case studies to recognize, evaluate, and mitigate risks while aligning with business goals.</p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/crafting-an-effective-overall-risk</link><guid isPermaLink="false">substack:post:161378364</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 15 Apr 2025 14:10:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/161378364/49049afc72094d0011a1234db16488d7.mp3" length="1839569" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>153</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/161378364/7863f89f7013710229be3ecdf0a9488f.jpg"/></item><item><title><![CDATA[Navigating NIST 800-171 Compliance: A Strategic Guide for SMBs]]></title><description><![CDATA[<p><strong>Discovering NIST 800-171 & CMMC Compliance</strong></p><p>The threat landscape is filled with growing cyber risks, making it vital for organizations to protect sensitive information. This is particularly critical for Small and Medium-sized Businesses (SMBs) operating within the Defense Industrial Base (DIB), where safeguarding Controlled Unclassified Information (CUI) is not just a matter of security but a prerequisite for survival. The National Institute of Standards and Technology (NIST) Special Publication 800-171 is the cornerstone for this protection in non-federal systems. Furthermore, the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework builds upon NIST 800-171, underscoring its importance. For SMBs in the DIB, achieving and maintaining compliance is not merely a regulatory hurdle; it represents a strategic imperative for accessing Department of Defense (DoD) contracts and ensuring the long-term viability of their business.1 NIST SP 800-171 provides the necessary guidelines and requirements for protecting this sensitive government data, making its adherence a contractual obligation for organizations that handle CUI.4</p><p><strong>The Dual Challenge and Opportunity: Balancing Security with SMB Realities</strong></p><p>While the importance of cybersecurity compliance is evident, SMBs often face a unique set of challenges in achieving NIST 800-171 and CMMC compliance. Limited resources, financial constraints, a scarcity of dedicated personnel, and a lack of in-house cybersecurity expertise frequently present significant obstacles.6 Implementing NIST SP 800-171 using only internal resources can demand a substantial investment of time and money, potentially straining the already tight budgets of smaller organizations.13 Furthermore, the technical and often intricate requirements of both NIST 800-171 and CMMC require specialized cybersecurity knowledge that many SMBs may lack internally, making accurate interpretation and practical implementation considerable challenges.7 The daily demands of running a small business often leave owners and employees with stretched schedules, making it difficult to allocate the dedicated time required for thorough compliance planning, implementation, and the creation of necessary documentation.7 Adding to this complexity is the fact that cybersecurity standards are not static; NIST 800-171 and CMMC are subject to revisions and updates, requiring SMBs to commit to ongoing monitoring and adaptation of their security practices to maintain a compliant posture.7 Finally, accurately identifying all instances of Controlled Unclassified Information (CUI) within an SMB's diverse IT environment and implementing the appropriate technologies for its effective management and protection can be a particularly challenging aspect of compliance.7</p><p>Despite these considerable challenges, achieving NIST 800-171 compliance presents significant opportunities for SMBs within the defense sector. Compliance is a key that unlocks access to the substantial and often high-value contracting opportunities available within the Department of Defense and its extensive network of partners.1 By implementing the security controls and measures mandated by NIST 800-171, SMBs significantly strengthen their defenses against various cyber threats, including data breaches, malware attacks, and unauthorized access, leading to a more resilient and secure business operation.1 Adhering to recognized cybersecurity standards such as NIST 800-171 sends a powerful message to customers, clients, and partners, showcasing a strong commitment to data security and privacy, which fosters greater trust and strengthens business relationships.1 Achieving NIST 800-171 compliance can also set an SMB apart from its competitors, particularly when vying for government contracts or seeking partnerships with larger organizations that prioritize robust cybersecurity practices, providing a distinct edge in the marketplace.1 Furthermore, by complying with NIST 800-171, SMBs can significantly reduce the likelihood and impact of data breaches, thereby mitigating potential reputational damage, avoiding costly legal repercussions, and safeguarding their business continuity.1 NIST 800-171 also includes specific requirements for developing and documenting an incident response plan, equipping SMBs with the necessary strategies and procedures to react swiftly and effectively to security incidents, minimizing potential damage and downtime, and enhancing overall business resilience.15 Finally, although there is an initial investment, the proactive measures taken to prevent cyber incidents through NIST 800-171 compliance can result in substantial long-term cost savings by avoiding the significant financial burdens often associated with data breach recovery, legal actions, and reputational damage repair.15</p><p><strong>Decoding the Frameworks: Understanding NIST 800-171 and CMMC 2.0</strong></p><p>NIST Special Publication 800-171 is a set of security guidelines and requirements designed to protect Controlled Unclassified Information (CUI) when handled by non-federal organizations, particularly those contracting with the U.S. Department of Defense.1 It is organized into 14 distinct families of security controls, initially comprising 110 individual controls aimed at safeguarding CUI, with a recent update in Revision 3 reducing the total number of controls to 97.16 The latest updates, introduced in NIST SP 800-171 Revision 3 (released in May 2024), bring significant changes, including a closer alignment with the more comprehensive NIST SP 800-53 Revision 5, the introduction of Organization-Defined Parameters (ODPs) allowing for tailored security requirements, and the addition of new control families focusing on proactive planning (PL), secure system and services acquisition (SA), and supply chain risk management (SR).1 These updates also include enhanced tailoring criteria, control recategorization, and detailed clarifications and consolidations to simplify the implementation process.14 The Supplier Performance Risk System (SPRS) is the official Department of Defense repository where contractors, including SMBs, are required to upload their self-assessment scores reflecting their compliance with NIST 800-171, making it a critical component for demonstrating cybersecurity readiness to the DoD.1</p><p>Building upon the foundation of NIST 800-171 is the Cybersecurity Maturity Model Certification (CMMC) 2.0, the Department of Defense's comprehensive framework specifically designed to ensure that all contractors within the Defense Industrial Base (DIB) implement and maintain adequate cybersecurity measures to protect sensitive government information, including Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).2 CMMC 2.0 features a streamlined three-tiered structure: Level 1 (Foundational) focuses on basic safeguarding of Federal Contract Information (FCI) through 15 fundamental security controls.7 Level 2 (Advanced) centers on protecting Controlled Unclassified Information (CUI) and requires adherence to the security controls outlined in NIST SP 800-171.1 Level 3 (Expert) aims to defend CUI against Advanced Persistent Threats (APTs) by incorporating controls from NIST SP 800-172.7 Assessment requirements vary by level, with Level 1 allowing for annual self-assessments. In contrast, Level 2 for prioritized contracts and Level 3 necessitate triennial third-party assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs), with some Level 2 contracts potentially allowing self-assessment.7 The Department of Defense plans to begin incorporating CMMC requirements into select new contracts starting in 2025, with a broader and phased enforcement expected to continue over the following years.2</p><p><strong>Your Actionable Roadmap to NIST 800-171 Compliance: Practical Steps for SMBs</strong></p><p>Navigating the path to NIST 800-171 compliance can seem daunting, but by breaking it down into manageable steps, SMBs can work towards a more secure future.</p><p><strong>Step 1: Understand Your Requirements and Scope.</strong> The first critical step involves determining if your business handles Controlled Unclassified Information (CUI) and identifying the specific Cybersecurity Maturity Model Certification (CMMC) level required by your Department of Defense contracts.9 It is also essential to clearly define the scope of your information systems subject to these compliance requirements, focusing on those that process, store, or transmit CUI.</p><p><strong>Step 2: Conduct a Gap Analysis.</strong> Once you understand the requirements, the next step is to assess your cybersecurity posture against the specific controls outlined in NIST 800-171.7. This involves systematically evaluating your security measures and identifying areas where your current practices fall short of the NIST 800-171 standards.</p><p><strong>Step 3: Develop a System Security Plan (SSP).</strong> A comprehensive System Security Plan (SSP) is the cornerstone of your compliance efforts.8 This document should detail how your organization implements each security control mandated by NIST 800-171, providing specific information about your IT infrastructure, security policies, and operational procedures.</p><p><strong>Step 4: Implement the Required Security Controls.</strong> Based on the findings of your gap analysis and the roadmap outlined in your SSP, you will need to implement the necessary technical, physical, and administrative security controls.5 This will involve focusing on key areas such as access control, security awareness and employee training, establishing audit and accountability mechanisms, implementing robust configuration management, and developing a comprehensive incident response plan.</p><p><strong>Step 5: Create a Plan of Action and Milestones (POA&M).</strong> For any security controls identified in your gap analysis that are not yet fully implemented, you will need to develop a detailed Plan of Action and Milestones (POA&M).1 The POA&M should document the specific steps you will take, the resources you will allocate, and the target dates you aim to comply with each outstanding control fully.</p><p><strong>Step 6: Implement Continuous Monitoring.</strong> Achieving NIST 800-171 compliance is not a one-time event but requires the establishment of continuous monitoring processes.8 This involves ongoing assessment of your security controls and systems to ensure their continued effectiveness and regularly reviewing and updating your SSP and POA&M to adapt to evolving threats and maintain your compliant posture.</p><p><strong>Step 7: Prepare for Assessment (if applicable).</strong> The final step for SMBs pursuing CMMC 2.0 Level 2 or Level 3 certification involves engaging with a Certified Third-Party Assessment Organization (C3PAO) to conduct the formal assessment.2 It is highly recommended to conduct internal readiness reviews or mock audits beforehand to identify and address any remaining compliance gaps, ensuring a smoother and more successful official assessment.</p><p><strong>Navigating the Hurdles: Addressing Common Pain Points and FAQs</strong></p><p>SMBs embarking on the journey to NIST 800-171 and CMMC compliance often encounter several common challenges. One frequent pain point is the ambiguity inherent in some of the NIST 800-171 requirements, making it difficult for SMBs to determine the specific controls they need to implement and whether their solutions are sufficient.100 The significant lack of time and resources, both in terms of personnel and finances, required to implement the necessary technical and procedural controls and to create and maintain the extensive documentation is another major hurdle for SMBs.109 Budget constraints and the potential costs associated with compliance, including investments in new technologies, consultant fees, and employee training, are significant concerns for many SMBs.109 Ensuring that cloud service providers and third-party vendors who may handle or have access to their data also meet the stringent security requirements of NIST 800-171 and CMMC adds another layer of complexity.14 Furthermore, many SMBs find it challenging to view and manage compliance as a continuous process that requires ongoing monitoring and regular updates rather than a one-time project.14 Finally, understanding the precise relationship between NIST 800-171 and CMMC, and how the specific requirements of NIST 800-171 map to the different levels and assessment processes within the CMMC framework, can also be a source of confusion.110</p><p>To help SMBs navigate these challenges, here are answers to some frequently asked questions:</p><p>* <strong>What CMMC level do I need?</strong> The required CMMC level is determined by the type of information handled under your Department of Defense contracts. Level 1 is for Federal Contract Information (FCI), Level 2 is for Controlled Unclassified Information (CUI), and Level 3 is for CUI requiring protection against Advanced Persistent Threats (APTs).7</p><p>* <strong>How long does the certification process take?</strong> The timeframe can vary significantly, typically ranging from several months to over a year, depending on your current cybersecurity maturity, the required CMMC level, the complexity of your IT environment, and the efficiency of your implementation process.6</p><p>* <strong>Can small businesses afford CMMC/NIST compliance?</strong> While the costs can be substantial, affordability is possible through strategies like reducing the compliance boundary, leveraging existing resources, exploring financial assistance, and adopting a phased implementation.6</p><p>* <strong>What happens if we are not compliant?</strong> Failure to achieve compliance can lead to severe consequences, including the loss of eligibility for bidding on new contracts, potential termination of existing agreements, imposition of financial penalties, and significant reputational damage.7</p><p><strong>Learning from Success: Case Studies of SMBs Achieving NIST 800-171 Compliance</strong></p><p>Examining the experiences of SMBs that have successfully navigated the complexities of NIST 800-171 and CMMC compliance can provide valuable insights and actionable strategies for others. Many SMBs have succeeded by implementing strategies such as creating secure enclaves for CUI, which limits the scope and cost of compliance.12 one SMB defense contractor achieved a perfect NIST SP 800-171 score by deploying PreVeil as an overlay on their existing Microsoft 365 environment, showcasing a cost-effective approach.92 Another federal contractor partnered with Cleared Systems to address technology limitations and successfully implement the necessary controls, positioning them for lucrative DoD contracts.117 Certified Manufacturing Inc., a woman-owned small business, with guidance from the MEP National Network™, achieved CMMC Level 3 compliance within a tight 90-day timeframe, leading to the renewal of a significant DoD contract.70 Cape Henry Associates, an SDVOSB, successfully achieved compliance with both NIST 800-171 and CMMC by using Apptega as their compliance system of record, improving their cybersecurity posture and demonstrating their commitment to security for DoD and contracting partners.69 These examples highlight the importance of understanding the specific requirements, leveraging appropriate tools and expertise, and implementing focused strategies to achieve compliance success.</p><p><strong>The Cost of Inaction: Risks and Consequences of Non-Compliance</strong></p><p>For SMBs operating within the defense supply chain, failing to comply with NIST 800-171 requirements carries significant risks and consequences, particularly when working with the DoD. A primary and substantial risk is the potential loss of eligibility to bid on and be awarded contracts from the Department of Defense, which can severely impact SMBs that rely on government work.2 Existing Department of Defense contracts held by SMBs could also be terminated if they do not comply with the mandatory NIST 800-171 cybersecurity standards.5 Furthermore, SMBs failing to comply may face financial penalties, including potential fines and legal repercussions, especially under the False Claims Act if they misrepresent their compliance status to the government.1 Non-compliance can also lead to significant reputational damage, eroding the trust built with government agencies, prime contractors, and other partners, potentially jeopardizing future collaborations and business opportunities.1 The Department of Defense has been increasing its scrutiny of contractors' cybersecurity compliance, making non-compliant SMBs more susceptible to audits and stricter oversight.42 Ultimately, SMBs that fail to achieve NIST 800-171 compliance will likely face a significant competitive disadvantage compared to those who have invested in meeting these cybersecurity standards.1</p><p><strong>Tools of the Trade: Leveraging Resources for NIST 800-171 Compliance</strong></p><p>Several valuable tools and resources can significantly aid SMBs in their journey toward NIST 800-171 compliance.</p><p><strong>Microsoft Purview</strong> offers a suite of features, including content search for identifying Controlled Unclassified Information (CUI), the ability to apply sensitivity labels for data classification and protection, and the implementation of Data Loss Prevention (DLP) rules, all of which can significantly assist SMBs in meeting various technical and administrative controls.120</p><p><strong>Tenable.io</strong> is a vulnerability management platform that provides SMBs with tools for actively and passively monitoring their IT environment, identifying vulnerabilities, and assessing compliance against the technical controls specified in NIST 800-171, offering dashboards, reports, and features to track and demonstrate conformance.130 <strong>Microsoft Defender</strong> now also provides a <strong>Vulnerability Managemen</strong>t subscription that could help assess the vulnerability environment.</p><p><strong>Certified Third-Party Assessment Organizations (C3PAOs)</strong> are authorized entities that play a crucial role in the CMMC 2.0 framework by conducting independent assessments of an organization's cybersecurity practices and issuing certifications for Level 2 and Level 3 compliance, which are often required for Department of Defense contracts.2 When selecting a C3PAO, SMBs should consider their experience with federal compliance frameworks, understanding of the SMB landscape, communication style, and availability.11 Other invaluable resources include the official websites of the National Institute of Standards and Technology (NIST) and the Department of Defense's CMMC program, which provide the latest requirements, guidelines, and documentation.18 Additionally, Manufacturing Extension Partnership (MEP) Centers can offer training, guidance, gap analyses, and connections to cybersecurity experts for SMBs.18</p><p><strong>Smart Investments: Understanding and Optimizing the Costs of Compliance</strong></p><p>NIST 800-171 compliance cost implications for SMBs can vary significantly. Initial costs often include conducting a thorough gap analysis, engaging cybersecurity consultants for guidance, upgrading existing hardware and software or investing in new solutions, and providing comprehensive cybersecurity awareness training to employees.5 Ongoing costs typically involve continuous security monitoring of systems and networks, regular maintenance of implemented controls, and the potential expense of periodic third-party assessments, particularly for higher CMMC levels.14 For SMBs seeking CMMC 2.0 Level 2 or Level 3 certification, a significant cost factor will be the expense of engaging a Certified Third-Party Assessment Organization (C3PAO) to conduct the required assessment and issue the certification.2</p><p>To optimize resource allocation and minimize these costs, SMBs can employ several strategies. Carefully defining and limiting the scope of their CUI environment, potentially by creating a secure enclave, can significantly reduce the number of systems and users that need to meet the stringent NIST 800-171 controls.56 Thoroughly assessing their current security infrastructure and leveraging existing technologies, processes, or policies that align with NIST 800-171 requirements can also minimize the need for costly new solutions.10 Taking advantage of free resources, guidance documents, and policy templates often provided by NIST and other cybersecurity organizations can help save money on consulting fees and the development of compliance documentation.107 Partnering with a reputable Managed Service Provider (MSP) or engaging cybersecurity consultants specializing in NIST 800-171 and CMMC compliance can provide the necessary expertise and guidance, potentially proving more cost-effective in the long run.2 Adopting a phased approach to NIST 800-171 compliance, focusing on implementing the most critical security controls first based on a thorough risk assessment, allows for better budget and resource management.8 Exploring available federal or state funding programs, grants, or tax credits designed to help small businesses offset cybersecurity compliance costs is also worthwhile.6 Finally, leveraging compliance automation tools and platforms can streamline various aspects of the process, reducing manual effort and associated expenses.8</p><p></p><p></p><p><strong>Embracing NIST 800-171 Compliance for a Secure and Prosperous Future</strong></p><p>For SMBs operating within the defense supply chain, NIST 800-171 compliance is more than just a regulatory obligation; it is a fundamental necessity for ensuring their security and continued participation in the lucrative Department of Defense marketplace. By adhering to these stringent cybersecurity standards, SMBs strengthen their defenses against increasingly sophisticated cyber threats and unlock significant business opportunities, build trust with essential partners, and mitigate the potentially devastating risks related to data breaches and non-compliance. While the path to compliance may present challenges, particularly for organizations with limited resources, viewing it as a strategic investment in the future is vital. By understanding the requirements, leveraging available resources and tools, and implementing cost-effective strategies, SMBs can successfully navigate the complexities of NIST 800-171 compliance and position themselves for a secure and prosperous future within the defense industrial base. Taking proactive steps today to understand and implement these critical cybersecurity standards is not just about meeting a requirement—it's about safeguarding your business and securing your place in the evolving landscape of government contracting.</p><p></p><p></p><p><strong>Works cited</strong></p><p>* NIST Special Publication 800-171: Staying Secure with LastPass, accessed April 10, 2025, <a target="_blank" href="https://blog.lastpass.com/posts/nist-special-publication-800-171">https://blog.lastpass.com/posts/nist-special-publication-800-171</a></p><p>* CMMC Compliance Guide: Understanding the Cybersecurity Maturity Model Certification (CMMC 2.0) for Defense Contractors - Summit 7, accessed April 10, 2025, <a target="_blank" href="https://www.summit7.us/cmmc">https://www.summit7.us/cmmc</a></p><p>* CMMC Requirements for Small Businesses: What to Know - BeMoPro, accessed April 10, 2025, <a target="_blank" href="https://www.bemopro.com/cybersecurity-blog/get-cmmc-compliant-cmmc-for-small-business">https://www.bemopro.com/cybersecurity-blog/get-cmmc-compliant-cmmc-for-small-business</a></p><p>* How updated guidelines on protecting controlled unclassified information impact SMBs, accessed April 10, 2025, <a target="_blank" href="https://blog.barracuda.com/2024/07/08/updated-guidelines-controlled-unclassified-information-smbs">https://blog.barracuda.com/2024/07/08/updated-guidelines-controlled-unclassified-information-smbs</a></p><p>* The Impact of NIST SP 800-171 on SMBs - Tripwire, accessed April 10, 2025, <a target="_blank" href="https://www.tripwire.com/state-of-security/impact-nist-sp-800-171-smbs">https://www.tripwire.com/state-of-security/impact-nist-sp-800-171-smbs</a></p><p>* CMMC Requirements for SMBs: Navigating Compliance on a Budget, accessed April 10, 2025, <a target="_blank" href="https://isidefense.com/blog/cmmc-requirements-for-small-businesses-navigating-the-road-to-compliance-on-a-budget">https://isidefense.com/blog/cmmc-requirements-for-small-businesses-navigating-the-road-to-compliance-on-a-budget</a></p><p>* CMMC Compliance for Small and Medium Businesses: Overcoming Challenges - Exostar, accessed April 10, 2025, <a target="_blank" href="https://www.exostar.com/blog/cmmc-compliance-for-small-and-medium-businesses-overcoming-challenges/">https://www.exostar.com/blog/cmmc-compliance-for-small-and-medium-businesses-overcoming-challenges/</a></p><p>* 8 Recommendations for Businesses Approaching CMMC in 2025 - Lazarus Alliance, Inc., accessed April 10, 2025, <a target="_blank" href="https://lazarusalliance.com/8-recommendations-for-businesses-approaching-cmmc-in-2025/">https://lazarusalliance.com/8-recommendations-for-businesses-approaching-cmmc-in-2025/</a></p><p>* CMMC: What It Means for Small Businesses | BizTech Magazine, accessed April 10, 2025, <a target="_blank" href="https://biztechmagazine.com/article/2025/01/cmmc-what-it-means-small-businesses">https://biztechmagazine.com/article/2025/01/cmmc-what-it-means-small-businesses</a></p><p>* The Economic Impact of CMMC Compliance on SMBs | RSI Security, accessed April 10, 2025, <a target="_blank" href="https://blog.rsisecurity.com/the-economic-impact-of-cmmc-compliance-on-smbs/">https://blog.rsisecurity.com/the-economic-impact-of-cmmc-compliance-on-smbs/</a></p><p>* CMMC Compliance for Small Businesses: Challenges and Recommendations - Kiteworks, accessed April 10, 2025, <a target="_blank" href="https://www.kiteworks.com/cmmc-compliance/small-business/">https://www.kiteworks.com/cmmc-compliance/small-business/</a></p><p>* The Impact of CMMC on Small Businesses - Core Business Solutions, accessed April 10, 2025, <a target="_blank" href="https://www.thecoresolution.com/the-impact-of-cmmc-on-small-businesses">https://www.thecoresolution.com/the-impact-of-cmmc-on-small-businesses</a></p><p>* The Cost of Taking on CMMC In-House - Summit 7, accessed April 10, 2025, <a target="_blank" href="https://www.summit7.us/blog/cost-of-taking-on-cmmc-in-house?hsLang=en">https://www.summit7.us/blog/cost-of-taking-on-cmmc-in-house?hsLang=en</a></p><p>* NIST 800-171 Compliance: What You Need to Know in 2025 - Cypago, accessed April 10, 2025, <a target="_blank" href="https://cypago.com/nist-800-171-2025/">https://cypago.com/nist-800-171-2025/</a></p><p>* NIST 800-171 Compliance for Small Business - Bright Defense, accessed April 10, 2025, <a target="_blank" href="https://www.brightdefense.com/resources/nist-800-171-compliance-for-small-business/">https://www.brightdefense.com/resources/nist-800-171-compliance-for-small-business/</a></p><p>* Breaking Down NIST 800-171 Controls: The Full List of Security Requirements - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/list-of-nist-800-171-controls/">https://sprinto.com/blog/list-of-nist-800-171-controls/</a></p><p>* NIST SP 800-171 Compliance: Essential Guide for Organizations - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/nist-800-171-compliance/">https://sprinto.com/blog/nist-800-171-compliance/</a></p><p>* What Is the NIST SP 800-171 and Who Needs to Follow It?, accessed April 10, 2025, <a target="_blank" href="https://www.nist.gov/blogs/manufacturing-innovation-blog/what-nist-sp-800-171-and-who-needs-follow-it-0">https://www.nist.gov/blogs/manufacturing-innovation-blog/what-nist-sp-800-171-and-who-needs-follow-it-0</a></p><p>* CMMC Compliance: Why It's Essential for National Security and Your Business Success, accessed April 10, 2025, <a target="_blank" href="https://convergetp.com/2025/04/03/cmmc-compliance-why-its-essential-for-national-security-and-your-business-success/">https://convergetp.com/2025/04/03/cmmc-compliance-why-its-essential-for-national-security-and-your-business-success/</a></p><p>* CMMC Compliance 2025: What Every Defense Contractor Must Know Now!, accessed April 10, 2025, <a target="_blank" href="https://www.ecisolutions.com/blog/manufacturing/cmmc-compliance-2025-updates/">https://www.ecisolutions.com/blog/manufacturing/cmmc-compliance-2025-updates/</a></p><p>* Everything DoD Contractors Need to Know About CMMC Compliance | Teal - tealtech.com, accessed April 10, 2025, <a target="_blank" href="https://tealtech.com/blog/cmmc-compliance-for-dod-contractors-dec162024/">https://tealtech.com/blog/cmmc-compliance-for-dod-contractors-dec162024/</a></p><p>* 20 Key Takeaways from the CMMC Final Rule for SMBs - Bright Defense, accessed April 10, 2025, <a target="_blank" href="https://www.brightdefense.com/resources/20-key-takeaways-cmmc-final-rule/">https://www.brightdefense.com/resources/20-key-takeaways-cmmc-final-rule/</a></p><p>* CMMC Compliance and Small Businesses: Why It's More Important Than You Think - BitLyft, accessed April 10, 2025, <a target="_blank" href="https://www.bitlyft.com/resources/cmmc-compliance-and-small-businesses-why-its-more-important-than-you-think">https://www.bitlyft.com/resources/cmmc-compliance-and-small-businesses-why-its-more-important-than-you-think</a></p><p>* NIST Compliance Checklist for Security-First Businesses 2025 - Cyphere, accessed April 10, 2025, <a target="_blank" href="https://thecyphere.com/blog/nist-compliance-checklist/">https://thecyphere.com/blog/nist-compliance-checklist/</a></p><p>* NIST 800-171 Compliance: How to Comply with the Latest Revision [+ Checklist], accessed April 10, 2025, <a target="_blank" href="https://secureframe.com/blog/nist-800-171-compliance">https://secureframe.com/blog/nist-800-171-compliance</a></p><p>* SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations - NIST Computer Security Resource Center - National Institute of Standards and Technology, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/r3/ipd">https://csrc.nist.gov/pubs/sp/800/171/r3/ipd</a></p><p>* SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations - NIST Computer Security Resource Center - National Institute of Standards and Technology, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/r3/final">https://csrc.nist.gov/pubs/sp/800/171/r3/final</a></p><p>* SP 800-171 Rev. 2, Protecting CUI in Nonfederal Systems and Organizations - CSRC, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.rip/publications/detail/sp/800-171/rev-2/final">https://csrc.nist.rip/publications/detail/sp/800-171/rev-2/final</a></p><p>* NIST.SP.800-171r2.pdf, accessed April 10, 2025, <a target="_blank" href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf</a></p><p>* NIST 800- 171 Compliance Checklist - Complete Guide - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/nist-800-171-compliance-checklist/">https://sprinto.com/blog/nist-800-171-compliance-checklist/</a></p><p>* Understanding NIST 800-171 & What it Means for Your Organization - PreVeil, accessed April 10, 2025, <a target="_blank" href="https://www.preveil.com/blog/understanding-nist-800-171-what-it-means-for-your-organization/">https://www.preveil.com/blog/understanding-nist-800-171-what-it-means-for-your-organization/</a></p><p>* SP 800-171 Rev. 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations - NIST Computer Security Resource Center - National Institute of Standards and Technology, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/r1/upd3/final">https://csrc.nist.gov/pubs/sp/800/171/r1/upd3/final</a></p><p>* SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations - NIST Computer Security Resource Center, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final">https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final</a></p><p>* SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations - NIST Computer Security Resource Center, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/r3/fpd">https://csrc.nist.gov/pubs/sp/800/171/r3/fpd</a></p><p>* NIST 800-171 Compliance | How Totem can help small businesses, accessed April 10, 2025, <a target="_blank" href="https://www.totem.tech/nist-800-171-compliance/">https://www.totem.tech/nist-800-171-compliance/</a></p><p>* Need-to-Know: Simplifying NIST SP 800-171 and CMMC for SMBs - Infinity Technologies, accessed April 10, 2025, <a target="_blank" href="https://it-va.com/need-to-know-simplifying-nist-sp-800-171-and-cmmc-for-smbs/">https://it-va.com/need-to-know-simplifying-nist-sp-800-171-and-cmmc-for-smbs/</a></p><p>* NIST SP 800-171 Revision 3 Goes Final: Who's Down with ODP?, accessed April 10, 2025, <a target="_blank" href="https://www.governmentcontractslaw.com/2024/05/nist-sp-800-171-revision-3-goes-final-whos-down-with-odp/">https://www.governmentcontractslaw.com/2024/05/nist-sp-800-171-revision-3-goes-final-whos-down-with-odp/</a></p><p>* Report finds large gap in CMMC readiness among defense industrial base - DefenseScoop, accessed April 10, 2025, <a target="_blank" href="https://defensescoop.com/2025/01/28/redspin-report-cmmc-readiness-gap-2025-defense-industrial-base/">https://defensescoop.com/2025/01/28/redspin-report-cmmc-readiness-gap-2025-defense-industrial-base/</a></p><p>* Supplier Performance Risk System (SPRS) - Cyber Reports, accessed April 10, 2025, <a target="_blank" href="https://www.sprs.csd.disa.mil/nistsp.htm">https://www.sprs.csd.disa.mil/nistsp.htm</a></p><p>* The Complete Guide to NIST SP 800-171 - Peerless Tech Solutions, accessed April 10, 2025, <a target="_blank" href="https://www.getpeerless.com/complete-guide-nist-800-171">https://www.getpeerless.com/complete-guide-nist-800-171</a></p><p>* About CMMC - DoD CIO - Department of Defense, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/cmmc/About/">https://dodcio.defense.gov/cmmc/About/</a></p><p>* Time for Compliance with DOD's Cybersecurity Regulations is NOW, accessed April 10, 2025, <a target="_blank" href="https://governmentcontractsnavigator.com/2024/04/24/time-for-compliance-with-dods-cybersecurity-regulations-is-now/">https://governmentcontractsnavigator.com/2024/04/24/time-for-compliance-with-dods-cybersecurity-regulations-is-now/</a></p><p>* Federal contractor, not 100% NIST 800-171 compliant, but working toward it, how do I explain this when bidding on contracts? - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/NISTControls/comments/kmjqwy/federal_contractor_not_100_nist_800171_compliant/">https://www.reddit.com/r/NISTControls/comments/kmjqwy/federal_contractor_not_100_nist_800171_compliant/</a></p><p>* KLC Consulting, Inc - C3PAO - CyberAB, accessed April 10, 2025, <a target="_blank" href="https://cyberab.org/Member/C3PAO-556-Klc-Consulting-Inc">https://cyberab.org/Member/C3PAO-556-Klc-Consulting-Inc</a></p><p>* Navigating CMMC Compliance and Key Insights from the National 8(a) Small Business Conference | Womble Bond Dickinson, accessed April 10, 2025, <a target="_blank" href="https://www.womblebonddickinson.com/us/insights/alerts/navigating-cmmc-compliance-and-key-insights-national-8a-small-business-conference">https://www.womblebonddickinson.com/us/insights/alerts/navigating-cmmc-compliance-and-key-insights-national-8a-small-business-conference</a></p><p>* The Federal Funding Freeze and Why CMMC Compliance Remains Critical for Contractors, accessed April 10, 2025, <a target="_blank" href="https://v2systems.com/blog/the-federal-funding-freeze-and-why-cmmc-compliance-remains-critical-for-contractors/">https://v2systems.com/blog/the-federal-funding-freeze-and-why-cmmc-compliance-remains-critical-for-contractors/</a></p><p>* DOD Issues Final CMMC Rule - SBA advocacy - Small Business Administration, accessed April 10, 2025, <a target="_blank" href="https://advocacy.sba.gov/2024/10/24/dod-final-cmmc-rule/">https://advocacy.sba.gov/2024/10/24/dod-final-cmmc-rule/</a></p><p>* Joint Intermediate Force Capabilities Office > Media > Multimedia > IFC Videos - Non-Lethal Weapons Program, accessed April 10, 2025, <a target="_blank" href="https://jifco.defense.gov/Media/Multimedia/IFC-Videos/?videoid=944070&#38;dvpTag=CIO">https://jifco.defense.gov/Media/Multimedia/IFC-Videos/?videoid=944070&dvpTag=CIO</a></p><p>* Cybersecurity Maturity Model Certification (CMMC) - Controlled Unclassified Information (CUI), accessed April 10, 2025, <a target="_blank" href="https://www.dcsa.mil/Industrial-Security/Controlled-Unclassified-Information-CUI/Cybersecurity-Maturity-Model-Certification-CMMC/">https://www.dcsa.mil/Industrial-Security/Controlled-Unclassified-Information-CUI/Cybersecurity-Maturity-Model-Certification-CMMC/</a></p><p>* Cybersecurity Maturity Model Certification (CMMC) Model Overview | Version 2.13 - DoD CIO - Department of Defense, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverviewv2.pdf">https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverviewv2.pdf</a></p><p>* Cybersecurity Maturity Model Certification - DoD CUI Program, accessed April 10, 2025, <a target="_blank" href="https://www.dodcui.mil/CMMC/Cybersecurity-Maturity-Model-Certification/">https://www.dodcui.mil/CMMC/Cybersecurity-Maturity-Model-Certification/</a></p><p>* Cybersecurity Maturity Model Certification (CMMC) Program - Federal Register, accessed April 10, 2025, <a target="_blank" href="https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program">https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program</a></p><p>* Policy - Cybersecurity Maturity Model Certification (CMMC) - Office of the Under Secretary of Defense for Acquisition and Sustainment, accessed April 10, 2025, <a target="_blank" href="https://www.acq.osd.mil/asda/dpc/cp/cyber/cmmc.html">https://www.acq.osd.mil/asda/dpc/cp/cyber/cmmc.html</a></p><p>* CMMC Controls for SMB Owners: A Guide to the 14 Controls - Bright Defense, accessed April 10, 2025, <a target="_blank" href="https://www.brightdefense.com/resources/cmmc-controls-for-smb-owners/">https://www.brightdefense.com/resources/cmmc-controls-for-smb-owners/</a></p><p>* Navigating CMMC Compliance and Risk Management: Essential Steps for SMBs - Sikich, accessed April 10, 2025, <a target="_blank" href="https://www.sikich.com/insight/navigating-cmmc-compliance-and-risk-management-essential-steps-for-smbs/">https://www.sikich.com/insight/navigating-cmmc-compliance-and-risk-management-essential-steps-for-smbs/</a></p><p>* A Guide for SMB Defense Contractors to Achieve CMMC Compliance, accessed April 10, 2025, <a target="_blank" href="https://www.cyberdefensemagazine.com/a-guide-for-smb-defense-contractors-to-achieve-cmmc-compliance/">https://www.cyberdefensemagazine.com/a-guide-for-smb-defense-contractors-to-achieve-cmmc-compliance/</a></p><p>* Unlocking CMMC Compliance: A Step-by-Step Guide for SMBs - ISI Enterprises, accessed April 10, 2025, <a target="_blank" href="https://isidefense.com/blog/unlocking-cmmc-compliance-a-step-by-step-guide-for-smbs">https://isidefense.com/blog/unlocking-cmmc-compliance-a-step-by-step-guide-for-smbs</a></p><p>* CMMC Requirements for Small Businesses - Vaultes, accessed April 10, 2025, <a target="_blank" href="https://www.vaultes.com/cmmc-requirements-for-small-businesses/">https://www.vaultes.com/cmmc-requirements-for-small-businesses/</a></p><p>* SMB DIBS guide to CMMC compliance: Essential checklist for cybersecurity - Hypori, accessed April 10, 2025, <a target="_blank" href="https://www.hypori.com/blog/smb-dibs-guide-to-cmmc-compliance">https://www.hypori.com/blog/smb-dibs-guide-to-cmmc-compliance</a></p><p>* CMMC Final Rule Published - What Small Businesses Need to Know, accessed April 10, 2025, <a target="_blank" href="https://www.thecoresolution.com/cmmc-final-rule-published">https://www.thecoresolution.com/cmmc-final-rule-published</a></p><p>* CMMC Compliance: What You Need to Know - MyWorkDrive, accessed April 10, 2025, <a target="_blank" href="https://www.myworkdrive.com/blog/cmmc-compliance-updates/">https://www.myworkdrive.com/blog/cmmc-compliance-updates/</a></p><p>* 10 Answers to Demystify CMMC 2.0 Compliance Challenges - Hypori, accessed April 10, 2025, <a target="_blank" href="https://www.hypori.com/blog/10-questions-answers-to-cmmc-compliance">https://www.hypori.com/blog/10-questions-answers-to-cmmc-compliance</a></p><p>* CMMC FAQs - DoD CIO, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/Portals/0/Documents/CMMC/CMMC-FAQs.pdf">https://dodcio.defense.gov/Portals/0/Documents/CMMC/CMMC-FAQs.pdf</a></p><p>* CMMC and NIST 800-171 compliance? - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/CMMC/comments/17hoboh/cmmc_and_nist_800171_compliance/">https://www.reddit.com/r/CMMC/comments/17hoboh/cmmc_and_nist_800171_compliance/</a></p><p>* Your Top CMMC Questions Answered - Pivot Point Security, accessed April 10, 2025, <a target="_blank" href="https://www.pivotpointsecurity.com/your-top-cmmc-questions-answered/">https://www.pivotpointsecurity.com/your-top-cmmc-questions-answered/</a></p><p>* How to get a small business CMMC compliant? (Asking for advice) - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/CMMC/comments/1d3cymb/how_to_get_a_small_business_cmmc_compliant_asking/">https://www.reddit.com/r/CMMC/comments/1d3cymb/how_to_get_a_small_business_cmmc_compliant_asking/</a></p><p>* CMMC Compliance: Key Strategies for Businesses - SMPL-C, accessed April 10, 2025, <a target="_blank" href="https://smpl-c.com/cmmc-compliance-key-strategies-for-businesses/">https://smpl-c.com/cmmc-compliance-key-strategies-for-businesses/</a></p><p>* CMMC 101: Mastering Compliance for Federal Contracting Success - USFCR Blog, accessed April 10, 2025, <a target="_blank" href="https://blogs.usfcr.com/cmmc-101">https://blogs.usfcr.com/cmmc-101</a></p><p>* Cape Henry Prepares for CMMC Certification and Accelerates Growth - Apptega, accessed April 10, 2025, <a target="_blank" href="https://www.apptega.com/case-studies/cape-henry">https://www.apptega.com/case-studies/cape-henry</a></p><p>* Leading the Way for CMMC Compliance | NIST, accessed April 10, 2025, <a target="_blank" href="https://www.nist.gov/mep/successstories/2020/leading-way-cmmc-compliance">https://www.nist.gov/mep/successstories/2020/leading-way-cmmc-compliance</a></p><p>* Understanding the Impact of CMMC on Small Businesses - SSE Inc., accessed April 10, 2025, <a target="_blank" href="https://www.sseinc.com/blog/cmmc-small-business-impact/">https://www.sseinc.com/blog/cmmc-small-business-impact/</a></p><p>* Common small business CMMC compliance challenges - - Totem Technologies, accessed April 10, 2025, <a target="_blank" href="https://www.totem.tech/cmmc-compliance-challenges-for-small-businesses/">https://www.totem.tech/cmmc-compliance-challenges-for-small-businesses/</a></p><p>* Economic impact of CMMC on Small Businesses and MSPs - Technology First, accessed April 10, 2025, <a target="_blank" href="https://www.technologyfirst.org/Tech-News/13377368">https://www.technologyfirst.org/Tech-News/13377368</a></p><p>* Seldom-Discussed CMMC Effects on a Defense Contractor's Business | PilieroMazza, Law Firm, Government Contracts Attorney, accessed April 10, 2025, <a target="_blank" href="https://www.pilieromazza.com/seldom-discussed-cmmc-effects-on-a-defense-contractors-business/">https://www.pilieromazza.com/seldom-discussed-cmmc-effects-on-a-defense-contractors-business/</a></p><p>* Proposed CMMC Rule Spells Out Liability Risks for Noncompliance, accessed April 10, 2025, <a target="_blank" href="https://www.nationaldefensemagazine.org/articles/2024/1/12/proposed-cmmc-rule-spells-out-liability-risks-for-noncompliance">https://www.nationaldefensemagazine.org/articles/2024/1/12/proposed-cmmc-rule-spells-out-liability-risks-for-noncompliance</a></p><p>* CMMC Non-Compliance Penalties – OrionNetworks, accessed April 10, 2025, <a target="_blank" href="https://www.orionnetworks.net/what-are-the-penalties-for-cmmc-non-compliance/">https://www.orionnetworks.net/what-are-the-penalties-for-cmmc-non-compliance/</a></p><p>* Regulated Cybersecurity: Where We Are - The Consequences of Non-Compliance (June 2023) - NIST Computer Security Resource Center, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/csrc/media/Presentations/2023/regulated-cybersecurity-the-consequences-of-non-co/images-media/RMetzger-ssca-forum-060123.pdf">https://csrc.nist.gov/csrc/media/Presentations/2023/regulated-cybersecurity-the-consequences-of-non-co/images-media/RMetzger-ssca-forum-060123.pdf</a></p><p>* Challenges of CMMC for Small Businesses - Cybernet Systems Corporation, accessed April 10, 2025, <a target="_blank" href="https://www.cybernet.com/challenges-of-cmmc-for-small-businesses/">https://www.cybernet.com/challenges-of-cmmc-for-small-businesses/</a></p><p>* Certified Third-Party Assessor Organizations (C3PAO): Understanding Their Role and How to Choose One for Your CMMC Certification - Secureframe, accessed April 10, 2025, <a target="_blank" href="https://secureframe.com/hub/cmmc/c3pao">https://secureframe.com/hub/cmmc/c3pao</a></p><p>* What Is a CMMC C3PAO and What Do They Do? - ISI Enterprises, accessed April 10, 2025, <a target="_blank" href="https://isidefense.com/blog/what-is-a-cmmc-c3pao-and-what-do-they-do">https://isidefense.com/blog/what-is-a-cmmc-c3pao-and-what-do-they-do</a></p><p>* CMMC Self-Assessed vs C3PAO Certified MSP - Corporate Information Technologies, accessed April 10, 2025, <a target="_blank" href="https://www.corp-infotech.com/blog/cmmc-self-assessed-vs-c3pao-certified-msp">https://www.corp-infotech.com/blog/cmmc-self-assessed-vs-c3pao-certified-msp</a></p><p>* CMMC Certified Third-Party Assessment Organization (C3PAOs) List - Secureframe, accessed April 10, 2025, <a target="_blank" href="https://secureframe.com/hub/cmmc/c3pao-list">https://secureframe.com/hub/cmmc/c3pao-list</a></p><p>* Digital Beachhead - Cybersecurity - C3PAO -vCISO - CMMC - Small Business, accessed April 10, 2025, https://digitalbeachhead.com/</p><p>* C3PAO Services - Kratos Defense, accessed April 10, 2025, <a target="_blank" href="https://www.kratosdefense.com/about/divisions/space-training-and-cybersecurity/cyber/c3pao-services">https://www.kratosdefense.com/about/divisions/space-training-and-cybersecurity/cyber/c3pao-services</a></p><p>* CMMC consulting services for small and medium-sized businesses - E-N Computers, accessed April 10, 2025, <a target="_blank" href="https://www.encomputers.com/cmmc-consulting-services-for-small-businesses/">https://www.encomputers.com/cmmc-consulting-services-for-small-businesses/</a></p><p>* SOCSoter becomes a Third-Party Accessor Organization (C3PAO) Candidate - SMB Nation, accessed April 10, 2025, <a target="_blank" href="https://www.smbnation.com/community-content/3916-socsoter-becomes-a-third-party-accessor-organization-c3pao-candidate">https://www.smbnation.com/community-content/3916-socsoter-becomes-a-third-party-accessor-organization-c3pao-candidate</a></p><p>* Cost of Compliance | CMMC and NIST 171 - Hyper Vigilance, accessed April 10, 2025, <a target="_blank" href="https://blog.hypervigilance.com/cost-of-cmmc-nist-compliance">https://blog.hypervigilance.com/cost-of-cmmc-nist-compliance</a></p><p>* How to Manage Costs for CMMC Level 2 Compliance - Axiom, accessed April 10, 2025, <a target="_blank" href="https://www.axiom.tech/how-to-manage-costs-for-cmmc-2-compliance/">https://www.axiom.tech/how-to-manage-costs-for-cmmc-2-compliance/</a></p><p>* 2 strategies to reduce your CMMC compliance costs - StreamScan, accessed April 10, 2025, <a target="_blank" href="https://streamscan.ai/en/blog/2strategies-reduction-couts-cmmc-fr/">https://streamscan.ai/en/blog/2strategies-reduction-couts-cmmc-fr/</a></p><p>* Cybersecurity Maturity Model Certification (CMMC) Compliance Guide - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/cmmc-compliance/">https://sprinto.com/blog/cmmc-compliance/</a></p><p>* Govt Should be Stroking Checks for SMBs Doing CMMC - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/CMMC/comments/1gvt4xh/govt_should_be_stroking_checks_for_smbs_doing_cmmc/">https://www.reddit.com/r/CMMC/comments/1gvt4xh/govt_should_be_stroking_checks_for_smbs_doing_cmmc/</a></p><p>* Case Study: Defense contractor achieves 110/110 score in NIST SP 800-171 DoD audit | PreVeil, accessed April 10, 2025, <a target="_blank" href="https://www.preveil.com/wp-content/uploads/2023/09/PreVeil-Case-Study-110-Score.pdf">https://www.preveil.com/wp-content/uploads/2023/09/PreVeil-Case-Study-110-Score.pdf</a></p><p>* 3 Reasons Why You Should Probably Focus on NIST SP 800-171, Not CMMC, accessed April 10, 2025, <a target="_blank" href="https://www.pivotpointsecurity.com/3-reasons-why-you-should-probably-focus-on-nist-sp-800-171-not-cmmc/">https://www.pivotpointsecurity.com/3-reasons-why-you-should-probably-focus-on-nist-sp-800-171-not-cmmc/</a></p><p>* www.brightdefense.com, accessed April 10, 2025, <a target="_blank" href="https://www.brightdefense.com/resources/nist-800-171-compliance-for-small-business/#:~:text=To%20achieve%20compliance%2C%20you&#39;ll,NIST%20800%2D171%20requirements%20effectively.">https://www.brightdefense.com/resources/nist-800-171-compliance-for-small-business/#:~:text=To%20achieve%20compliance%2C%20you'll,NIST%20800%2D171%20requirements%20effectively.</a></p><p>* Understanding NIST 800-171 Requirements for Small Businesses - KNC Strategic Services, accessed April 10, 2025, <a target="_blank" href="https://www.kncss.com/blog/understanding-requirements-for-small-businesses">https://www.kncss.com/blog/understanding-requirements-for-small-businesses</a></p><p>* NIST 800-171 Compliance Checklist - Cuick Trac, accessed April 10, 2025, <a target="_blank" href="https://www.cuicktrac.com/nist-compliance/nist-800-171-compliance-checklist/">https://www.cuicktrac.com/nist-compliance/nist-800-171-compliance-checklist/</a></p><p>* NIST'S 800-171 AS A CYBERSECURITY SYSTEM FOR SMB'S - Innovative Manufacturers Center, accessed April 10, 2025, <a target="_blank" href="https://imcpa.com/wp-content/uploads/2018/05/Zane-Patalive-800-171.pdf">https://imcpa.com/wp-content/uploads/2018/05/Zane-Patalive-800-171.pdf</a></p><p>* Securing the defense supply chain: Critical insights on CMMC 2.0 preparedness, accessed April 10, 2025, <a target="_blank" href="https://www.scmr.com/article/securing-the-defense-supply-chain-critical-insights-on-cmmc-2.0-preparedness/software-technology">https://www.scmr.com/article/securing-the-defense-supply-chain-critical-insights-on-cmmc-2.0-preparedness/software-technology</a></p><p>* NIST 800-171 Compliance: How Much Does NIST Certification Cost? - Kelser Corporation, accessed April 10, 2025, <a target="_blank" href="https://www.kelsercorp.com/blog/nist-800-171-compliance-certification-cost">https://www.kelsercorp.com/blog/nist-800-171-compliance-certification-cost</a></p><p>* Five Compliance Challenges Clients Face When Implementing NIST 800-171, accessed April 10, 2025, <a target="_blank" href="https://www.wiley.law/newsletter-Five-Compliance-Challenges-Clients-Face-When-Implementing-NIST-800-171">https://www.wiley.law/newsletter-Five-Compliance-Challenges-Clients-Face-When-Implementing-NIST-800-171</a></p><p>* 800-171 Implementation Guide: Requirements, Controls, Implementation - Cuick Trac, accessed April 10, 2025, <a target="_blank" href="https://www.cuicktrac.com/nist-compliance/800-171-implementation-guide/">https://www.cuicktrac.com/nist-compliance/800-171-implementation-guide/</a></p><p>* Where to begin with NIST SP 800-171 Implementation - SAF/CN, accessed April 10, 2025, <a target="_blank" href="https://www.safcn.af.mil/Portals/64/Documents/Small%20Business%20Innovation%20Research%20(SBIR)/Resources/BC%2010%20-%20Where%20to%20Begin%20with%20NIST%20SP%20800-171%20Implementation%20Cleared%20for%20Public%20Release%20AFRL-2021-3219%2022%20Sep%202021.pdf?ver=i1y9v3ffIEIWbOfZwQK8vw%3D%3D">https://www.safcn.af.mil/Portals/64/Documents/Small%20Business%20Innovation%20Research%20(SBIR)/Resources/BC%2010%20-%20Where%20to%20Begin%20with%20NIST%20SP%20800-171%20Implementation%20Cleared%20for%20Public%20Release%20AFRL-2021-3219%2022%20Sep%202021.pdf?ver=i1y9v3ffIEIWbOfZwQK8vw%3D%3D</a></p><p>* NIST 800-171 Implementation Guide for Small-Medium Sized Businesses | RSI Security, accessed April 10, 2025, <a target="_blank" href="https://blog.rsisecurity.com/nist-800-171-implementation-guide-for-small-medium-sized-businesses/">https://blog.rsisecurity.com/nist-800-171-implementation-guide-for-small-medium-sized-businesses/</a></p><p>* What is NIST Compliance? (The Ultimate Guide) - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/nist-compliance/">https://sprinto.com/blog/nist-compliance/</a></p><p>* NIST Compliance - Check Point Software, accessed April 10, 2025, <a target="_blank" href="https://www.checkpoint.com/cyber-hub/cyber-security/nist-compliance/">https://www.checkpoint.com/cyber-hub/cyber-security/nist-compliance/</a></p><p>* Guide to NIST Compliance - IS Partners, LLC, accessed April 10, 2025, <a target="_blank" href="https://www.ispartnersllc.com/blog/nist-compliance/">https://www.ispartnersllc.com/blog/nist-compliance/</a></p><p>* Very Small Business Becoming NIST SP 800-171 Compliant : r/NISTControls - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/NISTControls/comments/yl7e77/very_small_business_becoming_nist_sp_800171/">https://www.reddit.com/r/NISTControls/comments/yl7e77/very_small_business_becoming_nist_sp_800171/</a></p><p>* Navigate NIST 800-171 with Confidence, accessed April 10, 2025, </p><p>https://nist171.fortifiedservices.com/</p><p>* Top Six Challenges with DFARS and NIST 800-171 Compliance | True Digital Security, accessed April 10, 2025, <a target="_blank" href="https://truedigitalsecurity.com/blog/top-six-challenges-with-dfars-and-nist-800-171-compliance">https://truedigitalsecurity.com/blog/top-six-challenges-with-dfars-and-nist-800-171-compliance</a></p><p>* What have been your biggest challenges/pain points trying to comply with CMMC? - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/CMMC/comments/1e755tn/what_have_been_your_biggest_challengespain_points/">https://www.reddit.com/r/CMMC/comments/1e755tn/what_have_been_your_biggest_challengespain_points/</a></p><p>* Estimated Costs Associated with NIST 800-53 and NIST 800-171 Security Risk Assessments, accessed April 10, 2025, <a target="_blank" href="https://www.goldskysecurity.com/estimated-costs-associated-with-nist-800-53-and-nist-800-171-security-risk-assessments/">https://www.goldskysecurity.com/estimated-costs-associated-with-nist-800-53-and-nist-800-171-security-risk-assessments/</a></p><p>* Estimating the Cost of NIST SP 800-171 - YouTube, accessed April 10, 2025,  </p><p>* DoD Cybersecurity, DFARS, and NIST SP 800-171 Compliance, accessed April 10, 2025, <a target="_blank" href="https://compliancy-group.com/dod-cybersecurity-dfars-and-nist-sp-800-171-compliance/">https://compliancy-group.com/dod-cybersecurity-dfars-and-nist-sp-800-171-compliance/</a></p><p>* What Contractors Risk by Not Being NIST 800-171 Compliant - Peerless Tech Solutions, accessed April 10, 2025, <a target="_blank" href="https://www.getpeerless.com/blog/what-contractors-risk-by-not-being-nist-800-171-compliant">https://www.getpeerless.com/blog/what-contractors-risk-by-not-being-nist-800-171-compliant</a></p><p>* Top 5 Risks Of Non-Compliance With NIST SP 800-171, accessed April 10, 2025, <a target="_blank" href="https://nist800171compliance.com/top-5-risks-of-non-compliance-with-nist-sp-800-171/">https://nist800171compliance.com/top-5-risks-of-non-compliance-with-nist-sp-800-171/</a></p><p>* What Are the Consequences of Noncompliance? - The Charles IT Blog, accessed April 10, 2025, <a target="_blank" href="https://blog.charlesit.com/what-are-the-consequences-of-noncompliance">https://blog.charlesit.com/what-are-the-consequences-of-noncompliance</a></p><p>* Securing DoD Contracts: A Case Study in NIST SP 800-171 Compliance - Cleared Systems, accessed April 10, 2025, <a target="_blank" href="https://clearedsystems.com/nist-sp-800-171-compliance-success-story/">https://clearedsystems.com/nist-sp-800-171-compliance-success-story/</a></p><p>* Is Your SMB Concerned About Cybersecurity? - Corporate Information Technologies, accessed April 10, 2025, <a target="_blank" href="https://www.corp-infotech.com/blog/smb-concerned-about-cybersecurity">https://www.corp-infotech.com/blog/smb-concerned-about-cybersecurity</a></p><p>* NIST 800-171 Compliance: The Secret to Small Business Success! - YouTube, accessed April 10, 2025, </p><p>* Microsoft Purview Compliance Manager regulations list, accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/purview/compliance-manager-regulations-list">https://learn.microsoft.com/en-us/purview/compliance-manager-regulations-list</a></p><p>* How to Maintain NIST 800-171 Compliance in Microsoft 365 - Agile IT, accessed April 10, 2025, <a target="_blank" href="https://agileit.com/news/maintain-nist-800-171-compliance-microsoft-365/">https://agileit.com/news/maintain-nist-800-171-compliance-microsoft-365/</a></p><p>* National Institute of Standards and Technology (NIST) SP 800-171 - Azure Compliance, accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-nist-800-171">https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-nist-800-171</a></p><p>* Regulatory Compliance details for NIST SP 800-171 R2 - Azure Policy | Microsoft Learn, accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/azure/governance/policy/samples/nist-sp-800-171-r2">https://learn.microsoft.com/en-us/azure/governance/policy/samples/nist-sp-800-171-r2</a></p><p>* NIST SP 800-171 - Microsoft Compliance, accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/compliance/regulatory/offering-nist-sp-800-171">https://learn.microsoft.com/en-us/compliance/regulatory/offering-nist-sp-800-171</a></p><p>* Regulatory Compliance details for NIST SP 800-171 R2 (Azure Government), accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/azure/governance/policy/samples/gov-nist-sp-800-171-r2">https://learn.microsoft.com/en-us/azure/governance/policy/samples/gov-nist-sp-800-171-r2</a></p><p>* Put CUI Spillage in the Rearview with Microsoft Purview Information Protection (MPIP), accessed April 10, 2025, <a target="_blank" href="https://www.summit7.us/blog/microsoft-purview-information-protection">https://www.summit7.us/blog/microsoft-purview-information-protection</a></p><p>* Identifying CUI with Microsoft 365 For CMMC - Summit 7, accessed April 10, 2025, <a target="_blank" href="https://www.summit7.us/blog/identifying-cui-with-microsoft-365-for-cmmc">https://www.summit7.us/blog/identifying-cui-with-microsoft-365-for-cmmc</a></p><p>* Configure cloud settings for use with Compliance Manager - Learn Microsoft, accessed April 10, 2025, <a target="_blank" href="https://learn.microsoft.com/en-us/purview/compliance-manager-cloud-settings">https://learn.microsoft.com/en-us/purview/compliance-manager-cloud-settings</a></p><p>* Microsoft Office 365 NIST 800 171 Compliance: Top 5 Essential Steps, accessed April 10, 2025, <a target="_blank" href="https://ettebiz.com/microsoft-office-365-nist-800-171-compliance/">https://ettebiz.com/microsoft-office-365-nist-800-171-compliance/</a></p><p>* Solution Overview: NIST SP 800-171 | Tenable®, accessed April 10, 2025, <a target="_blank" href="https://www.tenable.com/solution-briefs/nist-sp-800-171">https://www.tenable.com/solution-briefs/nist-sp-800-171</a></p><p>* Compliance Frameworks - Tenable documentation, accessed April 10, 2025, <a target="_blank" href="https://docs.tenable.com/cyber-exposure-studies/host-audit-data/Content/compliance-frameworks.htm">https://docs.tenable.com/cyber-exposure-studies/host-audit-data/Content/compliance-frameworks.htm</a></p><p>* 800-171 Audit Summary (Explore) - Tenable.io Dashboard, accessed April 10, 2025, <a target="_blank" href="https://www.tenable.com/vulnerability-management-dashboards/800-171-audit-summary-explore">https://www.tenable.com/vulnerability-management-dashboards/800-171-audit-summary-explore</a></p><p>* NIST SP 800-171 | Tenable®, accessed April 10, 2025, <a target="_blank" href="https://pt-br.tenable.com/solutions/nist-sp-800-171">https://pt-br.tenable.com/solutions/nist-sp-800-171</a></p><p>* NIST SP 800-171 | Tenable®, accessed April 10, 2025, <a target="_blank" href="https://www.tenable.com/solutions/nist-sp-800-171">https://www.tenable.com/solutions/nist-sp-800-171</a></p><p>* Tenable.sc Support for NIST SP 800-171 - White Paper, accessed April 10, 2025, <a target="_blank" href="https://ar.tenable.com/whitepapers/tenable-sc-support-for-nist-sp-800-171">https://ar.tenable.com/whitepapers/tenable-sc-support-for-nist-sp-800-171</a></p><p>* NIST 800-171 based assessment using Nessus professional - Login, accessed April 10, 2025, <a target="_blank" href="https://tenable.my.site.com/s/question/0D53a00006dfgr8CAA/nist-800171-based-assessment-using-nessus-professional?language=en_US">https://tenable.my.site.com/s/question/0D53a00006dfgr8CAA/nist-800171-based-assessment-using-nessus-professional?language=en_US</a></p><p>* Apps that help with NIST SP 800-171 & CMMC : r/NISTControls - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/NISTControls/comments/epx0ud/apps_that_help_with_nist_sp_800171_cmmc/">https://www.reddit.com/r/NISTControls/comments/epx0ud/apps_that_help_with_nist_sp_800171_cmmc/</a></p><p>* How do I set up Policy Compliance Auditing for NIST compliance? - Tenable Community, accessed April 10, 2025, <a target="_blank" href="https://community.tenable.com/s/question/0D53a00007sQ2BBCA0/how-do-i-set-up-policy-compliance-auditing-for-nist-compliance?language=en_US">https://community.tenable.com/s/question/0D53a00007sQ2BBCA0/how-do-i-set-up-policy-compliance-auditing-for-nist-compliance?language=en_US</a></p><p>* Nessus professional compliance scan reports filtered using NIST SP 800-171 reference, accessed April 10, 2025, <a target="_blank" href="https://tenable.my.site.com/s/question/0D53a00006g8hxmCAA/nessus-professional-compliance-scan-reports-filtered-using-nist-sp-800171-reference?language=en_US">https://tenable.my.site.com/s/question/0D53a00006g8hxmCAA/nessus-professional-compliance-scan-reports-filtered-using-nist-sp-800171-reference?language=en_US</a></p><p>* NIST 800-171 Controlled Unclassified Information Course from Cybrary | NICCS, accessed April 10, 2025, <a target="_blank" href="https://niccs.cisa.gov/education-training/catalog/cybrary/nist-800-171-controlled-unclassified-information-course">https://niccs.cisa.gov/education-training/catalog/cybrary/nist-800-171-controlled-unclassified-information-course</a></p><p>* SP 800-171A Rev. 3, Assessing Security Requirements for Controlled Unclassified Information | CSRC, accessed April 10, 2025, <a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/171/a/r3/final">https://csrc.nist.gov/pubs/sp/800/171/a/r3/final</a></p><p>* Chief Information Officer > CMMC - DoD CIO - Department of Defense, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/CMMC/">https://dodcio.defense.gov/CMMC/</a></p><p>* CMMC Resources & Documentation - DoD CIO - Department of Defense, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/cmmc/Resources-Documentation/">https://dodcio.defense.gov/cmmc/Resources-Documentation/</a></p><p>* Contact CMMC - DoD CIO - Department of Defense, accessed April 10, 2025, <a target="_blank" href="https://dodcio.defense.gov/cmmc/Contact/">https://dodcio.defense.gov/cmmc/Contact/</a></p><p>* NIST 800-171 - National Defense Industrial Association, accessed April 10, 2025, <a target="_blank" href="https://www.ndia.org/-/media/sites/ndia/divisions/archive/nist-800-171-realities-of-the-market2.pptx">https://www.ndia.org/-/media/sites/ndia/divisions/archive/nist-800-171-realities-of-the-market2.pptx</a></p><p>* Guidance for a small business doing a NIST SP 800-171 self-assessment - Reddit, accessed April 10, 2025, <a target="_blank" href="https://www.reddit.com/r/NISTControls/comments/nhctno/guidance_for_a_small_business_doing_a_nist_sp/">https://www.reddit.com/r/NISTControls/comments/nhctno/guidance_for_a_small_business_doing_a_nist_sp/</a></p><p>* IT Cost Optimization for SMB & Mid-Size Businesses - Secur-Serv, accessed April 10, 2025, <a target="_blank" href="https://secur-serv.com/it-cost-optimization/">https://secur-serv.com/it-cost-optimization/</a></p><p>* Changing Attitudes to Cybersecurity in the SMB Segment - CYRISMA, accessed April 10, 2025, <a target="_blank" href="https://cyrisma.com/smb-cybersecurity/">https://cyrisma.com/smb-cybersecurity/</a></p><p>* Where to Focus Your Cybersecurity Budget for Maximum Protection - Sprinto, accessed April 10, 2025, <a target="_blank" href="https://sprinto.com/blog/cybersecurity-budget-optimization/">https://sprinto.com/blog/cybersecurity-budget-optimization/</a></p><p>* Simple, Cost-Effective Ways for SMBs to Achieve Compliance - Access Point Consulting, accessed April 10, 2025, <a target="_blank" href="https://www.accesspointconsulting.com/resources/simple-cost-effective-ways-for-smbs-to-achieve-compliance">https://www.accesspointconsulting.com/resources/simple-cost-effective-ways-for-smbs-to-achieve-compliance</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-nist-800-171-compliance</link><guid isPermaLink="false">substack:post:161029093</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 10 Apr 2025 18:41:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/161029093/c6ba25138aaea3571745a1d5a3e7255c.mp3" length="5888880" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>491</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/161029093/0df6d3686c14f2cac8d84078cfe8f8ea.jpg"/></item><item><title><![CDATA[Combating Security Platform Fatigue: A Strategic Approach to Tool Consolidation]]></title><description><![CDATA[<p>Discover how to combat security platform fatigue by strategically consolidating tools around your primary security provider while filling gaps with specialized solutions. Learn practical approaches to reduce complexity, improve visibility, and enhance your security posture without overwhelming your team.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/combating-security-platform-fatigue</link><guid isPermaLink="false">substack:post:160785786</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 07 Apr 2025 15:15:57 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/160785786/1eab1e84c8f67eeb839df9bebe734337.mp3" length="9870569" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>823</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/160785786/fb91614527dc3b41b0bf32946ce22d43.jpg"/></item><item><title><![CDATA[Safely Implementing AI for SMBs]]></title><description><![CDATA[<p>Discover how SMBs can boost productivity by safely using AI in areas like customer service, marketing, inventory, and cybersecurity.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/safely-implementing-ai-for-smb</link><guid isPermaLink="false">substack:post:159514593</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 21 Mar 2025 13:15:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/159514593/78a7377ccb3fa4e79d5df6817eeae918.mp3" length="11088084" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>924</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/159514593/a80f1fcf2d8f142230d394c3fe47425c.jpg"/></item><item><title><![CDATA[Implementing Zero Trust Security for Small and Medium Businesses with Microsoft Solutions]]></title><description><![CDATA[<p>Learn how small and medium businesses can enhance their cybersecurity with a Zero Trust strategy using Microsoft solutions. Discover practical steps to protect your business from evolving threats</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/implementing-zero-trust-security</link><guid isPermaLink="false">substack:post:159072666</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 14 Mar 2025 17:03:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/159072666/a00cab115cbaf1c5591c70e1d0e78724.mp3" length="8825148" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>735</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/159072666/c67805b4b02573635c6c366711d276f4.jpg"/></item><item><title><![CDATA[Proposed 2025 HIPAA Security Rule Changes & SMB Implications]]></title><description><![CDATA[<p></p><p>The 2024 HIPAA Security Rule amendments represent a significant overhaul, demanding strategic realignment of governance, risk management, and compliance (GRC) programs, particularly for SMBs. The proposed rule changes have an open commentary period, which ends on March 7th, 2025. To leave comments, go here: <a target="_blank" href="https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information">https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information</a> </p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>The elimination of the "addressable" implementation specifications, expanded technical safeguards, and compressed implementation timelines create compliance obligations and opportunities for strengthening organizational resilience. To navigate these changes successfully, SMBs must prioritize a phased approach, leveraging cost-optimization strategies and cultural change initiatives. The key is to transform compliance from a burden into a strategic advantage. Failing to adapt puts SMBs at considerable risk, as demonstrated by the statistic that "60% [of SMBs] fail within six months of a breach."</p><p><strong>1. Core Changes to the HIPAA Security Framework:</strong></p><p>* <strong>Elimination of "Addressable" Implementation Specifications:</strong> The removal of the distinction between "required" and "addressable" safeguards is a fundamental shift. The revised rule "mandates implementation of all security controls unless specific documented exceptions apply." This directly addresses the previous tendency of SMBs to treat these standards as optional. Specific examples now mandated include:</p><p>* <strong>Multi-Factor Authentication (MFA):</strong> "Now required for all system access points handling ePHI, replacing previous conditional implementations."</p><p>* <strong>Encryption:</strong> "Mandatory for ePHI both at rest and in transit, closing previous loopholes for internal network communications."</p><p>* <strong>Network Segmentation:</strong> "Requires documented segmentation strategies preventing lateral movement during breaches."</p><p>* <strong>Expanded Technical Safeguards:</strong> The updated Technical Safeguards (45 CFR §164.312) introduce 14 new implementation specifications aligning with NIST Cybersecurity Framework standards. This expansion creates "technical debt requiring immediate prioritization" for SMBs. Examples of the added or emphasized safeguards include:</p><p>* Maintaining comprehensive technology inventories updated quarterly.</p><p>* Developing network topology maps tracking ePHI flow across systems.</p><p>* Implementing session timeout policies for inactive systems.</p><p>* Extending workstation security controls to mobile devices.</p><p>* Automated patch management within 30 days of release.</p><p>* Removal of unnecessary software from ePHI systems.</p><p></p><p><strong>2. GRC Program Transformations:</strong></p><p>* <strong>Integrated Risk Management Frameworks:</strong> The updates mandate alignment between HIPAA compliance and enterprise risk management programs. Key integration points include:</p><p>* Unified risk register (mapping HIPAA vulnerabilities to corporate risk appetite).</p><p>* Annual security validation for all business associates.</p><p>* Contractual requirements for 24-hour breach notifications.</p><p>* Executive reporting (monthly dashboards and board-level briefings).</p><p>* <strong>Compliance Lifecycle Acceleration:</strong> Implementation timelines are being compressed, requiring more agile compliance processes:</p><p>* Previous Cycle: </p><p>* Risk analysis - Biannual</p><p>* Security training - Annual</p><p>* Policy updates - Event-driven</p><p>* 2024 Proposed Rule changes: </p><p>* Risk analysis - Continuous monitoring + annual formal review</p><p>* Security training - Quarterly + post-incident refreshers</p><p>*  Policy updates - Annual review + change-triggered updates </p><p></p><p><strong>3. Technical Implementation Roadmap:</strong></p><p>* <strong>Phased Control Deployment:</strong> For resource-constrained organizations, a phased approach is recommended:</p><p>* <strong>Phase 1 (0-6 months):</strong> Gap analysis, MFA implementation, enterprise encryption.</p><p>* <strong>Phase 2 (6-12 months):</strong> Asset inventory, penetration testing, and network segmentation.</p><p>* <strong>Phase 3 (12-18 months):</strong> GRC platform integration, automated vendor risk assessments, continuous monitoring.</p><p>* <strong>Cost Optimization Strategies:</strong></p><p>* <strong>Leverage compliance-as-a-service:</strong> MSP partnerships, cloud-based encryption.</p><p>* <strong>Automate documentation:</strong> Tools generating audit-ready reports and AI-assisted policy creation.</p><p>* <strong>Pool resources:</strong> Join healthcare ISACs and collaborate on training.</p><p><strong>4. Operationalizing Cultural Change:</strong></p><p>* <strong>Leadership Engagement Tactics:</strong> Map HIPAA requirements to business outcomes (e.g., reduced insurance premiums) and implement cross-functional governance committees.</p><p>* <strong>Staff Enablement Programs:</strong> Role-based compliance dashboards, gamified training, and recognition programs for control improvement suggestions.</p><p><strong>5. Anticipating Future Regulatory Trends:</strong></p><p>* <strong>Emerging Requirements:</strong> Anticipate requirements related to AI governance, Software Bill of Materials (SBOM) adoption, and Zero Trust architecture.</p><p>* <strong>Strategic Preparation Steps:</strong> Conduct tabletop exercises, allocate a budget for adaptive controls, and build partnerships with academic cybersecurity programs.</p><p></p><p>"The 2024 HIPAA changes present SMB cybersecurity leaders with challenges and strategic opportunities." By modernizing GRC programs, SMBs can "reduce breach risks," "improve operational efficiency," and "enhance market position." The immediate next steps include conducting a formal gap assessment, briefing executives, and exploring managed security services. For SMBs that successfully navigate this transition, the HIPAA updates offer a pathway to building cyber resilience that supports compliance and business growth.</p><p><strong>Key Statistics & Concerns Highlighted:</strong></p><p>* 747 large breaches exposing 168 million records in 2023</p><p>* 43% of SMBs historically treated "addressable" specifications as optional</p><p>* 60% of healthcare organizations targeted by ransomware</p><p>* 34% of breaches originate through business associates</p><p>* $1.85M average breach cost threatening SMB viability</p><p>* 49% of healthcare data breaches involving unencrypted devices</p><p>* 58% of breaches stem from human error</p><p>* 82% of healthcare employees targeted by social engineering</p><p>* 73% of surveyed providers expect mandatory zero trust architectures by 2026</p><p>* SMBs investing in HIPAA modernization achieve 34% faster audit cycles and 27% lower cyber insurance premiums</p><p><strong>Recommendations:</strong></p><p>* Prioritize gap assessments against the updated requirements.</p><p>* Secure executive-level buy-in and resource allocation.</p><p>* Explore managed security services and compliance-as-a-service solutions.</p><p>* Invest in staff training and awareness programs.</p><p>* Begin planning for future regulatory trends like AI governance and Zero Trust architectures.</p><p></p><p><p>Thank you for taking the time to read the SMB Tech & Cybersecurity Leadership Newsletter! I truly hope you found it valuable. If you did, I’d be grateful if you could share it with others who might also benefit from it!</p></p><p><a target="_blank" href="https://omnistruct.com/partners/influencers-meet-omnistruct/">Product Shoutout: Omnistruct</a></p><p><em>Expert Governance Team + GRC Platform = Your Outsourced Risk Management Leadership</em></p><p><strong>ELEVATE YOUR CYBERSECURITY WITH OMNISTRUCT’S PROVEN SERVICES.</strong></p><p>Achieve superior data and privacy security at a fraction of the cost of building an in-house team. We can fast-track compliance, reduce risks, and help you focus on what you do best.</p><p><strong>Learn more here:</strong> https://omnistruct.com/partners/influencers-meet-omnistruct/</p><p></p><p></p><p>References and resources:</p><p>https://www.hipaajournal.com/new-hipaa-regulations/</p><p>https://www.business-reporter.co.uk/management/the-future-of-grc-how-small-businesses-are-fighting-the-rise-of-cyber-crime</p><p>https://www.hipaajournal.com/hipaa-updates-hipaa-changes/</p><p>https://www.hipaajournal.com/hhs-strengthened-hipaa-security-rule/</p><p>https://www.tenfold-security.com/en/hipaa-security-rule-update/</p><p>https://hyperproof.io/resource/proposed-new-hipaa-rules-2025/</p><p>https://360advanced.com/hipaa-compliance-tips-for-small-to-mid-sized-business-smb-healthcare-providers/</p><p>https://greeneis.com/what-is-grc-in-cyber-security-comprehensive-guide/</p><p>https://www.kirkland.com/publications/kirkland-alert/2025/01/proposed-changes-to-the-hipaa-security-rule</p><p>https://www.techtarget.com/healthtechsecurity/feature/Things-to-know-about-proposed-HIPAA-Security-Rule-updates</p><p>https://www.elisity.com/blog/hipaa-security-rule-changes-2025-new-network-segmentation-requirements-and-implementation-guidelines</p><p>https://right-hand.ai/blog/grc-cyber-security/</p><p>https://www.morganfranklin.com/insights/hipaas-new-era-navigating-the-regulatory-changes-to-strengthen-cyber-risk-tprm-privacy-and-grc/</p><p>https://www.sheppardhealthlaw.com/2025/01/articles/hipaa/hhs-last-minute-holiday-gift-proposed-changes-to-the-hipaa-security-rule/</p><p>https://info.docxellent.com/blog/hippa-updates-and-changes</p><p>https://www.triagehealthlawblog.com/hipaa/hhs-publishes-notice-of-proposed-rulemaking-to-amend-hipaa-security-rule-requirements-comments-due-march-7-2025/</p><p>https://www.hklaw.com/en/insights/publications/2024/12/big-changes-proposed-for-the-hipaa-security-rule</p><p>https://www.cov.com/en/news-and-insights/insights/2025/01/hhs-issues-notice-of-proposed-rulemaking-to-update-the-hipaa-security-rule</p><p>https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html</p><p>https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html</p><p>https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information</p><p>https://www.hipaaguide.net/new-hipaa-regulations/</p><p>https://www.foley.com/insights/publications/2025/01/hhs-proposes-changes-strengthen-hipaa-security-rule/</p><p>https://hallboothsmith.com/hipaa-privacy-rule-changes-2024/</p><p>https://www.nixonpeabody.com/insights/alerts/2024/12/31/ocr-announces-proposed-updates-to-hipaa-security-rule</p><p>https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy</p><p>https://www.hipaaguide.net/recent-hipaa-changes/</p><p>https://www.paubox.com/blog/upcoming-2024-hipaa-updates-and-changes</p><p>https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202310\&RIN=0945-AA22</p><p>https://deandorton.com/2024-hipaa-regulations-update/</p><p>https://www.maynardnexsen.com/publication-hipaa-reproductive-health-care-phi-rules-compliance-date-approaching</p><p>https://www.healthcarelawinsights.com/2025/01/ocr-announces-proposed-updates-to-hipaa-security-rule-raises-the-bar-for-healthcare-cybersecurity/</p><p>https://www.barradvisory.com/resource/2024-year-in-review/</p><p>https://www.onetrust.com/blog/10-grc-trends/</p><p>https://www.navex.com/en-us/blog/article/the-state-of-cybersecurity-for-small-and-medium-businesses/</p><p>https://blog.procircular.com/how-the-new-hipaa-security-rule-changes-will-affect-healthcare</p><p>https://www.brightdefense.com/resources/cybersecurity-compliance-statistics/</p><p>https://www.barradvisory.com/resource/hipaa-security-rule-changing/</p><p>https://blog.rsisecurity.com/understanding-hipaa-violations-and-their-consequences/</p><p>https://www.frazierdeeter.com/insights/article/understanding-the-proposed-changes-to-hipaas-security-rule/</p><p>https://www.brightdefense.com/resources/hipaa-compliance-for-startups/</p><p>https://hallboothsmith.com/hipaa-2024-and-beyond/</p><p>https://www.sai360.com/resources/grc/hipaa-cybersecurity-updates-coming-soon-8-things-to-know-blog</p><p>https://www.cybernetman.com/blog/hipaa-compliant-technology-the-ultimate-guide/</p><p>https://www.compliancemanagergrc.com/blog/</p><p>https://blog.cspire.com/outsourced-it-can-improve-hipaa-compliance.-heres-how</p><p>https://clearwatersecurity.com/blog/ocrs-proposed-hipaa-security-rule-notice-of-proposed-rulemaking/</p><p>https://thoropass.com/blog/compliance/hipaa-requirements-healthcare-smb/</p><p>https://sprinto.com/blog/hipaa-security-rule-update/</p><p>https://www.brightdefense.com/resources/what-is-grc-in-cybersecurity-2/</p><p>https://www.fepbl.com/index.php/csitrj/article/view/1277/1509</p><p>https://www.metricstream.com/insights/utilizing-HIPAA-as-the-starting-point-for-comprehensive-cyber-risk-and-compliance.html</p><p>https://www.healthcarecompliancepros.com/blog/top-5-hipaa-challenges-for-small-health-practices</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/proposed-2025-hipaa-security-rule</link><guid isPermaLink="false">substack:post:157221022</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 20 Feb 2025 15:55:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/157221022/d8bb1514d38b2187778c893f95c691a6.mp3" length="16421138" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1368</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/157221022/7332f82197e6f34d68c9078270dc6408.jpg"/></item><item><title><![CDATA[The Importance of Data Security Posture Management for SMB Leaders]]></title><description><![CDATA[<p>Embracing the Importance of Data Security Posture Management (DSPM) for SMB Tech, Cyber, and Business Leaders</p><p></p><p>In today’s digital-first world, data is the lifeblood of every organization, including small and medium-sized businesses (SMBs). However, with the increasing adoption of cloud services, artificial intelligence (AI), and remote work environments, managing data security has become more complex. Data Security Posture Management (DSPM) is emerging as a critical solution for modern businesses to protect sensitive information, ensure compliance, and mitigate risks.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p></p><p><strong>Why DSPM Matters for SMBs</strong></p><p>DSPM is essential for SMBs because it provides comprehensive visibility into where sensitive data resides, whether on-premises, in the cloud, or across SaaS platforms. This level of insight is particularly valuable for smaller organizations that often face challenges with shadow IT and data sprawl. By understanding where their data lives, SMBs can better manage it and reduce risks associated with unknown or unprotected assets.</p><p>Another critical benefit of DSPM is its ability to identify and mitigate risks proactively. It continuously monitors data access and usage patterns to detect vulnerabilities such as misconfigurations or over-permissive access controls. For SMBs operating with limited security resources, this proactive approach ensures that potential issues are addressed before they escalate into costly breaches.</p><p>DSPM also simplifies compliance efforts by mapping regulatory requirements to an organization’s data policies. For SMBs that must adhere to regulations like GDPR, HIPAA, or PCI DSS, DSPM automates many processes involved in audits and reporting. This reduces the burden on internal teams and ensures compliance gaps are identified and resolved efficiently.</p><p>From a financial perspective, DSPM offers cost efficiency by reducing the likelihood of data breaches. This provides an invaluable safeguard for SMBs that may struggle to recover from the economic and reputational damage caused by such incidents. Additionally, it enables secure collaboration by ensuring that sensitive data is only accessible to authorized users without disrupting workflows—an essential feature for businesses aiming to balance security with operational efficiency.</p><p></p><p><strong>Comparison of Leading DSPM Tools</strong></p><p>Here’s a summary of some notable DSPM tools, including Microsoft Purview and other competitors:</p><p>* <strong>Microsoft Purview</strong> is a strong choice for organizations already embedded in the Microsoft ecosystem. It integrates seamlessly with Microsoft 365 and Azure environments and offers advanced features like insider risk management and dynamic reporting. However, its effectiveness diminishes for businesses outside the Microsoft ecosystem or those using non-Azure platforms.</p><p>* <strong>Varonis DSPM</strong> excels in automated risk remediation and insider threat detection while supporting multi-cloud environments. Its robust capabilities make it a good fit for SMBs looking for a comprehensive solution. However, it less emphasizes cloud-native environments and may require hands-on setup expertise.</p><p>* <strong>CloudDefense.AI</strong> offers real-time monitoring and robust compliance automation features that are scalable for growing businesses. While its capabilities are impressive, initial setup can be challenging for teams without specialized knowledge, and new users may experience a steep learning curve.</p><p>* <strong>Prisma Cloud</strong> by Palo Alto Networks provides comprehensive support for cloud-native environments and includes prebuilt classifiers for identifying sensitive data. Despite its strengths, its high cost may be prohibitive for smaller organizations, and scanning performance can slow down in larger cloud systems.</p><p>* <strong>Securiti DSPM</strong> is particularly well-suited for compliance-heavy industries due to its extensive support of regulatory frameworks. However, its feature-rich platform can be overwhelming for smaller teams, and more effective improvements could be made in scanning unstructured data.</p><p><strong>How SMB Leaders Can Leverage DSPM</strong></p><p>To successfully implement DSPM, SMB leaders should begin by conducting thorough discovery processes to identify all sensitive data across their organization’s environments. This includes structured data like databases and unstructured data stored in SaaS applications or cloud platforms. Understanding where sensitive information resides is the foundation of any effective DSPM strategy.</p><p>Once discovery is complete, leveraging AI-driven classification capabilities to categorize data based on sensitivity levels, such as personally identifiable information (PII) or protected health information (PHI) is crucial. Automating this process minimizes human error while ensuring consistent application of security policies across all environments.</p><p>Continuous monitoring should also be prioritized to detect real-time unauthorized access or suspicious activity. This proactive approach allows SMBs to respond quickly to potential threats before they escalate into significant incidents. Simultaneously, organizations must focus on aligning their data policies with relevant regulations using DSPM tools that offer automated compliance checks. This ensures that regulatory requirements are met without burdening internal teams.</p><p>Integration with existing tools is another key consideration when adopting DSPM solutions. Choosing a tool that works seamlessly with an organization’s current cybersecurity stack—such as CSPM tools for infrastructure security—can enhance overall efficiency and effectiveness. Finally, educating employees about secure data practices and how DSPM supports business resilience is critical to fostering a culture of security awareness within the organization.</p><p></p><p></p><p><strong>Actionable Summary</strong></p><p>Implementing a robust DSPM strategy is no longer optional for SMB tech, cyber, and business leaders seeking to strengthen their cybersecurity posture—it’s essential. Organizations can gain critical visibility into their sensitive data while proactively mitigating risks by embracing DSPM solutions like Microsoft Purview or alternatives such as Varonis or CloudDefense.AI. Automation should be leveraged wherever possible to reduce manual workloads while ensuring compliance with evolving regulations.</p><p>Ultimately, SMBs must align their chosen DSPM solution with their business needs and industry requirements while prioritizing ease of integration with existing systems. Through careful planning and execution, DSPM can safeguard your most valuable asset—data—while enabling your business to thrive in an increasingly competitive digital landscape.</p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you gained value from this post, please share it with others. </p></p><p>Partner Shoutout: <a target="_blank" href="https://omnistruct.com/partners/influencers-meet-omnistruct/">Omnistruct</a></p><p>Expert Governance Team + GRC Platform =</p><p><strong>Your Outsourced Risk Management Leadership</strong></p><p><strong>ELEVATE YOUR CYBERSECURITY WITH OMNISTRUCT’S PROVEN SERVICES.</strong></p><p>Achieve top-notch data and privacy security for a fraction of the cost of creating an in-house team. We can expedite compliance, minimize risks, and enable you to concentrate on what you do best.</p><p></p><p><a target="_blank" href="https://omnistruct.com/partners/influencers-meet-omnistruct/">Find out more here</a></p><p></p><p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-importance-of-data-security-posture</link><guid isPermaLink="false">substack:post:156666185</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 07 Feb 2025 13:44:42 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/156666185/2653058c6fd39a539ed0fbf848850511.mp3" length="4422494" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>368</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/156666185/23c0143ac4b77b233d6ba243ad529bc1.jpg"/></item><item><title><![CDATA[The Future of Cybersecurity for SMBs: Trends to Watch]]></title><description><![CDATA[<p>The digital landscape is evolving rapidly, posing greater cybersecurity challenges for small and medium-sized businesses (SMBs). In 2024, 94% of SMBs reported experiencing cyberattacks—a sharp increase from 73% the year before. Despite limited resources, SMBs are prime targets due to perceived vulnerabilities. This guide explores critical cybersecurity trends shaping the SMB environment and actionable steps businesses can take to mitigate risks.</p><p>Investing in robust cybersecurity strategies is not just about preventing attacks—it’s about safeguarding business continuity, customer trust, and long-term profitability. By staying ahead of emerging threats and implementing effective security measures, SMBs can reduce downtime, avoid costly breaches, and maintain a competitive edge in an increasingly digital economy.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>Key Cybersecurity Trends for SMBs</p><p>1. <strong>Ransomware Evolution</strong></p><p>Ransomware-as-a-Service (RaaS) platforms are becoming more accessible, targeting businesses with fewer than 1,000 employees. With 82% of such companies already in the crosshairs, SMBs must adopt multi-layered defenses.</p><p>Implementing ransomware protection ensures business continuity by minimizing operational disruptions and safeguarding sensitive data from extortion attempts.</p><p><strong>Actionable Takeaway:</strong> Implement advanced endpoint protection, regular backups, and ransomware-specific incident response plans.</p><p>2. <strong>Cloud Security Challenges</strong></p><p>As more SMBs migrate to the cloud, misconfigurations and incomplete data deletion pose serious risks. Unsecured cloud storage can expose sensitive data.</p><p>Securing cloud environments enables scalable business operations while protecting critical business assets and customer information.</p><p><strong>Actionable Takeaway:</strong> Conduct regular cloud configuration audits, enforce strict access control policies, and adopt Zero Trust security models.</p><p>3. <strong>AI-Enhanced Threats</strong></p><p>Cybercriminals increasingly leverage AI for more sophisticated attacks. Deepfakes for business impersonation and AI-driven phishing campaigns are on the rise.</p><p>Staying ahead of AI-driven threats protects brand reputation and prevents financial and legal repercussions associated with data breaches.</p><p><strong>Actionable Takeaway:</strong> Invest in AI-powered threat detection tools, continuously train staff on spotting AI-driven scams, and update phishing simulations regularly.</p><p>Strategic Cybersecurity Focus Areas</p><p>In a world where cyber threats evolve daily, SMBs must focus on key cybersecurity areas that deliver both immediate and long-term protection. The following strategic focus areas are foundational pillars that enable businesses to defend against modern cyber risks while aligning with broader organizational goals.</p><p>Adopting a strategic cybersecurity approach helps SMBs enhance operational resilience, reduce financial and reputational risks, and ensure compliance with industry standards. By addressing these key areas, SMBs can transform cybersecurity from a reactive expense into a proactive investment that drives business success.</p><p>1. <strong>Essential Security Measures</strong></p><p>Robust security measures form the foundation of any effective cybersecurity strategy. SMBs must adopt comprehensive and proactive approaches to safeguard their digital assets. This includes technical safeguards, system maintenance, and policy enforcement that collectively create a resilient security posture.</p><p>* <strong>Multi-Factor Authentication (MFA):</strong> Strengthen access controls by requiring multiple verification methods, reducing the risk of unauthorized access.</p><p>* <strong>Regular Updates & Patches:</strong> Keep all systems, applications, and devices up-to-date with the latest patches to fix known vulnerabilities and reduce exposure to cyber threats.</p><p>* <strong>Endpoint Protection:</strong> Implement advanced endpoint protection solutions to detect, prevent, and respond to cyber threats targeting connected devices.</p><p>By enforcing these security measures, SMBs can minimize vulnerabilities, improve incident response capabilities, and ensure data integrity, ultimately reducing potential business disruptions and fostering a secure operational environment.</p><p>2. <strong>Employee Security Awareness</strong></p><p>Cybersecurity is only as strong as its weakest link, and employees often represent the first line of defense against cyber threats. Building a culture of security awareness through continuous training and clear policies can significantly reduce human-error-driven breaches.</p><p>* <strong>Phishing Recognition Training:</strong> Conduct quarterly simulated phishing tests to help employees recognize and report suspicious emails, links, and attachments.</p><p>* <strong>Remote Work Security:</strong> Enforce secure remote work protocols, including VPNs, encrypted devices, and secure communication tools.</p><p>* <strong>Security Awareness Campaigns:</strong> Promote ongoing staff education through workshops, newsletters, and interactive modules that cover emerging threats and best practices.</p><p>* <strong>Incident Reporting Protocols:</strong> Establish clear procedures for employees to report security incidents promptly, ensuring swift responses and minimal impact.</p><p>An informed workforce strengthens organizational defenses and fosters a proactive security culture that continuously adapts to evolving threats.</p><p>3. <strong>Zero Trust Architecture</strong></p><p>Zero Trust Architecture (ZTA) is a comprehensive cybersecurity framework built on "never trust, always verify." It assumes that threats can originate inside and outside the network, necessitating strict access controls and continuous verification of every user, device, and application attempting to access resources.</p><p>* <strong>Adopt the "Never Trust, Always Verify" Principle:</strong> Every access request should be considered untrusted until verified through identity checks, contextual data, and system health verification.</p><p>* <strong>Enhance Identity Verification and Access Management:</strong> Use authentication methods such as Multi-Factor Authentication (MFA), role-based access controls, and biometric authentication to ensure only authorized users gain access.</p><p>* <strong>Deploy Automated Threat Detection and Incident Response Tools:</strong> Use AI-powered monitoring systems to detect real-time anomalies, initiate automated responses, and isolate affected systems to contain breaches.</p><p>* <strong>Micro-Segmentation:</strong> Divide the network into isolated segments to minimize potential damage from breaches by limiting lateral movement within the network.</p><p>* <strong>Least Privilege Access:</strong> Restrict users to the minimum access required for their roles, reducing the risk of insider threats and compromised credentials.</p><p>Implementing a zero-trust framework ensures continuous protection by verifying every access request, reducing potential damages from insider threats, and strengthening an organization’s overall security posture.</p><p>Conclusion</p><p>Cybersecurity threats against SMBs are intensifying. By understanding these emerging risks and implementing strategic security measures, SMBs can fortify their defenses and maintain operational resilience. Stay proactive and secure your business against the evolving cyber threat landscape.</p><p>Protect your business today! Contact our cybersecurity experts for a personalized security consultation and ensure your SMB stays ahead of cyber threats in 2025 and beyond.</p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you have gained value from this post, please share it with others!</p></p><p></p><p>Product of the Week Shout out: <a target="_blank" href="https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77">Cyvatar.ai</a></p><p> How often do you track the maturity of your program or the implementation status of your controls? As an SMB, it can sometimes be hard to access cybersecurity assessments and tooling; here is a self-assessment tool that you can use to see where your business stands.</p><p>If you are looking for a security resource to help guide you through the assessment or the maturation of your security program.</p><p>See where your program scores <a target="_blank" href="https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77">https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/2025-smb-cybersecurity-trends</link><guid isPermaLink="false">substack:post:153386114</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 20 Dec 2024 15:10:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/153386114/4d3eaee5924be1acd49a0fafcff15588.mp3" length="6220252" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>518</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/153386114/b3bdb213a989fb101e567835238d52e7.jpg"/></item><item><title><![CDATA[Enhancing Cybersecurity for SMBs: Key Metrics That Matter]]></title><description><![CDATA[<p>Discover essential cybersecurity metrics that can enhance the security posture and resilience of small and medium-sized businesses (SMBs) in a rapidly evolving digital landscape.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-cybersecurity-for-smbs</link><guid isPermaLink="false">substack:post:153080379</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 14 Dec 2024 19:20:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/153080379/4d4104c78e77a507cef2f2359b3d80ef.mp3" length="8295162" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>691</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/153080379/786fb51aa9740b2c045ac972fb2c5ddf.jpg"/></item><item><title><![CDATA[Understanding the Cybersecurity Insurance Landscape for SMBs]]></title><description><![CDATA[<p>An essential guide for SMBs to navigate cybersecurity insurance, covering key components, types, costs, and tips for selecting the right policy.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/understanding-the-cybersecurity-insurance</link><guid isPermaLink="false">substack:post:152935812</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 11 Dec 2024 17:21:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/152935812/1f10fff858ea749cd661d1d442af953f.mp3" length="14443306" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1204</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/152935812/622c36ed52606847aa32f95769926390.jpg"/></item><item><title><![CDATA[Crafting a Robust Cybersecurity Budget for Small Businesses]]></title><description><![CDATA[<p>Cybersecurity protects digital assets, your business's reputation, and operational continuity. Recent trends reveal that nearly half of all cyberattacks target SMBs. The consequences of inadequate cybersecurity include data breaches, financial losses, and erosion of customer trust.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/crafting-a-robust-cybersecurity-budget</link><guid isPermaLink="false">substack:post:152030097</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 22 Nov 2024 21:49:04 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/152030097/0595e80569a98ebaf55bb585e19d3c27.mp3" length="5382627" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>449</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/152030097/7aa3f4368d34f5f04bb995fd7e0b9551.jpg"/></item><item><title><![CDATA[NetFlow Analysis: A Game-Changer for SMB Network Security and Efficiency]]></title><description><![CDATA[<p>Small and medium-sized businesses (SMBs) often struggle with network security. The landscape can feel overwhelming, especially with limited budgets, constrained resources, and the need to wear multiple hats. Many SMBs view advanced security tools as out of reach and reserved for large organizations with expansive budgets and dedicated teams. However, NetFlow is a hidden gem within reach of most businesses.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p></p><p>NetFlow is like having a security camera on your network. Still, instead of capturing visual data, it records the conversations happening within your network—who’s talking to whom, when, and what information is being exchanged. This network protocol collects IP traffic data flowing through your routers and switches, allowing you to monitor and analyze your network in real-time. With the right tools, NetFlow transforms this data into actionable insights, allowing you to proactively identify unusual patterns and address potential threats.</p><p>Imagine a scenario where your business experiences a sudden website crash. This might be due to a Distributed Denial of Service (DDoS) attack. NetFlow analysis can help you detect such attacks early by identifying unusual traffic spikes from malicious IP addresses, enabling you to mitigate the threat before it disrupts your operations. Similarly, NetFlow can highlight subtle signs of data breaches, like unusual data transfers to unknown locations, even during off-hours.</p><p>One of NetFlow's most compelling aspects is its accessibility for SMBs. Unlike many high-cost solutions, NetFlow leverages existing network infrastructure, making it cost-effective. Most modern routers and switches already support it, so there’s no need for expensive hardware upgrades.</p><p>Beyond security, NetFlow offers operational benefits. It provides insights into bandwidth usage, application performance, and network bottlenecks, enabling you to optimize your network and plan for future growth. Additionally, its ability to integrate seamlessly with tools like Security Information and Event Management (SIEM) systems creates a unified security ecosystem, enhancing threat detection and response.</p><p>For SMBs looking to get started with NetFlow, the first step is to assess your network infrastructure for compatibility. Begin by monitoring critical network segments, such as servers with sensitive data, and invest in training for your IT team to ensure they can interpret NetFlow data effectively. Consider your specific security and operational goals when choosing a tool that balances functionality, ease of use, and affordability.</p><p>NetFlow empowers SMBs to improve their security, enhance network performance, and gain a competitive edge. It’s an essential tool in today’s cybersecurity landscape—powerful, accessible, and transformative. The journey begins with a single step: check your infrastructure, train your team, and start leveraging NetFlow's power.</p><p></p><p><strong>A Caveat for SMBs Using Cloud Services</strong>For SMBs relying heavily on cloud services or Infrastructure as a Service (IaaS) platforms, NetFlow analysis might not fully apply. Many cloud providers do not offer granular access to traffic flow data at the level required for NetFlow analysis. Instead, these organizations might need to rely on the cloud provider’s monitoring tools and security features. If this applies to you, it’s essential to understand what visibility and controls your cloud provider offers and explore complementary solutions.</p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you found value in this post, feel free to share it.</p></p><p></p><p>Product shoutout: <a target="_blank" href="https://shop.tenable.com/cpf-coaching">Tenable</a></p><p>CPF Coaching Recommends Tenable for your vulnerability scanning needs. Proactive vulnerability management is crucial to your organization's healthy hygiene.</p><p><strong><em>Check it out here</em></strong>: <a target="_blank" href="https://shop.tenable.com/cpf-coaching">https://shop.tenable.com/cpf-coaching</a></p><p><a target="_blank" href="https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77">Cyvatar.ai</a></p><p>How often do you track the maturity of your program or the implementation status of your controls? As an SMB, it can sometimes be hard to access cybersecurity assessments and tooling; here is a self-assessment tool that you can use to see where your business stands.</p><p>If you are looking for a security resource to help guide you through the assessment or the maturation of your security program.</p><p>See where your program scores <a target="_blank" href="https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77">https://cyvatar.ai/cybersecurity-self-assessment/?via-rr=CHRISTOPHE77</a></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/netflow-analysis-a-game-changer-for</link><guid isPermaLink="false">substack:post:151719991</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 15 Nov 2024 21:55:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/151719991/41689a3cb9c5006d27549706e85d562d.mp3" length="1833262" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>153</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/151719991/2519fabb434eeccb958de658429ec46f.jpg"/></item><item><title><![CDATA[Maximizing Cybersecurity for SMBs: The Power of Alerting Systems]]></title><description><![CDATA[<p>Maximizing Cybersecurity for SMBs: The Power of Alerting Systems</p><p>As a senior cybersecurity leader and advisor, I've witnessed firsthand the evolving landscape of digital threats facing small and medium-sized businesses (SMBs). In today's interconnected world, cybersecurity is no longer a luxury but a necessity for businesses of all sizes. The rapid digitalization of operations, coupled with the increasing sophistication of cyber attacks, has made it imperative for SMBs to implement robust security measures.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/maximizing-cybersecurity-for-smbs</link><guid isPermaLink="false">substack:post:151378667</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 08 Nov 2024 15:55:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/151378667/b043c3293809b539f8d5813230961f41.mp3" length="5129754" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>427</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/151378667/596077f84e74dbff807135b17f962c9f.jpg"/></item><item><title><![CDATA[Essential Cybersecurity Tips for Small Businesses in 2024]]></title><description><![CDATA[<p>Cybercriminals are progressively targeting small businesses. Implementing strong cybersecurity measures is essential to safeguarding your business. This guide provides a thorough overview of how to help protect your small business from cyber threats in 2024.</p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/essential-cybersecurity-tips-for</link><guid isPermaLink="false">substack:post:150982389</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 31 Oct 2024 16:09:22 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/150982389/d135c37ed74080e658d42317b6e27d07.mp3" length="8977270" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>748</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/150982389/c794db31d05a61d231fe1c6cc1ed7932.jpg"/></item><item><title><![CDATA[Securing Remote Workforces: Best Practices for SMBs]]></title><description><![CDATA[<p>Learn the best practices for securing remote workforces, including implementing strong security policies, enhancing team-wide cybersecurity, and securing home networks. Protect your SMB from cyber threats with these expert insights.</p><p>Subscribe for future episodes!</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/securing-remote-workforces-best-practices</link><guid isPermaLink="false">substack:post:150568627</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 22 Oct 2024 16:17:05 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/150568627/80e612ea0ab8305a3f8ddac603d6d77e.mp3" length="2831462" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>236</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/150568627/4ec6f79e80f9e933f2c1783e8cbac9f1.jpg"/></item><item><title><![CDATA[Enabling SMBs to understand and address Insider Threats in their businesses ]]></title><description><![CDATA[<p>Small and Medium-sized Businesses (SMBs) face numerous security challenges, with insider threats ranking among the most damaging but often undiscussed; with the right strategies and a proactive approach, these threats can be effectively mitigated. Insider threats arise from individuals within an organization who abuse their access to sensitive information or systems for unauthorized purposes and harm the company, intentionally or unintentionally. These threats can lead to data breaches, financial losses, reputational damage, and operational disruptions. Unlike external cyber-attacks, insider threats are more challenging to detect because the individuals involved already have authorized access to sensitive resources. Let's explore the growing concern of insider threats in SMBs and offer practical strategies to mitigate them, with the potential for success and a more secure future for your business.</p><p></p><p></p><p><strong>1. Introduction to Insider Threats in SMBs</strong></p><p><strong>Defining Insider Threats</strong></p><p>An insider threat occurs when someone authorized access to a company's systems and data misuses that privilege, maliciously or unintentionally, to harm the organization. This threat can come from current or former employees, contractors, or business partners with legitimate access to sensitive resources. In small and medium-sized businesses (SMBs), insider threats are particularly worrisome because these businesses often have fewer layers of security than larger enterprises. Employees in SMBs may have broader access to systems, which increases the risk of misuse. Insider threats can significantly impact a company's success, leading to severe consequences such as data breaches, financial losses, reputational damage, and operational disruptions. Whether the intent is to steal data, sabotage operations, or unintentionally expose sensitive information, the effects of insider threats can be devastating.</p><p><strong>The Growing Concern for SMBs</strong></p><p>Recent cybersecurity reports, such as one from the Ponemon Institute, indicate that insider threats have grown by nearly 50% over the past few years. This trend is alarming, particularly for SMBs, which often lack the sophisticated security infrastructure of larger organizations. These larger organizations might have dedicated security teams, advanced threat detection systems, and regular security audits, which SMBs may need more resources to implement. The smaller teams and limited resources of SMBs make it challenging to implement comprehensive security measures, leaving them more vulnerable to insider attacks. Additionally, SMBs may only sometimes have dedicated IT staff to monitor security threats in real-time. With the rise of remote work and increased digital reliance, insider threats are becoming an even more pressing issue for small businesses.</p><p><strong>2. Mitigating Employee-Related Risks</strong></p><p><strong>Identifying Potential Risks</strong></p><p>The first step in addressing insider threats is identifying the potential risks that employees may pose. Common risk factors include disgruntled employees who may be motivated to harm the business, accidental data leaks due to negligence, and weak access control policies that give too much access to sensitive information. SMBs can reduce these risks by employing behavioral monitoring technologies that track abnormal employee activities. For example, unusual login times, unauthorized file access, or abnormal data transfers can serve as red flags. Identifying these risks early on enables SMBs to take proactive steps before damage occurs.</p><p><strong>Implementing Preventative Measures</strong></p><p>Small and medium-sized businesses (SMBs) need to establish and enforce strong preventive measures to minimize the risk of insider threats. Implementing strict access control policies is one of the most effective methods for protecting sensitive data. These policies should follow the principle of least privilege, meaning that employees should only have access to the data and systems necessary for their specific roles. This principle ensures that even if an employee's credentials are compromised, the potential damage is limited to the data and systems they access, reducing the overall risk. It's crucial to regularly review and update these access controls to prevent employees from retaining unnecessary permissions after role changes. Additionally, businesses need to conduct thorough background checks on new hires, closely monitor employee activities for any signs of suspicious behavior, and ensure the encryption of sensitive data to prevent unauthorized access.</p><p><strong>3. Insider Threat Identification Techniques</strong></p><p><strong>Behavioral Monitoring Technologies</strong></p><p>Behavioral monitoring technologies are crucial in identifying insider threats; these technologies monitor and analyze employee activities, including email communications, network access, file transfers, and login patterns. For instance, sudden access to large volumes of sensitive data or downloading files outside of regular business hours could indicate an insider threat. However, small and medium-sized businesses (SMBs) must balance these technologies with privacy concerns by ensuring employees are aware of the monitoring while safeguarding their data. It's important to note that while these tools are powerful, they are not infallible and may sometimes produce false positives that require careful interpretation.</p><p><strong>Early Detection Strategies</strong></p><p>Early detection of insider threats is critical to limiting potential damage. Anomaly detection systems, user behavior analytics (UBA), and machine learning algorithms are powerful tools that can flag suspicious activities before they escalate into major incidents. These tools establish a baseline of normal behavior for each employee and then detect deviations that may signal malicious intent or accidental data exposure. For example, an anomaly detection system could identify employees accessing customer data they usually wouldn't, prompting a deeper investigation. SMBs that deploy these strategies can reduce the risk of significant financial or reputational harm by catching threats in their early stages.</p><p><strong>4. Effective Access Control Policies</strong></p><p><strong>Developing Robust Policies</strong></p><p>Small and medium-sized businesses (SMBs) must establish effective access control policies to safeguard sensitive information. The following guidelines dictate which employees can access particular data, ensuring access is only given to those needing it for their specific roles. Small and medium-sized businesses (SMBs) should focus on implementing role-based access control (RBAC) systems, where permissions are based on the employee's job function rather than their seniority or length of employment. This approach reduces the risk of unauthorized access. Additionally, these policies should include multi-factor authentication (MFA), which necessitates employees to confirm their identity through multiple methods before accessing critical systems. By limiting access, SMBs can significantly minimize their risk exposure.</p><p><strong>Regular Audits and Updates</strong></p><p>Access control policies must be regularly audited and updated to remain effective. As companies grow, adopt new technologies, or restructure their teams, access requirements may change, making it necessary to review who has access to sensitive information. Regular audits of user permissions ensure access is appropriately restricted and help uncover potential vulnerabilities. SMBs should also keep up with technological advancements and regulatory changes that may impact their security policies. For example, a company handling personal data may need to adjust its access policies to comply with new data protection laws, such as GDPR or CCPA.</p><p><strong>5. Enhancing Employee Security Awareness</strong></p><p><strong>Training Programs for Employees</strong></p><p>Security awareness training is an essential part of any insider threat mitigation strategy. Employees are often the first line of defense against insider threats, and ensuring they understand security best practices can significantly reduce risks. SMBs should implement regular training programs to educate staff on identifying phishing emails, recognizing suspicious behavior, and protecting sensitive data. These training sessions should be mandatory and updated to reflect new threats or technologies. By instilling a strong sense of security and responsibility among employees, businesses can reduce accidental leaks and empower workers to report potential threats.</p><p><strong>Creating a Security-Conscious Culture</strong></p><p>Beyond training, SMBs must foster a security culture where employees feel a shared responsibility for protecting the organization's data. This can be achieved by encouraging open communication about security risks and promoting a non-punitive approach to reporting mistakes. When employees are comfortable reporting potential security issues or acknowledging errors without fear of retribution, the organization can address vulnerabilities faster. Leadership should lead by example, emphasizing the importance of security at all company levels. Secure password managers and data encryption software can help employees make better daily security decisions.</p><p><strong>6. SMB Insider Threat Solutions</strong></p><p><strong>Customized Solutions for SMBs</strong></p><p>SMBs face unique challenges regarding insider threats, and several solutions are designed specifically for smaller businesses. These solutions often prioritize ease of use, scalability, and cost-effectiveness, ensuring that SMBs can implement them without needing a large IT team. Some options include cloud-based security platforms that offer real-time threat monitoring, employee behavior analysis, and integrated access control management. SMBs should evaluate these solutions based on their specific needs, ensuring that the chosen tools can seamlessly integrate into existing systems without disrupting business operations.</p><p><strong>Integration and Implementation</strong></p><p>Careful planning and a clear understanding of the organization's security infrastructure are necessary to implement an insider threat solution. Small and medium-sized businesses (SMBs) should begin by thoroughly assessing their current systems and identifying gaps in their defenses. Once a solution has been chosen, it is essential to ensure that employees are effectively trained to use it. Integration should be carried out in phases, with continuous monitoring to measure the new system's effectiveness. Regular reviews and updates are necessary to adapt the solution to evolving threats and ensure ongoing protection.</p><p><strong>Summary of Key Points</strong></p><p>Insider threats pose a significant risk to SMBs, especially those with limited resources dedicated to security. Businesses can significantly reduce the chances of a damaging insider attack by identifying potential hazards, implementing robust access control policies, and leveraging behavioral monitoring technologies. Additionally, enhancing employee security awareness and creating a culture can help prevent accidental leaks and deter malicious actors.</p><p>As cybersecurity technology advances, small and medium-sized businesses (SMBs) must proactively address insider threats. In the future, managing insider threats will likely involve improvements in AI-powered detection systems and more customized solutions for smaller businesses. SMBs that stay vigilant, regularly update their security measures, and cultivate a security-conscious workforce will be better equipped to protect their assets and succeed in the digital age.</p><p>If you need help with your security strategy, CPF Coaching is here for you.</p><p>Visit https://www.cpf-coaching.com/booking to have an introductory conversation.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enabling-smbs-to-understand-and-address</link><guid isPermaLink="false">substack:post:150216202</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 14 Oct 2024 16:47:11 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/150216202/c5f169d6088eeea95fe902a35f95c8ac.mp3" length="7323863" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>610</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/150216202/a593db8cfc3b3b014f820a9d3b1240fb.jpg"/></item><item><title><![CDATA[Understanding and Mitigating Phishing Attacks in SMBs]]></title><description><![CDATA[<p></p><p>Phishing attacks pose a growing threat to Small and Medium Businesses (SMBs), targeting their sensitive data and financial resources. These deceptive tactics, often delivered through fraudulent emails, trick employees into revealing confidential information or unknowingly downloading malware. For SMBs, the impact of a successful phishing attack can be devastating, leading to significant financial loss, data breaches, and reputational damage. In this guide, we'll explore the rising danger of phishing and the importance of solid email security. We'll also provide actionable strategies to protect your business from these increasingly sophisticated threats.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p><strong>1. Introduction to Phishing Attacks in SMBs</strong>Phishing attacks have significantly threatened Small and Medium Businesses (SMBs). These attacks involve malicious actors sending deceptive emails to trick recipients into revealing sensitive information. The impact on SMBs can be severe, leading to financial loss, data breaches, and reputational damage. Recent statistics show a sharp rise in phishing attacks targeting SMBs, highlighting the need for robust security measures.Email security is crucial in protecting SMBs from phishing attacks. Without proper safeguards, businesses are vulnerable to various email security threats such as malware, ransomware, and spear-phishing. Ensuring robust email security helps prevent unauthorized access and protects sensitive information.This guide educates readers on phishing prevention, threat identification, and effective response strategies. By the end, you will have a comprehensive understanding of how to protect your SMB from phishing attacks.</p><p><strong>2. Phishing Prevention Strategies</strong>Implementing robust email security measures is one of the first steps in phishing prevention. These include using email filters and spam detection tools to identify and block suspicious emails. Secure email gateways add another layer of protection by inspecting inbound and outbound emails for threats.It is crucial to train employees to recognize phishing attempts. Regular updates and simulated phishing exercises can help employees stay vigilant. Teaching them to look for red flags, such as suspicious links and unfamiliar senders, can significantly reduce the risk of falling for phishing scams.Crafting clear policies on email use and security is essential. These policies should outline acceptable email practices and procedures for reporting suspicious emails. Regular audits and compliance checks ensure guidelines are followed and updated.<strong>3. Identifying Phishing Threats</strong>Understanding common phishing tactics is critical to identifying threats. Phishing emails often contain urgent messages prompting immediate action, such as clicking a link or providing personal information. Differentiating between phishing and spear-phishing attacks, which are more targeted, is also essential.Utilizing AI and machine learning can enhance threat detection. These technologies analyze email patterns and flag suspicious activities. Integrating threat intelligence feeds into your security infrastructure provides real-time updates on emerging threats.Continuous monitoring is vital for identifying phishing threats promptly. Tools and software that offer 24/7 monitoring ensure that any suspicious activity is detected and addressed immediately. This proactive approach helps in mitigating potential damage.<strong>4. Developing Effective Response Strategies</strong>Once a phishing attempt is identified, immediate action is required. Isolating affected systems prevents the spread of malicious software. Following a predefined response plan is crucial to minimize damage and secure your network.Informing stakeholders and affected parties is critical in managing a phishing incident. Transparent communication helps maintain trust, and managing public relations effectively ensures that your business reputation remains intact.After addressing the immediate threat, reviewing and revising security measures is essential. Conducting a post-mortem analysis helps identify weaknesses and prevent future attacks. Implementing lessons learned ensures continuous improvement in your security posture.<strong>5. Attack Simulation and Continuous Improvement</strong></p><p>Regular phishing attack simulations prepare your team for real threats. These simulations help identify vulnerabilities and improve response strategies. They also provide valuable insights into how employees react to phishing attempts.Continuous improvement is vital for maintaining strong security measures. Regular updates and enhancements based on simulation results ensure your defenses remain effective. Encouraging a culture of constant learning and adaptation keeps your team prepared for evolving threats.Collecting and analyzing user feedback is crucial for refining training and security protocols. This feedback helps identify areas for improvement and ensures that security measures are effective and current.<strong>Conclusion</strong>Email security, phishing prevention strategies, threat identification, user training, and effective response strategies are essential. Each plays a crucial role in protecting SMBs from phishing attacks.Mitigating phishing attacks requires a proactive and comprehensive approach. SMBs must stay vigilant and continuously improve security measures to protect against evolving threats. By implementing the strategies outlined in this guide, SMBs can significantly reduce the risk of phishing attacks and safeguard their business.Phishing attacks pose a severe threat to SMBs, but with robust email security, user training, and effective response strategies, businesses can defend against these malicious threats. Continuous improvement and vigilance are vital to maintaining a secure environment. Stay informed, stay prepared, and keep your business safe.</p><p></p><p></p><p>Product of the Week: <a target="_blank" href="https://get.ine.com/cpf-coaching">INE Training</a></p><p></p><p><a target="_blank" href="https://get.ine.com/cpf-coaching">INE</a> offers a wide range of training programs to help your technical and development teams take the necessary actions to protect your organization. These teams can then serve as your first line of support in aiding your users with their awareness and security posture. Whether you are an individual or a company, <a target="_blank" href="https://get.ine.com/cpf-coaching">INE</a> provides training options that you can use today!</p><p></p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you found value in this post, share it with others who might appreciate it as well. </p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/understanding-and-mitigating-phishing</link><guid isPermaLink="false">substack:post:149458501</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 27 Sep 2024 14:26:57 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/149458501/12b5daa7c4cafff2a0d15f265a33f021.mp3" length="3822593" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>318</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/149458501/3f00d15b8a60bc7a2d04a1eee852c296.jpg"/></item><item><title><![CDATA[Navigating Third-Party Risk Management: Essential Strategies for SMBs]]></title><description><![CDATA[<p>Mastering Third-Party Risk Management for SMBs</p><p>In today's interconnected business environment, SMBs increasingly rely on third-party vendors and partners, heightening risk factors. This episode dives into essential strategies for effective Third-Party Risk Management (TPRM). Learn to inventory and assess third-party relationships, conduct thorough due diligence, set clear contractual requirements, and continuously monitor and reassess security postures. Discover how to form incident response plans, train your team effectively, and leverage external resources to bolster your TPRM program. Enhance your cybersecurity approach to safeguard assets, reputation, and customer trust. For personalized assistance, contact <a target="_blank" href="mailto:info@cpf-coaching.com">info@cpf-coaching.com</a>. Plus, discover how easyDMARC can ensure your emails reach their intended destination.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-third-party-risk-management</link><guid isPermaLink="false">substack:post:148586170</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 13 Jul 2025 13:52:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/148586170/a71645f4083c3448d67352011c0ded56.mp3" length="4511134" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>376</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/148586170/8a0a2ca791530a9db2a459082aa017b1.jpg"/></item><item><title><![CDATA[Enabling a SMB Security with Log Analysis and SIEM]]></title><description><![CDATA[<p><strong>The Business Value of Log Analysis and SIEM for SMBs</strong></p><p>As threats become more sophisticated, robust security measures are paramount, even for small-medium businesses. One critical component of a comprehensive security strategy is log analysis and Security Information and Event Management (SIEM). These tools allow SMBs to detect potential threats early, allowing for timely intervention and mitigation. Log analysis involves reviewing and interpreting logs generated by computers, networks, and applications. These logs capture a wide range of activities, from user actions to system errors, providing invaluable insights into the health and security of IT environments. SIEM systems take this further by centralizing log data from multiple sources, correlating events, and providing real-time analysis to detect and respond to security incidents. For SMB leaders and security teams, investing in log analysis and SIEM can significantly enhance threat detection capabilities, improve compliance, and optimize operational efficiency.</p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p>Log analysis is the foundation of effective cybersecurity, providing invaluable insights into the activities occurring within an organization's IT infrastructure. Businesses can uncover patterns, anomalies, and potential security incidents that might go unnoticed by meticulously examining log files generated by various systems, applications, and network devices. SIEM systems take this further by aggregating and correlating data from multiple sources, offering a holistic view of an organization's security posture and enabling real-time threat detection and response.</p><p><strong>Tasks and Organizational Value</strong></p><p>Implementing log analysis and SIEM can transform how SMBs manage their cybersecurity efforts. These solutions go beyond mere security enhancements; they contribute to operational efficiency, regulatory compliance, and overall business resilience.</p><p>* <strong>Real-time Threat Detection</strong>: By continuously monitoring logs, SIEM systems can identify suspicious activities, such as unauthorized access attempts or unusual network traffic patterns. This allows businesses to respond quickly, minimizing potential damage from cyber threats.</p><p>* <strong>Compliance and Reporting</strong>: Many industries have strict regulatory requirements for data security and privacy. Log analysis helps ensure compliance by providing detailed audit trails and reports that can be used to demonstrate adherence to regulations like GDPR or HIPAA.</p><p>* <strong>Operational Efficiency</strong>: Log analysis tools automate the collection and parsing of log data, reducing the manual effort required by IT teams. This saves time and allows staff to focus on more strategic initiatives, improving overall productivity.</p><p><strong>Current Challenges and Solutions</strong></p><p>Despite the clear benefits of implementing log analysis, SIEM systems, and partnering with MSSPs, SMBs often encounter significant challenges in adopting and optimizing these solutions. These obstacles range from resource constraints to the sheer complexity of modern cyber threats, creating a landscape that can be daunting for businesses with limited IT and security resources.</p><p>* <strong>Resource Constraints</strong>: Limited budgets and personnel can make it difficult for SMBs to deploy and maintain sophisticated SIEM systems. To address this, businesses can explore open-source or cloud-based services that offer scalability and cost-effectiveness.</p><p>* <strong>Data Overload</strong>: The sheer volume of log data can be overwhelming, leading to alert fatigue and potential oversight of critical incidents. Effective log management strategies, such as data filtering and prioritization, can help manage this influx and ensure that only relevant alerts are escalated.</p><p>* <strong>Complexity of Integration</strong>: Integrating SIEM systems with existing IT infrastructure can be complex. Choosing solutions with user-friendly interfaces and robust support can ease this process, ensuring seamless integration and operation. Partnering with a Managed Security Service Provider could be another avenue to consider.</p><p><strong>Optimizing with Future Solutions</strong></p><p>As the cybersecurity landscape evolves, so must the strategies and tools used to protect digital assets. The future of log analysis, SIEM systems, and managed security services holds exciting possibilities for enhancing threat detection, streamlining operations, and improving overall security postures.</p><p>* <strong>Leverage AI and Machine Learning</strong>: Incorporating AI and machine learning into log analysis can enhance threat detection by identifying patterns and anomalies that traditional methods might miss. These technologies can also automate responses, reducing the time to mitigate threats.</p><p>* <strong>Adopt a Zero Trust Model</strong>: Implementing a Zero Trust security framework can complement log analysis efforts by ensuring all access requests are verified and monitored, regardless of origin. This approach enhances security by minimizing the risk of insider threats and lateral movement within networks.</p><p>* <strong>Continuous Training and Education</strong>: The cybersecurity landscape constantly evolves, so ongoing training for security teams is crucial. Investing in education ensures that staff are equipped with the latest skills and knowledge to effectively utilize log analysis and SIEM tools.</p><p>Using a Managed Security Service Provider (MSSP) over an in-house Security Operations Center (SOC) offers several cost benefits, particularly for small and medium-sized businesses (SMBs). Here are the primary cost advantages:</p><p><strong>Cost Benefits of Using an MSSP</strong></p><p>* <strong>Cost Efficiency</strong>: Cost efficiency is one of the most significant benefits of using an MSSP. Establishing an in-house SOC involves substantial expenses, including hiring skilled cybersecurity professionals, purchasing hardware and software, and maintaining facilities. MSSPs, on the other hand, spread these costs across multiple clients, allowing businesses to access high-quality security services at a fraction of the cost.</p><p>* <strong>Scalability and Flexibility</strong>: MSSPs offer scalable solutions that can adjust to a business's changing needs without additional capital investment. This flexibility is particularly beneficial for SMBs that may experience fluctuating demands and cannot afford the financial burden of constantly upgrading their in-house SOC capabilities.</p><p>* <strong>Access to Advanced Technologies</strong>: MSSPs provide access to cutting-edge security tools and technologies, such as Security Information and Event Management (SIEM) systems, without the direct costs associated with purchasing and maintaining these tools in-house. This access ensures businesses can leverage the latest security innovations without significant expenses.</p><p>* <strong>24/7 Monitoring and Support</strong>: MSSPs offer round-the-clock monitoring and support, which would require significant investment if managed internally. This continuous service ensures that businesses are protected at all times, including nights, weekends, and holidays, without hiring additional staff for these shifts.</p><p>* <strong>Reduced Overhead and Operational Costs</strong>: By outsourcing to an MSSP, businesses can convert fixed costs into variable costs, allowing them to pay only for the needed services. This model reduces overhead and operational costs, freeing up resources that can be allocated to other strategic business initiatives.</p><p>Partnering with an MSSP can provide SMBs with a cost-effective, scalable, and technologically advanced security solution. This allows them to focus on their core business activities while ensuring robust cybersecurity protection.</p><p><strong>Actionable Summary</strong></p><p>A strategic approach is essential for SMB leaders looking to harness the power of log analysis, SIEM systems, and MSSPs to bolster their cybersecurity defenses. This section provides a roadmap for organizations seeking to implement or optimize these critical security measures, offering practical steps to enhance threat detection capabilities, ensure compliance, and improve overall security posture.</p><p>* <strong>Evaluate and Choose the Right Tools</strong>: Assess your organization's needs and select log analysis and SIEM solutions that align with your budget and operational requirements.</p><p>* <strong>Implement and Integrate</strong>: Ensure seamless integration of chosen tools with existing IT infrastructure, prioritizing solutions with user-friendly interfaces and firm support. Assess whether an MSSP could help optimize your monitoring posture.</p><p>* <strong>Train and Educate</strong>: Train your security teams on the latest technologies and best practices in log analysis and threat detection.</p><p>By focusing on these areas, SMBs can significantly improve their ability to detect and respond to cybersecurity threats, safeguard their operations, and ensure compliance with industry regulations.</p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you have found value in this post, please share it with others and consider becoming a subscriber.</p></p><p></p><p>Proudshout out: <a target="_blank" href="https://get.ine.com/cpf-coaching">INE</a></p><p>Ready to learn with INE? Discover content across Networking, Cybersecurity, Cloud Computing, and Data Science for IT professionals at every level.</p><p><a target="_blank" href="https://get.ine.com/cpf-coaching"><strong>Why INE? Affordable | Hands-On | Continuous</strong></a></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enabling-a-smb-security-with-log</link><guid isPermaLink="false">substack:post:148318008</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 02 Sep 2024 12:40:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/148318008/6ece9e9c89da87a8b53e001f4d04a7b5.mp3" length="5554561" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>463</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/148318008/1e60c82b234028ab55a47a59340467bb.jpg"/></item><item><title><![CDATA[Enhancing Threat Detection in SMBs: A Guide to NIST CSF Detection Capabilities]]></title><description><![CDATA[<p>Understanding the Importance of Threat Detection in SMBs</p><p>Small and medium-sized businesses are increasingly vulnerable to cyber threats. To effectively scale and innovate, they must insert cybersecurity mechanisms that secure their assets and data for their customers. In any robust cybersecurity strategy, threat detection certainly needs to be included. This goes above traditional monitoring by hunting for potential threats across all planes of business operations: data, control, and identity. It is in these broad areas that the leaders of SMBs can make a difference in the detection capabilities of the NIST Cybersecurity Framework and provide a more secure environment for their business.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p></p><p><strong>The Role of Data, Control, and Identity Planes</strong></p><p>In cybersecurity, understanding the different planes of business operations—data, control, and identity—is crucial for effective threat detection. Each plane represents a unique aspect of your business's digital ecosystem that requires specific attention and strategies to safeguard against potential threats. By focusing on these planes, SMB leaders can develop a more comprehensive approach to threat detection that aligns with the NIST Cybersecurity Framework (CSF). This section will explore the significance of each plane and how they contribute to a robust cybersecurity posture.</p><p><strong>Data Plane:</strong> The data plane involves processing, storing, and transmitting data within a business. Effective threat detection ensures that sensitive information is safeguarded against unauthorized access and breaches. Here's where advanced data monitoring tools come in. These tools can help identify unusual patterns or anomalies that may indicate a cyber threat, giving you the reassurance that you're one step ahead in protecting your business.</p><p><strong>Control Plane:</strong> The control plane includes the systems and processes that manage data flow and access within the organization. Threat detection here focuses on ensuring that only authorized personnel have access to critical systems and data. By monitoring control plane activities, businesses can prevent unauthorized changes and detect potential insider threats, keeping you vigilant and aware of potential risks.</p><p><strong>Identity Plane:</strong> The identity plane pertains to the authentication and authorization of users accessing business systems. Effective threat detection in this plane involves monitoring user activities and ensuring robust access controls. Implementing multi-factor authentication and identity management solutions can significantly reduce the risk of identity-based attacks.</p><p><strong>Examples of Threat Detection Tasks and Their Value</strong></p><p>Implementing threat detection capabilities involves various tasks that, when executed effectively, can significantly enhance an organization's security posture. From continuous monitoring to anomaly detection, these tasks are designed to identify and mitigate potential threats before they can cause harm. Understanding the value of these tasks helps build a resilient cybersecurity strategy and demonstrates the tangible benefits to stakeholders. This section will delve into specific threat detection tasks and highlight their importance to your organization.</p><p>* <strong>Continuous Monitoring:</strong> By continuously monitoring network traffic and user activities, businesses can quickly identify and respond to potential threats. This proactive approach helps minimize the impact of cyber incidents and ensures business continuity.</p><p>* <strong>Anomaly Detection:</strong> Machine learning algorithms can be utilized to detect anomalies in data and user behavior, providing early warnings of potential threats. This allows businesses to address vulnerabilities before attackers exploit them.</p><p>* <strong>Incident Response Planning:</strong> Developing and regularly updating an incident response plan ensures businesses are prepared to handle cyber incidents effectively. This reduces downtime and mitigates the financial and reputational impact of breaches.</p><p><strong>Current Environmental Challenges and Overcoming Them</strong></p><p>The cybersecurity landscape constantly evolves, presenting SMBs with many challenges in implementing effective threat detection strategies. Limited resources, a shortage of skilled personnel, and the ever-changing nature of cyber threats are just a few hurdles businesses must overcome. However, with the right approach and tools, these challenges can be transformed into opportunities for strengthening security measures. This section will discuss the challenges SMBs face and provide insights into overcoming them to build a more secure business environment.</p><p>SMBs face several challenges in implementing effective threat detection strategies, including limited resources, lack of expertise, and evolving threat landscapes. To overcome these challenges, businesses can:</p><p>* <strong>Leverage Managed Security Services:</strong> Partnering with managed security service providers (MSSPs) can provide SMBs with access to advanced threat detection tools and expertise without significant in-house investment.</p><p>* <strong>Invest in Employee Training:</strong> Regularly training employees on cybersecurity best practices can help prevent human errors that lead to security breaches.</p><p>* <strong>Adopt Scalable Solutions:</strong> Implementing scalable cybersecurity solutions allows businesses to adapt to changing threats and needs without significant disruptions.</p><p><strong>Optimizing Threat Detection with Future Solutions</strong></p><p>As technology advances, so do the methods and tools available for threat detection. Embracing these innovations can provide SMBs with more efficient and effective ways to protect their digital assets. Future solutions offer promising avenues for optimizing threat detection capabilities, from artificial intelligence to zero trust architectures. In this section, we will explore potential future solutions that SMBs can leverage to enhance their cybersecurity strategies and stay ahead of emerging threats.</p><p>Looking ahead, SMBs can optimize their threat detection capabilities by:</p><p>* <strong>Embracing Artificial Intelligence (AI):</strong> AI-driven threat detection solutions can analyze vast amounts of data in real time, providing more accurate and timely threat identification.</p><p>* <strong>Implementing Zero Trust Architecture:</strong> Adopting a zero-trust approach ensures that all users and devices are continuously verified, reducing the risk of unauthorized access.</p><p>* <strong>Utilizing Threat Intelligence:</strong> Integrating threat intelligence feeds into security systems can provide businesses with up-to-date information on emerging threats, enabling proactive defense measures.</p><p><strong>Actionable Summary</strong></p><p>To enhance threat detection capabilities, SMB leaders should focus on the following action items:</p><p>* <strong>Assess Current Security Posture:</strong> Conduct a thorough assessment of existing security measures and identify areas for improvement.</p><p>* <strong>Invest in Technology and Training:</strong> Allocate resources to implement advanced threat detection tools and provide ongoing employee training.</p><p>* <strong>Develop a Comprehensive Incident Response Plan:</strong> Ensure the business is prepared to respond swiftly and effectively to cyber incidents.</p><p>By prioritizing threat detection across the data, control, and identity planes, SMBs can build a resilient cybersecurity posture that supports their growth and innovation goals.</p><p></p><p>Product of the Week: YouAttest</p><p>YouAttest has created a tool that is right for MSPs for identity compliance:</p><p>• Plugs into existing identity systems in minutes</p><p>• With NO API/coding experience, 100% GUI-driven</p><p>• Can be integrated/supported with/ current MSP personnel</p><p>• Anyone who can manage Azure AD, Okta, or similar IAM can manage YouAttest</p><p>YouAttest is the fastest time-to-value identity audit product on the market.</p><p></p><p>YouAttest identity audits specifically map to NIST SP 800-53 AC-1, AC-4, AC-6 and meet the following identity compliance requirements for the following markets:</p><p>• Health Care: HIPAA/HITRUST</p><p>• Financial: SOX, GLB</p><p>• Retail: PCI-DSS</p><p>• Cloud: SOC</p><p>• D.o.D. Contractors: CMMC</p><p>• Int’l: ISO 27001, GDPR</p><p>If you would like to learn more about how YouAttest or if I can help you with your identity governance, reach out to me. </p><p>YouAttest: info@youattest.com (Let them know CPF Coaching sent you their way)</p><p><a target="_blank" href="https://youattest.com/youattest-in-the-news/">https://youattest.com/youattest-in-the-news/</a></p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If this episode has provided you with value and you know others who could use this, please do share with them. </p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-threat-detection-in-smbs</link><guid isPermaLink="false">substack:post:148110196</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 26 Aug 2024 13:33:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/148110196/99b59c6ce38cf02838de18888369e317.mp3" length="5305694" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>442</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/148110196/6d51893ecea3b5f9ac29ff5bffc07504.jpg"/></item><item><title><![CDATA[Enhancing Security in Open-Source Code for SMBs]]></title><description><![CDATA[<p>In the digital world today, it is more often than not that small and medium-sized businesses are found turning to open-source code and public software repositories to be able to build and enhance their technological capabilities. On one hand, such resources bring about considerable cost savings and advantages of innovation, but on the other hand, they also bear the potential security risks that might compromise the integrity of business operations. It is against this backdrop that, as a senior cybersecurity leader and advisor, I come forth to place emphasis on the security and integrity of open-source code and how SMB leaders and security teams can effectively deal with these risks.</p><p></p><p><p>SMB Tech & Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>Open-source software has become a cornerstone for many businesses, providing a flexible and cost-effective way to access cutting-edge technology. However, the very nature of open-source code—its openness and collaborative development—can also make it a target for malicious actors seeking to exploit vulnerabilities. For SMBs, which may lack the extensive resources of larger enterprises, the challenge is to harness the benefits of open-source software while mitigating the associated risks. By prioritizing security and integrity in open-source code, SMBs can protect their assets, maintain customer trust, and ensure business continuity.</p><p>Examples of Use Cases and their value</p><p>* <strong>Code Review and Vulnerability Assessment</strong>: It is crucial to regularly review open-source code for vulnerabilities. This task helps identify potential security flaws before they can be exploited, thereby protecting the organization from breaches and data loss.</p><p>* <strong>Implementing Security Tools</strong>: Tools such as static code analyzers and dependency checkers can automate the process of detecting vulnerabilities in open-source components. This not only saves time but also enhances the organization's overall security posture.</p><p>* <strong>Community Engagement and Contribution</strong>: Participating in open-source communities lets businesses stay informed about the latest security patches and updates. Contributing to these communities can foster goodwill and collaboration, leading to more robust and secure software solutions.</p><p>Current Environmental Challenges and Solutions</p><p>The open-source ecosystem is vast and constantly evolving, which presents several challenges:</p><p>* <strong>Rapidly Changing Codebases</strong>: Maintaining frequent updates and patches can be daunting. SMBs can overcome this by implementing automated update management systems that ensure the timely application of security patches.</p><p>* <strong>Lack of In-House Expertise</strong>: Many SMBs struggle with limited cybersecurity expertise. Partnering with external cybersecurity firms or consultants can provide support and guidance to manage open-source risks effectively.</p><p>* <strong>Supply Chain Vulnerabilities</strong>: Software dependencies' interconnected nature can introduce vulnerabilities. Conducting thorough supply chain risk assessments and utilizing tools that map and monitor dependencies can help mitigate these risks.</p><p>Potential Future Solutions</p><p>Looking ahead, SMBs can optimize their approach to open-source security by:</p><p>* <strong>Adopting AI and Machine Learning</strong>: These technologies can enhance threat detection and response capabilities, providing real-time insights into potential vulnerabilities and threats.</p><p>* One possible use case includes the ability to analyze SBOMs, connect software packages to those in use in the environment, and aid with the remediation of patching or updates.</p><p>* <strong>Developing a Security-First Culture</strong>: Encouraging a mindset where security is integrated into every aspect of software development and deployment can lead to more secure outcomes. This involves training employees and fostering an environment where security is everyone's responsibility.</p><p>Actionable Summary</p><p>To effectively manage the security and integrity of open-source code, SMB leaders and security teams should focus on the following action items:</p><p>* Conduct regular code reviews and vulnerability assessments.</p><p>* Implement automated tools for detecting and managing vulnerabilities.</p><p>* Engage with open-source communities for the latest security updates.</p><p>* Partner with cybersecurity experts to enhance in-house capabilities.</p><p>* Foster a security-first culture within the organization.</p><p>By taking these steps, SMBs can leverage the benefits of open-source software while minimizing security risks, ultimately enhancing their resilience in an increasingly digital world.</p><p><p>Thanks for reading SMB Tech & Cybersecurity Leadership Newsletter! If you found value from this post, sharing it with others would mean the world to us.</p></p><p>Product shout-out: <a target="_blank" href="https://get.learnworlds.com/cpf-coaching">LearnWorlds</a></p><p>At CPF Coaching, we're always on the lookout for top-notch tools that empower our clients to the max. This is why we couldn't, but we are very excited about recommending <a target="_blank" href="https://get.learnworlds.com/cpf-coaching">LearnWorlds</a>. Just recently named "Top User-rated Online Course Platform & LMS," <a target="_blank" href="https://get.learnworlds.com/cpf-coaching">LearnWorlds</a> is a supreme platform that allows the world to leverage your knowledge and talents. Whether you're an educator, coach, or business leader, it really has everything you need to run highly engaging and impactful online courses. Time to make a difference—find a way to share your value with those who need it the most!</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-security-in-open-source</link><guid isPermaLink="false">substack:post:147801583</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 19 Aug 2024 14:27:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/147801583/340217e8ede17b8d053417134c6c4e5a.mp3" length="4019762" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>335</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/147801583/e5e258f7d270565ed407fac53cae009c.jpg"/></item><item><title><![CDATA[The Business Value of PKI Encryption for SMBs: Enhancing Security and Compliance]]></title><description><![CDATA[<p>With a digital and cloud-first approach used by Small and medium-sized businesses (SMBs), they face ever-increasing cybersecurity threats. As a cybersecurity leader, it is crucial to implement robust security measures that protect your organization and align with industry standards like the NIST Cybersecurity Framework (CSF). One such measure is Public Key Infrastructure (PKI) encryption. PKI is a framework that uses cryptographic keys to secure communications, authenticate users, and ensure data integrity. This blog post will delve into PKI encryption's purpose and business value, how it can help identify and detect potential threats, and how these steps align with the NIST CSF framework.</p><p><p>Cybersecurity Leadership & SMB Security Development  is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p>How PKI Encryption Can Help SMBs Detect Threats and Align with NIST CSF</p><p>As we navigate the complexities of cybersecurity, it's essential to understand that PKI is not just a technical solution but a strategic asset that can significantly enhance your business's security posture and operational efficiency.</p><p></p><p>Using PKI Encryption in SMBs</p><p>In an era where data breaches and cyber attacks are becoming increasingly common, PKI encryption is a powerful tool in the SMB's cybersecurity arsenal. By implementing PKI, businesses can create a secure environment protecting sensitive information and fostering stakeholder trust and confidence. Let's explore the key benefits that make PKI encryption invaluable for SMBs.</p><p><strong>Enhancing Security and Trust:</strong> PKI encryption provides a high level of security by encrypting data and ensuring that only authorized parties can access it. This is particularly important for SMBs that handle sensitive customer information, financial data, or intellectual property. By implementing PKI, businesses can build trust with their clients and partners, knowing their data is protected against unauthorized access.</p><p><strong>Authentication and Access Control:</strong> PKI enables robust authentication mechanisms, such as digital certificates, which verify the identity of users and devices. This helps prevent unauthorized access to critical systems and data. For SMBs, this means a reduced risk of data breaches and insider threats, leading to a more secure business environment.</p><p><strong>Compliance and Regulatory Requirements:</strong> Many industries have stringent compliance requirements regarding data security and privacy. PKI helps SMBs meet these requirements by providing a robust framework for securing communications and data. This ensures compliance and reduces the risk of legal and financial penalties associated with data breaches.</p><p>PKI Tasks in your Day-to-Day and Their Value</p><p>Understanding the practical applications of PKI is crucial for SMB leaders to appreciate its value entirely. PKI isn't just a theoretical concept; it has tangible, real-world applications that can significantly improve your business's security and operational efficiency. Let's examine some critical PKI tasks and how they translate into concrete benefits for your organization.</p><p><strong>Digital Signatures:</strong> Implementing digital signatures for documents and transactions ensures data integrity and non-repudiation. This means that any changes to the document can be detected, and the sender cannot deny having sent the document. For SMBs, this is invaluable in maintaining the authenticity of contracts, invoices, and other critical business documents.</p><p><strong>Secure Email Communication:</strong> PKI can encrypt email communications, ensuring that sensitive information is only accessible to the intended recipient. This is particularly important for SMBs that frequently communicate confidential information with clients and partners.</p><p><strong>SSL/TLS Certificates:</strong> Using SSL/TLS certificates to secure websites and online services helps protect against man-in-the-middle attacks and ensures that data transmitted between the user and the server is encrypted. This protects customer data and enhances the business's reputation by providing a secure online experience.</p><p>Current Environmental Challenges for SMBs and Some Potential Solutions</p><p>While the benefits of PKI are clear, implementing and maintaining this infrastructure is not without its challenges. Many SMBs face hurdles that can seem daunting at first glance. However, with the right approach and understanding, these obstacles can be overcome, allowing businesses to reap the full benefits of PKI. Let's explore some of the common challenges and their solutions.</p><p><strong>Complexity and Cost:</strong> One of the main challenges SMBs face when implementing PKI is its perceived complexity and cost. To overcome this, businesses can leverage managed PKI services that offer scalable solutions without the need for extensive in-house expertise. These services provide the necessary infrastructure and support, making PKI implementation more accessible and cost-effective.</p><p><strong>Integration with Existing Systems:</strong> Integrating PKI with existing IT systems and applications can be challenging. SMBs can address this by working with vendors that offer seamless integration options and provide comprehensive documentation and support. Additionally, thorough planning and testing before full-scale implementation can help identify and resolve potential issues.</p><p><strong>Ongoing Management and Maintenance:</strong> Maintaining a PKI infrastructure requires ongoing management, including certificate renewal, revocation, and monitoring. SMBs can streamline this process by using automated tools and services that handle these tasks, reducing the administrative burden on IT teams.</p><p>Future Optimization Possibilities</p><p>As technology continues to evolve rapidly, so too does the potential for PKI optimization. The future of PKI holds exciting possibilities for SMBs, with emerging technologies and innovative approaches promising to make PKI even more powerful and accessible. By staying ahead of these trends, businesses can position themselves to leverage PKI in increasingly sophisticated ways. Let's explore some future optimization possibilities that SMBs should keep on their radar.</p><p><strong>Automated Certificate Management:</strong> As PKI adoption grows, automated certificate management solutions are becoming more prevalent. These tools can automatically issue, renew, and revoke certificates, reducing the risk of human error and ensuring continuous security.</p><p><strong>Integration with Emerging Technologies:</strong> PKI can be integrated with emerging technologies such as the Internet of Things (IoT) and blockchain to enhance security. For example, PKI can provide secure communication and authentication for IoT devices, ensuring that only authorized devices can access the network.</p><p><strong>Advanced Threat Detection:</strong> By integrating PKI with advanced threat detection and response systems, SMBs can enhance their ability to detect and respond to potential threats. This includes using PKI to secure communication channels and authenticate users in real-time, providing an additional layer of security.</p><p>Advanced threat detection is crucial for SMBs to stay ahead of potential attacks, by integrating Public Key Infrastructure (PKI) with advanced threat detection and response systems. This integration creates a powerful synergy that not only secures communications but also provides real-time threat intelligence and response capabilities.

<strong>Secure Communication Channels:</strong> PKI forms the backbone of secure communication within an organization's network. When integrated with threat detection systems, it ensures that all data exchanged between systems, devices, and users is encrypted and authenticated. This means that even if a threat actor manages to intercept communications, they won't be able to decipher the content. Moreover, any attempt to tamper with the data will be immediately detected, triggering an alert in the threat detection system.

<em>For example, if an attacker tries to inject malicious code into an encrypted communication channel, the PKI system will detect the breach of integrity, and the threat detection system can immediately isolate the affected systems to prevent further spread.

</em><strong>Real-Time User Authentication:</strong> PKI provides strong authentication mechanisms through digital certificates. When combined with advanced threat detection, this allows for continuous, real-time verification of user identities. Any anomalies in user behavior or attempts to use compromised credentials can be instantly flagged and investigated.

<em>Consider a scenario where an employee's credentials are stolen. Even if the attacker uses the correct username and password, the PKI-based authentication can detect that the login attempt is coming from an unfamiliar location or device. The threat detection system can then trigger additional authentication steps or block the access attempt altogether, preventing a potential data breach.

</em><strong>Automated Certificate Management and Monitoring:</strong> Advanced threat detection systems can monitor the status of digital certificates issued by the PKI. This automated monitoring can alert security teams to expired or revoked certificates, preventing potential vulnerabilities that could be exploited by attackers.

<em>For instance, if a certificate is about to expire, the system can automatically initiate the renewal process. If a certificate is suddenly revoked, it can trigger an investigation to determine if this is due to a security breach or a routine administrative action.

</em><strong>Enhanced Visibility and Threat Intelligence:</strong> By integrating PKI with threat detection systems, SMBs gain enhanced visibility into their network activities. Every authenticated action, encrypted communication, and digital signature can be logged and analyzed. This wealth of data can be used to build comprehensive threat intelligence, helping to identify patterns of suspicious behavior or potential vulnerabilities.

<em>For example, the system might detect an unusual pattern of certificate requests from a particular department, which could indicate a compromised system attempting to establish rogue secure connections.

</em><strong>Rapid Incident Response:</strong> In the event of a detected threat, the integration of PKI with advanced threat detection systems allows for rapid and precise response. The system can quickly revoke compromised certificates, isolate affected systems, and re-establish secure communications through new certificate issuance.

<em>Imagine a scenario where a malware infection is detected on a company device. The threat detection system can immediately revoke the device's certificates, preventing it from accessing sensitive resources. Simultaneously, it can issue new certificates to clean devices, ensuring business continuity while the threat is contained and investigated.

</em>By leveraging PKI in conjunction with advanced threat detection and response systems, SMBs can create a robust, multi-layered security environment. This integration not only secures communications and authenticates users but also provides the real-time intelligence and response capabilities necessary to combat today's sophisticated cyber threats. For SMBs looking to enhance their cybersecurity posture, this approach offers a powerful way to align with the NIST CSF framework, particularly in the areas of Identifying, Protecting, Detecting, and Responding.</p><p>Actionable Summary</p><p>As explored throughout this post, PKI encryption offers significant benefits for SMBs, from enhanced security to improved compliance and threat detection. However, understanding these benefits is just the first step. To truly leverage the power of PKI and align with the NIST CSF framework, SMB leaders and security teams need to take concrete actions. Here's a summary of key steps you can take to implement and optimize PKI in your organization.</p><p>To leverage the full potential of PKI encryption and align with the NIST CSF framework, SMB leaders and security teams should:</p><p>* <strong>Implement Digital Certificates:</strong> Use digital certificates for authentication, secure email communication, and SSL/TLS for websites.</p><p>* <strong>Leverage Managed PKI Services:</strong> Consider using managed PKI services to reduce complexity and cost.</p><p>* <strong>Automate Certificate Management:</strong> Utilize automated tools to manage the lifecycle of digital certificates, ensuring continuous security.</p><p>By focusing on these critical areas, SMBs can enhance their security posture, build trust with clients and partners, and align with the NIST CSF framework.</p><p>For more information on PKI encryption and its benefits, visit <a target="_blank" href="https://cpf-coaching.com/">https://cpf-coaching.com/</a></p><p><p>Thanks for checking out the SMB Tech & Cybersecurity Leadership Newsletter! If you found this post valuable, please consider sharing it with others who would appreciate it.</p></p><p>Product of the Week: <a target="_blank" href="https://register.clym.io/r-CPFCoaching/p-cpfcoachingllc-referral_start">Clym</a></p><p></p><p>As business owners, it is vital to grasp and uphold data privacy in the modern interconnected business world. <strong>Ensuring data privacy is not just a trend; it is an essential responsibility.</strong> This means effectively managing your customers' personal information and understanding its acquisition, storage, and usage. By recognizing and respecting this right, you can establish transparent practices for handling customer data.</p><p><em>It helps tailor your website’s privacy and accessibility requirements. </em></p><p>I used it on my own website, and it was as simple as adding a small header/footer script to your page, into your Google Tag Manager, or a plugin for most website hosting providers. <a target="_blank" href="https://register.clym.io/r-CPFCoaching/p-cpfcoachingllc-referral_start">Check out getting Clym for your business’ website today.</a></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/pki-encryption-for-smb</link><guid isPermaLink="false">substack:post:147305713</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 05 Aug 2024 14:14:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/147305713/4f9ddc82061544e5e4971cd791abbd4d.mp3" length="9529004" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>737</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/147305713/1d10fd5dc4325b4e5bb65f208e3616ef.jpg"/></item><item><title><![CDATA[Empowering Small and Medium-Sized Businesses to Detect and Prevent Cyber Threats]]></title><description><![CDATA[<p>Discover how Encryption & SSL can strengthen your SMB's cybersecurity posture, align with NIST CSF, and protect against emerging threats. Learn actionable steps to implement these vital security measures.</p><p></p><p></p><p><p>Cybersecurity Leadership & SMB Security Development  is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p>Encryption & SSL: Cornerstones of SMB Cybersecurity and NIST CSF Alignment</p><p>In today's digital landscape, small and medium-sized businesses (SMBs) face an ever-growing array of cyber threats. As a seasoned cybersecurity advisor, I've witnessed firsthand the devastating impact of data breaches and cyber attacks on businesses that were caught unprepared. That's why I'm passionate about empowering SMB leaders and their security teams with the knowledge and tools they need to protect their digital assets effectively.</p><p>One of the most crucial aspects of a robust cybersecurity strategy is the implementation of strong encryption and Secure Sockets Layer (SSL) protocols. These technologies safeguard your sensitive data and play a pivotal role in aligning your security practices with the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF). In this post, we'll explore the business value of focusing on encryption and SSL and how these measures can significantly enhance your ability to identify and detect potential threats.</p><p>The Business Value of Encryption and SSL for SMBs</p><p>Encryption and SSL are not just technical jargon; they're powerful tools that provide tangible benefits to your business. By implementing these security measures, you're taking proactive steps to protect your company's most valuable assets: its data and reputation.</p><p>Encryption ensures that your sensitive information remains confidential, even if it falls into the wrong hands. This is particularly crucial for SMBs that handle customer data, financial information, or proprietary business strategies. On the other hand, SSL creates a secure data transmission channel, protecting information as it travels across networks. Together, these technologies form a formidable defense against data breaches and unauthorized access.</p><p>Aligning with NIST CSF: Identify and Detect</p><p>The NIST Cybersecurity Framework provides a comprehensive approach to managing and reducing cybersecurity risk. Two critical functions within this framework are "Identify" and "Detect," which are significantly enhanced by properly implementing encryption and SSL.</p><p>In the "Identify" function, encryption and SSL help you catalog and understand the data assets that need protection. Implementing these technologies requires you to take stock of sensitive information and prioritize its security. This process aligns perfectly with the emphasis of NIST CSF's asset management and risk assessment.</p><p>For the "Detect" function, SSL certificates and encryption protocols can serve as early warning systems. Unusual encryption activities or attempts to bypass SSL can indicate potential threats, allowing your security team to detect and respond to incidents quickly.</p><p>Practical Implementation and Challenges</p><p>Implementing encryption and SSL across your organization may seem daunting, but it's necessary in today's threat landscape. Start by identifying your most sensitive data and prioritizing its encryption. This could include customer information, financial records, and intellectual property.</p><p>For SSL, ensure that all your public-facing websites and applications use HTTPS. This protects data in transit and boosts your search engine rankings and customer trust.</p><p>One common challenge SMBs face is the misconception that robust encryption is too complex or expensive to implement. However, with the proper guidance and tools, even small businesses can achieve high security. Cloud-based solutions and managed security services have made enterprise-grade encryption more accessible.</p><p>Another hurdle is keeping up with evolving encryption standards and SSL certificate management. Regular audits and updates are crucial to maintain the effectiveness of your security measures. Consider automating certificate renewals and implementing a centralized management system to streamline this process.</p><p>Future-Proofing Your Encryption Strategy</p><p>As we look to the future, the importance of encryption and SSL will only grow. Quantum computing poses both a threat and an opportunity in encryption. While it can potentially break current encryption methods, it also paves the way for quantum-resistant algorithms.</p><p>To stay ahead of the curve, SMBs should monitor post-quantum cryptography developments. The National Institute of Standards and Technology (NIST) is already working on standardizing quantum-resistant cryptographic algorithms. Familiarizing yourself with these emerging standards can help you prepare for the future of data protection.</p><p>Additionally, consider exploring homomorphic encryption, which allows computations on encrypted data without decrypting it first. This technology could revolutionize handling sensitive data, especially in cloud environments.</p><p>Actionable Summary: Strengthening Your SMB's Cybersecurity Posture</p><p>* Conduct a thorough data inventory to identify sensitive information that requires encryption.</p><p>* Implement SSL certificates on all public-facing websites and applications.</p><p>* Develop an encryption key management strategy to ensure the security and availability of your encryption keys.</p><p>To deepen your understanding of encryption and SSL in the context of SMB cybersecurity:</p><p>* Enroll in online courses focused on cryptography and network security.</p><p>* Attend cybersecurity conferences and workshops tailored for SMBs.</p><p>* Engage with cybersecurity communities and forums to stay updated on best practices and emerging threats.</p><p>Remember, cybersecurity is an ongoing journey, not a destination. By focusing on encryption and SSL, you're taking significant steps toward a more secure and resilient business. Stay vigilant, keep learning, and don't hesitate to seek expert advice when needed.</p><p></p><p></p><p><p>Thank you for reading Cybersecurity Leadership & SMB Security Development. Share this post with SMB and tech leaders who might find it helpful and want to develop their cybersecurity programs.</p></p><p></p><p></p><p></p><p><a target="_blank" href="https://try.sanebox.com/cpfcoaching"><strong>Product of the Week: SaneBox</strong></a></p><p>Are you tired of sorting through junk in your inbox just to find the emails you really need? SaneBox does the sorting for you, saving the average user more than two hours a week on email management. </p><p>Using its proprietary AI, SaneBox organizes your incoming emails into appropriate folders, so you’ll only see the important emails when you open your inbox. You don’t have to lift a finger, and there is nothing to install, either.</p><p>With glowing reviews from TechCrunch, Forbes, The New York Times, and emailers everywhere, you can rest assured that you will fall in love with email again. </p><p><strong><em>TLDR</em></strong><em>: </em>SaneBox is an AI-driven email management tool that saves the average user 2.5 hours per week by seamlessly organizing and filtering emails. </p><p></p><p></p><p><a target="_blank" href="https://try.sanebox.com/cpfcoaching"><strong>Other SaneBox Features</strong></a></p><p>In addition to our acclaimed email management software, SaneBox offers additional features that help you spend more time outside the inbox. </p><p><em>Some fan-favorite features include:</em></p><p>* <strong>SaneLater</strong> - moves all unimportant emails into a separate folder (this is our bread and butter feature) </p><p>* 🕳 <strong>SaneBlackHole:</strong> Banish unwelcome email senders and never hear from them again.</p><p>* 🔔 <strong>SaneReminders</strong>: We’ll send a reminder to follow up when an email goes unanswered for 5 days.</p><p>* ⏰ <strong>Snooze Folders:</strong> Hit “snooze” on an email, and it’ll pop back into your inbox when you’re ready for it.</p><p><em>Additional features people love too:</em></p><p>* 🌙 <strong>DoNotDisturb:</strong> Vacation? Focus time? Turn off emails so you don’t receive them until you want them.</p><p>* 📥 <strong>Email Deep:</strong> Clean and Clear out unnecessary emails in bulk to declutter and save storage space.</p><p>* 📎 <strong>SaneAttachments</strong>: Connect your email to your cloud services to safely store attachments.</p><p>* 📄 <strong>SaneDigest</strong>: Get a daily digest of your emails to understand what’s going where and better train SaneBox.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/empowering-smbs-with-ssl</link><guid isPermaLink="false">substack:post:147109554</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 29 Jul 2024 15:37:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/147109554/cd7d00a8411010fde602b4fd1713776f.mp3" length="3727608" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>311</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/147109554/d60f7d3492a3aa7638a03ed1aff70fda.jpg"/></item><item><title><![CDATA[Lessons from Crowdstrike/Windows Cyber Outage: Key Takeaways for Robust Cybersecurity]]></title><description><![CDATA[<p>Discover essential takeaways from yesterday’s cyber outage, including understanding digital supply chain risks, implementing robust change management, and developing a comprehensive incident response plan. Enhance your cybersecurity resilience today.</p><p></p><p><p>Cybersecurity Leadership & SMB Security Development  is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p>Lessons from Yesterday’s Cyber Outage: Key Takeaways for Robust Cybersecurity</p><p>Cyber (or IT) outages can have devastating impacts on businesses, causing not only financial losses but also reputational damage. Yesterday's cyber outage was a stark reminder of the vulnerabilities that lurk within our interconnected systems. As organizations rely increasingly on digital technologies, understanding and mitigating these risks becomes paramount. Reflecting on the recent incident, several critical lessons have emerged that can help organizations fortify their defenses and enhance their incident response strategies. These takeaways highlight the importance of a comprehensive approach to cybersecurity, emphasizing the need for thorough risk assessment, robust change management, and an inclusive incident response plan. </p><p></p><p>1. Understand the Risks in Your Digital Supply Chain</p><p>One of the most crucial aspects of maintaining a secure digital environment is understanding the risks inherent in your digital supply chain or software development life cycle (SDLC). The cyber outage underscored the importance of thoroughly testing changes before large-scale deployments into production. This proactive approach identifies and mitigates potential vulnerabilities early, preventing disruptions and security breaches.</p><p>* <strong>Risk Assessment</strong>: Regularly conduct risk assessments to identify and evaluate potential threats within your digital supply chain and SDLC. This includes understanding third-party dependencies and their associated risks.</p><p>* <strong>Testing and Validation</strong>: Implement rigorous testing protocols, including penetration testing and vulnerability assessments, to validate changes before deployment. This helps in detecting flaws that cyber attackers could exploit.</p><p>* <strong>Continuous Monitoring</strong>: Establish constant monitoring systems to monitor changes and their environmental impacts. This enables real-time detection of anomalies and swift action to mitigate risks.</p><p></p><p>2. Implement a Robust Change Management Process</p><p>A robust change management process is essential for handling unforeseen issues during deployments. The recent outage demonstrated the importance of being prepared to roll back changes that do not go as expected and responding effectively to minimize disruption.</p><p>* <strong>Change Control</strong>: Develop a structured change control process that includes detailed documentation, approval workflows, and rollback procedures. This ensures that all changes are tracked and can be reversed if necessary.</p><p>* <strong>Rollback Plans</strong>: Prepare rollback plans for every deployment. These plans should be tested regularly to ensure smooth execution in case of an unexpected issue.</p><p>* <strong>Responsive Actions:</strong> Train your team to respond quickly and efficiently to unforeseen changes. This includes having a clear communication plan to inform stakeholders about the status and impact of the change.</p><p></p><p>3. Develop a Comprehensive Incident Response Plan</p><p>Having an incident response plan that encompasses the entire business is vital. Cyber incidents can affect various aspects of operations, IT, cybersecurity, development, and other business functions. An inclusive incident response plan ensures that everyone knows their role and can contribute to a coordinated response.</p><p>* <strong>Holistic Planning</strong>: Create an incident response plan that involves all business functions. Ensure that all team members clearly define and understand roles and responsibilities.</p><p>* <strong>Decision Trees</strong>: Develop decision trees to guide actions during different incidents. This helps make informed decisions quickly, even when the nature of the incident is unclear.</p><p>* <strong>Regular Drills</strong>: Conduct incident response drills to ensure all team members are prepared to act swiftly and effectively. These drills should simulate malicious and non-malicious incidents to cover all potential scenarios.</p><p><p><strong><em>Thank you for reading Cybersecurity Leadership & SMB Security Development. If you love the content of this post, we would love it if you shared it with others.</em></strong></p></p><p></p><p>Conclusion</p><p>Yesterday’s cyber outage powerfully reminds us of the importance of robust cybersecurity practices. By understanding and mitigating risks in your digital supply chain, implementing a solid change management process, and developing a comprehensive incident response plan, organizations can significantly enhance their resilience against cyber threats. Proactive preparation and continuous improvement are vital in maintaining a secure and reliable digital environment.</p><p></p><p><a target="_blank" href="https://shop.tenable.com/cpf-coaching">Product of the Week: Nessus from Tenable</a></p><p></p><p>Secure Cloud Infrastructure Before Deployment </p><p>The reliance on the cloud and infrastructure as code (IaC) to streamline development lifecycles has become crucial to every organization’s business. Yet, developers aren’t following security best practices before pushing to production, which increases risk. If unknown vulnerabilities are moved into production, taking the environment down will disrupt business continuity or force the organization to take on more risk. </p><p>•Scans IaC repositories to programmatically detect cloud infrastructure misconfigurations and vulnerabilities in the software development lifecycle's design and build phases. </p><p>•Leverages 500 prebuilt policies for IaC scanning </p><p>•Prevents misconfigurations and vulnerabilities from reaching cloud instances </p><p>•Provides a proactive approach to vulnerability assessment for cloud workloads </p><p>•Scan for disruptive and costly vulnerabilities before code is deployed. </p><p>•Prevent the downtime and additional costs and resources associated with remediating code after deployment</p><p><p>Thank you for reading Cybersecurity Leadership & SMB Security Development. If you love the content of this post, we would love it if you shared it with others.</p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/lessons-from-yesterdays-cyber-outage</link><guid isPermaLink="false">substack:post:146818273</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 20 Jul 2024 14:18:40 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/146818273/2f2a24e8ac618a97a5d5dd852cda29f2.mp3" length="4389036" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>366</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/146818273/f0e7b8aa4e6dcd38ab2d4e2c99c2557c.jpg"/></item><item><title><![CDATA[Enhancing SMB Security: The Critical Role of Desktop Protection]]></title><description><![CDATA[<p>In today's digital age, small and medium-sized businesses (SMBs) face increasing threats from cyber attacks, which can compromise sensitive data and disrupt operations. Desktop security, often overlooked, plays a crucial role in defending against these threats. For SMB leaders, focusing on desktop security not only helps in identifying and detecting potential threats but also aligns with the NIST Cybersecurity Framework (CSF) to enhance overall security posture.</p><p></p><p><p>Cybersecurity Leadership & SMB Security Development  is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>Desktop security involves protecting endpoint devices such as computers, laptops, and workstations from cyber threats. Given that these devices are gateways to the organization's network, ensuring their security is paramount. By integrating desktop security measures with the NIST CSF, SMBs can create a robust defense mechanism that supports their business objectives and regulatory compliance requirements.</p><p>Tasks and Their Business Value</p><p>Implementing desktop security involves several critical tasks that offer substantial value to the organization.</p><p>* <strong>Endpoint Protection Solutions</strong>: Deploying antivirus and anti-malware software is the first line of defense against cyber threats. These solutions help detect and eliminate malicious software, protecting sensitive business data and maintaining operational continuity.</p><p>* <strong>Patch Management</strong>: Regularly updating software and operating systems on desktops ensures that known vulnerabilities are patched. This reduces the risk of exploitation by cybercriminals and minimizes potential security breaches.</p><p>* <strong>Access Control</strong>: Implementing strict access controls, such as multi-factor authentication (MFA) and role-based access, ensures that only authorized personnel can access critical systems and data. This helps prevent unauthorized access and potential data breaches.</p><p>These tasks align with the NIST CSF’s core functions: Identify, Protect, Detect, Respond, and Recover. By addressing these areas, SMBs can systematically enhance their security posture, making it harder for attackers to compromise their systems.</p><p>Current Environmental Challenges</p><p>SMBs often face unique challenges in implementing effective desktop security. Limited budgets and resources can make it difficult to invest in advanced security solutions. Additionally, the lack of dedicated IT security staff means that many SMBs do not have the expertise needed to manage and respond to security threats effectively.</p><p>To overcome these challenges, SMBs can leverage cost-effective solutions such as cloud-based security services, which offer robust protection without the need for significant upfront investment. Training employees on basic cybersecurity practices can also enhance the overall security posture by reducing the likelihood of human error leading to security incidents.</p><p>Optimizing Desktop Security with Future Solutions</p><p>Looking ahead, SMBs can optimize desktop security by adopting innovative technologies and practices.</p><p>* <strong>Behavioral Analytics</strong>: Implementing tools that use machine learning to analyze user behavior can help detect anomalies and potential threats in real-time, providing an additional layer of security.</p><p>* <strong>Zero Trust Architecture</strong>: Moving towards a zero trust model, where every access request is authenticated, authorized, and encrypted, ensures that even if a device is compromised, the risk of further exploitation is minimized.</p><p>* <strong>Automation</strong>: Using automated tools for patch management, threat detection, and response can significantly reduce the burden on IT staff and ensure that security measures are consistently applied.</p><p>By staying abreast of these advancements, SMBs can continuously improve their desktop security measures, aligning them with the evolving threat landscape and maintaining compliance with the NIST CSF.</p><p>Summary</p><p>In conclusion, focusing on desktop security is vital for SMB leaders to protect their organizations from potential cyber threats. By implementing endpoint protection solutions, managing patches effectively, and enforcing strict access controls, SMBs can align their security efforts with the NIST CSF. Overcoming challenges such as limited resources and expertise can be achieved through cost-effective solutions and employee training. Looking to the future, adopting behavioral analytics, zero trust architecture, and automation will help optimize desktop security, ensuring a robust defense against evolving cyber threats.</p><p><strong>Action Items</strong>:</p><p>* Assess current desktop security measures and identify gaps.</p><p>* Implement endpoint protection solutions and ensure regular patch management.</p><p>* Enforce strict access controls and consider adopting MFA.</p><p>* Train employees on basic cybersecurity practices.</p><p>* Explore and adopt advanced security technologies like behavioral analytics and zero-trust architecture.</p><p><p>Thank you for reading Cybersecurity Leadership & SMB Security Development . If you enjoyed this post, please share it with SMB and tech leaders.</p></p><p>Product shout out of the week: <a target="_blank" href="https://try.sanebox.com/cpfcoaching">SaneBox</a></p><p><strong>Keeping a clean inbox is one of my most important productivity hacks.</strong></p><p>It makes everything easier. Nowadays, we get so much junk in our emails. And it's a waste of time going through it.</p><p><em>But I've found a solution to steer clear of inbox overload.</em></p><p><a target="_blank" href="https://try.sanebox.com/cpfcoaching"><strong>SaneBox</strong></a> is the all-in-one solution to email overload, called a "lifesaver" by PCMag, saving you at least 3 hours per week.</p><p>Their <em>trainable AI assistant</em> identifies important emails and automatically organizes the rest to help you stay focused.</p><p><a target="_blank" href="https://editor.systeme.io/page/14874655/edit">Sign</a> up today and save $25 on any subscription.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-smb-desktop-security</link><guid isPermaLink="false">substack:post:146528022</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 12 Jul 2024 13:48:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/146528022/65580c57509249ae43770035e1b9bbff.mp3" length="3107780" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>259</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/146528022/f5a4c6799ac4549813bf330e18cbe4af.jpg"/></item><item><title><![CDATA[Maximize Business Security: The Critical Purpose and Value of DDoS Protection]]></title><description><![CDATA[<p>Learn how DDoS protection can safeguard your business by aligning with the Identify and Protect stages of the NIST Cybersecurity Framework. Discover practical strategies and future solutions for SMBs.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/maximize-business-security-the-critical-e24</link><guid isPermaLink="false">substack:post:146087166</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 28 Jun 2024 17:54:45 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/146087166/77b6ab94544339574b54291339bac4a0.mp3" length="6170798" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>514</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/146087166/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[The Framework Foundation of NIST CSF as Risk Management for CISO & Practitioners]]></title><description><![CDATA[<p>Understanding and Implementing the NIST Cybersecurity Framework (CSF): A Guide for CISOs and Practitioners</p><p></p><p>In this episode of the Cyber Hub podcast, James Azar and Chris Filone discuss the practical application of the NIST Cybersecurity Framework (CSF) for organizational risk management. They delve into the framework's components, such as Identify, Protect, Detect, Respond, and Recover, and provide insights on how these can be tailored to suit the specific needs of any organization. The discussion emphasizes the importance of integrating privacy considerations and continuously monitoring and updating security measures to adapt to evolving threats and regulatory requirements.</p><p></p><p>Actionable Takeaways:</p><p>* <strong>Understand the NIST CSF Structure</strong>: Familiarize yourself with the framework’s components and their application.</p><p>* <strong>Perform a Gap Analysis</strong>: Identify gaps in your organization’s cybersecurity posture using the NIST CSF.</p><p>* <strong>Implement Relevant Controls</strong>: Select and apply controls that align with your organization’s risk profile.</p><p>* <strong>Integrate Privacy Considerations</strong>: Ensure privacy requirements are part of your cybersecurity strategy.</p><p>* <strong>Continuous Monitoring and Improvement</strong>: Establish ongoing monitoring processes and regularly update security measures.</p><p></p><p>Referenced links:</p><p></p><p><a target="_blank" href="https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final">The NIST Cybersecurity Framework (CSF) 2.0</a> (This is for the publication and links to many other resources)</p><p><a target="_blank" href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">Cybersecurity Framework (CSF) - NIST CSWP 29</a> (This is the NICSF CSF Framework webpage)</p><p><a target="_blank" href="https://www.nist.gov/quick-start-guides"> Navigating NIST's CSF 2.0 Quick Start Guides</a> (Business and Community profile recommendations available here)</p><p><a target="_blank" href="https://csrc.nist.gov/Projects/Cybersecurity-Framework/Filters#/csf/filters">NIST Cybersecurity Framework (CSF) 2.0 Reference Tool</a> (Exportable in Excel and JSON)</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-framework-foundation-of-nist-csf</link><guid isPermaLink="false">substack:post:144948645</guid><dc:creator><![CDATA[Christophe Foulon 📓 and James Azar]]></dc:creator><pubDate>Fri, 24 May 2024 16:21:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/144948645/31d6dcce6beab3fa12daa409c86be260.mp3" length="31560244" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and James Azar</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1972</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/144948645/4640b20dccde8efc8a0e324f71e2a15b.jpg"/></item><item><title><![CDATA[Friday Conversation: Cybersecurity Frameworks Explained CIS, NIST, MITRE & More]]></title><description><![CDATA[<p>Join James Azar and Chris Foulon on Friday Conversations podcast to unravel the complexities of cybersecurity frameworks like CIS, NIST, and MITRE. Learn their differences, practical applications, and how they impact cybersecurity strategies. Tune in for expert insights and actionable advice.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/friday-conversation-cybersecurity</link><guid isPermaLink="false">substack:post:144906837</guid><dc:creator><![CDATA[Christophe Foulon 📓 and James Azar]]></dc:creator><pubDate>Thu, 23 May 2024 13:18:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/144906837/bda002d9e091d61a2389efba2da90db6.mp3" length="27445018" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and James Azar</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1715</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/144906837/e1676bd956629fada5c9229eb1882f4c.jpg"/></item><item><title><![CDATA[Enhancing Business Security Through Identity Management in the NIST Cybersecurity Framework]]></title><description><![CDATA[<p>Harnessing the Identify and Protect Stages of NIST CSF for Enhanced Threat Protection</p><p>Explore how identity management is pivotal in the Identify and Protect stages of the NIST Cybersecurity Framework (CSF), offering robust defenses against evolving cyber threats.</p><p>In today's digital-first environment, managing internal identities efficiently and securely is paramount for organizations across all industries. Identity management encompasses the methodologies and systems that allow businesses to authenticate and authorize individuals or groups to access resources within corporate environments. However, this process comes with complex challenges that can impact security, compliance, and operational efficiency. Understanding these challenges and employing strategic improvements is crucial for maintaining robust security protocols and safeguarding sensitive information. This introduction delves into organizations' everyday challenges in managing internal identities and provides practical tips for enhancing these processes. Additionally, it highlights the critical role of collaboration among various business units, such as Human Resources, IT, Compliance, and departmental management, in fostering a secure and compliant identity management framework.</p><p><strong>Introduction to Identity Management and the NIST Cybersecurity Framework</strong></p><p>Identity management is critical to any organization’s cybersecurity strategy, particularly within the Identify and Protect stages of the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF). This framework provides guidelines on preventing, detecting, and responding to cyber threats, with identity management as a cornerstone for safeguarding digital assets. It involves processes and technologies that help manage and secure identity information to ensure the right individuals access the appropriate resources at the right times for the right reasons.</p><p><strong>The Value and Impact of Identity Management Tasks</strong></p><p>Effective identity management encompasses various tasks, each contributing uniquely to the organization's security posture. Key tasks include creating and managing user credentials, implementing multi-factor authentication (MFA), and continuously monitoring and updating access controls. These measures help reduce the risk of unauthorized access and potential breaches. For example, MFA adds layer of security that significantly mitigates the risk of compromised passwords.</p><p><strong>Challenges and Solutions in the Current Environment</strong></p><p>Today’s businesses face numerous challenges in identity management, including managing access across varied IT environments and the growing sophistication of cyber threats. Organizations are increasingly turning to cloud-based identity and access management solutions that offer scalability, real-time access updates, and integrated security features to address these issues. Additionally, adopting artificial intelligence and machine learning for behavioral analysis can predict and prevent unauthorized access based on usage patterns.</p><p><strong>Looking Forward: Innovations and Strategies in Identity Management</strong></p><p>Looking ahead, the future of identity management is geared towards more integrated and predictive systems. Innovations such as blockchain for secure, decentralized management of digital identities and biometric authentication methods are on the rise. These technologies not only enhance security but also improve user experience by streamlining authentication processes.</p><p><strong>Actionable Summary</strong></p><p>To fully leverage identity management within the Identify and Protect stages of the NIST CSF, organizations should:</p><p>* Evaluate and update their identity management policies regularly.</p><p>* Invest in training for IT staff and users to recognize phishing attempts and other common cyber threats.</p><p>* Consider adopting emerging technologies like blockchain and advanced biometrics to stay ahead of potential security threats.</p><p>For further learning and detailed understanding, professionals are encouraged to consult resources such as NIST’s official guidelines on identity management and participate in cybersecurity forums and webinars.</p><p><strong>Challenges of Internal Identity Management</strong></p><p>* <strong>The complexity of Managing Diverse User Roles:</strong> Organizations often struggle with the complexity involved in managing diverse user roles and access rights. As companies grow and roles change, keeping track of who has access to what becomes increasingly challenging.</p><p>* <strong>Integration Across Multiple Platforms:</strong> Many businesses use various applications and platforms, each with its own identity management controls. Integrating these systems without creating security gaps or user friction is a significant challenge.</p><p>* <strong>Compliance and Regulatory Requirements:</strong> Adhering to regulatory requirements for data access and protection, such as GDPR or HIPAA, adds another layer of complexity to identity management. Compliance requires meticulous control and auditing of access rights.</p><p>* <strong>Insider Threats:</strong> Managing the risk posed by insider threats is a continuous challenge. Employees with excessive access rights can accidentally or maliciously expose sensitive data.</p><p><strong>Tips for Improving Internal Identity Management Processes</strong></p><p>* <strong>Regular Audits and Reviews:</strong> Regularly audit access rights and user activities. This helps ensure that only the appropriate personnel can access sensitive systems and that any anomalous behavior is quickly detected.</p><p>* <strong>Role-based Access Control (RBAC):</strong> Implement role-based access control to minimize access privileges. Users should only have access rights essential to their job functions, reducing the risk of insider threats and data breaches.</p><p>* <strong>Unified Identity Management Solutions:</strong> Use a unified identity management system that integrates all user management across various platforms. This improves security and enhances user experience by providing single sign-on (SSO) capabilities.</p><p>* <strong>Multi-factor Authentication (MFA):</strong> Enhance security by implementing multi-factor authentication across all systems. MFA adds an extra layer of protection, making it more difficult for unauthorized users to gain access even if they have compromised credentials.</p><p><strong>Involvement of Other Business Units</strong></p><p>* <strong>Human Resources:</strong> HR plays a crucial role in identity management by initiating the user identity setup and termination processes. They ensure the right access is granted when employees join, move within, or leave the company.</p><p>* <strong>IT and Security Teams:</strong> These teams implement and maintain the identity management infrastructure. They handle the technical aspects of access controls, audits, compliance, and integrating security measures like MFA.</p><p>* <strong>Compliance and Legal Departments:</strong> These units ensure identity management processes comply with relevant laws and regulations. They also help address legal implications related to data breaches or non-compliance.</p><p>* <strong>Departmental Managers:</strong> Managers within specific departments must communicate role or employment status changes to HR and IT. They are also responsible for reviewing and approving access requests for their team members, ensuring appropriate access levels.</p><p>By addressing these challenges and leveraging cross-departmental collaboration, organizations can enhance their identity management practices, strengthening their security posture and compliance with regulatory standards.</p><p><strong>Actionable and Results-Focused Summary</strong></p><p>Efficient and secure management of internal identities is essential in today's digital-first environment, where safeguarding sensitive information and maintaining robust security protocols are paramount. Identity management is vital in authenticating and authorizing individuals within an organization, directly impacting security, compliance, and operational efficiency. Organizations can effectively enhance their security measures by understanding and addressing the complexities involved in managing diverse user roles and integrating multiple platforms.</p><p>To improve internal identity management processes, organizations should focus on several key actions:</p><p>* <strong>Implement Regular Audits and Reviews:</strong> Regular checks on access rights and user activities help maintain security integrity and quickly identify anomalies.</p><p>* <strong>Adopt Role-based Access Control (RBAC):</strong> RBAC minimizes access privileges to align with job functions, significantly reducing insider threat risks and potential data breaches.</p><p>* <strong>Utilize Unified Identity Management Solutions:</strong> Integrating all user management systems under a single framework enhances security and user experience through single sign-on (SSO) features.</p><p>* <strong>Deploy Multi-factor Authentication (MFA):</strong> Strengthening login protocols with MFA ensures an additional layer of security, protecting against unauthorized access even if credentials are compromised.</p><p>Furthermore, collaboration among various business units—such as Human Resources, IT, Compliance, and Departmental Management—is critical in fostering a secure and compliant identity management framework. HR's role in managing the lifecycle of employee access IT's responsibility for maintaining the identity management infrastructure and Compliance's oversight of regulatory adherence form a comprehensive approach to internal identity management.</p><p>By effectively addressing these areas, organizations can improve their identity management processes and enhance their overall security posture, ensuring that they remain resilient against emerging cyber threats. This strategic approach to identity management supports the broader goal of safeguarding digital assets while maintaining compliance and operational efficiency.</p><p>Citation: NIST Cybersecurity Framework (CSF). (n.d.). Framework for Improving Critical Infrastructure Cybersecurity. National Institute of Standards and Technology. <a target="_blank" href="https://www.nist.gov/cyberframework">https://www.nist.gov/cyberframework</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-business-security-through-593</link><guid isPermaLink="false">substack:post:144330721</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 05 May 2024 14:04:22 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/144330721/569b47fde049502282122e3089a49567.mp3" length="8385351" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>699</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/144330721/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Mastering Shadow IT: Strategies for Integrating Unsanctioned Tech into Your Golden Road Develop]]></title><description><![CDATA[<p>Explore practical strategies to manage and integrate shadow IT into your secured development processes, enhancing security and compliance without stifling innovation. Learn how MSSPs and security consultants can help your business transform shadow IT challenges into assets for growth and security.</p><p>See post for more detailed write up:</p><p><a target="_blank" href="https://substack.cpf-coaching.com/p/mastering-shadow-it-strategies-for">https://substack.cpf-coaching.com/p/mastering-shadow-it-strategies</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/mastering-shadow-it-strategies</link><guid isPermaLink="false">substack:post:144198532</guid><dc:creator><![CDATA[Christophe Foulon 📓 and Jon Salisbury]]></dc:creator><pubDate>Wed, 01 May 2024 10:43:16 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/144198532/0aafed1769f9253627c446126ae02b36.mp3" length="12925328" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and Jon Salisbury</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1077</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/144198532/8fa5edc1e1db4d1ec105b65a5afba269.jpg"/></item><item><title><![CDATA[The Pillars of Zero Trust, Trust but Verify feat Chris Foulon & James Azar]]></title><description><![CDATA[<p>Join us live on Fridays at 11 am EST and ask your questions live. If you like a topic covered, send it over to us. </p><p>The concept of "Trust but verify" within the realm of "Zero Trust" security frameworks is quite intriguing, as it merges a traditional approach to security with a more contemporary, stringent model.</p><p>Originally, "Trust but verify" was a security principle that emphasized the need for continuous validation. In practice, this means that while organizations might initially trust users or systems, they must consistently verify their credentials and permissions to maintain security. This approach recognizes that trust is essential but must be accompanied by ongoing scrutiny to be effective.</p><p>On the other hand, "Zero Trust" is a security model based on the philosophy of "never trust, always verify." This model assumes that threats could be internal or external, requiring strict identity verification, strict access controls, and network segmentation to minimize risks. Zero Trust does not inherently trust any entity inside or outside its perimeters at the outset; instead, it demands continuous validation of every request as if it originates from an untrusted source.</p><p>When we discuss blending "Trust but verify" with "Zero Trust," we look at a nuanced approach that applies rigorous and continuous verification processes in every interaction within an IT environment, regardless of the origin's assumed trustworthiness. This integration helps businesses protect sensitive data and systems by enforcing strict access controls while ensuring that every action is subject to security checks, reducing potential breaches and enhancing overall security posture.</p><p>For businesses, adopting a "Trust but verify" stance within a zero-trust framework means securing their networks and data more effectively and fostering a culture of security that aligns with dynamic business environments and evolving threat landscapes. This approach ensures that security measures are robust, scalable, and capable of supporting immediate operational needs and long-term strategic goals.</p><p>When practitioners focus on the "Trust but Verify" pillar within a Zero Trust framework, they should be vigilant about several key aspects that ensure this principle is effectively implemented to safeguard their organization's IT environment. Here are some essential points of concern:</p><p>* <strong>Continuous Verification</strong>: Continuous verification is at the heart of the "Trust but Verify" approach. Practitioners need to ensure that verification processes are not just a one-time event but ongoing. This includes re-authenticating users and re-validating their access rights on a regular basis or dynamically based on context, such as changes in user behavior or risk level.</p><p>* <strong>Multi-Factor Authentication (MFA)</strong>: Implementing MFA is crucial. This security measure adds an extra layer of protection by requiring two or more credentials to verify a user’s identity. Practitioners should ensure these authentication factors are robust and diverse (something you know, something you have, and something you are).</p><p>* <strong>Least Privilege Access Control</strong>: Access rights should be tightly controlled and restricted based on the principle of least privilege. This means users are granted only the access necessary to perform their job functions. Practitioners must regularly review and adjust these permissions to adapt to changes in roles and responsibilities.</p><p>* <strong>Audit and Log Review</strong>: Regular audits and log reviews are critical for detecting and responding to anomalies and potential security threats. Practitioners should implement automated tools to help monitor and analyze activity logs for unusual actions that could indicate a breach or security risk.</p><p>* <strong>Endpoint Security</strong>: With numerous devices accessing the network, securing these endpoints is vital. Practitioners should ensure that all devices are regularly updated, monitored for compliance with security policies, and scanned for vulnerabilities.</p><p>* <strong>Encryption and Data Security</strong>: Data should be encrypted at rest and in transit to protect it from unauthorized access. Practitioners must enforce strong encryption standards and regularly update cryptographic keys and protocols to guard against emerging threats.</p><p>* <strong>Segmentation of Network</strong>: Network segmentation divides the network into smaller, manageable segments, which can limit the spread of breaches within systems. Practitioners should ensure that these segments are properly secured and that their interactions are monitored to prevent attackers' lateral movement.</p><p>* <strong>User Education and Awareness</strong>: Human error often leads to security breaches. Practitioners should invest in regular training programs to keep users aware of security best practices and the latest phishing tactics, thereby reducing the risk of security lapses.</p><p>* <strong>Adaptive Security Policies</strong>: Security policies should be adaptable based on context and risk. This includes adjusting access controls based on the user's location, device security posture, and network threats.</p><p>By concentrating on these points, practitioners can effectively implement the "Trust but Verify" pillar within a zero-trust framework, enhancing their organization's security posture while accommodating the flexibility needed for business operations. This approach strengthens defenses and supports a proactive, resilient security culture.</p><p></p><p>We talked about the course I developed at the end to help students understand the foundations of LLM and prompt engineering. Here is the course for those interested. </p><p></p><p>Join us to unlock the full potential of LLM technology and stay ahead in the competitive landscape.</p><p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-pillars-of-zero-trust-trust-but</link><guid isPermaLink="false">substack:post:143748475</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 19 Apr 2024 15:58:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/143748475/a90cf60384a9cc45e271eb60febacfa2.mp3" length="29229704" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1827</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/143748475/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[The Pillars of Zero Trust_ Assuming Breach feat Chris Foulon & James Azar]]></title><description><![CDATA[<p>The "Assume Breach" pillar of the Zero Trust model is grounded in the understanding that security breaches are not just possible; they are inevitable. This pragmatic approach dictates that organizations should plan and build their security architectures as if the attackers are already inside their network. Here’s a detailed exploration of the critical strategies under this pillar:</p><p><strong><em> 1. Detect and Respond</em></strong></p><p>Under the assumption of a breach, detection, and response capabilities are designed to identify and mitigate threats swiftly before they can cause significant damage. This includes:</p><p>- Intrusion Detection Systems (IDS): monitor network traffic for suspicious activities and known threats, signaling alerts when potential security breaches are detected.</p><p><strong>- Security Information and Event Management (SIEM) Systems:</strong> SIEM systems collect and aggregate logs from various sources within the network, applying analytics to detect patterns or anomalies that might indicate malicious activity.</p><p><strong>- Automated Response Solutions:</strong> Upon detecting a threat, automated systems can respond immediately by isolating affected segments, blocking malicious communications, or terminating harmful processes, thereby reducing the window of opportunity for attackers to exploit.</p><p><strong><em>2. Limit Lateral Movement</em></strong></p><p>Once an attacker gains access to a part of the network, their next goal is often to move laterally to reach valuable data or systems. Strategies to limit this movement include:</p><p>- <strong>Network Segmentation:</strong> Dividing the network into smaller, isolated segments or zones can control how traffic moves across the network and limit access to critical assets. Firewalls and access control lists (ACLs) enforce these boundaries by controlling traffic flow based on security policies.</p><p>- <strong>Application Segmentation:</strong> Beyond network segmentation, application-level segmentation can further restrict access to applications based on user identity and context, limiting an attacker’s ability to access sensitive applications.</p><p>- <strong>User and Entity Behavior Analytics (UEBA)</strong>: This technology uses machine learning to understand normal user behavior and can detect deviations that suggest malicious activity, such as an unauthorized attempt to access data.</p><p><strong><em> 3. Enhance Monitoring</em></strong></p><p>Comprehensive monitoring is essential for detecting unusual activities that may indicate a breach. Enhanced monitoring techniques include:</p><p>- <strong>Log Management:</strong> Collecting and analyzing logs from all devices and applications across the network provides visibility into activities and potential security incidents.</p><p>- <strong>Endpoint Detection and Response (EDR)</strong>: EDR tools are deployed on endpoints to monitor and collect data about potentially malicious activities, which can be used to identify and respond to threats.</p><p>Continuous Monitoring: Continuous monitoring involves the ongoing analysis of security controls and user activities, ensuring that any deviations from the norm can be detected and responded to in real-time.</p><p>The "Assume Breach" approach shifts the security strategy from merely trying to prevent perimeter attacks to actively managing network security, acknowledging that perfect perimeter defense is unachievable. This mindset encourages continuous improvement of internal controls and rapid response strategies, ultimately strengthening the organization’s resilience against attacks.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-pillars-of-zero-trust_-assuming</link><guid isPermaLink="false">substack:post:143527777</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 12 Apr 2024 17:56:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/143527777/a3cb2b840b73fae9f69f62b8224a49b5.mp3" length="28738601" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1796</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/143527777/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Podcast - Mastering Vulnerability Management: The Power of Prioritization with EPSS]]></title><description><![CDATA[<p>Discover how EPSS transforms vulnerability management for business leaders, offering strategic insights into cybersecurity's most pressing challenges and future-proof solutions.</p><p>Originally posted here :</p><p>https://substack.cpf-coaching.com/p/mastering-vulnerability-management-e45</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/podcast-mastering-vulnerability-management</link><guid isPermaLink="false">substack:post:143414965</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 10 Apr 2024 12:47:33 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/143414965/81c40da362c47e8df8e5cb4ae5017054.mp3" length="2960449" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>247</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/143414965/1c17fb92391cf39fe9f992847fa91fbf.jpg"/></item><item><title><![CDATA[Understanding Container Security: Essential Insights for Business Leaders ]]></title><description><![CDATA[<p>Audio Version | Discover the critical role of container security in managing vulnerabilities and shaping the future of cybersecurity for business leaders. Gain actionable insights and explore forward-thinking solutions in our guide.</p><p>Originally posted here: <a target="_blank" href="https://substack.cpf-coaching.com/p/understanding-container-security">https://substack.cpf-coaching.com/p/understanding-container-security</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/understanding-container-security-1ed</link><guid isPermaLink="false">substack:post:143284568</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 05 Apr 2024 15:26:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/143284568/c875efea860b97562100dabe76c0ba82.mp3" length="1818794" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>152</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/143284568/524ec0dc918b1140336da14b0263767f.jpg"/></item><item><title><![CDATA[Two CISOs Talking Cyber Podcast - Zero Trust Security: Least Privilege]]></title><description><![CDATA[<p>Two CISOs Talking Cyber Podcast - Zero Trust Security: Least Privilege</p><p><a target="_blank" href="https://substack.com/profile/27297742-james-azar">James Azar</a> and I discussed the first tenet of Zero Trust Architecture in today’s podcast. I will include additional resources and references for those looking to go deeper down the Rabbit Hole.</p><p></p><p>Previous blogs on the topic from me:</p><p></p><p>NIST SP 800-207 <a target="_blank" href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf">https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf</a></p><p>Summary:</p><p>Understanding the principle of Least Privilege is essential for enhancing cybersecurity within an organization. Here's a breakdown of the minimum pros, cons, opportunities, and challenges associated with its use:</p><p><strong>Pros:</strong></p><p>* <strong>Enhanced Security:</strong> By limiting access rights for users to the bare minimum necessary to perform their tasks, the principle of Least Privilege reduces the potential attack surface for cybercriminals.</p><p>* <strong>Reduced Insider Threats:</strong> It minimizes the risk of insider threats, whether intentional or accidental, by restricting access to sensitive information and critical systems.</p><p>* <strong>Easier Compliance:</strong> Helps organizations comply with regulatory standards and privacy laws by demonstrating that access controls are in place and that data exposure is minimized.</p><p><strong>Cons:</strong></p><p>* <strong>Implementation Complexity:</strong> Setting up Least Privilege access can be complex and time-consuming, requiring a detailed understanding of every user's role and responsibilities.</p><p>* <strong>Potential Productivity Impact:</strong> If not managed properly, it could lead to situations where employees are unable to access necessary resources promptly, affecting productivity.</p><p>* <strong>Ongoing Management:</strong> Requires continuous monitoring and adjustment as roles change within an organization, adding to administrative overhead.</p><p><strong>Opportunities:</strong></p><p>* <strong>Improved Security Posture:</strong> Implementing Least Privilege can significantly enhance an organization's overall security posture, making it more resilient to attacks.</p><p>* <strong>Cost Savings:</strong> By reducing the risk of data breaches, organizations can save on the costs associated with cyber incidents, including fines, remediation efforts, and reputational damage.</p><p>* <strong>Adaptability to Cloud Environments:</strong> As more organizations move to cloud-based services, Least Privilege can be efficiently implemented to manage access in these dynamic environments.</p><p><strong>Challenges:</strong></p><p>* <strong>Determining Access Levels:</strong> Accurately defining the access levels required for each user or system can be challenging, especially in complex environments with many interdependent systems and applications.</p><p>* <strong>Resistance from Users:</strong> Users accustomed to having broad access may resist the imposition of more restrictive controls, perceiving it as a loss of autonomy or trust.</p><p>* <strong>Keeping Policies Up-to-Date:</strong> As organizations evolve, keeping access privileges aligned with current roles and responsibilities requires ongoing vigilance and effort.</p><p>Incorporating Least Privilege within an organization's security framework presents a balanced set of pros and cons. While it significantly enhances security and compliance, it demands careful planning and continuous management. However, the opportunities it presents for improving an organization's security posture and reducing the risk of data breaches are compelling reasons to overcome these challenges.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/two-cisos-talking-cyber-podcast-zero</link><guid isPermaLink="false">substack:post:142864342</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 22 Mar 2024 16:55:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142864342/4e319bbd2c3ed83a71ccd8623c217efe.mp3" length="26604084" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1662</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142864342/c2a73593ff02b13d5a707bd22c7b400b.jpg"/></item><item><title><![CDATA[Unlocking the Power of API Security for Business Success]]></title><description><![CDATA[<p>Fortify Your Digital Frontiers: The Power of API Security</p><p>Explore the critical role of API (Application Programming Interface) security in safeguarding your applications and business. Understand its tasks, challenges, and future solutions through our comprehensive guide designed for business leaders.</p><p>Originally posted here: <a target="_blank" href="https://substack.cpf-coaching.com/p/unlocking-the-power-of-api-security">https://substack.cpf-coaching.com/p/unlocking-the-power-of-api-security</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/unlocking-the-power-of-api-security-3f5</link><guid isPermaLink="false">substack:post:142832776</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 21 Mar 2024 17:09:47 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142832776/5621c093cd3ae8a16d4422726178c514.mp3" length="1965184" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>164</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142832776/88de32867209e82e2bb7c2079e3305c1.jpg"/></item><item><title><![CDATA[Secure Your Code, Secure Your Future: The Pillar of Application Security]]></title><description><![CDATA[<p>In an era where digital innovation is king, the integrity of application development processes has never been more critical. At the heart of this digital fortress lies Source Code Supply Chain Security, a linchpin in safeguarding our digital assets against the ever-evolving threats of the cyber world. This introductory dive explores the unseen vulnerabilities within our applications and unveils the paramount importance of securing the very DNA of our software - the source code. As we navigate the complexities of application security, understanding and implementing robust source code supply chain security measures emerge as a basic practice and a necessity in protecting our digital future. Join us as we unravel the layers of protection between your applications and potential adversaries, shedding light on the silent guardians of the digital age. </p><p></p><p>Original article posted here:</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/secure-your-code-secure-your-future-34f</link><guid isPermaLink="false">substack:post:142647251</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 15 Mar 2024 15:39:14 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142647251/5a8e19420f377e2f564a091b52aaed0d.mp3" length="1908760" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>159</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142647251/29061eacfa57976923b4da707aa39aee.jpg"/></item><item><title><![CDATA[Two CISOs Talking Cyber - The Pillars of Zero Trust and Least Privilege: featuring Chris Foulon and James Azar]]></title><description><![CDATA[<p>The conversation, hosted by James Azar on the Cyber Hub Podcast, delves into the concepts of zero trust and least privilege in cybersecurity. With contributions from speakers including Chris Foulon, they explore the multifaceted approach to access and data management within the framework of zero trust, providing insights into practical implementation and the underlying philosophy guiding these principles.</p><p>Main Points:</p><p>* <strong>Concept and Importance of Least Privilege</strong>: The discussion highlights least privilege as a critical aspect of cybersecurity, emphasizing its role beyond mere access management. It's portrayed as a comprehensive framework that includes access, availability, data classification, and understanding, ensuring individuals access the necessary resources and information precisely when needed, thereby enhancing security and efficiency.</p><p>* <strong>Implementation Challenges and Strategies</strong>: Speakers touch upon the practical challenges of implementing least privilege, including the need for a nuanced understanding of business operations and the role of security in enabling business objectives. They discuss the importance of balancing security measures with business productivity, avoiding overly restrictive practices that may hinder operational efficiency or encourage circumvention of security protocols.</p><p>* <strong>Evolution of Access Management</strong>: The conversation also covers the evolution of access management towards automation and just-in-time access, reflecting on the advancements in technology that enable more dynamic, context-sensitive, and efficient control over access rights. This approach facilitates the application of least privilege principles by granting access based on immediate need, thereby reducing the risk of excessive privileges accumulating over time.</p><p>The podcast provides a deep dive into the principles of least privilege and zero trust, illustrating their significance in contemporary cybersecurity practices. It underscores the balance required between enforcing robust security measures and supporting the operational needs of a business, all while adapting to the evolving landscape of threats and technological advancements.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/two-cisos-talking-cyber-the-pillars</link><guid isPermaLink="false">substack:post:142426908</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 08 Mar 2024 17:25:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142426908/4b6a631189caebacdaab28733e25a78d.mp3" length="26604084" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1662</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142426908/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[What do CISO’s Really think of NIST CSF 2.0 featuring Chris Foulon and James Azar Exploring NIST CSF 2.0: A Fresh Perspective on Cybersecurity Frameworks ]]></title><description><![CDATA[<p>Co-produced with James Azar - Exploring NIST CSF 2.0: A Fresh Perspective on Cybersecurity Frameworks A Dive into the Enhanced NIST Cybersecurity Framework</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/what-do-cisos-really-think-of-nist-12d</link><guid isPermaLink="false">substack:post:142221588</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 01 Mar 2024 20:05:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142221588/316fd5505f8ec74596c3526dd2c08273.mp3" length="28232035" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1764</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142221588/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Embracing Evolution: Navigating the Shift from NIST CSF 1.0 to 2.0]]></title><description><![CDATA[<p></p><p>Introduction to NIST Cybersecurity Framework (CSF)</p><p>Before exploring the changes, let's understand the NIST Cybersecurity Framework. Consider it a comprehensive guide for organizations to manage cybersecurity risks. Like a detailed map that helps you navigate an unknown city, the NIST CSF helps organizations navigate the complex landscape of cybersecurity threats and practices.</p><p>Transitioning from NIST CSF 1.0 to 2.0</p><p>Expanding on the specific changes introduced in NIST CSF 2.0 provides a clearer picture of how the framework has evolved to address the dynamic landscape of cybersecurity threats and the increasing importance of privacy.</p><p>The changes introduced in NIST CSF 2.0 reflect a natural evolution of the framework in response to the ever-changing cybersecurity landscape. By incorporating privacy considerations, emphasizing supply chain security, clarifying language, offering customization, and aligning with other NIST publications, the updated framework aims to provide organizations with a more effective, flexible, and comprehensive tool for managing cybersecurity risks.</p><p>For business stakeholders, understanding these specific changes is crucial for effectively leveraging the NIST CSF to enhance their organization's cybersecurity posture. Implementing the updated practices and principles of NIST CSF 2.0 can help organizations protect against evolving cyber threats, ensure personal data privacy, and foster a resilient and secure digital environment.</p><p>Originally posted: </p><p><a target="_blank" href="https://substack.cpf-coaching.com/p/csf-2">https://substack.cpf-coaching.com/p/csf-2</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/embracing-evolution-navigating-the</link><guid isPermaLink="false">substack:post:142207990</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 01 Mar 2024 20:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/142207990/cacc1cc4e446efaf5941fcb8c4d9d63c.mp3" length="5650017" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>471</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/142207990/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Is Zero Trust a Buzzword or something SMBs can implement?]]></title><description><![CDATA[<p>Imagine your business as a modern-day fortress in an era of digital warfare, where threats don't march in broad daylight but lurk in the shadows of the digital world. Traditional moats and walls (perimeter-based security) are no longer sufficient in this landscape. Enter Zero Trust is a strategy not just of defense but of intelligent, dynamic warfare against cyber threats. This blog post deciphers the principles and tenants of Zero Trust, transforming them into a blueprint for constructing an impregnable digital fortress.</p><p><p>Cybersecurity Leadership Development Coaching | CPF Coaching is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>Originally posted:</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/is-zero-trust-a-buzzword-or-something-c1a</link><guid isPermaLink="false">substack:post:141996969</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 24 Feb 2024 15:57:52 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141996969/78a77e80cf9d59acffe3702b38492da8.mp3" length="2717511" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>226</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141996969/052822dcde2178f55b78f914f167d4ab.jpg"/></item><item><title><![CDATA[Zero Trust Done Right with James Azar & Christophe Foulon ]]></title><description><![CDATA[<p>Lists of books mentioned</p><p>Start-Up Secure: Baking Cybersecurity into Your Company from Founding to Exit <a target="_blank" href="https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736">https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736</a></p><p>Project Zero Trust: A Story About a Strategy for Aligning Security and the Business <a target="_blank" href="https://www.amazon.com/Project-Zero-Trust-Strategy-Aligning/dp/B0BG6D1J26/">https://www.amazon.com/Project-Zero-Trust-Strategy-Aligning/dp/B0BG6D1J26/</a></p><p>A Data-Driven Computer Defense: THE Computer Defense You Should Be Using <a target="_blank" href="https://www.amazon.com/Data-Driven-Computer-Defense-Should-Using/dp/B0BR9KS3ZF/">https://www.amazon.com/Data-Driven-Computer-Defense-Should-Using/dp/B0BR9KS3ZF/</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/zero-trust-done-right-with-james</link><guid isPermaLink="false">substack:post:141968626</guid><dc:creator><![CDATA[Christophe Foulon 📓 and James Azar]]></dc:creator><pubDate>Fri, 23 Feb 2024 20:15:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141968626/afa2467876e8bdd8f3d51c76279fdccb.mp3" length="28381246" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓 and James Azar</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1774</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141968626/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Maximizing Application Security with OSS]]></title><description><![CDATA[<p>Discover the critical importance of inventorying open-source components in your application security program. Learn how this practice can safeguard your business from vulnerabilities and enhance your software's integrity.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/maximizing-application-security-with-81c</link><guid isPermaLink="false">substack:post:141870856</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 20 Feb 2024 19:58:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141870856/0e6b89fe7a7688b001f17595d49f14ee.mp3" length="2761396" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>230</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141870856/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Breaking into Cybersecurity Leadership Roselle Safran]]></title><description><![CDATA[<p></p><p><p>Thank you for reading Cybersecurity Leadership Development Coaching | CPF Coaching. This post is public, so feel free to share it.</p></p><p>Breaking into Cybersecurity Leadership Roselle Safran</p><p></p><p>Roselle Safran on LinkedIn https://www.linkedin.com/in/rosellesafran/</p><p>Sponsored by CPF Coaching LLC - http://cpf-coaching.com</p><p>The Breaking into Cybersecurity: It’s a conversation about what they did before, why did they pivot into cyber, what the process was they went through Breaking Into Cybersecurity, how they keep up, and advice/tips/tricks along the way.</p><p>The Breaking into Cybersecurity Leadership Series is an additional series focused on cybersecurity leadership and hearing directly from different leaders in cybersecurity (high and low) on what it takes to be a successful leader. We focus on the skills and competencies associated with cybersecurity leadership and tips/tricks/advice from cybersecurity leaders.</p><p>This podcast runs on listener support and funding. Consider supporting this podcast:</p><p><a target="_blank" href="https://breaking-into-cybersecurity.captivate.fm/support">https://breaking-into-cybersecurity.captivate.fm/support</a></p><p>Check out our books:</p><p>Develop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level: <a target="_blank" href="https://amzn.to/3443AUI">https://amzn.to/3443AUI</a> Hack the Cybersecurity Interview: A complete interview preparation guide for jumpstarting your cybersecurity career <a target="_blank" href="https://www.amazon.com/dp/1801816638/">https://www.amazon.com/dp/1801816638/</a></p><p>About the hosts:</p><p>Renee Small is the CEO of Cyber Human Capital, one of the leading human resources business partners in the field of cybersecurity, and author of the Amazon #1 best-selling book, Magnetic Hiring: Your Company's  Secret Weapon to Attracting Top Cyber Security Talent. She is committed to helping leaders close the cybersecurity talent gap by hiring from within and helping more people get into the lucrative cybersecurity profession. <a target="_blank" href="https://www.linkedin.com/in/reneebrownsmall/">https://www.linkedin.com/in/reneebrownsmall/ </a></p><p>Download a free copy of her book at <a target="_blank" href="http://magnetichiring.com/book">magnetichiring.com/book</a></p><p>Christophe Foulon focuses on helping to secure people and processes with a solid understanding of the technology involved. He has over ten years of experience as an experienced Information Security Manager and Cybersecurity Strategist with a passion for customer service, process improvement, and information security. He has significant experience in optimizing the use of technology while balancing the implications to people, processes, and information security by using a consultative approach.</p><p><a target="_blank" href="https://www.linkedin.com/in/christophefoulon/">https://www.linkedin.com/in/christophefoulon/</a></p><p>Find out more about CPF-Coaching at </p><p>https://www.cpf-coaching.com</p><p>* Website: <a target="_blank" href="https://www.cyberhubpodcast.com/breakingintocybersecurity">https://www.cyberhubpodcast.com/breakingintocybersecurity</a></p><p>* Podcast: <a target="_blank" href="https://feeds.captivate.fm/breaking-into-cybersecurity/">https://feeds.captivate.fm/breaking-into-cybersecurity/</a></p><p>* YouTube: <a target="_blank" href="https://www.youtube.com/c/BreakingIntoCybersecurity">https://www.youtube.com/c/BreakingIntoCybersecurity</a></p><p>* Linkedin: <a target="_blank" href="https://www.linkedin.com/company/breaking-into-cybersecurity/">https://www.linkedin.com/company/breaking-into-cybersecurity/</a></p><p>* Twitter: <a target="_blank" href="https://twitter.com/BreakintoCyber">https://twitter.com/BreakintoCyber</a></p><p>* Twitch: <a target="_blank" href="https://www.twitch.tv/breakingintocybersecurity">https://www.twitch.tv/breakingintocybersecurity</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/breaking-into-cybersecurity-leadership</link><guid isPermaLink="false">substack:post:141733918</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 16 Feb 2024 16:25:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141733918/64b1ac73b813ea20f9e5a5a48c5c3043.mp3" length="20337374" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>1695</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141733918/623cd90db71dabd45815599dd6152e24.jpg"/></item><item><title><![CDATA[The Strategic Imperative of Application Security Integration into the SDLC and Project Delivery The Strategic Imperative of Application Security Integration into the SDLC and Project Delivery]]></title><description><![CDATA[<p>In the dynamic realm of digital transformation, <strong>integrating</strong> application security into the Software Development Life Cycle (SDLC) and project delivery has emerged as a pivotal strategy for businesses aiming to navigate the complexities of the modern cybersecurity landscape.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-strategic-imperative-of-application-518</link><guid isPermaLink="false">substack:post:141609126</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 12 Feb 2024 16:58:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141609126/de054e6a48b48b80c90e52dda0e00100.mp3" length="2515323" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>210</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141609126/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Enhancing Application Security: A Deep Dive into OWASP and SANS Top 10 Training and Review]]></title><description><![CDATA[<p>Step up your application security game! Our latest blog explores how training and reviewing with OWASP & SANS Top 10 can make a difference. #ApplicationSecurity #OWASP #SANSTop10</p><p>This expanded blog post provides a more in-depth look at the significance of training and review in application security, specifically through the lens of the OWASP and SANS Top 10. It aims to educate and motivate a broad range of stakeholders to adopt these practices for enhanced security.</p><p>This podcast runs on listener support and funding. Consider supporting this podcast:</p><p>https://breaking-into-cybersecurity.captivate.fm/support</p><p>Check out our books: </p><p>Develop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level: https://amzn.to/3443AUI</p><p>Hack the Cybersecurity Interview: A complete interview preparation guide for jumpstarting your cybersecurity career https://www.amazon.com/dp/1801816638/</p><p>_________________________________________</p><p>About the hosts:   </p><p>Christophe Foulon focuses on helping to secure people and processes with a solid understanding of the technology involved. He has over ten years of experience as an experienced Information Security Manager and Cybersecurity Strategist with a passion for customer service, process improvement, and information security. He has significant experience in optimizing the use of technology while balancing the implications to people, processes, and information security by using a consultative approach.</p><p>https://www.linkedin.com/in/christophefoulon/</p><p>Find out more about CPF-Coaching at https://www.cpf-coaching.com</p><p>- Website: https://www.cyberhubpodcast.com/breakingintocybersecurity</p><p>- Podcast: https://feeds.captivate.fm/breaking-into-cybersecurity/</p><p>- YouTube: https://www.youtube.com/c/BreakingIntoCybersecurity</p><p>- Linkedin: https://www.linkedin.com/company/breaking-into-cybersecurity/</p><p>- Twitter: https://twitter.com/BreakintoCyber</p><p>- Twitch: https://www.twitch.tv/breakingintocybersecurity</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/enhancing-application-security-a-805</link><guid isPermaLink="false">substack:post:141074351</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 26 Jan 2024 17:01:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/141074351/b9eae90ba823de146edb71e06ccbe07d.mp3" length="3618419" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>226</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/141074351/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Insights into the CISO MindMap - Mastering Vulnerabilities: Elevating Business Security with a Priority Focused Approach]]></title><description><![CDATA[<p>Dive deep into vulnerability classification, and learn why a Priority Focused Approach is a game-changer for business cybersecurity in the digital era.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/insights-into-the-ciso-mindmap-mastering</link><guid isPermaLink="false">substack:post:137069228</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 15 Sep 2023 13:51:02 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/137069228/9bb94f49ed67645e5dfd42e67cb552cb.mp3" length="2796630" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>233</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/137069228/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[The Power of Identification in Continuous Vulnerability Management]]></title><description><![CDATA[<p>Uncover the significance of identification in periodic vulnerability management. Stay updated on current challenges and future-forward solutions to safeguard your digital assets.</p><p>Diving into the CISO Mindmap - A series providing increased clarity into the role of a CISO</p><p>I wanted to pay homage to the work of Rafeeq Rehman and the CISO Mind Map https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/ so with the approval of Rafeeq; I will take an overview or summary of the different areas.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-power-of-identification-in-continuous</link><guid isPermaLink="false">substack:post:136339952</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 28 Aug 2023 15:24:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/136339952/8a92549431fe5ea607be7cc0ee0fcde2.mp3" length="5210432" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>242</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/136339952/bf5fd15b614dd9d0dad2e193137e7589.jpg"/></item><item><title><![CDATA[Strengthening Your Armor_ A Guide to Effective Vulnerability Management]]></title><description><![CDATA[<p>As a business leader, ensuring a secure digital environment is crucial. Our latest blog post covers the importance of vulnerability management, offering insights into identification tasks, environmental challenges, and forward-looking solutions. Stay ahead of the curve! #Cybersecurity #VulnerabilityManagement</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/strengthening-your-armor_-a-guide</link><guid isPermaLink="false">substack:post:136339879</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 25 Aug 2023 15:22:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/136339879/f6c19baea699e8068fbf7b04ce79d753.mp3" length="3586622" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>299</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/136339879/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Unveiling Cybersecurity's Secret Weapon_ A Deep Dive into Identification in Comprehensive Vulnerability Management]]></title><description><![CDATA[<p>The Indispensable Role of Identification in Comprehensive Vulnerability Management: In-depth Insights for Modern Business Leaders</p><p>Diving into the CISO Mindmap - A series providing increased clarity into the role of a CISO</p><p>I wanted to pay homage to the work of Rafeeq Rehman and the CISO Mind Map <a target="_blank" href="https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/">https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/</a> so with the approval of Rafeeq; I will take an overview or summary of the different areas.</p><p> Unearth the essential function of identification within comprehensive vulnerability management, the associated tasks, present environmental challenges, and innovative future solutions. Equip your business with practical strategies and action plans to bolster your cybersecurity preparedness.</p><p>Posted: <a target="_blank" href="https://substack.cpf-coaching.com">https://substack.cpf-coaching.com</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/unveiling-cybersecuritys-secret-weapon_</link><guid isPermaLink="false">substack:post:136339813</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Aug 2023 15:21:38 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/136339813/774d434a1db9880a6de01d8008e7e564.mp3" length="3226979" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>269</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/136339813/93471f954e0edcfd7a82cd4bb413a681.jpg"/></item><item><title><![CDATA[Navigating the Cyber Landscape: IoT Vulnerability Management, Challenges and Solutions]]></title><description><![CDATA[<p>Navigating the Cyber Landscape: IoT Vulnerability Management, Challenges and Solutions</p><p>Uncover the scope of IoT in vulnerability management.</p><p>I wanted to pay homage to the work of Rafeeq Rehman and the CISO Mind Map https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/ so with the approval of Rafeeq; I will take an overview or summary of the different areas. </p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-the-cyber-landscape-iot-b14</link><guid isPermaLink="false">substack:post:132981847</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 04 Jul 2023 12:28:19 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/132981847/abd8c7540770c415c17823c28611bb8a.mp3" length="3051787" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>254</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/132981847/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Optimizing Security: The Importance of Scoping Network Devices in Your Vulnerability Management Program]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/optimizing-security-the-importance-ec0</link><guid isPermaLink="false">substack:post:127547025</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 14 Jun 2023 13:46:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/127547025/b00e261c4a28dacfc10330becccf3bb0.mp3" length="2753006" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>229</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/127547025/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Navigating Vulnerability Management_ Scoping Operating Systems for a Secure Business Future]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-vulnerability-management_</link><guid isPermaLink="false">substack:post:127547047</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 13 Jun 2023 13:41:05 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/127547047/db39e055506962692cbc63c79d593051.mp3" length="2176899" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>181</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/127547047/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[Insights into the CISO Mind Map — Vulnerability Management]]></title><description><![CDATA[<p></p><p>Diving into the CISO Mindmap - A series providing increased clarity into the role of a CISO</p><p>I wanted to pay homage to the work of <strong>Rafeeq Rehman</strong> and the CISO Mind Map <a target="_blank" href="https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/">https://rafeeqrehman.com/2023/03/25/ciso-mindmap-2023-what-do-infosec-professionals-really-do/</a> so with the approval of Rafeeq; I will take an overview or summary of the different areas.</p><p>Posted: </p><p></p><p>Extreme Productivity, by Robert C. Pozen</p><p>At some point, we’ve all asked ourselves “Where can I get more time to do the things I want to do?” The answer, from Robert C. Pozen, is found in his fascinating new book Extreme Productivity.</p><p><a target="_blank" href="https://community.cpf-coaching.com/episode/167">Click here to view this summary.</a></p><p></p><p></p><p>If you have read this far into my blog, I pick you as a continuous learner. Amy right? I know I am!</p><p>Check out this new leadership and soft skill development approach called Social Nano Learning.</p><p>It has been proven to increase team engagement, learning outcomes, and psychological well-being in only 3 minutes daily.</p><p>I’ve partnered with NanoCourses and can offer you and your team your first NanoCourse (based on the 7 Habits of Highly Effective People) free of charge.</p><p>There’s a quick 3-minute video describing exactly what NanoCourses is, and how you can get started, here:<a target="_blank" href="https://nancourses.io/cpf-coaching-partners">www.nancourses.io/cpf-coaching-partners</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/insights-into-the-ciso-mind-map-vulnerability-b1f</link><guid isPermaLink="false">substack:post:125746822</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 03 Jun 2023 14:57:03 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/125746822/3e774ef8be0002fb31307a26b2cbf6a5.mp3" length="3296489" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>275</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/125746822/9fca343749754de29ad232d670fe1b26.jpg"/></item><item><title><![CDATA[Insights into the CISO Mindmap - Network/Application Firewalls]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/insights-into-the-ciso-mindmap-networkapplicatio</link><guid isPermaLink="false">substack:post:125738360</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 03 Jun 2023 13:56:23 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/125738360/c6767215fe0073b08cd8bff31abf9128.mp3" length="4353507" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>363</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/125738360/0b0d5d684b4fbf80ed2dd32cff5a0d50.jpg"/></item><item><title><![CDATA[Diving into the CISO Mindmap - Security Operations Resilience]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/diving-into-the-ciso-mindmap-security-603</link><guid isPermaLink="false">substack:post:125737948</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 03 Jun 2023 13:53:56 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/125737948/777ba9ec8d05d9bba6db51acf28d2d26.mp3" length="4050069" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>337</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/125737948/912cd0c44c615b4354fb3bd2cecf3fec.jpg"/></item><item><title><![CDATA[Insights into the CISO Mind Map - Threat Prevention (NIST CSF Identify & Protect)]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/diving-into-the-ciso-mindmap-security</link><guid isPermaLink="false">substack:post:125737657</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 03 Jun 2023 13:52:28 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/125737657/035f36fb82a3cb4d279215ad9c5a5f03.mp3" length="2934745" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>245</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/125737657/dfbaf6d5b75311458cb79c151cc9e3e7.jpg"/></item><item><title><![CDATA[Navigating Remote Networking as a Cybersecurity Leader]]></title><description><![CDATA[<p>Also shared on <a target="_blank" href="https://medium.cpf-coaching.com/navigating-remote-networking-as-a-cybersecurity-leader-challenges-strategies-and-benefits-76eaee53fa09?source=friends_link&#38;sk=e7ea8826a3eb1f8ab0864f615bd06810">Medium</a></p><p><p>Cybersecurity Leadership Development Coaching | CPF Coaching is a reader-supported publication. Support authors by subscribing and supporting the community. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></p><p></p><p>Book of the Week</p><p>Remote Work Revolution, by Tsedal Neeley</p><p>Uncover the secrets to successfully navigating remote work, boosting productivity, fostering collaboration, and unlocking the full potential of your team in a virtual environment.</p><p><a target="_blank" href="https://community.cpf-coaching.com/episode/709">Click here to view this summary.</a></p><p></p><p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/navigating-remote-networking-as-a-9b0</link><guid isPermaLink="false">substack:post:124373361</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 28 May 2023 13:53:59 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/124373361/a457c3a25dd477c00d84c060aeb2f911.mp3" length="2736946" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>228</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/124373361/5f092b54cd7460358761a8ea0d89936a.jpg"/></item><item><title><![CDATA[Understanding your digital supply chain risk ]]></title><description><![CDATA[<p>Originally published here: https://www.capitalone.com/tech/cloud/understanding-your-digital-supply-chain-risk/  Removed</p><p></p><p>Understanding your digital supply chain risk</p><p>Managing the risks associated with digital supply chains</p><p>TL;DR</p><p>Understanding your digital supply chain risk is becoming one of the major challenges many businesses face today, especially with the move to cloud and globalization of the computing behind those services. Recommendations on addressing the additional detailing of the supply chain which might be part of any major applications</p><p>* Ensure that COTS/Third Party Suppliers/SaaS are documented on the security context diagram, threat model, CMDB and any other sources of record, as well as potential platforms which might support them as part of their digital supply chain </p><p>* Ensuring that these dependencies are captured will help to better identify supply chain risks, threat model potential mitigations for them, as well as a myriad of other detection and response activities </p><p>What are digital supply chain risks?</p><p>As companies move to the cloud and computing becomes globalized, it is important to understand your digital supply chain risk and how to mitigate the risks. Risks we will discuss today include gaps in: </p><p>* Cyber architecture requirements </p><p>* Change management databases (CMDB)</p><p>* Software supply chain & software development lifecycles </p><p>* Supply chain risk management process</p><p>How does supply chain risk affect businesses?</p><p>An organization’s understanding of the supply chain risk of any given system can range in varying degrees based on the number of integrators or suppliers a company might use to generate its revenue through the production of software or delivery of services. In addition to understanding those integrators or suppliers, understanding the external factors which might affect them, and in-turn affect the producer. </p><p>An organization’s ability to identify, detect and respond to those environmental threats/influences to the supply chain become a critical factor in maintaining the integrity of the production of software and services. An organization’s Third Party Management (TPM) program helps monitor its Third Parties. This program also helps with the lifecycle management of suppliers while servicing the Organization. </p><p>Due to the complexity of an organization's supply chain, there might be multiple layers of suppliers or intermediaries downstream of the organization. As the layers of downstream supplier’s increase, Organization’s ability to have visibility into those suppliers decreases.</p><p>In the figure below from NIST SP 800-161r1 demonstrate the decreased invisibility as the layers of the supply chain increase.</p><p>This blog focuses on the digital supply chain risks which affect organizations. </p><p>Risk #1: Gaps in cyber architecture requirements </p><p>What is the risk associated with cyber architecture?</p><p>Organizations might not document or track 3rd parties/supplier chain infrastructure as part of its supply chain in its Change Management Database (CMDB) and it is not a requirement for it to be completed.</p><p>Why does the gap in cyber architecture matter? </p><p>This means that the Organization might not be able to proactively respond to major vulnerabilities in our supply chain which have been integrated or used to build organizations products on. (e.g. Log4J)</p><p>What is a potential mitigation? </p><p>Having the ability to understand the technologies used to support solutions by our critical suppliers and have them linked as an artifact in CMDB and TPM. This will provide the organization with the ability to proactively understand the risk exposure from suppliers.</p><p>Risk #2: Gaps in Change Management Databases (CMDB)</p><p>Oftentimes, companies do not connect their suppliers or third party applications in CMDB to the authoritative system of record for TPM, therefore understanding the digital supply chain risks caused by those third parties to the applications that they support. </p><p>The probable impact of gaps in CMDB</p><p>This has the potential to limit an organization's ability to proactively respond to major vulnerabilities in the supply chain which have been integrated or used to build organization products on. </p><p>The potential mitigation of gaps in CMDB </p><p>Require understanding of the technologies used to support solutions by our critical suppliers and have them linked as an artifact in CMDB and TPM. <a target="_blank" href="https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us">This aDolus blog</a> includes a diagram demonstrating a software supply chain attack. </p><p>Risk #3: Gaps in software supply chain and software development lifecycles </p><p>Currently, an organization has a potential lack of/limited visibility into some of the software libraries ingested from software providers, open source software, etc. </p><p>Take Log4j as an example. The <a target="_blank" href="https://blackkite.com/research/log4j-rce-vulnerability-log4shell-puts-millions-at-risk/">Black Kite Research Team</a> analyzed nearly 3,000 companies known to be affected or explicitly disclosed to be unaffected by the vulnerability, as shown int he figure below.</p><p>Potential mitigations of software supply chain and software development lifecycles </p><p>One of the potential mitigations for increased visibility into the software libraries ingested from software providers, open source software, etc. is the Software Bill of Materials. With a Software Bill of Materials (SBOM), you can respond quickly to the security, license and operational risks that come with open source use. This could also be potentially used to track the integration of Commercial Off the Shelf (COTS) Software into organization business applications groups. </p><p>Below is a software lifecycle. Also, check out <a target="_blank" href="https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains-software-1">National Institute of Standards and Technology (NITA)’s illustration of a software lifecycle and SBOM</a>.</p><p>The use of the software bill of materials concept can even be expanded to include firmware down at the hardware level. There has been an increase in organizations adopting SBOM as part of their supply chain, as well as future regulator requirements from the federal government. </p><p>Industry resources for SBOMs: </p><p>In May 2022, President Biden issued an <a target="_blank" href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/">executive order</a> advocating for mandatory <a target="_blank" href="https://www.ntia.gov/SBOM">software bills of materials</a>, or <a target="_blank" href="https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf">SBOM</a>, to increase software transparency and counter supply-chain attacks. Some examples of these include:</p><p>* <a target="_blank" href="https://github.com/CycloneDX/bom-examples">CycloneDX SBOM</a> </p><p>* <a target="_blank" href="https://www.ntia.doc.gov/files/ntia/publications/ntia_sbom_formats_energy_brief_2021.pdf">NITA SBOM, formats and tooling</a></p><p>* <a target="_blank" href="https://www.jupiterone.com/sbom">Jupiter One SBOM</a></p><p>* <a target="_blank" href="https://slsa.dev/">Google Supply-Chain Levels for Software Artifacts (SLSA) framework </a></p><p>* <a target="_blank" href="https://media.defense.gov/2022/Sep/01/2003068942/-1/-1/0/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDF">NSA recommended practices for developers to secure the software supply chain</a></p><p>Risk #4: Gaps in the supply chain risk management process </p><p>An organization’s third-party applications which might in CMDB are not linked to/associated with the authoritative system of record for third party relationships (TPM Central) (e.g., Solarwinds, VMware, Microsoft, etc). </p><p>Potential mitigation of supply chain risk management process </p><p>It is also recommended that there should be an integration implemented between CMDB and the TPM system of record to organize/document the relationship between business applications and third party records/engagements. This will allow for TPM and other downstream groups to consume this information from systems of record CMDB when needed. </p><p>Industry resources for supply chain risk management </p><p>NIST’s Computer Security Resource Center (CSRC) offers this <a target="_blank" href="https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management">Cybersecurity Supply Chain Risk Management C-SCRM</a>.</p><p>Enterprise’s supply chain </p><p>Contemporary enterprises run complex information systems and networks to support their missions. These information systems and networks comprise ICT/OT products and components made available by suppliers, developers, and system integrators. Enterprises also acquire and deploy an array of products and services, including: </p><p>* Custom software for information systems built to be deployed within the enterprise, made available by developers; </p><p>* Operations, maintenance, and disposal support for information systems and networks within and outside of the enterprise’s boundaries, made available by system integrators or other ICT/OT-related service providers; and </p><p>* External services to support the enterprise’s operations are positioned both inside and outside the authorization boundaries, and made available by external system service providers. </p><p>Below are some additional resources: </p><p>* <a target="_blank" href="https://s3.amazonaws.com/content-production.cloudsecurityalliance/u3elrqa9geii4qcrnygw90iy2l3n?response-content-disposition=inline%3B%20filename%3D%22SaaSGovernanceBestPracticesforCloudCustomers.pdf%22%3B%20filename%2A%3DUTF-8%27%27SaaSGovernanceBestPracticesforCloudCustomers.pdf&#38;response-content-type=application%2Fpdf&#38;X-Amz-Algorithm=AWS4-HMAC-SHA256&#38;X-Amz-Credential=AKIAS6XDIRHKHO4F5SU4%2F20220629%2Fus-east-1%2Fs3%2Faws4_request&#38;X-Amz-Date=20220629T204454Z&#38;X-Amz-Expires=300&#38;X-Amz-SignedHeaders=host&#38;X-Amz-Signature=60c114077df46419fa922f381d0610407bec04d28a093c1c5d799d6df49f9dda">CSA SaaS Governance and Security Best Practices</a></p><p>* <a target="_blank" href="https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management">Cybersecurity Supply Chain Risk Management C-SCRM</a></p><p>* <a target="_blank" href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf">NIST SP 800-161 R1</a></p><p>* <a target="_blank" href="https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf">Key Practices in Cyber Supply Chain Risk Management:Observations from Industry</a></p><p>* <a target="_blank" href="https://sot.mitre.org/">MITRE Systems of Trust</a></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/understanding-your-digital-supply</link><guid isPermaLink="false">substack:post:113729052</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 09 Apr 2023 19:17:26 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/113729052/851a7d6e8c924756160b739c0d472ded.mp3" length="6080410" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>507</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/113729052/364c0618df04f60494aac69ec398fa5d.jpg"/></item><item><title><![CDATA[Developing cybersecurity leadership talent pipelines]]></title><description><![CDATA[<p></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/developing-cybersecurity-leadership-e6a</link><guid isPermaLink="false">substack:post:113727633</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 09 Apr 2023 19:08:22 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/113727633/a901852161e05f1f05155d1d6b56a87d.mp3" length="942960" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>79</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/113727633/0d594b2c0bea6e467069b55ec226b66e.jpg"/></item><item><title><![CDATA[The Top 10 LinkedIn Security Tips: Leaderboards are no longer just in the office]]></title><description><![CDATA[<p>Section 1: Understand the Risks</p><p>As a cybersecurity professional, you understand the importance of protecting sensitive information. However, it’s essential to understand the specific risks associated with LinkedIn. For example, hackers often use LinkedIn to gather information for social engineering attacks. Be aware of the risks and take steps to mitigate them.</p><p>One way to do this is to limit your personal information on LinkedIn. Don’t include sensitive details like your home address or phone number. Also, be cautious about what you post in your profile or status updates. Avoid sharing information that could be used to guess your security questions, like your mother’s maiden name or your first pet’s name.</p><p>Finally, be aware of phishing scams. Hackers may send you messages on LinkedIn that look legitimate but contain malware or links to fake login pages. Double-check the sender’s email address and verify any links before clicking on them.</p><p>Section 2: Secure Your Account</p><p>The first step to securing your LinkedIn account is to enable two-factor authentication (2FA). This adds an extra layer of security by requiring a code and your password to log in. LinkedIn offers several 2FA options, including SMS messages, phone calls, and authentication apps like Google Authenticator.</p><p>It would be best if you also chose a strong, unique password for your LinkedIn account. Avoid using the same password for multiple accounts, and use a combination of letters, numbers, and symbols to make your password more secure.</p><p>Finally, keep your account up-to-date by regularly reviewing your security settings and checking for suspicious activity.</p><p>Section 3: Be Mindful of Your Connections</p><p>LinkedIn is designed to help you connect with other professionals, but it’s essential to be mindful of who you connect with. Before accepting a connection request, please take a few minutes to review the person’s profile and confirm that they are who they say they are.</p><p>Additionally, be cautious about accepting requests from people you don’t know. Hackers often use fake LinkedIn profiles to gather information or spread malware. If you’re unsure about a connection request, it’s better to err on caution and decline it.</p><p>Finally, be careful about what you share with your connections. Don’t post sensitive information or business secrets; be cautious about sharing personal details like your home address or phone number.</p><p>Section 4: Keep Your Profile Secure</p><p>Your LinkedIn profile is a valuable source of information for hackers, so it’s essential to keep it secure. One way to do this is to limit the information you share. For example, think about when you might share or add to your entire work history or include your phone number.</p><p>Be cautious about what you post on your profile. Avoid sharing information that could be used to guess your security questions, like your mother’s maiden name or your first pet’s name.</p><p>Finally, you can set your profile to private if you’re not actively looking for a job. This will prevent recruiters and others from seeing your profile and potentially using your information for phishing scams or other attacks.</p><p>Section 5: Monitor Your Activity</p><p>Monitoring your LinkedIn activity regularly is essential to ensure your account hasn’t been compromised. Check your login history and review any changes to your profile or connections.</p><p>If you notice any suspicious activity, such as logins from unfamiliar locations or changes to your profile that you didn’t make, take immediate action. Change your password, review your security settings, and contact LinkedIn support if necessary.</p><p>Additionally, be on the lookout for phishing scams or other suspicious messages. If you receive a message that seems too good to be accurate or asks for sensitive information, it’s likely a scam.</p><p>Section 6: Use LinkedIn Safely on Public Wi-Fi</p><p>Public Wi-Fi networks often need to be more secure, which means that hackers can easily intercept your data if you’re not careful. To stay safe using LinkedIn on public Wi-Fi, ensure you use a secure connection. Consider using a virtual private network (VPN) to encrypt your data and protect your privacy.</p><p>Additionally, be cautious about using public computers to access LinkedIn. Use your device and make sure it’s secure before logging in.</p><p>Finally, be mindful of who is watching you when using LinkedIn in public. Don’t type in sensitive information if people nearby could see your screen.</p><p>Section 7: Keep Your LinkedIn App Up-to-Date</p><p>If you use the LinkedIn app on your smartphone or tablet, it’s essential to keep it up-to-date. App updates often include security patches that can help protect your data and prevent attacks.</p><p>Additionally, be cautious about downloading apps from third-party sources. Stick to official app stores like the Apple App Store or Google Play Store to reduce the risk of downloading malware or other malicious apps.</p><p>Finally, be careful about the permissions you grant to apps on your device. Don’t grant unnecessary permissions, and be cautious about giving access to your contacts or other sensitive information.</p><p>Section 8: Use LinkedIn Learning Safely</p><p>LinkedIn Learning is a valuable resource for cybersecurity professionals, but it’s essential to use it safely. Be cautious when downloading course materials or other files: Ensure you’re downloading files from trusted sources and scan them for viruses or malware before opening them.</p><p>Section 9: Protect Your Company’s Information</p><p>If you’re a cybersecurity professional working for a company, protecting your company’s information on LinkedIn is essential. Ensure your employees know the risks associated with LinkedIn and train them on best practices for using the platform safely.</p><p>Additionally, consider setting up a company page on LinkedIn to control the information shared about your company. Review your employees’ profiles to ensure they’re not sharing sensitive information, and monitor your company’s activity on the platform regularly.</p><p>Finally, be cautious about sharing information about your company’s products or services on LinkedIn. Don’t post sensitive information or business secrets, and be careful about sharing personal details like your home address or phone number.</p><p>Section 10: Be Prepared for a Data Breach</p><p>Even if you take all the necessary precautions, there’s always a risk of a data breach. Be prepared by having a plan in place for responding to a violation.</p><p>Make sure you know who to contact in the event of a breach, and have a plan for notifying affected individuals and authorities if necessary. Consider working with a cybersecurity firm to help you respond to breaking and minimize the damage.</p><p>Finally, review your insurance policies to ensure adequate coverage in a breach. Cyber insurance can help cover the costs associated with a breach, including legal fees, notification costs, and damage to your reputation.</p><p>Summing it all up</p><p>In conclusion, LinkedIn can be a valuable resource for professionals, but it’s also important to be mindful of the security risks associated with the platform. By following these top 10 security tips, including understanding the risks, securing your account, being aware of your connections, keeping your profile secure, monitoring your activity, using LinkedIn safely on public Wi-Fi, keeping your LinkedIn app up-to-date, using LinkedIn Learning safely, and protecting your company’s information, you can stay ahead of the cybersecurity game and help ensure that your personal and professional information remains secure. By taking these simple precautions, you can enjoy all the benefits of LinkedIn without putting yourself or your company at risk of cyberattacks.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-top-10-linkedin-security-tips</link><guid isPermaLink="false">substack:post:109201715</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 18 Mar 2023 14:53:57 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/109201715/2b6cc2ae6491378e0405b24e0392f987.mp3" length="5290467" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>441</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/109201715/eeb14997935bc0523d2ca984c1145ffb.jpg"/></item><item><title><![CDATA[ The Digital Risk Digest Live Feat. Christophe Foulon ]]></title><description><![CDATA[<p>The Digital Risk Digest Live Feat. Christophe Foulon By https://www.youtube.com/@valor-cybersecurity </p><p>Welcome to another episode of the Digital Risk Digest Live. We go live every Friday with industry leaders about digital threats, opportunities, and more. Curious about the intersection of business and technology? </p><p>Tune in today! Let’s give Chris a massive welcome to the show!</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/the-digital-risk-digest-live-feat</link><guid isPermaLink="false">substack:post:103903280</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 19 Feb 2023 19:32:33 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/103903280/ab03622a9bbce3ea377f685805a9a6a1.mp3" length="28911350" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>3614</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/103903280/4d19d83cdd3c7f39dd30f54f7973e277.jpg"/></item><item><title><![CDATA[New Year Resolutions or Intentions]]></title><description><![CDATA[<p>This is a video about New Year Resolutions or Intentions. </p><br/><p>I strive to shine a light on the value of others so they can see it in themselves.  </p><br/><p>Developing today's leaders for the generation of tomorrow.  </p><br/><p><a href="https://www.cpf-coaching.com" class="linkified" target="_blank">https://www.cpf-coaching.com</a>  </p><br/><p>Also, check out the <a href="https://studio.youtube.com/channel/UCM3YAEDu6W7JmQc0kb-CNtw"> @BreakingIntoCybersecurity </a> Channel for more cybersecurity advice.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/new-year-resolutions-or-intentions-516</link><guid isPermaLink="false">2d764ad3-475b-4d67-b47f-1b9c7f322acc</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 02 Jan 2023 20:39:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473567/6878097b67ef7b790819755189268cc6.mp3" length="5710412" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>285</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473567/bf06f54325f3c625af477675bbeb57bd.jpg"/></item><item><title><![CDATA[New Year Resolutions or Intentions]]></title><description><![CDATA[<p>This is a episode about New Year Resolutions or Intentions. </p><br/><p>I strive to shine a light on the value of others so they can see it in themselves.  </p><br/><p>Developing today's leaders for the generation of tomorrow.  </p><br/><p><a href="https://www.cpf-coaching.com" class="linkified" target="_blank">https://www.cpf-coaching.com</a>  </p><br/><p>Also, check out the <a href="https://studio.youtube.com/channel/UCM3YAEDu6W7JmQc0kb-CNtw"> @BreakingIntoCybersecurity </a> podcast for more cybersecurity advice.</p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/new-year-resolutions-or-intentions-14a</link><guid isPermaLink="false">5a8dfb51-281b-4490-9e11-a2b1cecb9ac8</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 02 Jan 2023 20:37:29 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473568/50e1499530d18715a49a06caddd90dbd.mp3" length="5710511" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>285</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473568/8fd57eaa11aa3bcbc4b530494645df4d.jpg"/></item><item><title><![CDATA[Threat Informed Defense Approach to your Career!]]></title><description><![CDATA[<p>This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/05/15/threat-informed-defense-approach-to-your-career/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/05/15/threat-informed-defense-approach-to-your-career/</a></p><br/><p>Technical blog link: <a href="https://medium.com/@christophefoulon_55618/threat-informed-defense-be36d989016c" class="linkified" target="_blank">https://medium.com/@christophefoulon_55618/threat-informed-defense-be36d989016c</a></p><br/><p><br/></p> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/threat-informed-defense-approach-c87</link><guid isPermaLink="false">5fa4e653-6000-4a85-b755-603f5e92aaa0</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 15 May 2022 15:29:01 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473569/8213993bbe41963a0ef380acf87d355e.mp3" length="1058944" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>88</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473569/aa6f47f7d3812fc55aac87867df24a09.jpg"/></item><item><title><![CDATA[Reflections on a week with inspiring cybersecurity leaders]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/04/26/reflections-on-a-week-with-inspiring-cybersecurity-leaders/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/04/26/reflections-on-a-week-with-inspiring-cybersecurity-leaders/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/reflections-on-a-week-with-inspiring-8c4</link><guid isPermaLink="false">0430418a-9dc7-466b-b36f-837cededcd65</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 26 Apr 2022 10:34:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473570/d89bcb4281e8b6789b313403a18645fe.mp3" length="4545037" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>379</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473570/0280957b062f9640fedb00abd9c6f4cf.jpg"/></item><item><title><![CDATA[Growing yourself enable you to grow others]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/04/15/growing-yourself-enable-you-to-grow-others/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/04/15/growing-yourself-enable-you-to-grow-others/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/growing-yourself-enable-you-to-grow-dec</link><guid isPermaLink="false">edb0f502-e9f5-453f-8ebb-bdccf9079fcd</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 15 Apr 2022 12:44:32 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473571/c3ae273196688b16af12849e4d07c3fc.mp3" length="996564" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>83</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473571/80ee7fd84a32c6f598ded7b95235094a.jpg"/></item><item><title><![CDATA[Max Capacity Reached?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/04/08/max-capacity-reached/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/04/08/max-capacity-reached/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/max-capacity-reached-a87</link><guid isPermaLink="false">ae201179-b397-4c7e-9408-a5eabd108f41</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 08 Apr 2022 16:24:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473572/8934d2e1747f8cf8e99efb0d649b5901.mp3" length="1497174" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>125</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473572/3abe757ba69807add90d6305d476bd4f.jpg"/></item><item><title><![CDATA[Got Coach?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/03/29/got-coach/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/03/29/got-coach/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/got-coach-51e</link><guid isPermaLink="false">1b478ad3-4672-498d-9dea-5c918d003cdd</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 29 Mar 2022 18:29:26 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473573/51100a6f2c60eb504552ea7cfbec5154.mp3" length="1273984" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>106</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473573/14f3ea97fe71e82f275236c69e664eed.jpg"/></item><item><title><![CDATA[What does Waiting Cost you?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/03/28/what-does-waiting-cost-you/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/03/28/what-does-waiting-cost-you/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/what-does-waiting-cost-you-b27</link><guid isPermaLink="false">a4580ebb-d4d9-416b-a765-5d62019abb37</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Mon, 28 Mar 2022 13:05:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473574/faf34bb3db33f5680718ca5d1d3e8d3b.mp3" length="265240" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>22</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473574/afdd0d5e97d52fb957d569702b6d3d2b.jpg"/></item><item><title><![CDATA[Are you curious or do you say you are?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/03/25/are-you-curious-or-do-you-say-you-are/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/03/25/are-you-curious-or-do-you-say-you-are/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-curious-or-do-you-say-you-d51</link><guid isPermaLink="false">bfcb73a0-8308-4a78-a8e4-352c10ca5f7f</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 25 Mar 2022 15:41:15 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473575/6bdecc17ae3482836ed50c0c5ba77bca.mp3" length="1658925" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>138</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473575/29ca542db49025ba3706d6005a3960c5.jpg"/></item><item><title><![CDATA[A Personal Board of Directors]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpfcoaching.wordpress.com/2022/03/24/a-personal-board-of-directors/" class="linkified" target="_blank">https://cpfcoaching.wordpress.com/2022/03/24/a-personal-board-of-directors/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/a-personal-board-of-directors-254</link><guid isPermaLink="false">f80804db-9df1-46b2-9e04-d07b3ddcd79f</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 25 Mar 2022 15:39:18 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473576/d850e00277b37959f13846085e557eab.mp3" length="305364" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>25</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473576/d2d63e438d57e36007e052e81d5d397e.jpg"/></item><item><title><![CDATA[Is stretching a word in your vocabulary?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="http://cpf-coaching.com/2022/03/09/is-stretching-a-word-in-your-vocabulary/" class="linkified" target="_blank">http://cpf-coaching.com/2022/03/09/is-stretching-a-word-in-your-vocabulary/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/is-stretching-a-word-in-your-vocabulary-703</link><guid isPermaLink="false">15ae13a7-62b8-4338-8080-0c9f350eb1e1</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 09 Mar 2022 12:29:47 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473577/6887a937c334b58395ce1e439ba3e91f.mp3" length="1839169" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>153</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473577/90e626097d8a21d7fa5b49a3e8a89a93.jpg"/></item><item><title><![CDATA[Are you climbing your ladder?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-climbing-your-ladder/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-climbing-your-ladder/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-climbing-your-ladder-bb6</link><guid isPermaLink="false">0683d26d-09aa-4f1e-8147-9d36331d8804</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 25 Feb 2022 15:53:16 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473578/238ee45f1a51901f9c9dcb3b390cabbd.mp3" length="1453602" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>121</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473578/2bcc92fdf0a57000b65306188fcaeef0.jpg"/></item><item><title><![CDATA[Wrapping Up 2021]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/wrapping-up-2021/" class="linkified" target="_blank">https://cpf-coaching.com/wrapping-up-2021/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/wrapping-up-2021-a10</link><guid isPermaLink="false">7eda04e3-4139-4099-963c-e1271952c65d</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 22:02:50 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473579/65d4412042a3d74da156bcb75b104cbd.mp3" length="2124113" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>177</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473579/3314d8a0ccbf10e28c4906e858253792.jpg"/></item><item><title><![CDATA[Fall 2021]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/fall-2021/" class="linkified" target="_blank">https://cpf-coaching.com/fall-2021/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/fall-2021-069</link><guid isPermaLink="false">97c41430-ec74-4cd1-b85c-ade41ea777e7</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:57:16 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473580/f71784f6090847399afa4d6971505381.mp3" length="2343855" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>195</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473580/c47c13afe1a7a3f2691a14838c6c5bfa.jpg"/></item><item><title><![CDATA[Have you developed your career path?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/have-you-developed-your-career-path/" class="linkified" target="_blank">https://cpf-coaching.com/have-you-developed-your-career-path/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/have-you-developed-your-career-path-f25</link><guid isPermaLink="false">c5a7837c-a9bc-41e5-a7ff-71373a824703</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:53:23 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473581/c4abddf005829f6acc939fab028bfbe3.mp3" length="862085" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>72</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473581/d1ea290ca5503a459cfa65e81b01bd00.jpg"/></item><item><title><![CDATA[Are you a Victim or Victor of your Circumstances?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-a-victim-or-victor-of-your-circumstances/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-a-victim-or-victor-of-your-circumstances/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-a-victim-or-victor-of-your-dd5</link><guid isPermaLink="false">cba7a3a7-178c-4fdc-829e-080a6de6aa46</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:46:19 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473582/a85289443ac1e23a6778bd6d11fb5c4b.mp3" length="790301" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>66</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473582/1f95d5adc5a7dd7bb786268f91fbf73c.jpg"/></item><item><title><![CDATA[Have you been taking the time to reflect on the strategies that work or do not work for you on your growth journey?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/have-you-been-taking-the-time-to-reflect-on-the-strategies-that-work-or-do-not-work-for-you-on-your-growth-journey/" class="linkified" target="_blank">https://cpf-coaching.com/have-you-been-taking-the-time-to-reflect-on-the-strategies-that-work-or-do-not-work-for-you-on-your-growth-journey/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/have-you-been-taking-the-time-to-305</link><guid isPermaLink="false">563bed1a-bbc2-41b9-8489-6ca2e14bbbfe</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:44:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473583/5678e92a4cab3e2100d85ac85ff7bb4a.mp3" length="789047" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>66</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473583/7bdb9fc1ccf253364799d3e71da6163b.jpg"/></item><item><title><![CDATA[Are you the smartest person in the room?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-the-smartest-person-in-the-room/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-the-smartest-person-in-the-room/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-the-smartest-person-in-the-6a2</link><guid isPermaLink="false">64d5e38a-1b03-40cb-94dc-a72afca161e5</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:18:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473584/81272044b373c6015b61afeffc5318a8.mp3" length="936378" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>78</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473584/76feb3618c01e5fd67f11f83b9a5f48d.jpg"/></item><item><title><![CDATA[Is your growth hampered by your consistency?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/is-your-growth-hampered-by-your-consistency/" class="linkified" target="_blank">https://cpf-coaching.com/is-your-growth-hampered-by-your-consistency/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/is-your-growth-hampered-by-your-consistency-3e9</link><guid isPermaLink="false">b3b9a478-a109-47f2-87e0-e56bd3bbfb42</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:14:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473585/9ed4bb595c2f4a2a710bc3e6cb50a9b5.mp3" length="682154" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>57</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473585/7713d190821d461ae6da2c7b7dfd150e.jpg"/></item><item><title><![CDATA[Are You Reflecting On Your Growth?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-reflecting-on-your-growth/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-reflecting-on-your-growth/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-reflecting-on-your-growth-990</link><guid isPermaLink="false">cc49e198-3d26-43b5-8f2b-39016159c940</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:06:42 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473586/94c563c6e4c9f98dc61c693f63b0b016.mp3" length="645478" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>54</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473586/89f0ae40228afb5427427833b4d03dd9.jpg"/></item><item><title><![CDATA[Is Self-Limiting Beliefs Affecting Your Career?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/is-self-limiting-beliefs-affecting-your-career/" class="linkified" target="_blank">https://cpf-coaching.com/is-self-limiting-beliefs-affecting-your-career/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/is-self-limiting-beliefs-affecting-c10</link><guid isPermaLink="false">4e68150c-12ed-4cf7-bcc8-b2f130b0d17b</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:04:16 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473587/5fd5e6b1592179d74a934df1267ae31d.mp3" length="777135" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>65</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473587/c37a4dc2379dbf683231fe47acd76306.jpg"/></item><item><title><![CDATA[Are You Self Aware?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-self-aware/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-self-aware/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-self-aware-44b</link><guid isPermaLink="false">f5dc2efa-d8f4-4f02-badf-f70f9b153819</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 21:01:33 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473588/7821edaba3ced3daeb1f182e72330952.mp3" length="794376" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>66</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473588/d8c9f936b9f95db2d7a0b97d896faed7.jpg"/></item><item><title><![CDATA[Is Your Growth Accidental?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/is-your-growth-accidental/" class="linkified" target="_blank">https://cpf-coaching.com/is-your-growth-accidental/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/is-your-growth-accidental-dcd</link><guid isPermaLink="false">243b90d9-3ad1-445a-b0e6-f2f15bf6c7d0</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:59:01 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473589/009a5301dddc3e16a320474bf78cca48.mp3" length="1070856" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>89</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473589/c37aeaaec536876461c8ecf5bd2638f1.jpg"/></item><item><title><![CDATA[Are You Asking The Right Questions?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-asking-the-right-questions/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-asking-the-right-questions/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-asking-the-right-questions-a9e</link><guid isPermaLink="false">334cb14d-8a8f-42c4-a39d-7e534ef5c007</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:53:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473590/519d90d970ec3621066c1cc9b704cd3b.mp3" length="901269" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>75</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473590/1c79a896e5b56bc42eefdc2b7cd2adbc.jpg"/></item><item><title><![CDATA[What Human Needs are driving your decision making?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/what-human-needs-are-driving-your-decision-making/" class="linkified" target="_blank">https://cpf-coaching.com/what-human-needs-are-driving-your-decision-making/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/what-human-needs-are-driving-your-3cc</link><guid isPermaLink="false">4e7dab8f-f017-46de-b0bc-2f4afe01eb7e</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:50:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473591/096ed889c63fcf2bd2bfcbea13761dc4.mp3" length="807855" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>67</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473591/6cff9bd7547d4bf3ee8ceb2c9cc77fb4.jpg"/></item><item><title><![CDATA[Are you in a Rut?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/are-you-in-a-rut/" class="linkified" target="_blank">https://cpf-coaching.com/are-you-in-a-rut/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/are-you-in-a-rut-a13</link><guid isPermaLink="false">39f9cb98-2fe6-4978-9a02-0e05e33e1b28</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:21:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473592/4b93c2a3864876204ec381072d782f4a.mp3" length="1248280" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>104</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473592/2d2ccdf931e53d5678651741eb8b5ace.jpg"/></item><item><title><![CDATA[Sometimes you win, Sometimes you learn]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/sometimes-you-win-sometimes-you-learn/" class="linkified" target="_blank">https://cpf-coaching.com/sometimes-you-win-sometimes-you-learn/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/sometimes-you-win-sometimes-you-learn-09c</link><guid isPermaLink="false">c59a77f4-4f84-42ab-a3ef-105a98c93611</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:21:30 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473593/c3c2e677e530db68ccd39f62370110ac.mp3" length="1252041" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>104</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473593/a4b9da3f5ef94c5adf025b2b586e1098.jpg"/></item><item><title><![CDATA[New year, New experiences]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/new-year-new-experiences/" class="linkified" target="_blank">https://cpf-coaching.com/new-year-new-experiences/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/new-year-new-experiences-de6</link><guid isPermaLink="false">b8002df4-1cdb-40cb-96c0-c7d0148d256f</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:19:49 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473594/d77a28bfd36b1cfd8d0887b3be0d02c3.mp3" length="3483630" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>290</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473594/8aa6db5dabb3d7a5bee44cb8f5f1aae3.jpg"/></item><item><title><![CDATA[I want to get into cyber, what should I do?]]></title><description><![CDATA[This episode is also available as a blog post: <a href="https://cpf-coaching.com/i-want-to-get-into-cyber-what-should-i-do/" class="linkified" target="_blank">https://cpf-coaching.com/i-want-to-get-into-cyber-what-should-i-do/</a> <br/><br/>This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit <a href="https://substack.cpf-coaching.com/subscribe?utm_medium=podcast&#38;utm_campaign=CTA_2">substack.cpf-coaching.com/subscribe</a>]]></description><link>https://substack.cpf-coaching.com/p/i-want-to-get-into-cyber-what-should-73c</link><guid isPermaLink="false">a2d7e660-2dc5-44d9-8cca-7c4fd11a94c5</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 24 Feb 2022 20:18:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/101473595/0bd1e02d4c9b7a64a128d6a2e103c353.mp3" length="2114082" type="audio/mpeg"/><itunes:author>Christophe Foulon 📓</itunes:author><itunes:explicit>No</itunes:explicit><itunes:duration>176</itunes:duration><itunes:image href="https://substackcdn.com/feed/podcast/1338707/post/101473595/aed4c4ed115642cfb1d0ad9d7840e7ab.jpg"/></item></channel></rss>