by Ron Samson | | Email Security, Managed Security, Network Security
PCI DSS 4.0.1 makes security monitoring an operating discipline For many merchants, PCI DSS compliance has traditionally centered on annual evidence collection: firewall screenshots, vulnerability scans, access reviews, policies, and attestation paperwork. PCI DSS...
by Ron Samson | | Email Security, Managed Security, Network Security
Why Business Email Compromise Remains Dangerous After MFA Multifactor authentication is essential, but it is not a business email compromise control by itself. BEC operators increasingly avoid the noisy, password-only intrusion that MFA was designed to stop. They...
by Ron Samson | | Email Security, Managed Security, Network Security
Choosing a 24/7 SOC Provider Is an Operating Model Decision A 24/7 security operations center is not simply an after-hours alert desk. The provider becomes part of your incident-handling chain, technology stack, executive reporting process, and risk posture. That...
by Ron Samson | | Email Security, Managed Security, Network Security
Manufacturers cannot protect operational technology (OT) the same way they protect office IT. A plant network contains assets that may be decades old, run proprietary protocols, and control machinery where a delayed command, unexpected reboot, or blocked packet can...
by Ron Samson | | Email Security, SOC as a Service, Threat Detection and Response
A Microsoft 365 takeover is a financial incident, not just an identity incident A business email compromise (BEC) event moves quickly because the attacker is already operating from a trusted identity. Once they control a Microsoft 365 mailbox, they can read invoice...
by Ron Samson | | Email Security, Managed Security, Network Security
EDR, MDR, and XDR Solve Different Security Operations Problems Security leaders often compare EDR, MDR, and XDR as if they are interchangeable products. They are not. Each represents a different operating model, level of responsibility, and investment in people,...