by Ron Samson | | Email Security, Managed Security, Network Security
Manufacturers cannot protect operational technology (OT) the same way they protect office IT. A plant network contains assets that may be decades old, run proprietary protocols, and control machinery where a delayed command, unexpected reboot, or blocked packet can...
by Ron Samson | | Email Security, SOC as a Service, Threat Detection and Response
A Microsoft 365 takeover is a financial incident, not just an identity incident A business email compromise (BEC) event moves quickly because the attacker is already operating from a trusted identity. Once they control a Microsoft 365 mailbox, they can read invoice...
by Ron Samson | | Email Security, Managed Security, Network Security
EDR, MDR, and XDR Solve Different Security Operations Problems Security leaders often compare EDR, MDR, and XDR as if they are interchangeable products. They are not. Each represents a different operating model, level of responsibility, and investment in people,...
by Ron Samson | | Email Security, Managed Security, Network Security
PCI DSS 4.0 monitoring is now an operating model, not an audit exercise For merchants, PCI DSS 4.0 changes the security-monitoring conversation from “do we collect logs?” to “can we prove that our controls detect, investigate, and respond to meaningful events in the...
by Ron Samson | | Email Security, Managed Security, Network Security
A firewall change is not just a network task Firewall rules are often treated as routine administration: open a port for a supplier, permit a cloud workload, publish a new application, or temporarily allow an engineer to troubleshoot a connection. In practice, every...
by Ron Samson | | Email Security, Threat Detection and Response
A fraudulent payment request is an incident, not an accounting exception Business email compromise (BEC) succeeds because it exploits trusted business processes: an executive approval, a vendor invoice, a payroll change, or an urgent wire instruction. The message may...