Cybersecurity Best Practices

Explore top LinkedIn content from expert professionals.

  • View profile for Kelly Hood

    EVP & Cybersecurity Engineer @ Optic Cyber Solutions | Cybersecurity Translator | Compliance Therapist | Making sense of CMMC & CSF | CISSP, CMMC Lead CCA & CCP, CCI, CDPSE

    8,606 followers

    As I’ve been digging into the #CybersecurityFramework 2.0, and helping clients navigate the changes, I’ve found several areas where the new additions feel pretty significant. If you’re already using the #CSF and trying to figure out where to focus first, take note of these new Categories: ◾ The POLICY (GV.PO) Category was created to encompass ALL cybersecurity policies and guidance. Now, on one hand it might seem like a "well, of course" moment to consolidate all cybersecurity policies into one place - on the other hand, policies were previously sprinkled throughout the CSF, and were tied to specific actions like Asset Management or Incident Response. Now, it's all in one area, which makes a ton of sense and simplifies things, but also means we've got to remember that this one Category covers everything! ◾ Another significant addition is the PLATFORM SECURITY (PR.PS) Category which largely pulls together key topics from the previous Information Protection Processes & Procedures (PR.IP) and Protective Technology (PR.PT) focusing on security protections around broader platform types (hardware, software, virtual, etc.). If you’re looking for things like configuration management, maintenance, and SDLC – you’ll now find them here.  ◾ The TECHNOLOGY INFRASTRUCTURE RESILIENCE (PR.IR) Category pulls largely from the previous Information Protection Processes & Procedures (PR.IP) and Protective Technology (PR.PT) as well, but also pulls in key aspects from Data Security (PR.DS). This new Category highlights the need for managing an organization’s security architecture and includes security protections around networks as well as your environment to ensure resource capacity, resilience, etc. So, what does all this mean for your organization? Whether you're just starting out, or you're looking to refine your existing cybersecurity strategies, CSF 2.0 offers a more streamlined framework to use to bolster your cyber resilience. Remember, staying ahead in cybersecurity is a continuous journey of adaptation and improvement. Embrace these changes as an opportunity to review and enhance your cybersecurity posture, leveraging the expanded resources and guidance provided by #NIST! Have you seen the updated mapping NIST released from v1.1 to v2.0? Check it out here to get started and “directly download all the Informative References for CSF 2.0” 👇 https://lnkd.in/e3F6hn9Y

  • View profile for Sanjay Katkar

    Co-Founder & Jt. MD Quick Heal Technologies | Ex CTO | Cybersecurity Expert | Entrepreneur | Technology speaker | Investor | Startup Mentor

    35,782 followers

    The next-generation CISO will be half hacker, half psychologist. Over the last three decades, I have watched security technology evolve in layers. From signature-based antivirus to EDR, from EDR to XDR, and now to AI-assisted detection systems that promise predictive intelligence. And yet, when I sit down and study most serious breaches, the root cause rarely begins with a sophisticated zero-day exploit. It usually begins with a human decision. (and attackers understand this very well.) They do not begin by writing code. They begin by studying behavior. They ask themselves quiet questions: Who inside this organisation is under pressure to deliver? Who has accumulated access over time that nobody reviewed? Who believes policy is flexible “just this once”? Who is tired? Who is overconfident? In one real scenario, an engineer bypassed three independent security controls because a deployment deadline was approaching and the system “had to go live.” There was no malicious intent. No insider conspiracy. Just urgency combined with authority and access. That is enough. When we look at such cases later, we often focus on the missing patch or the control gap. But the more important question is different: Why did someone feel comfortable overriding those controls in the first place? This is why I believe the CISO of the future must develop two parallel instincts. First, the technical instinct. They must still understand lateral movement, identity abuse, cloud misconfiguration, API exposure, privilege escalation, and the ways attackers chain small weaknesses into systemic compromise. But alongside that, they must develop a behavioural instinct. They must understand:  • how incentives are structured inside teams • how deadlines distort judgment • how developers perceive security teams • how executives interpret “risk” versus “delay” • how culture silently encourages shortcuts Attackers exploit psychology with precision. They send emails that create urgency. They impersonate authority. They trigger fear. They trigger curiosity. They trigger ego. And sometimes, they do not even need to. Internal pressure does the work for them. So the next-generation CISO cannot rely only on dashboards. Cybersecurity is no longer just a contest of tools. It is a contest of human behaviour under pressure. The CISO who understands both, the code and the mind, will not only detect threats more effectively. They will reduce the conditions that create them. Seqrite #Cybersecurity #CISO #SecurityLeadership #CyberLeadership #InformationSecurity #CyberRisk #SecurityCulture #CyberDefense #SecurityStrategy #Leadership #HumanFactor #CyberResilience #Infosec #EnterpriseSecurity

  • View profile for Wendi Whitmore

    Chief Security Intelligence Officer @ Palo Alto Networks | Cyber Risk Translator | AI Security & National Security Leader | Former CrowdStrike & Mandiant | Congressional Witness | USAF Veteran | Keynote Speaker

    22,699 followers

    The OpenAI and Hugging Face disclosure may be one of the most useful insights our industry has published this year. A frontier model, tested with reduced safeguards, escaped its sandbox during a cyber evaluation and reached production infrastructure. Both companies put the details in the open. That takes some courage, and the rest of us should treat it as a free lesson instead of a headline. Here is what I am telling security teams and boards to do with it: 1️⃣ Design for the agent that does not stop on its own. It had no real stopping point, so it kept working the problem until it found a gap. Treat that as the default. Cap session time and tool calls for the agents you operate, and pair the caps with monitoring, since long tasks can split across sessions. Log the full trajectory. It will not stop an escape, but it is what lets you catch and reconstruct one. 2️⃣Build detection that works before you can attribute. Hugging Face contained this while the attacker was still unknown. That is the standard now. Instrument for anomalous behavior. If your detection depends on naming the adversary first, it is already too slow. 3️⃣Pre-authorize decision rights before the incident. Machine speed attacks do not wait for an approval chain. Decide now who can isolate a system, revoke credentials, or pull a service, and under what conditions. Write it down. Rehearse it. The middle of an incident is the worst time to learn you need three signatures to act. 4️⃣Assume breakout and limit the blast radius. Scoped credentials. Real segmentation. Least privilege that is actually enforced. If something gets out of its box, you want it to stay small and get noticed fast. 5️⃣Hold test and dev to production controls. This started inside a lab. Your pre-production environments run real code with real access and thinner guardrails, and attackers know it. Bring them into scope. 6️⃣Confirm your defensive tooling will work under fire. During response, some frontier models blocked analysis of the live payloads, because the safety filters could not tell a defender from an attacker. Test your defensive AI against real incident artifacts before you need it. 7️⃣Rehearse the response, including out of band. Assume your primary channels may be noisy or compromised. Have an out of band way to coordinate and decide. Run the tabletop. The teams that do well in the first hour are the ones who practiced it. None of this is about panic, and none of it is about any single lab. The capability is real and it is only going up. The gap that decides outcomes is visibility and control. That is where boards should put attention and budget this year. If your team read this incident and felt behind, you’re not alone. Use it. It is the cheapest lesson you will get all year.

  • View profile for Gabriela Guiu-Sorsa

    Cyber Security Strategist | Security Operations | Incident Management | Crisis Management | NIST | ISO27001 | PSPF | Workforce Architect | Community Builder | DEI Advocate | Loving wife | Cat aficionado

    10,432 followers

    🔥 Australia just turned up the heat on digital resilience. With the Cyber Security Bill 2024 now passed, compliance is no longer optional—it’s the law.  The newly law that passed both Houses yesterday, pushes all levels of government and public sector entities toward stronger digital resilience. While some may argue we’re behind global standards like GDPR, this legislation lays the groundwork for a unified, proactive approach to cyber risk management. Read details here: https://lnkd.in/gXnBwzqP Key Changes You Need to Know: 1️⃣ Baseline Standards: Mandatory cyber security requirements for all levels of government, setting a uniform defense against growing threats. 2️⃣ Ransomware Transparency: Report ransomware payments within 72 hours to boost national response capabilities. 3️⃣ Supply Chain Security: No more passing the buck - organisations must secure their third-party ecosystems. 4️⃣ Centralised Incident Leadership: A Cyber Incident Review Board and National Cyber Security Coordinator to streamline responses to significant breaches. 5️⃣ Accountability at the Top: Leaders are on the hook, with penalties for non-compliance. What This Means for Decision-Makers: 🔹 Build Resilience: Proactive risk management and regular incident simulations. 🔹 Vendor Partnerships: Choosing secure, compliant vendors isn’t optional anymore. 🔹 Team Readiness: Equip your workforce to meet rigorous reporting and operational requirements. 🔖 The Big Question: Cyber security is now a boardroom conversation. Are your governance frameworks ready for this new era of cyber accountability?

  • View profile for Confidence Staveley
    Confidence Staveley Confidence Staveley is an Influencer

    Multi-Award Winning Cybersecurity Leader | Author | Int’l Speaker | On a mission to simplify cybersecurity, attract more women, drive AI Security awareness and raise high-agency humans who defy odds & change the world.

    101,597 followers

    Using unverified container images, over-permissioning service accounts, postponing network policy implementation, skipping regular image scans and running everything on default namespaces…. What do all these have in common ? Bad cybersecurity practices! It’s best to always do this instead; 1. Only use verified images, and scan them for vulnerabilities before deploying them in a Kubernetes cluster. 2. Assign the least amount of privilege required. Use tools like Open Policy Agent (OPA) and Kubernetes' native RBAC policies to define and enforce strict access controls. Avoid using the cluster-admin role unless absolutely necessary. 3. Network Policies should be implemented from the start to limit which pods can communicate with one another. This can prevent unauthorized access and reduce the impact of a potential breach. 4. Automate regular image scanning using tools integrated into the CI/CD pipeline to ensure that images are always up-to-date and free of known vulnerabilities before being deployed. 5. Always organize workloads into namespaces based on their function, environment (e.g., dev, staging, production), or team ownership. This helps in managing resources, applying security policies, and isolating workloads effectively. PS: If necessary, you can ask me in the comment section specific questions on why these bad practices are a problem. #cybersecurity #informationsecurity #softwareengineering

  • View profile for Arvind Jain
    Arvind Jain Arvind Jain is an Influencer
    85,348 followers

    Security can’t be an afterthought - it must be built into the fabric of a product at every stage: design, development, deployment, and operation. I came across an interesting read in The Information on the risks from enterprise AI adoption. How do we do this at Glean? Our platform combines native security features with open data governance - providing up-to-date insights on data activity, identity, and permissions, making external security tools even more effective. Some other key steps and considerations: • Adopt modern security principles: Embrace zero trust models, apply the principle of least privilege, and shift-left by integrating security early. • Access controls: Implement strict authentication and adjust permissions dynamically to ensure users see only what they’re authorized to access. • Logging and audit trails: Maintain detailed, application-specific logs for user activity and security events to ensure compliance and visibility. • Customizable controls: Provide admins with tools to exclude specific data, documents, or sources from exposure to AI systems and other services. Security shouldn’t be a patchwork of bolted-on solutions. It needs to be embedded into every layer of a product, ensuring organizations remain compliant, resilient, and equipped to navigate evolving threats and regulatory demands.

  • View profile for Ayoub Fandi

    GRC Engineering @ Lovable | Engineering the Future of GRC

    29,986 followers

    Pretty Heatmaps, Empty Backlogs: Why Risk Management Fails Security Engineering 📊 Let's be real - traditional risk management is the PowerPoint of security: looks impressive but rarely changes anything 🚗 The Enterprise Risk Reality 📊 "We've identified key enterprise risks including cybersecurity incidents, third-party failures, and identity risks..." Translation: We created heat maps with high/medium/low ratings that: - Give executives colourful slides 🟥🟧🟨 - Transform uncertainty into bureaucratic certainty - Give engineers zero actionable direction - Generate more accepted risks than mitigated ones Meanwhile, in the Actual Security Trenches 🔍 Your security teams are battling - Containers running with --privileged in production - IAM roles with more wildcards than a Texas poker tournament - Hard-coded secrets with longer lifespans than your screenshot cadence - Terraform plans with more exceptions than your security policy The disconnect? Your risk register makes for great board presentations but terrible for sprint planning. Why GRC has become irrelevant to security teams - Risk assessment timeframes: Annual vs. continuous deployment - Output format: PDFs vs. code - Scale: Enterprise-wide vs. specific infrastructure - Language: "Material impact to business" vs. "public S3 bucket" - Resolution: "Accept risk" vs. "merge PR #1337" Your competitors are embedding risk management into engineering/product while you're still treating it like paperwork. The difference? Their risks become PRs/stories while yours become PDFs that nobody reads. If your "Critical Risk #1" doesn't map to specific technical debt, IAM issues, or deployment vulnerabilities, you're not driving security - you're just collecting theoretical disasters that security teams can't act on. PS: Stop with the "Three Lines of Defence" stuff if you're not working on a heavily regulated industry. Often, it looks more like three lines of confusion: the first line doesn't know they're responsible, the second line creates spreadsheets, and the third line tells everyone what they did wrong after the fact. How to break the cycle? 🛠️ Start by creating a technical risk register alongside your enterprise one. Map each high-level risk to specific technical vulnerabilities and exposures in your environment. If "unauthorized access" is your enterprise risk, translate it into actionable items: "IAM roles with wildcard permissions," "service accounts without MFA," or "direct SSH access to production." Then invite your security engineers to review and help prioritise this technical backlog. Run joint sessions where GRC and security engineering collaborate on risk scenarios that can be directly converted into work items. Risk brings the business context, engineers bring the technical reality, and together you build something everyone can use. When your risk reduction becomes measurable in merged MRs rather than just updated spreadsheets, you're on the right path. #GRCEngineering

  • CISA has released its new Operational Technology (OT) Cybersecurity Guide, and it deserves board-level attention. For years, OT systems, the technology behind our power grids, water systems, manufacturing plants, and pipelines, were designed for reliability and safety, not cybersecurity. But as IT and OT environments have converged, the attack surface has expanded dramatically. We’ve already seen what this means in practice: ⚠️ Colonial Pipeline (fuel supply disruption) ⚠️ Oldsmar Water Plant (attempted poisoning) ⚠️ Ransomware groups are increasingly threatening physical operations to force payment. The CISA guide is a practical step forward, outlining what every OT-dependent organization should do: ✔️ Know your assets. Visibility is the foundation of OT security. ✔️ Segment IT and OT networks. Strong separation is essential. ✔️ Secure remote access. Enforce MFA, monitor, and log everything. ✔️ Patch with care. Use compensating controls when downtime isn’t possible. ✔️ Prepare for incidents. OT-specific monitoring, response plans, and recovery options must be in place. ✔️ Build resilience. Backups, redundancy, and even manual controls as a fallback. ✔️ Train people. Both IT and OT teams need a shared understanding of cyber risk. This isn’t just a technology problem. It’s a resilience problem. For executives, OT risk belongs on the same agenda as financial, legal, and regulatory risk. The impact of failure isn’t just data loss; it’s downtime, safety hazards, and national security implications. CISA’s guide is a reminder that OT security is no longer optional. It is a core part of modern business continuity. Please feel free to contact me if you need help or want more information on this. 🔔 Follow me for more real-world takes on cybersecurity, leadership, and tech strategy ♻️ Useful? Share to help others! #CyberSecurity #OperationalTechnology #RiskManagement #CriticalInfrastructure #CISA #BusinessContinuity

  • View profile for Tony Vizza
    Tony Vizza Tony Vizza is an Influencer

    AI, Cybersecurity and IT Risk | Lawyer | Managing Partner | Teaching Fellow | Independent Expert

    14,229 followers

    The Government of New South Wales (NSW Government) has released the 2026–2028 Cyber Security Strategy, which contains the #cybersecurity blueprint for the NSW Government for the next 3 years. The NSW Government is working towards 5 main #cyber objectives, including: ➣ Strengthen #riskmanagement, #governance and #compliance. ➣ Improve incident response and cyber intelligence capability. ➣ Uplift cyber resilience ➣ Drive continuous development of cybersecurity tools, processes and methodology. ➣ Support NSW communities to be #cybersafe. What I like about this strategy is that it is people-centric and avoids the fluff. It explicitly frames cyber as foundational to service continuity and public confidence, while calling out the modern accelerants we’re all seeing: commoditised #cybercrime and generative #AI supercharging #phishing, #socialengineering, and #malware creation. What I also like about the 2026-28 NSW Government Strategy is that it aligns with both the NSW Digital Strategy and the 2023-2030 Australian Cyber Security Strategy (page 7). The full strategy can be downloaded below or directly at https://lnkd.in/gCW9j55W. Novera is very proud to be a prequalified and approved supplier to the NSW Government under the SCM0020 ICT Services scheme and welcomes the NSW State Government's focus on uplifting cyber resilience across Australia's largest state, which makes up over one-third of the national economy.

  • View profile for Sean Connelly🦉
    Sean Connelly🦉 Sean Connelly🦉 is an Influencer

    Architect of U.S. Federal Zero Trust | Co-author NIST SP 800-207 & CISA Zero Trust Maturity Model | Former CISA Zero Trust Initiative Director | Advising Governments & Enterprises

    23,566 followers

    🌍International Guidance for Enhanced Cybersecurity: Best Practices for Event Logging and Threat Detection🌍 The Australian Government's Australian Cyber Security Centre (ACSC), in collaboration with global partners like the #NSA, #CISA, the UK's #NCSC, and agencies from Canada, New Zealand, Japan, South Korea, Singapore, and the Netherlands, has released a comprehensive report on best practices for event logging and threat detection. 🚀The report defines a baseline for event logging best practices and emphasizes the importance of robust event logging to enhance security and resilience in the face of evolving cyber threats. Why Event Logging Matters: Event logging isn't just about keeping records—it's about empowering organizations to detect, respond to, and mitigate cyber threats more effectively. The guidance provided in this report aims to bolster an organization’s resilience by enhancing network visibility and enabling timely detection of malicious activities. 🔍 Key Highlights: 🔹Enterprise-Approved Event Logging Policy: Develop and implement a consistent logging policy across all environments to enhance the detection of malicious activities and support incident response. 🔹Centralized Log Collection and Correlation: Utilize a centralized logging facility to aggregate logs, making detecting anomalies and potential security breaches easier. 🔹Secure Storage and Event Log Integrity: Implement secure mechanisms for storing and transporting event logs to prevent unauthorized access, modification, or deletion. 🔹Detection Strategy for Relevant Threats: Leverage behavioral analytics and SIEM tools to detect advanced threats, including "Living off the Land" (LOTL) techniques used by sophisticated threat actors. 📊 Use Case: Detecting "Living Off the Land" Techniques: One highlighted use case involves detecting LOTL techniques, where attackers use legitimate tools available in the environment to carry out malicious activities. The report showcases how the Volt Typhoon group leveraged LOTL techniques, such as using PowerShell and other native tools on compromised Windows systems, to evade detection and conduct espionage. Effective event logging, including process creation events and command-line auditing, was crucial in identifying these activities as abnormal compared to regular operations. Couple this report with the CISA Zero Trust Maturity Model (ZTMM): The report's best practices align with CISA's ZTMM's Visibility and Analytics capability. By following these publications, organizations can progress along their maturity path toward optimal dynamic monitoring and advanced analysis. (Full disclosure: I was co-author of CISA's ZTMM) 💪Implementing these best practices from the Australian Signals Directorate & others is critical to achieving comprehensive visibility and security, aligning with global cybersecurity frameworks. #cybersecurity #zerotrust #digitaltransformation #technology #cloudcomputing #informationsecurity

Explore categories