<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Incident Prevention Archives | Fortress SRM</title>
	<atom:link href="https://fortresssrm.com/category/incident-prevention/feed/" rel="self" type="application/rss+xml" />
	<link>https://fortresssrm.com/category/incident-prevention/</link>
	<description>Full-Spectrum Cybersecurity Protection</description>
	<lastBuildDate>Fri, 11 Apr 2025 01:39:55 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://fortresssrm.com/wp-content/uploads/2021/05/cropped-FORT_Favicon-32x32.png</url>
	<title>Incident Prevention Archives | Fortress SRM</title>
	<link>https://fortresssrm.com/category/incident-prevention/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 2)</title>
		<link>https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-2/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Wed, 05 Mar 2025 14:54:29 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1590</guid>

					<description><![CDATA[<p>Professional &#38; Organized: How the GTSEZ Encourages the Multi-functional Criminal Enterprise, and What To Do About It By Chuck Mackey Introduction In Part 1, we introduced you to the Golden ...</p>
<p>The post <a href="https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-2/">The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 2)</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Professional &amp; Organized: How the GTSEZ Encourages the Multi-functional Criminal Enterprise, and What To Do About It</strong></p>



<p class="wp-block-paragraph"><strong><em>By Chuck Mackey</em></strong></p>



<p class="wp-block-paragraph"><strong>Introduction</strong></p>



<p class="wp-block-paragraph">In Part 1, we introduced you to the <strong>Golden Triangle Special Economic Zone (GTSEZ)</strong>, established in 2007 in Laos&#8217; Bokeo Province. Initially envisioned as a beacon of economic development, the GTEZ, located at the convergence of Laos, Myanmar, and Thailand, promised prosperity and growth. However, behind its glittering facade, a dark unchecked underworld has flourished over the last 15 years.</p>



<p class="wp-block-paragraph">The GTSEZ is now a notorious hub for <strong>transnational crime</strong>, including <em>drug trafficking, human trafficking, wildlife smuggling, and cybercrime</em>. Despite international sanctions and efforts to curb ever-expanding criminal activities, the zone remains a lawless enclave, where corruption and exploitation thrive unabated.</p>



<p class="wp-block-paragraph">In this article, we will explore how the Multi-functional Criminal Enterprise (MFCE) has flourished by adopting the same professional management doctrines and principles used by legitimate businesses worldwide. These criminal organizations have evolved beyond traditional illicit activities, employing sophisticated business strategies to expand their operations and maximize profits. By understanding their methods, we can better develop strategies to disrupt their activities and mitigate their impact.<strong></strong></p>



<p class="wp-block-paragraph"><strong>How a Multi-functional Criminal Enterprise is Professionally Organized<a href="#_ftn1" id="_ftnref1"><strong>[1]</strong></a></strong></p>



<p class="wp-block-paragraph"><strong><em>The Principle of Diversification</em></strong><strong><em></em></strong></p>



<p class="wp-block-paragraph">MFCEs have evolved into sophisticated operations, engaging in a wide array of illicit activities. Beyond traditional drug trafficking and extortion, they now delve heavily into cybercrime, human trafficking, arms smuggling, and environmental crimes. This diversification spreads risk across their entire operation and maximizes profits across various illegal markets.</p>



<p class="wp-block-paragraph"><strong><em>Business-like Operations</em></strong><strong><em></em></strong></p>



<p class="wp-block-paragraph">MFCEs operate with a chilling level of professionalism. <em>They</em> <em>employ business strategies such as market analysis, supply chain management, and financial planning</em>. Legitimate businesses are often used as fronts to launder money and facilitate illegal activities. For instance, they invest in real estate, hospitality, or import-export businesses to mask their operations, creating a facade of legitimacy while conducting heinous crimes behind closed doors and aggressive expansion tactics.</p>



<p class="wp-block-paragraph"><strong><em>Use of Technology</em></strong></p>



<p class="wp-block-paragraph">Advancements in technology have exponentially boosted the capabilities of MFCEs. They use encrypted communication, cryptocurrencies, and the dark web to conduct their activities with greater anonymity and security.</p>



<p class="wp-block-paragraph">Cybercrime has become THE major component of their operations, with activities ranging from <em>ransomware attacks to large-scale financial fraud</em>. These enterprises exploit the anonymity of the Internet to perpetrate crimes on a global scale, often leaving victims powerless and law enforcement agencies struggling to keep up. Technology shrinks their “time-to-market” and enables cybercrime to expand on a global basis, hitting every single continent with endless phishing <a>scams</a>.</p>



<p class="wp-block-paragraph"><strong><em>Organizational Structure</em></strong></p>



<p class="wp-block-paragraph">MFCEs have a hierarchical structure, not unlike any major corporation, with clear roles, responsibilities, and paychecks. This includes leaders, senior managers, advisors, and various heads of operations, finance, security, and external relations. Each division manages specific criminal activities, ensuring efficient and coordinated operations. This meticulous organization allows them to operate like well-oiled machines, executing complex criminal schemes with precision. See chart below.</p>



<figure class="wp-block-image size-full"><a href="https://fortresssrm.com/wp-content/uploads/2025/03/Org-structure.png"><img fetchpriority="high" decoding="async" width="685" height="634" src="https://fortresssrm.com/wp-content/uploads/2025/03/Org-structure.png" alt="" class="wp-image-1594" srcset="https://fortresssrm.com/wp-content/uploads/2025/03/Org-structure.png 685w, https://fortresssrm.com/wp-content/uploads/2025/03/Org-structure-300x278.png 300w, https://fortresssrm.com/wp-content/uploads/2025/03/Org-structure-100x93.png 100w" sizes="(max-width: 685px) 100vw, 685px" /></a></figure>



<p class="wp-block-paragraph"><strong>The GTSEZ Encourages the MFCE</strong></p>



<p class="wp-block-paragraph"><strong><em>Strategic Location</em></strong><em>&nbsp;</em></p>



<p class="wp-block-paragraph">The GTSEZ&#8217;s location makes it an ideal transit point for illicit goods and activities. This strategic positioning facilitates the flow of drugs, human trafficking, smuggling, technology, and other illegal operations. The zone&#8217;s geographical advantage is exploited to the fullest, turning it into a bustling hub of criminal activity.</p>



<p class="wp-block-paragraph"><strong><em>Economic Development Facade</em></strong></p>



<p class="wp-block-paragraph">The GTSEZ was initially established to promote economic development, attracting investments and tourists. However, this facade of legitimate economic activity provides perfect cover for criminal enterprises to operate with minimal scrutiny. Mixing legitimate and illegal operations blurs the line, creating a confusing, hard-to-unravel web of deceit.</p>



<p class="wp-block-paragraph"><strong><em>Corruption and Weak Law Enforcement</em></strong></p>



<p class="wp-block-paragraph">The influx of illicit money has fueled corruption, undermined the rule of law, and eroded public trust in authorities. Efforts by Lao authorities to crack down on these activities have been severely limited and ineffective, allowing the GTSEZ to continue operating as a haven for transnational crime. Corrupt officials <a>turn a blind eye to</a> the rampant criminality, further entrenching the zone&#8217;s lawlessness.</p>



<p class="wp-block-paragraph"><strong><em>Cybercrime Operations</em></strong></p>



<p class="wp-block-paragraph">The GTSEZ has become a breeding ground for cybercrime. Fraud factories, staffed by human trafficking victims operate within the zone, conducting elaborate global <a>scam</a> operations. The phishing email or text you receive liking was generated by a MFCE, not some random lone criminal. Victims (human trafficking) are coerced into working in these <a>scam</a> centers and “Phishing Farms” where they are forced to make fraudulent calls and outbound texts and engage in other illegal activities. The exploitation of human trafficking victims for cybercrime adds a horrifying layer to the already grim reality of the GTSEZ.</p>



<figure class="wp-block-image size-large"><a href="https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-scaled.jpeg"><img decoding="async" width="1024" height="683" src="https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-1024x683.jpeg" alt="" class="wp-image-1591" srcset="https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-1024x683.jpeg 1024w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-300x200.jpeg 300w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-768x512.jpeg 768w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-1536x1024.jpeg 1536w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-2048x1365.jpeg 2048w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-100x67.jpeg 100w, https://fortresssrm.com/wp-content/uploads/2025/03/Criminal-enterprise-1900x1267.jpeg 1900w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<p class="wp-block-paragraph"><strong>What To Do About It</strong></p>



<p class="wp-block-paragraph"><strong><em>Strengthen Law Enforcement</em></strong></p>



<p class="wp-block-paragraph">There is a need for stronger law enforcement within the GTSEZ to crack down on criminal activities. This includes increasing the capacity of local police, improving investigative techniques, and ensuring that law enforcement agencies are free from corruption. Without robust law enforcement, the cycle of crime and exploitation will continue unabated.</p>



<p class="wp-block-paragraph"><strong><em>International Cooperation</em></strong></p>



<p class="wp-block-paragraph">Given the transnational nature of the crimes associated with the GTSEZ and MFCEs, international cooperation is crucial. Countries need to work together to share intelligence, conduct joint operations, and apply consistent pressure on criminal enterprises operating within the zone. A united global front is essential to dismantle these sophisticated criminal networks.</p>



<p class="wp-block-paragraph"><strong><em>Promote Legitimate Economic Development</em></strong></p>



<p class="wp-block-paragraph">Efforts should be made to promote legitimate economic development within the GTSEZ. This includes attracting genuine investors, creating job opportunities for local populations, and ensuring that economic activities are transparent and accountable. By fostering legitimate economic growth, the grip of criminal enterprises on the zone is weakened.</p>



<p class="wp-block-paragraph"><strong><em>Protect Victims</em></strong></p>



<p class="wp-block-paragraph">There should be a focus on protecting victims of human trafficking and exploitation within the GTSEZ. This includes providing support services, safe havens, and legal assistance to help victims escape from criminal enterprises and rebuild their lives. The human cost of the GTSEZ&#8217;s criminality is immense, and addressing it requires a compassionate and comprehensive approach.</p>



<p class="wp-block-paragraph"><strong><em>Address Corruption</em></strong></p>



<p class="wp-block-paragraph">Combating corruption is essential to restoring the rule of law within the GTSEZ. This involves implementing anti-corruption measures, holding corrupt officials accountable, and promoting transparency in government operations. Without addressing the root cause of corruption, any efforts to combat crime in the GTSEZ will be futile.</p>



<p class="wp-block-paragraph"><strong><em>Public Awareness and Advocacy</em></strong></p>



<p class="wp-block-paragraph">Raising public awareness about the criminal activities within the GTSEZ and the broader operations of MFCEs is also a critical component of the response. Media investigations and reports have shed light on the dark underworld of the GTSEZ, prompting calls for action from the international community. Advocacy efforts by human rights organizations are also putting pressure on governments to take decisive action.</p>



<p class="wp-block-paragraph">These advancements represent significant steps forward in the fight against the criminal enterprises operating within the GTSEZ. Continued international cooperation, technological innovation, and robust law enforcement efforts are essential to achieving lasting success.</p>



<p class="wp-block-paragraph"><strong><em>Increased Regulation and Oversight</em></strong></p>



<p class="wp-block-paragraph">Efforts by Lao authorities to improve regulations and increase law enforcement within the GTSEZ have been ongoing. Although challenges remain, these efforts are aimed at curbing the rampant criminal activities and restoring some level of order within the zone. This includes stricter enforcement of existing laws and the implementation of new regulations to address emerging threats.</p>



<p class="wp-block-paragraph"><strong><em>Technological Advancements</em></strong></p>



<p class="wp-block-paragraph">Law enforcement agencies are leveraging advancements in technology to combat MFCEs more effectively. This includes the use of artificial intelligence (AI) for predictive policing, improved surveillance capabilities, and more efficient identification of potential threats. AI technologies are being deployed to analyze large datasets, identify patterns, and predict crime hotspots, enhancing the ability of law enforcement to respond proactively.</p>



<p class="wp-block-paragraph"><strong><em>Heightened International Scrutiny and Sanctions</em></strong></p>



<p class="wp-block-paragraph">The GTSEZ faces intense scrutiny from international bodies and human rights organizations due to persistent human rights concerns and criminal activities. The United States Treasury Department has sanctioned the Kings Romans Group, its owner Zhao Wei, and the &#8220;Zhao Wei Transnational Crime Organization&#8221; for their involvement in money laundering and drug trafficking. These sanctions aim to disrupt the financial networks supporting these criminal enterprises.</p>



<p class="wp-block-paragraph">By addressing these issues, the international community can help dismantle the criminal enterprises operating within the GTSEZ and support efforts to restore law and order in this troubled region. The stakes are high, and the consequences of inaction are dire.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"> <a id="_ftn1" href="#_ftnref1">[1]</a>Sources: Police 1, Business &amp; Human Rights Resource Centre, Forbes, Sci-Tech Today, Infosec Institute, Bolster AI, Living Security, The Diplomat, purplesec.us.</p>
<p>The post <a href="https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-2/">The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 2)</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 1)</title>
		<link>https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-1/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Mon, 24 Feb 2025 16:41:43 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1582</guid>

					<description><![CDATA[<p>Introduction In 2007, the Lao government, in collaboration with the Hong Kong-registered Kings Romans Group, established the Golden Triangle Special Economic Zone (GTSEZ)[1] in the Ton Pheung District of Bokeo ...</p>
<p>The post <a href="https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-1/">The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 1)</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Introduction</strong></p>



<p class="wp-block-paragraph">In 2007, the Lao government, in collaboration with the Hong Kong-registered Kings Romans Group, established the <strong>Golden Triangle Special Economic Zone (GTSEZ)<a href="#_ftn1" id="_ftnref1"><strong>[1]</strong></a></strong> in the Ton Pheung District of Bokeo Province, Laos.</p>



<p class="wp-block-paragraph">This 3,000-hectare zone, nestled along the Mekong River, was envisioned as a beacon of economic development, promising prosperity, and growth. However, beneath the veneer of progress, a sinister underworld has flourished, transforming the GTSEZ into a notorious hub of criminal enterprises.</p>



<p class="wp-block-paragraph">From its inception in 2007, the GTSEZ was dominated by the Kings Romans Casino, a glittering facade that attracted Chinese tourists and gamblers. Behind the casino&#8217;s opulent doors, a dark network of illicit activities began to take root. The zone quickly gained a reputation for being a lawless enclave, where <strong><em>drug trafficking, human trafficking, and wildlife smuggling</em></strong> thrived.</p>



<p class="wp-block-paragraph">In January 2018, the United States Treasury Department sanctioned the Kings Romans Group, its owner Zhao Wei, and the<strong> &#8220;Zhao Wei Transnational Crime Organization,&#8221;</strong> accusing them of using the casino to <strong>launder money</strong> and traffic drugs.</p>



<p class="wp-block-paragraph">Despite these sanctions, the criminal activities within the GTSEZ have only intensified. Reports of <strong>high-grade crystal methamphetamine seizures</strong> linked to the zone surged, with drugs and precursor chemicals flowing through Laos to neighboring countries.</p>



<p class="wp-block-paragraph"><strong>Now, the GTSEZ has become a breeding ground for cybercrime.</strong> Fraud factories, staffed by human trafficking victims, operate within the zone, conducting elaborate global scam operations. Victims from various countries are lured or coerced into working in these fraud centers and Phishing Farms<a href="#_ftn2" id="_ftnref2">[2]</a>, where they are forced to make fraudulent calls and engage in other illegal activities.</p>



<figure class="wp-block-image size-full is-resized"><a href="https://fortresssrm.com/wp-content/uploads/2025/02/Laos.jpg"><img decoding="async" width="2200" height="1467" src="https://fortresssrm.com/wp-content/uploads/2025/02/Laos.jpg" alt="" class="wp-image-1586" style="width:560px;height:auto" srcset="https://fortresssrm.com/wp-content/uploads/2025/02/Laos.jpg 2200w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-300x200.jpg 300w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-1024x683.jpg 1024w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-768x512.jpg 768w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-1536x1024.jpg 1536w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-2048x1366.jpg 2048w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-100x67.jpg 100w, https://fortresssrm.com/wp-content/uploads/2025/02/Laos-1900x1267.jpg 1900w" sizes="(max-width: 2200px) 100vw, 2200px" /></a></figure>



<p class="wp-block-paragraph"><strong>The Rise of the Multi-functional Criminal Enterprise</strong></p>



<p class="wp-block-paragraph"><strong>Multi-functional criminal enterprises (MFCE)</strong> have expanded beyond traditional activities like drug trafficking and extortion to include a wide range of illicit operations. These enterprises now engage in <strong><em>cybercrime, human trafficking for labor, arms smuggling, and environmental crimes</em></strong>.</p>



<p class="wp-block-paragraph">This diversification allows them to spread risk and capitalize on various illegal markets.</p>



<p class="wp-block-paragraph"><strong><em>Business-like Operations</em></strong></p>



<p class="wp-block-paragraph">The MFCE operate with a high degree of professionalism, employing business strategies such as <strong><em>market analysis, supply chain management, and financial planning</em></strong>.</p>



<p class="wp-block-paragraph">They often use legitimate businesses as fronts to launder money and facilitate illegal activities. For example, they might invest in real estate, hospitality, or import-export businesses to mask their operations.</p>



<p class="wp-block-paragraph">The zone&#8217;s unchecked criminality has had devastating consequences for the local population and the broader region<a href="#_ftn3" id="_ftnref3">[3]</a>. The influx of illicit money has fueled corruption, undermined the rule of law, and eroded public trust in authorities. Efforts by Lao authorities to crack down on these activities have been sporadic and ineffective, allowing the GTSEZ to continue operating as a haven for transnational crime.</p>



<p class="wp-block-paragraph"><strong><em>Worker Exploitation</em></strong></p>



<p class="wp-block-paragraph">Worker exploitation within the MFCE takes many forms, often involving severe abuse and coercion.&nbsp;Here are just a few examples:</p>



<ul class="wp-block-list">
<li><strong>Forced labor</strong>&nbsp;is a common practice where workers are compelled to work under threat or coercion. They are subjected to long hours, minimal pay, and unsafe working conditions.</li>



<li><strong>Human Trafficking</strong>&nbsp;involves the recruitment, transportation, and harboring of individuals through force, fraud, or coercion for the purpose of exploitation. Victims are forced into labor or sexual exploitation. But a growing area of trafficking means victims are used in cybercrime operations, where they are made to send fraudulent emails or manage fake websites.</li>



<li><strong>Debt Bondage</strong>&nbsp;occurs when workers are forced to work to repay a debt. The debt is often manipulated to ensure that it can never be fully repaid, trapping the worker in a cycle of exploitation.</li>



<li><strong>Wage Theft</strong> occurs when employers withhold wages or deny workers the compensation to which they are legally entitled. This can include not paying for overtime, underreporting hours worked, or paying below the minimum wage.</li>



<li><strong>Psychological and Physical Abuse</strong> where workers are subjected to threats, intimidation, and violence to ensure compliance and prevent escape. This abuse can have long-lasting effects on their mental and physical health.</li>



<li><strong>Document Confiscation </strong>is where employers confiscate workers&#8217; identification documents, such as passports and work permits, to prevent them from leaving or seeking help.</li>
</ul>



<p class="wp-block-paragraph"><strong><em>Cybercrime: THE New Growth Strategy of the MFCE</em></strong></p>



<p class="wp-block-paragraph">Cybercrime is a growing strategy. Although there are many forms, three are highly represented throughout the GTSEZ:</p>



<ol start="1" class="wp-block-list">
<li><strong>Phishing</strong>: Workers send emails that are from legitimate sources, tricking recipients into providing sensitive information. Launched from the GTSEZ, they are perpetrated on a global basis.</li>



<li><strong>Ransomware</strong>: Victims are made to deploy ransomware, which encrypts data on a victim&#8217;s computer and demands a ransom for its release.</li>



<li><strong>Fraud</strong>: This includes creating fake websites or profiles (synthetic fraud) to deceive individuals into providing personal information or making payments, and fraudulent wire transfers.</li>
</ol>



<p class="wp-block-paragraph"><strong><em>The GTSEZ Impact on the World</em></strong></p>



<p class="wp-block-paragraph">The Golden Triangle Special Economic Zone (GTSEZ) has significant implications for the rest of the world, particularly in terms of its role in <em>transnational crime</em>, economic development, and regional stability.</p>



<p class="wp-block-paragraph"><strong>Hub of Transnational Crime</strong></p>



<p class="wp-block-paragraph">The GTSEZ has become a notorious hub for various forms of transnational crime, including drug trafficking, human trafficking, wildlife smuggling, and cybercrime. The zone&#8217;s strategic location along the Mekong River, where Laos, Myanmar, and Thailand meet, makes it an ideal transit point for illicit goods and activities.</p>



<p class="wp-block-paragraph">This has global repercussions, as the drugs and other illegal products trafficked through the GTSEZ often end up in markets around the world, fueling addiction, crime, and violence.</p>



<p class="wp-block-paragraph"><strong>Economic Development and Corruption</strong></p>



<p class="wp-block-paragraph">While the GTSEZ was initially established to promote economic development, the influx of illicit money has led to widespread corruption and undermined the rule of law.</p>



<p class="wp-block-paragraph">The economic benefits promised by the zone have been overshadowed by the criminal activities that dominate it. This has created a challenging environment for legitimate businesses and investors, deterring foreign investment and hindering sustainable development in the region.</p>



<p class="wp-block-paragraph"><strong>Regional Stability</strong></p>



<p class="wp-block-paragraph">The criminal activities within the GTSEZ have significant implications for regional stability. The flow of drugs and precursor chemicals through Laos has exacerbated the drug crisis in neighboring countries, particularly Thailand and Vietnam. Additionally, the human trafficking operations within the zone contribute to regional instability by exploiting vulnerable populations and fueling illegal migration.</p>



<p class="wp-block-paragraph"><strong>International Response</strong></p>



<p class="wp-block-paragraph">The international community has taken notice of the GTSEZ&#8217;s role in transnational crime. The United States Treasury Department sanctioned the Kings Romans Group, its owner Zhao Wei, and the &#8220;Zhao Wei Transnational Crime Organization&#8221; for their involvement in money laundering and drug trafficking. These sanctions have had no impact on the GTSEZ’s growth and expansion.</p>



<p class="wp-block-paragraph"><strong>Conclusion</strong></p>



<p class="wp-block-paragraph">The GTSEZ serves as a stark example of how economic development initiatives can be co-opted by criminal enterprises, leading to significant negative consequences for the region and the world. Addressing the challenges posed by the GTSEZ requires a multifaceted approach, including stronger law enforcement, international cooperation, and efforts to promote legitimate economic development.</p>



<p class="wp-block-paragraph"><strong>Next Issue</strong></p>



<p class="wp-block-paragraph"><strong><em>Part 2: Professional &amp; Organized: How the GTSEZ Encourages the MFCE and What To Do About It</em></strong></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><a href="#_ftnref1" id="_ftn1">[1]</a> Sources: Berkeley Policial Review, Wikipedia, Bloomberg, Newsweek, LA Times, United States Department of State, Journal of Illicit Economies and Development, Development and Surges of Organized Crime: An Application of Enterprise Theory, United Nations Office of Drugs and Crime: The Role of Technology in Human Trafficking, Arkose Labs, and other news and research authorities.</p>



<p class="wp-block-paragraph"><a href="#_ftnref2" id="_ftn2">[2]</a> Phishing farms represent a dangerous intersection of human trafficking and cybercrime. Addressing this issue requires a coordinated effort from international law enforcement agencies, cybersecurity experts, and policymakers to dismantle these operations and protect vulnerable individuals from exploitation.</p>



<p class="wp-block-paragraph"><a href="#_ftnref3" id="_ftn3">[3]</a> Forecasted population growth is to 300,000 people by 2026.</p>
<p>The post <a href="https://fortresssrm.com/the-golden-triangle-welcome-to-the-modern-wild-wild-east-part-1/">The Golden Triangle: Welcome to the Modern Wild, Wild, East (Part 1)</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Understanding the Known Knowns, Known Unknowns, and Unknown Unknowns in Cybersecurity</title>
		<link>https://fortresssrm.com/understanding-the-known-knowns/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Tue, 28 Jan 2025 16:28:16 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1570</guid>

					<description><![CDATA[<p>In cybersecurity, navigating the murky waters of risk management requires a deep understanding of the "known knowns," "known unknowns," and "unknown unknowns." These concepts, borrowed from military strategy, are incredibly relevant as businesses face increasingly sophisticated cyber threats in a constantly shifting landscape.</p>
<p>The post <a href="https://fortresssrm.com/understanding-the-known-knowns/">Understanding the Known Knowns, Known Unknowns, and Unknown Unknowns in Cybersecurity</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Cybersecurity Matters Blog<br>Kevin Baker</em>, <em>CISO</em></p>



<p class="wp-block-paragraph">In cybersecurity, navigating the murky waters of&nbsp;<strong>risk management</strong>&nbsp;requires a deep understanding of the &#8220;known knowns,&#8221; &#8220;known unknowns,&#8221; and &#8220;unknown unknowns.&#8221; These concepts, borrowed from <strong>military strategy</strong>, are incredibly relevant as businesses face increasingly sophisticated cyber threats in a constantly shifting landscape.</p>



<p class="wp-block-paragraph"><strong>Known Knowns: The Clear and Present Dangers</strong></p>



<p class="wp-block-paragraph">The&nbsp;<strong>known knowns</strong>&nbsp;in cybersecurity are the risks we are already familiar with. These include everyday threats like&nbsp;<strong>phishing emails</strong>,&nbsp;<strong>ransomware attacks</strong>, and&nbsp;<strong>social engineering</strong>&nbsp;scams. The advantage of known threats is that we can deploy well-established defenses:&nbsp;<strong>firewalls</strong>,&nbsp;<strong>intrusion detection systems</strong>, and&nbsp;<strong>encryption protocols</strong>&nbsp;all work to mitigate these risks.</p>



<p class="wp-block-paragraph">However, just because these threats are familiar doesn’t mean they can be ignored.&nbsp;Cybercriminals are constantly evolving their tactics, finding new ways to bypass security measures. The&nbsp;frequency and sophistication&nbsp;of ransomware attacks, for example, have skyrocketed in recent years. Therefore, while the threats may be known, businesses must continually refine their defenses and adapt to the evolving nature of these risks.</p>



<p class="wp-block-paragraph"><strong>Known Unknowns: A Step into Uncertainty</strong></p>



<p class="wp-block-paragraph">The&nbsp;<strong>known unknowns</strong>&nbsp;are the risks we know exist, but don’t fully understand or predict. These might include&nbsp;<strong>zero-day vulnerabilities</strong>—undiscovered flaws in software that cybercriminals can exploit before a patch is released—or&nbsp;<strong>emerging threats</strong>&nbsp;from new technologies like&nbsp;<strong>quantum computing</strong>&nbsp;or&nbsp;<strong>AI-powered attacks</strong>.</p>



<p class="wp-block-paragraph">While we may know the general areas where these threats could arise, we often don’t know their exact nature or the timing of an attack. Companies combat known unknowns by investing in&nbsp;<strong>advanced threat intelligence</strong>,&nbsp;<strong>AI-driven detection systems</strong>, and&nbsp;<strong>continuous monitoring</strong>. These tools allow organizations to rapidly detect anomalies and respond to new forms of attacks in real-time, giving them a fighting chance in an environment where the next exploit could emerge without warning.</p>



<p class="wp-block-paragraph"><strong>Unknown Unknowns: The Invisible Threats</strong></p>



<p class="wp-block-paragraph">The&nbsp;<strong>unknown unknowns</strong>&nbsp;are the most dangerous category. These are threats that we can’t foresee because they exist outside the scope of our current understanding. Think of the&nbsp;<strong>2017 WannaCry ransomware attack</strong>—it crippled organizations worldwide and came seemingly out of nowhere. No one anticipated how quickly a worm-like ransomware could spread across the globe using a previously patched Windows vulnerability.</p>



<p class="wp-block-paragraph">The rise of&nbsp;<strong>machine learning</strong>,&nbsp;<strong>IoT</strong>&nbsp;devices, and&nbsp;<strong>5G networks</strong>&nbsp;introduces a whole new set of unknown risks. Cybercriminals are likely already exploring weaknesses in these new technologies, preparing to launch attacks in ways we haven’t even imagined yet. To defend against the unknown, companies need more than just technological tools. They need to build&nbsp;<strong>adaptive, resilient systems</strong>&nbsp;and foster a culture of&nbsp;<strong>cybersecurity awareness</strong>. Regular&nbsp;<strong>tabletop exercises</strong>,&nbsp;<strong>disaster recovery simulations</strong>, and&nbsp;<strong>cross-industry collaboration</strong>&nbsp;are key to ensuring that when an unknown threat strikes, the organization can respond effectively.</p>



<p class="wp-block-paragraph"><strong>The Importance of a Holistic Approach</strong></p>



<p class="wp-block-paragraph">In this complex landscape, it’s not enough to react to threats as they appear. Businesses need to be&nbsp;<strong>proactive</strong>, understanding that the cybersecurity battleground is constantly evolving. Companies that can skillfully navigate the known knowns while preparing for both the known unknowns and the unknown unknowns will be the ones that emerge resilient, even in the face of the next unexpected cyber onslaught.</p>



<p class="wp-block-paragraph">The future of cybersecurity lies in&nbsp;<strong>adaptability</strong>—balancing technology and strategy while fostering a culture ready to face any challenge, whether we see it coming or not.</p>
<p>The post <a href="https://fortresssrm.com/understanding-the-known-knowns/">Understanding the Known Knowns, Known Unknowns, and Unknown Unknowns in Cybersecurity</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Protecting Your Business from Fraud: Sharing Knowledge Series</title>
		<link>https://fortresssrm.com/protecting-your-business-from-fraud-sharing-knowledge-series/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Thu, 19 Dec 2024 16:03:35 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<category><![CDATA[Videos]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1562</guid>

					<description><![CDATA[<p>The post <a href="https://fortresssrm.com/protecting-your-business-from-fraud-sharing-knowledge-series/">Protecting Your Business from Fraud: Sharing Knowledge Series</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<div class="x-resp-embed x-is-video x-is-youtube"><iframe loading="lazy" title="Protecting your business from fraud: Sharing Knowledge Series" width="1778" height="1000" src="https://www.youtube.com/embed/Xpm52hlTx7k?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>
<p>The post <a href="https://fortresssrm.com/protecting-your-business-from-fraud-sharing-knowledge-series/">Protecting Your Business from Fraud: Sharing Knowledge Series</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Cyber Security Recruiter talks to Jess Walpole, Chief Technology Officer, Fortress SRM</title>
		<link>https://fortresssrm.com/the-cyber-security-recruiter-talks-to-jess-walpole-fortress-srm/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Thu, 19 Dec 2024 15:54:23 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<category><![CDATA[Videos]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1560</guid>

					<description><![CDATA[<p>The post <a href="https://fortresssrm.com/the-cyber-security-recruiter-talks-to-jess-walpole-fortress-srm/">The Cyber Security Recruiter talks to Jess Walpole, Chief Technology Officer, Fortress SRM</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube"><div class="wp-block-embed__wrapper">
<div class="x-resp-embed x-is-video x-is-youtube"><iframe loading="lazy" title="The Cyber Security Recruiter talks to Jess Walpole, Chief Technology Officer, Fortress SRM" width="1333" height="1000" src="https://www.youtube.com/embed/dmfY3U_A01U?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>
<p>The post <a href="https://fortresssrm.com/the-cyber-security-recruiter-talks-to-jess-walpole-fortress-srm/">The Cyber Security Recruiter talks to Jess Walpole, Chief Technology Officer, Fortress SRM</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How the Grinch Stole Your Cookies: A Christmas Tale of AiTM Phishing Attacks</title>
		<link>https://fortresssrm.com/a-christmas-tale-of-aitm-phishing-attacks/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Tue, 17 Dec 2024 18:19:11 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1558</guid>

					<description><![CDATA[<p>In the bustling city of Cyberville, the holiday season was in full swing, while a sinister threat lurked in the shadows of the digital world.</p>
<p>The post <a href="https://fortresssrm.com/a-christmas-tale-of-aitm-phishing-attacks/">How the Grinch Stole Your Cookies: A Christmas Tale of AiTM Phishing Attacks</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Once upon a time, in the bustling city of Cyberville, the holiday season was in full swing. The streets were adorned with twinkling lights, and the air was filled with the scent of pine and freshly baked cookies. As families gathered to celebrate Christmas, little did they know that a sinister threat lurked in the shadows of the digital world.&nbsp;</p>



<p class="wp-block-paragraph">In a cozy home on Elm Street, the Johnson family was preparing for their annual Christmas Eve celebration. The children, Emma and Jack, were eagerly awaiting Santa&#8217;s arrival, while their parents, Sarah and Tom, were busy wrapping presents and setting up the Christmas tree. Unbeknownst to them, a group of cybercriminals was plotting an Adversary-in-the-Middle (AiTM) phishing attack to steal their session cookies and hijack their online accounts.&nbsp;</p>



<p class="wp-block-paragraph">The cybercriminals, led by a notorious hacker known as &#8220;The Grinch,&#8221; had devised a plan to intercept the Johnson family&#8217;s online communications. They crafted a convincing phishing email that appeared to be from a popular online retailer, complete with festive graphics and a special Christmas discount offer. The email contained a link to a fake login page designed to capture the family&#8217;s credentials and session cookies.&nbsp;</p>



<p class="wp-block-paragraph">As the Johnsons received the email, they were excited by the prospect of last-minute Christmas deals. Without suspecting any foul play, they clicked on the link and entered their login details on the fake page. The Grinch and his team began their attack, intercepting the family&#8217;s session cookies, which are small pieces of data that keep users logged into their accounts. By stealing these cookies, The Grinch could bypass the need for passwords and multi-factor authentication (MFA), gaining unauthorized access to the Johnsons&#8217; online accounts.&nbsp;</p>



<p class="wp-block-paragraph">The Grinch chuckled as he watched the session cookies flow into his servers, knowing that he could use them to hijack the family&#8217;s accounts, steal sensitive information, and carry out fraudulent transactions. He relished the thought of ruining their holiday cheer.&nbsp;</p>



<p class="wp-block-paragraph">However, not all hope was lost. In the heart of Cyberville, a group of cybersecurity experts known as the &#8220;Fortress Elves&#8221; was on high alert. Led by a brilliant analyst named Saint Nick, the Fortress Elves had been monitoring suspicious activity in the area. When they detected the phishing campaign, they sprang into action.&nbsp;</p>



<p class="wp-block-paragraph">Saint Nick and his team quickly identified the source of the attack and began working to shut it down. They deployed advanced threat detection tools and initiated a counterattack to disrupt The Grinch&#8217;s operations. As the Fortress Elves worked tirelessly, they sent out warnings to the residents of Cyberville, urging them to be cautious of phishing emails and to verify the authenticity of any links before clicking.&nbsp;</p>



<p class="wp-block-paragraph">Back at the Johnson household, Tom received the alert just in time. He quickly realized that they had fallen victim to a phishing attack and took immediate action. He changed all their passwords, enabled multi-factor authentication (MFA) on their accounts, and cleared their browser cookies and cache to remove any compromised session information. The family gathered around the fireplace, relieved that their personal information was safe, thanks to the quick actions of the Fortress Elves.&nbsp;</p>



<p class="wp-block-paragraph">Meanwhile, The Grinch&#8217;s plans were falling apart. His servers were being overwhelmed by the Fortress Elves&#8217; counterattack, and his stolen session cookies were being invalidated. Frustrated and defeated, he realized that his scheme had been foiled.&nbsp;</p>



<p class="wp-block-paragraph">As the clock struck midnight, the Johnson family celebrated Christmas with renewed joy and gratitude. They knew that the true spirit of the holiday was not just about presents and decorations, but also about the kindness and bravery of those who protect others from harm.&nbsp;</p>



<p class="wp-block-paragraph">In the end, the Fortress Elves saved Christmas in Cyberville, ensuring that families could enjoy the holiday season without fear of cyber threats. And as for The Grinch, he learned a valuable lesson: that even in the digital world, good will always triumph over evil.&nbsp;</p>



<p class="wp-block-paragraph">Merry Christmas to all, and to all a safe and secure night!</p>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>About Fortress SRM:</strong>&nbsp;<br>Fortress Security Risk Management protects companies&nbsp;from the financial, operational, and emotional trauma of&nbsp;cybercrime by&nbsp;enhancing&nbsp;the performance of their people, processes, and technology.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Offering a robust, co-managed solution to enhance an internal IT team’s capability and capacity, Fortress SRM features a full suite of managed security services (24/7/365 U.S. based monitoring, cyber hygiene (managed patching), &nbsp;endpoint detection and response (EDR), and air-gapped and immutable cloud backups) plus specialized services like Cybersecurity-as-a-Service, Incident Response including disaster recovery &amp; remediation, M&amp;A cyber due diligence, GRC advisory, identity &amp; access management, threat intelligence, vulnerability assessments, and technical testing.&nbsp;With headquarters in Cleveland, Fortress SRM supports companies with both domestic and international operations.&nbsp;</p>



<p class="wp-block-paragraph">In Case of Emergency:&nbsp;<br><strong>Cyber Attack Hotline: 888-207-0123 | Report an Attack: IR911.com&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">For Preventative and Emergency Resources, please visit:&nbsp;<br><a href="https://ransomwareclock.org/" target="_blank" rel="noreferrer noopener"><strong>RansomwareClock.org</strong></a><strong><u></u></strong></p>
<p>The post <a href="https://fortresssrm.com/a-christmas-tale-of-aitm-phishing-attacks/">How the Grinch Stole Your Cookies: A Christmas Tale of AiTM Phishing Attacks</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Quick Case Study in Zero Trust Architecture</title>
		<link>https://fortresssrm.com/a-quick-case-study-in-zero-trust-architecture/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Tue, 17 Dec 2024 16:20:02 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1556</guid>

					<description><![CDATA[<p>By Chuck Mackey, Fortress Security Risk Management Senior Security Principal You work in a bustling hospital. Physicians, nurses, and administrative staff are constantly on the move, accessing patient records, medical ...</p>
<p>The post <a href="https://fortresssrm.com/a-quick-case-study-in-zero-trust-architecture/">A Quick Case Study in Zero Trust Architecture</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>By Chuck Mackey, Fortress Security Risk Management Senior Security Principal</em></p>



<p class="wp-block-paragraph">You work in a bustling hospital. Physicians, nurses, and administrative staff are constantly on the move, accessing patient records, medical devices, back-office, and administrative systems, all directed at patient care. Data is stored, transmitted, and applied everywhere. From patient onboarding until they are discharged. But your hospital is different. Practitioners and administrators work diligently to keep all this data secure. To do so, your hospital adopted Zero Trust Architecture (ZTA), a security model that operates on the principle of <strong>&#8220;Never Trust, Always Verify.&#8221;</strong></p>



<p class="wp-block-paragraph">This is not some sharp rebuke; it is an organizational and cultural buy-in. From practitioners to office workers, to suppliers and key stakeholders. Your hospital is keen to provide the absolute best in care, but that care transcends the patient’s direct health concerns. It is just as much about patient data. It concerns Protected Health Information (PHI), Personally Identifiable Information (PII), and all that is associated with both. Security. Compliance. Governance. Risk Mitigation. </p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Never Trust, Always Verify</strong></p>



<p class="wp-block-paragraph">In your hospital, every time a doctor or nurse accesses patient records, they go through <strong>Multi-Factor Authentication (MFA)</strong>. This means after entering their password, they also need to verify their identity with a code sent to their phone or they access an Authenticator app. Even the devices they use, like tablets and computers, are verified to ensure they have the latest security updates. The same holds true for administrative staff. MFA is applied to the applications and systems they use to run the hospital and exchange data with patients and key stakeholders. Whether it is via a desktop, laptop, or mobile device.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><strong>Least Privilege Access</strong></strong></p>



<p class="wp-block-paragraph">Your hospital’s Information Security team has implemented <strong>Least Privilege Access</strong>. Each staff member has access <strong><em>only</em></strong> to the information and systems necessary for them to perform their job. A nurse can access patient records but not the hospital&#8217;s financial data. Additionally, when an IT admin needs to install software updates, she is granted elevated privileges<strong><em> only</em></strong> for the duration of the task, thanks to <strong>Just-In-Time (JIT) Access</strong>.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><strong>Micro-Segmentation</strong></strong></p>



<p class="wp-block-paragraph">Your hospital’s security and network team use <strong>Micro-Segmentation</strong> to further advance its security. The network is divided into smaller segments, each with its own security controls. Patient records are in one segment, medical devices in another, and administrative systems in yet another. This way, even if an attacker gains access to one segment, they cannot easily move to another.</p>



<div style="height:10px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><strong>Continuous Monitoring</strong></strong></p>



<p class="wp-block-paragraph">Finally, your hospital employs <strong>Continuous Monitoring</strong> to keep an eye on all activities. <strong>Security Information and Event Management (SIEM)</strong> systems collect and analyze log data from various sources in real-time, detecting any unusual patterns or behaviors. <strong>Endpoint Detection and Response (EDR)</strong> tools continuously monitor devices for suspicious activities, ensuring any threats are quickly identified and addressed. Email is analyzed for threats, quickly identifying phishing, spam, or other non-essential email, and automatically quarantining against ransomware and business email compromise.</p>



<div style="height:10px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Tools, Technologies, and Processes</strong></p>



<p class="wp-block-paragraph">To implement these principles, the hospital uses a variety of tools and technologies. For <strong>Never Trust, Always Verify</strong>, security relies on state-of-the-art MFA solutions and Identity Management Systems. For <strong>Least Privilege Access</strong>, you use role-based access control tools and for <strong>Micro-Segmentation</strong>, you employ the latest available technology in effective segmentation. Finally, for <strong>Continuous Monitoring</strong>, you have implemented world-renowned SIEM and EDR/MDR solutions. Your hospital also understands that training, development, and process improvement are all necessary components for securing data.</p>



<div style="height:10px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">By implementing Zero Trust Architecture, your hospital ensures that every access request is verified, access is limited to what is necessary, the network is segmented to contain potential breaches, and all activities are continuously monitored through governed and compliant processes. This comprehensive approach keeps the hospital&#8217;s data and systems secure, allowing staff to focus on providing the best possible care to their patients.</p>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>About Fortress SRM:</strong>&nbsp;<br>Fortress Security Risk Management protects companies&nbsp;from the financial, operational, and emotional trauma of&nbsp;cybercrime by&nbsp;enhancing&nbsp;the performance of their people, processes, and technology.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Offering a robust, co-managed solution to enhance an internal IT team’s capability and capacity, Fortress SRM features a full suite of managed security services (24/7/365 U.S. based monitoring, cyber hygiene (managed patching), &nbsp;endpoint detection and response (EDR), and air-gapped and immutable cloud backups) plus specialized services like Cybersecurity-as-a-Service, Incident Response including disaster recovery &amp; remediation, M&amp;A cyber due diligence, GRC advisory, identity &amp; access management, threat intelligence, vulnerability assessments, and technical testing.&nbsp;With headquarters in Cleveland, Fortress SRM supports companies with both domestic and international operations.&nbsp;</p>



<p class="wp-block-paragraph">In Case of Emergency:&nbsp;<br><strong>Cyber Attack Hotline: 888-207-0123 | Report an Attack: IR911.com&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">For Preventative and Emergency Resources, please visit:&nbsp;<br><a href="https://ransomwareclock.org/" target="_blank" rel="noreferrer noopener"><strong>RansomwareClock.org</strong></a><strong><u></u></strong></p>
<p>The post <a href="https://fortresssrm.com/a-quick-case-study-in-zero-trust-architecture/">A Quick Case Study in Zero Trust Architecture</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Is Your Cyber Tech Stack the Right One?</title>
		<link>https://fortresssrm.com/is-your-cyber-tech-stack-the-right-one/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Tue, 10 Dec 2024 19:59:55 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1549</guid>

					<description><![CDATA[<p>Is your cybersecurity ecosystem future-ready, agile, and aligned with your business goals? If not, it’s time for a serious upgrade.</p>
<p>The post <a href="https://fortresssrm.com/is-your-cyber-tech-stack-the-right-one/">Is Your Cyber Tech Stack the Right One?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>by Kevin Baker, CISO</em></p>



<p class="wp-block-paragraph">In an era where cyber threats are evolving daily, businesses must grapple with a tough but necessary question: <strong>Is your cyber tech stack the right one</strong>? It’s not just about having a suite of high-tech tools—it’s about having the right combination of tools that are tailored to your specific business needs, seamlessly integrated, and future-proofed against emerging threats. The answer to this question could be the difference between thwarting a cyberattack and suffering a catastrophic breach.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><strong>More Tools, More Problems?</strong></strong> </p>



<p class="wp-block-paragraph">There’s a common misconception that <strong>more tools equal more security</strong>. Businesses often believe that if they load up their cybersecurity defenses with a diverse array of solutions—firewalls, intrusion detection systems, antivirus software, and more—they’ll be untouchable. However, this approach can backfire. In reality, a <strong>disjointed tech stack</strong> filled with overlapping functionalities, poorly integrated solutions, and redundant alerts can create more vulnerabilities than it fixes. </p>



<p class="wp-block-paragraph"><strong>Security gaps</strong> are created when tools fail to communicate with each other, and cybercriminals are adept at exploiting these cracks. For instance, a monitoring system might raise a red flag, but if the information isn’t immediately passed on to an incident response team due to lack of integration, it can delay your ability to act in real time. A cyber tech stack should function as a <strong>well-oiled machine</strong>, not a clunky collection of mismatched parts.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>The Need for Agility in a Dynamic Threat Landscape</strong></p>



<p class="wp-block-paragraph">Cyber threats have also become smarter, faster, and more complex. AI-driven attacks, phishing schemes powered by social engineering, and ransomware as a service (RaaS) are all on the rise. Legacy cybersecurity solutions—while reliable in the past—simply cannot keep pace with the new breed of digital predators. Today’s cybersecurity environment demands agility, requiring organizations to adopt <strong>AI-enhanced tools</strong> capable of predictive analytics, real-time response, and proactive threat hunting. </p>



<p class="wp-block-paragraph">The question here is not just whether your tech stack is powerful enough, but whether it’s <strong>adaptive</strong>. Can your system evolve to meet tomorrow’s threats, or will it struggle to respond when a novel type of attack emerges? If your tech stack cannot <strong>scale</strong> with your business, it’s a liability, not an asset.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Optimizing for Efficiency: Less Complexity, More Control</strong></p>



<p class="wp-block-paragraph">An overly complex tech stack is a burden. According to a <strong>Ponemon Institute</strong> report, more than half of companies use over 50 security solutions, yet many still struggle with incident response and visibility. <strong>The right cybersecurity tech stack should simplify, not complicate</strong>. Rather than being reactive to an overwhelming number of alerts, your system should provide targeted insights and facilitate a streamlined workflow that moves from detection to mitigation with precision. </p>



<p class="wp-block-paragraph"><strong>Automation</strong> plays a critical role in this regard. Businesses should automate repetitive tasks and free up analysts to focus on higher-level challenges, improving both efficiency and effectiveness. This eliminates alert fatigue and allows for a sharper focus on the truly important threats.</p>



<div style="height:10px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>The Strategic Fit</strong></p>



<p class="wp-block-paragraph">Lastly, consider this: <strong>Does your cybersecurity tech stack align with your business strategy</strong>? Every organization is different, with unique operational demands, regulatory requirements, and threat profiles. What works for a global enterprise may not be suited for a mid-sized business. A smart cyber tech stack is one that is <strong>customized</strong> to your environment, industry, and risk tolerance. </p>



<p class="wp-block-paragraph"><strong>The right tech stack</strong> isn’t just about blocking cybercriminals—it’s about supporting your overall business objectives. It’s about <strong>ensuring continuity, protecting critical assets, and maintaining customer trust</strong>. So, take a critical look at your cybersecurity ecosystem. Is it future-ready, agile, and aligned with your business goals? If not, it’s time for a serious upgrade. </p>



<p class="wp-block-paragraph">After all, in the world of cybersecurity, anything less than the right tech stack is a risk waiting to happen.</p>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>About Fortress SRM:</strong>&nbsp;<br>Fortress Security Risk Management protects companies&nbsp;from the financial, operational, and emotional trauma of&nbsp;cybercrime by&nbsp;enhancing&nbsp;the performance of their people, processes, and technology.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Offering a robust, co-managed solution to enhance an internal IT team’s capability and capacity, Fortress SRM features a full suite of managed security services (24/7/365 U.S. based monitoring, cyber hygiene (managed patching), &nbsp;endpoint detection and response (EDR), and air-gapped and immutable cloud backups) plus specialized services like Cybersecurity-as-a-Service, Incident Response including disaster recovery &amp; remediation, M&amp;A cyber due diligence, GRC advisory, identity &amp; access management, threat intelligence, vulnerability assessments, and technical testing.&nbsp;With headquarters in Cleveland, Fortress SRM supports companies with both domestic and international operations.&nbsp;</p>



<p class="wp-block-paragraph">In Case of Emergency:&nbsp;<br><strong>Cyber Attack Hotline: 888-207-0123 | Report an Attack: IR911.com&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">For Preventative and Emergency Resources, please visit:&nbsp;<br><a href="https://ransomwareclock.org/" target="_blank" rel="noreferrer noopener"><strong>RansomwareClock.org</strong></a><strong><u></u></strong></p>
<p>The post <a href="https://fortresssrm.com/is-your-cyber-tech-stack-the-right-one/">Is Your Cyber Tech Stack the Right One?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8220;My Data is Safe in the Cloud&#8221;—Truth or Dangerous Fallacy?</title>
		<link>https://fortresssrm.com/my-data-is-safe-in-the-cloud-truth-or-dangerous-fallacy/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Tue, 03 Dec 2024 13:21:12 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1546</guid>

					<description><![CDATA[<p>In the Cloud, safety is a shared responsibility—one that businesses must take seriously to protect their most valuable asset: their data.</p>
<p>The post <a href="https://fortresssrm.com/my-data-is-safe-in-the-cloud-truth-or-dangerous-fallacy/">&#8220;My Data is Safe in the Cloud&#8221;—Truth or Dangerous Fallacy?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>by Kevin Baker, CISO</em></p>



<p class="wp-block-paragraph">In the digital age, <strong>Cloud technology</strong> has become synonymous with innovation, scalability, and ease of use. The Cloud enables businesses to store vast amounts of data, access software remotely, and scale operations with a few clicks. But here&#8217;s where the problem lies: too many business leaders assume that <strong>&#8220;My data is safe; it&#8217;s in the Cloud&#8221;</strong> &#8211; a sentiment that can lead to disastrous consequences if not properly scrutinized. </p>



<p class="wp-block-paragraph">While Cloud providers boast impressive security features, it’s a <strong>fallacy</strong> to believe that putting your data in the Cloud means it is automatically secure. Cybercriminals are well aware of the central role the Cloud plays in business operations, making it a prime target for attacks.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Understanding Digital Supply Chain Risk</strong>&nbsp;</p>



<p class="wp-block-paragraph">One of the most significant security challenges in the Cloud environment is the <strong>digital supply chain risk</strong> that comes from third-party Software-as-a-Service (SaaS) platforms. Cloud services are rarely one-stop solutions; they are a web of interconnected vendors, applications, and systems. Each third-party service introduces its own risk. How many organizations thoroughly assess the <strong>security posture of their SaaS providers</strong>? How many businesses fully understand how their data is <strong>stored, accessed, and manipulated</strong> within these services? </p>



<p class="wp-block-paragraph">In reality, your data is often shared across multiple servers, potentially housed in various geographic regions with differing laws and regulations. These variations in security standards, compounded with <strong>human error, misconfigurations, and insufficient encryption</strong>, create vulnerabilities in the supply chain. A breach in one part of the chain can ripple through to your data, resulting in significant exposure of sensitive information.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Data Access and Storage in the Cloud</strong>&nbsp;</p>



<p class="wp-block-paragraph">One of the critical misconceptions about the Cloud is the assumption that you always have control over <strong>who can access your data</strong>. In practice, <strong>SaaS providers</strong> and their subcontractors often have access to the data you store in the Cloud. While Cloud providers typically implement strong encryption, both in transit and at rest, the actual <strong>access to your data</strong>—whether by internal staff at the provider or due to lax third-party policies—remains a gray area.&nbsp;</p>



<p class="wp-block-paragraph">This is particularly troubling when <strong>cyberattacks</strong> exploit weak access control measures, allowing hackers to gain access to the provider’s infrastructure or the systems that manage customer data. If an attack breaches a single layer of defense, it could allow unauthorized access to sensitive company information. Without rigorous <strong>access controls, audits, and compliance standards</strong>, the Cloud environment becomes fertile ground for sophisticated cybercriminals.</p>



<div style="height:20px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Mitigating Risk—What Should Businesses Do?</strong>&nbsp;</p>



<p class="wp-block-paragraph">The key takeaway here is that <strong>Cloud security is a shared responsibility</strong>. While Cloud providers offer infrastructure security, businesses need to actively manage their own end of the security bargain. This includes:</p>



<ol class="wp-block-list" start="1">
<li><strong>Vetting Third-Party Providers</strong>: It’s essential to thoroughly assess the security protocols and certifications of your Cloud and SaaS providers. Ensure they comply with recognized standards such as <strong>ISO 27001</strong> or <strong>SOC 2</strong>. </li>



<li><strong>Encryption</strong>: Always ensure that data is encrypted both in transit and at rest. This minimizes exposure even in the event of unauthorized access. </li>



<li><strong>Access Control and Monitoring</strong>: Implement strict access control policies, including <strong>role-based permissions</strong> and continuous monitoring of access logs to detect unusual activities. </li>



<li><strong>Regular Security Audits</strong>: Periodically review the Cloud provider’s security posture, conducting <strong>third-party audits</strong> where necessary, to ensure ongoing compliance with your security needs.</li>
</ol>



<ol class="wp-block-list" start="3"></ol>



<ol class="wp-block-list" start="4"></ol>



<div style="height:10px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Conclusion: No Data is Safe Without Due Diligence</strong>&nbsp;</p>



<p class="wp-block-paragraph">While the Cloud offers immense business benefits, security isn’t automatic. Understanding the risks associated with <strong>third-party SaaS platforms</strong>, implementing strong <strong>access controls</strong>, and maintaining <strong>continuous oversight</strong> are essential to ensuring that your data remains protected. In the Cloud, safety is a shared responsibility—one that businesses must take seriously to protect their most valuable asset: their data.</p>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>About Fortress SRM:</strong>&nbsp;<br>Fortress Security Risk Management protects companies&nbsp;from the financial, operational, and emotional trauma of&nbsp;cybercrime by&nbsp;enhancing&nbsp;the performance of their people, processes, and technology.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Offering a robust, co-managed solution to enhance an internal IT team’s capability and capacity, Fortress SRM features a full suite of managed security services (24/7/365 U.S. based monitoring, cyber hygiene (managed patching), &nbsp;endpoint detection and response (EDR), and air-gapped and immutable cloud backups) plus specialized services like Cybersecurity-as-a-Service, Incident Response including disaster recovery &amp; remediation, M&amp;A cyber due diligence, GRC advisory, identity &amp; access management, threat intelligence, vulnerability assessments, and technical testing.&nbsp;With headquarters in Cleveland, Fortress SRM supports companies with both domestic and international operations.&nbsp;</p>



<p class="wp-block-paragraph">In Case of Emergency:&nbsp;<br><strong>Cyber Attack Hotline: 888-207-0123 | Report an Attack: IR911.com&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">For Preventative and Emergency Resources, please visit:&nbsp;<br><a href="https://ransomwareclock.org/" target="_blank" rel="noreferrer noopener"><strong>RansomwareClock.org</strong></a><strong><u></u></strong></p>
<p>The post <a href="https://fortresssrm.com/my-data-is-safe-in-the-cloud-truth-or-dangerous-fallacy/">&#8220;My Data is Safe in the Cloud&#8221;—Truth or Dangerous Fallacy?</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Shadow IT &#8211; The Silent Cyber Threat Lurking in Your Organization</title>
		<link>https://fortresssrm.com/shadow-it/</link>
		
		<dc:creator><![CDATA[kclark@fortresssrm.com]]></dc:creator>
		<pubDate>Thu, 21 Nov 2024 15:06:52 +0000</pubDate>
				<category><![CDATA[Incident Prevention]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<guid isPermaLink="false">https://fortresssrmstg.wpenginepowered.com/?p=1542</guid>

					<description><![CDATA[<p>As cyber threats advance, Shadow IT represents an unnecessary vulnerability. With the right approach, organizations can close these gaps.</p>
<p>The post <a href="https://fortresssrm.com/shadow-it/">Shadow IT &#8211; The Silent Cyber Threat Lurking in Your Organization</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>by Kevin Baker, CISO</em></p>



<p class="wp-block-paragraph">In the fast-paced world of modern business, <strong>Shadow IT</strong> has quietly emerged as a silent cyber threat. On the surface, it appears to offer employees the flexibility to choose their own tools—think cloud storage, third-party apps, and software-as-a-service (SaaS) platforms—often in pursuit of productivity gains and innovation. However, the flip side of this convenience is a <strong>cybersecurity nightmare</strong>, and for many organizations, it represents one of the most significant threats to their digital defenses.</p>



<p class="wp-block-paragraph">So, what exactly is Shadow IT? It’s the practice of employees adopting or deploying technology systems without formal approval or oversight from their organization’s IT department. On paper, it sounds harmless—after all, workers just want the best tools for the job. But the reality is that these unsanctioned systems introduce <strong>blind spots</strong> into an organization&#8217;s cybersecurity strategy.</p>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Why Shadow IT is Risky</strong>&nbsp;</p>



<p class="wp-block-paragraph">When technology operates outside of the knowledge and control of IT, it bypasses essential security measures. Shadow IT tools may not be covered by <strong>corporate security policies</strong>, leaving them unmonitored, unpatched, and vulnerable to exploitation by cybercriminals. In 2023, <strong>a staggering 80% of workers admitted to using software not approved by IT</strong>, opening the door to potentially catastrophic data breaches. The lack of visibility means that sensitive company data might be floating in unsecured environments or stored on unprotected personal devices. This increases the risk of data leaks, non-compliance with data protection regulations, and compromises to intellectual property.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">And when a breach occurs, the question looms large: Who is responsible? Without formal approval, IT departments are left scrambling to identify how and where the breach occurred &#8211; often too late to contain the damage.&nbsp;</p>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><strong>The Need for Consistency, Transparency, and Accountability</strong></strong></p>



<p class="wp-block-paragraph">The antidote to Shadow IT lies in consistency, transparency, accountability, and responsibility. To combat the threat effectively, businesses need clear and consistent policies that govern the use of technology, ensuring that <strong>every tool and system</strong> is accounted for and integrated into the organization’s security framework.</p>



<ol class="wp-block-list">
<li><strong>Establish Transparency</strong>: Employees need to understand the risks posed by unauthorized tools. Encourage an open dialogue where workers feel comfortable seeking approval for the technology they need. This creates an environment where transparency is rewarded, reducing the temptation to go rogue.&nbsp;</li>



<li><strong>Implement Clear Processes</strong>: Create a streamlined process for employees to request new tools. By removing bureaucratic roadblocks, IT departments can ensure that the necessary security controls are in place while fostering an atmosphere of collaboration.&nbsp;</li>



<li><strong>Perform Regular Audits</strong>: Blind spots cannot be managed if they aren’t known. Regular technology audits can reveal unapproved apps or software running on the network. Automated tools can also detect and block unauthorized systems before they pose a threat.&nbsp;</li>



<li><strong>Foster a Culture of Accountability</strong>: When everyone in the organization understands their role in maintaining cybersecurity, Shadow IT becomes less of a risk. Make it clear that employees are accountable for their technology choices, ensuring there is no question of responsibility in the event of a breach.</li>
</ol>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>No More Blind Spots</strong>&nbsp;</p>



<p class="wp-block-paragraph">In a time when cyber threats are becoming more advanced, Shadow IT represents an unnecessary vulnerability. However, with the right approach, organizations can close these gaps. By fostering <strong>consistency, transparency, accountability, and responsibility</strong>, businesses can ensure that there are no blind spots in their cyber defenses and that they remain resilient against the unseen dangers lurking in the shadows of their IT environments.&nbsp;</p>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>About Fortress SRM:</strong>&nbsp;<br>Fortress Security Risk Management protects companies&nbsp;from the financial, operational, and emotional trauma of&nbsp;cybercrime by&nbsp;enhancing&nbsp;the performance of their people, processes, and technology.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Offering a robust, co-managed solution to enhance an internal IT team’s capability and capacity, Fortress SRM features a full suite of managed security services (24/7/365 U.S. based monitoring, cyber hygiene (managed patching), &nbsp;endpoint detection and response (EDR), and air-gapped and immutable cloud backups) plus specialized services like Cybersecurity-as-a-Service, Incident Response including disaster recovery &amp; remediation, M&amp;A cyber due diligence, GRC advisory, identity &amp; access management, threat intelligence, vulnerability assessments, and technical testing.&nbsp;With headquarters in Cleveland, Fortress SRM supports companies with both domestic and international operations.&nbsp;</p>



<p class="wp-block-paragraph">In Case of Emergency:&nbsp;<br><strong>Cyber Attack Hotline: 888-207-0123 | Report an Attack: IR911.com&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">For Preventative and Emergency Resources, please visit:&nbsp;<br><a href="https://ransomwareclock.org/" target="_blank" rel="noreferrer noopener"><strong>RansomwareClock.org</strong></a><strong><u></u></strong></p>
<p>The post <a href="https://fortresssrm.com/shadow-it/">Shadow IT &#8211; The Silent Cyber Threat Lurking in Your Organization</a> appeared first on <a href="https://fortresssrm.com">Fortress SRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
