<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Highlight Archives | Fortress SRM</title>
	<atom:link href="https://fortresssrm.com/category/highlight/feed/" rel="self" type="application/rss+xml" />
	<link>https://fortresssrm.com/category/highlight/</link>
	<description>Full-Spectrum Cybersecurity Protection</description>
	<lastBuildDate>Wed, 19 Apr 2023 14:01:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://fortresssrm.com/wp-content/uploads/2021/05/cropped-FORT_Favicon-32x32.png</url>
	<title>Highlight Archives | Fortress SRM</title>
	<link>https://fortresssrm.com/category/highlight/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyber Resiliency is Business Resiliency</title>
		<link>https://fortresssrm.com/cyber-resiliency-is-business-resiliency/</link>
		
		<dc:creator><![CDATA[Fortress SRM]]></dc:creator>
		<pubDate>Mon, 01 Mar 2021 19:02:00 +0000</pubDate>
				<category><![CDATA[Highlight]]></category>
		<category><![CDATA[Incident Prevention]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=469</guid>

					<description><![CDATA[<p>Cyber resiliency is an organization’s ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on cybersecurity resources. This standard definition of cyber resilience was ...</p>
<p>The post <a href="https://fortresssrm.com/cyber-resiliency-is-business-resiliency/">Cyber Resiliency is Business Resiliency</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Cyber resiliency is an organization’s ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on cybersecurity resources. This standard definition of cyber resilience was created by the <a href="https://www.nist.gov/" target="_blank" rel="noreferrer noopener">National Institute of Standards and Technology</a> and we believe it is spot-on.<br><br>Cyber resiliency is also business resiliency. A business that is cyber resilient can defend itself against cyber-attacks, limit the negative impact a security incident can have, and ensure business continuity and uninterrupted operation during and after the attack. Being cyber resilient also helps organizations withstand and recover from other business interruptions, such as natural disasters, hardware failures, data loss, and power outages.<br><br>There is a distinct difference between cybersecurity and cyber resiliency. Cybersecurity is preventing a cyber-attack using tools such as endpoint detection and response (EDR), firewalls, malware detection software, and improving security behaviors with employee anti-phishing email training and timely security patch updates.<br><br>Being cyber resilient is letting go of the belief that an organization can create an impenetrable barrier between it and cyber criminals. Instead, cyber resiliency assumes that attacks will happen, and operations will be disrupted so safety precautions must be implemented to respond to, and recover from, cyber-attacks.<br><br>A cyber and business resiliency mindset seeks to identify the parts of a business that can be disrupted, and once identified, is focused on limiting the impact of a disruption. As an example, if a power outage occurs, are there data backups in place for critical and non-critical business systems? How soon can systems be restored? Are there multiple backups in different locations in the event of a natural disaster?<br><br>Not until measures are put in place to minimize the impact of disruptions can a business consider itself resilient.<br><br>There are three main elements of cyber resiliency: <strong>Cybersecurity Protection</strong>, <strong>Continuation of Normal Business</strong>, and <strong>Adaptability</strong>.</p>



<ul class="wp-block-list"><li><strong>Cybersecurity Protection</strong>&nbsp;is putting security measures and tools in place to prevent unauthorized access to your systems and network. It includes using EDR, firewalls, VPNs, and staff training to defend against cyber-attacks.<br></li><li><strong>Continuation of Normal Business</strong>&nbsp;is the point at which an organization is operating normally&nbsp;after&nbsp;a security incident or can continue operating&nbsp;during&nbsp;an incident. This includes the time it takes to restore all systems from backups.<br></li><li><strong>Adaptability&nbsp;</strong>refers to how easily the organization can defend against ever evolving and changing cyber-attacks. The more adaptable an organization is, the more cyber resilient it is.</li></ul>



<p>Achieving cyber resiliency is like seeing a city on a map – you know where it is, but the important question is, how do you get there?<br><br>We hope these&nbsp;<strong>6 Steps to Cyber Resiliency</strong>&nbsp;can help your organization become more business resilient:</p>



<ol class="wp-block-list"><li><strong>Plan</strong><br>Create an incident response team and response plan, test your security, and practice, practice, practice what to do in the event of a security incident.<br></li><li><strong>Protect</strong><br>Put cybersecurity tools in place, such as EDR, SIEM, and firewalls to create a defense system that can withstand most cyber threats your organization may face.<br></li><li><strong>Defend</strong><br>With an active cybersecurity framework established, your security tools can defend your business against most security threats and disruptive events and allow you to keep operating during an incident.<br></li><li><strong>Restore</strong><br>Have a plan and safety measures in place to restore your critical and non-critical business systems from on-site, offsite, or cloud-based data backups.<br></li><li><strong>Observe &amp; Analyze</strong><br>Implement software tools that report, log, and repel cyber treats in real-time. These tools rely on machine learning, artificial intelligence, and automated threat hunting and can learn and adapt to prevent future cyber threats.<br></li><li><strong>Adapt</strong><br>Always assess your threat-readiness and cybersecurity protection to maintain normal operations now, and in the future.</li></ol>



<p>Cyber resiliency takes work but is essential for business survival in the information age. It’s also important to know that it’s OK to ask for help!<br><br>Fortress Security Risk Management is a global data protection company that helps organizations dramatically minimize their risk of disruption from unforeseen events like cyber-attacks and data breaches by providing industry-best cybersecurity services to prepare your organization to be cyber resilient. Our goal is to help every client secure their future with the highest degree of security and the least amount of risk.</p>
<p>The post <a href="https://fortresssrm.com/cyber-resiliency-is-business-resiliency/">Cyber Resiliency is Business Resiliency</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Planning a Merger or Acquisition? Cybersecurity is Step One</title>
		<link>https://fortresssrm.com/planning-a-merger-or-acquisition-cybersecurity-is-step-one/</link>
		
		<dc:creator><![CDATA[Fortress SRM]]></dc:creator>
		<pubDate>Sun, 15 Nov 2020 22:25:00 +0000</pubDate>
				<category><![CDATA[Highlight]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=512</guid>

					<description><![CDATA[<p>True story: It’s Monday morning, and today, Company X is going to announce a large acquisition, but as employees arrive to work, they find the company’s systems are locked. Even ...</p>
<p>The post <a href="https://fortresssrm.com/planning-a-merger-or-acquisition-cybersecurity-is-step-one/">Planning a Merger or Acquisition? Cybersecurity is Step One</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>True story: It’s Monday morning, and today, Company X is going to announce a large acquisition, but as employees arrive to work, they find the company’s systems are locked. Even worse, their data has been ransomed, and the unknown attacker is threatening to expose proprietary secrets and specifics of the acquisition and destroy data unless the company pays a seven-figure ransom.<br><br>It’s a nightmare scenario, and it is happening more and more often to companies engaged in a merger or acquisition (M&amp;A).<br><br>Cyber-attacks based on M&amp;A activity aren’t coincidental; they happen because cybercriminals are skilled at finding companies involved in M&amp;A and carefully time their attack, because they know that in the haste to get the deal done, the company is probably willing to do just about anything to make the problem go away.<br><br>With merger and acquisition activity projected to increase for the remainder of 2020 and into 2021, and data protection and related privacy regulations among the issues impacting M&amp;A strategy and activity (Deloitte 2020), is there anything you can do to prevent a cyber-attack before, during, or after a merger or acquisition?<br><br>Absolutely.</p>



<h2 class="wp-block-heading"><strong>Pre-M&amp;A Cybersecurity</strong></h2>



<p>During the investigatory or planning stages of a merger or acquisition, before the plans are set in motion, your organization should perform a complete security program and vulnerability assessment. This should be done by your in-house security team, or if you don’t have the internal resources, an outside cybersecurity consultant should be brought in.<br><br>Your security assessment will identify gaps in your Cybersecurity Incident Response Plan, determine if your network is secure from intrusion, and most importantly, verify that a cybercriminal hasn’t already infiltrated your network, because if they have, they will almost certainly exploit your M&amp;A for their own gain.<br><br>It is also important to understand that normal M&amp;A activity can tip off cybercriminals. A few actions that can call attention to a merger and acquisition:</p>



<ul class="wp-block-list"><li>Posting jobs that require previous M&amp;A experience</li><li>Securing funding from investors to boost financial strength</li><li>Reports from industry analysts that predict future M&amp;A activity</li></ul>



<p>&nbsp;Sophisticated cybercriminals will watch for these types of behaviors to identify targets so your organization needs to be vigilant to protect itself. This is also a good time to train company executives to not fall for spear phishing or malware attacks and to refrain from using unsecured networks or personal email to discuss details of the proposed transaction. Once a cybercriminal gains access to your network, they can expose the potential deal earlier than you intended, or derail it all together with a ransomware attack.<br><br>Cybersecurity awareness applies to both buying and selling companies, and both need to do their best to ensure their network environments are free of uninvited hackers, waiting for the right time to attack.</p>



<h2 class="wp-block-heading"><strong>In-Process M&amp;A Cybersecurity</strong></h2>



<p>Accomplished cybercriminals watch for telltale M&amp;A behavior while it is in process.<br><br>Changes in marketing behavior is a sign that a company may be exploring an acquisition or is positioning itself to be acquired. Sudden decreases in advertising and PR and slower product introductions and rollouts can alert a trained eye to an impending deal. Staff reductions to inflate profitability is another tell, and cybercriminals may phish former employees to confirm their theories and acquire valuable data and / or network access.<br><br>During a M&amp;A due diligence period, the buying and selling companies exchange a great deal of information, which provides cybercriminals many opportunities to intercept and steal data. Employees of both companies may also be hit with spear phishing attempts that allow a bad actor access to network assets.<br><br>While negotiations are happening, company executives are especially susceptible to an attack. Organizations with poorly secured endpoints, like laptops and smartphones, or an executive using unsecured public Wi-Fi or their own device to review documents while they travel, are exposing high-value data to potential thieves.</p>



<h2 class="wp-block-heading"><strong>Post M&amp;A Cybersecurity</strong></h2>



<p>The largest risk after a M&amp;A has been announced are employees that fear their jobs will be eliminated or drastically changed. They may steal sensitive company data, or inadvertently leak it, and are vulnerable to phishing and social engineering attempts by a cybercriminal to gain access, or deeper access, to the network environment.<br><br>Once the two companies are one, the risk is twice as great because a larger company, still integrating technologies, give cybercriminals a larger opening through which to enter. Board members and Leadership of both companies should give secure technology integrations a high priority, both during the process and after the deal is closed.</p>



<h2 class="wp-block-heading"><strong>Putting it All Together</strong></h2>



<p>Cyber-attacks can have disastrous effects on a merger or acquisition. In 2016, Abbott acquired a medical device manufacturer and had to recall 500,000 pacemakers because of a hacking risk. Also in 2016, Marriott International acquired Starwood for $13.6 billion, only to learn about a cyber-attack that exposed sensitive personal data of nearly 500 million customers; a liability that could cost the company up to $1 billion in legal expenses and regulatory fines.<br><br>Cybersecurity vigilance is needed throughout the entire M&amp;A process. Cybercriminals can take advantage of individuals’ behaviors, unintentional clues, and network vulnerabilities to create cyber risk. Organizations that are especially cautious and cyber mature through every step of the process, will undoubtably mitigate the risks associated with cybercrime during a M&amp;A.<br><br>Mergers and acquisitions are difficult enough to navigate, but when a cyber-attack happens to either company, the results can be disastrous. If you are exploring a M&amp;A and would like to have a confidential conversation with one of our cybersecurity experts to improve your cybersecurity readiness, simply complete the form below &#8211; we’re here to help!<br><br>Fortress Security Risk Management is a global data protection company that helps organizations dramatically minimize their risk of disruption from unforeseen events like cyber-attacks and data breaches. Our goal is to help every client achieve the highest degree of security and the least amount of risk their organization can afford, or what we call, SecurityCertainty<sup>SM</sup>.</p>
<p>The post <a href="https://fortresssrm.com/planning-a-merger-or-acquisition-cybersecurity-is-step-one/">Planning a Merger or Acquisition? Cybersecurity is Step One</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Will A Data Breach Cost You?</title>
		<link>https://fortresssrm.com/what-will-a-data-breach-cost-you/</link>
		
		<dc:creator><![CDATA[Fortress SRM]]></dc:creator>
		<pubDate>Sat, 15 Aug 2020 16:35:17 +0000</pubDate>
				<category><![CDATA[Highlight]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Infographics]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?post_type=infographic&#038;p=578</guid>

					<description><![CDATA[<p>Only you will be able to estimate the financial impact and business disruption a data breach will have on your company, so we provide some potential costs to guide your ...</p>
<p>The post <a href="https://fortresssrm.com/what-will-a-data-breach-cost-you/">What Will A Data Breach Cost You?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Only you will be able to estimate the financial impact and business disruption a data breach will have on your company, so we provide some potential costs to guide your estimations.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="801" height="2434" src="https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic.png" alt="" class="wp-image-1163" srcset="https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic.png 801w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-99x300.png 99w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-337x1024.png 337w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-768x2334.png 768w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-505x1536.png 505w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-674x2048.png 674w, https://fortresssrm.com/wp-content/uploads/2023/04/fsrm-what-will-data-breach-cost-infographic-100x304.png 100w" sizes="(max-width: 801px) 100vw, 801px" /></figure>
<p>The post <a href="https://fortresssrm.com/what-will-a-data-breach-cost-you/">What Will A Data Breach Cost You?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
