Introduction to Secure Network Infrastructure with Azure network security
Learn to protect your network from cyber security attacks to secure your networking infrastructure.
Welcome to RecertHero!
Submit bugs, feature requests, and feedbackBrowse · 27 certifications tracked
Search webinars, courses, videos, and vendor training — each mapped to the certifications you’re actually renewing.
84 results for “Network Security”
Learn to protect your network from cyber security attacks to secure your networking infrastructure.
Azure Security Engineer Associate AZ 500 Secure Networking — Pluralsight course. Visit the course page for full details, prerequisites, and pricing.
Updated in May 2025. This course now features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Strengthen your expertise in network security and troubleshooting with this advanced course. Delve into the latest techniques to secure networks, establish robust connections, and proactively address vulnerabilities. You’ll learn how to counter sophisticated cyber threats, optimize remote access, and implement wireless security measures effectively. The course begins with a deep dive into network security essentials. Explore topics such as remote access protocols, social engineering tactics, VPN implementation, and enterprise physical security. Understand best practices for network hardening, from securing SNMP communications to advanced wireless protections like geofencing and EAP. Transitioning to troubleshooting, the course follows CompTIA's structured model, guiding you through problem identification, testing theories, implementing solutions, and system verification. You’ll master essential tools for diagnosing and resolving network issues, including cabling challenges, software tools, IP commands, and DNS troubleshooting techniques. Designed for IT professionals, network administrators, and cybersecurity specialists, this course requires a foundational understanding of networking concepts. If you’re ready to tackle advanced security and troubleshooting challenges, this course is for you.
Implement defense-in-depth network security controls in Azure. Segment workloads to control lateral movement, centralize traffic inspection with Azure Firewall, harden remote and hybrid connectivity, and eliminate public network exposure of PaaS and AI services using private endpoints.
Cisco is redefining network security by offering superior threat visibility, ensuring protection for modern apps & hybrid workforce, and empowering firewall users with dynamic policies for application environments. Join Cisco and (ISC)2 on June 10, 2021 at 1:00 p.m Eastern/10:00 a.m. Pacific as we reimagine network security and learn how the firewall can keep pace with DevOps and the application team and offer threat defense with encrypted traffic, TLS 1.3, and accelerate investigation & remediation with the platform approach.
Today’s sophisticated cybersecurity attacks often unfold in the blink of an eye. To respond quickly, your security teams need to see security incidents as they happen to ensure that attempts to hack your server environment are thwarted before entry into your machines. Whether detecting malware, helping to prevent and disrupt command and control communication, ransomware and phishing attacks – DNS can help with this and much more. But are you leveraging it as part of your cyber strategy? Nearly all threats use the DNS system therefore threats in your network can easily be seen in your DNS data. Join Infoblox and (ISC)2 on March 21, 2019 at 1:00PM Eastern as we bring in experts from IDC and ELEVI for a discussion on how leveraging DNS can help identify attacks as they happen or even prevent them before they happen, remediate attacks faster, and help detect and stop malware from spreading.
The pandemic Work From Home (WFH) era fueled a dramatic shift to edge networking using technologies like SASE, SD-WAN, and cloud. With all the changes in the network, it is only reasonable to expect change in how you test and troubleshoot these new technologies and approaches. Join Keysight and (ISC)2 on July 22, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore the industry’s first cloud-native test solution, Keysight CyPerf as a new way of testing.
Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today!
Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today!
Discover the integrated approach to network security and efficiency in our upcoming webinar, where we unravel the synergy between Security Service Edge (SSE), Software-Defined Wide Area Network (SD-WAN), and Secure Access Service Edge (SASE). This session will illuminate how the convergence of these technologies creates a robust, scalable, and agile framework for businesses navigating the complexities of digital transformation. Join HPE and ISC2 as we discuss practical insights on leveraging SSE and SD-WAN as foundational blocks to transition towards a comprehensive SASE model, ensuring end-to-end security and optimal network performance. This webinar will provide actionable strategies to enhance your business’s security posture and network management in the cloud era.
As the insatiable demand for bandwidth drives the need for faster networks, organizations still need to inspect and enforce network security policies at wire speed. And that is particularly challenging when you are upgrading networks from 10GB to 40GB or from 40GB to 100GB. Join Gigamon and (ISC)2 on April 4, 2019 at 1:00PM Eastern as we discuss how to solve the security headaches that go with these network upgrades and new architectures that strengthen your security posture, simplify IT and reduce costs. We’ll also discuss how to increase your security ROI, reduce your security risk and improve threat response.
5G networks, almost by definition, are hybrid cloud networks. Any company adopting 5G is in effect adopting a hybrid cloud model. As mobile network service providers launch their 5G services around the world starting with radio access network (RAN) deployment followed by the core network, security vulnerabilities, including preventing or mitigating their effects, are top of mind. Whether the network functions and services are physical, virtual on-prem, or public cloud, ensuring comprehensive continuous visibility into the network is crucial to ensuring and maintaining adequate security. Join Gigamon and (ISC)2 on April 9, 2021 at 1:00PM Eastern for a discussion on understanding how coherent, high-fidelity network data can enable a strong security posture without breaking the bank.
It’s now or never to modernize security. Our networks can no longer stretch to the apps living in the cloud and teams working remotely, plus cyber threats routinely exploiting the excessive trust built into them. Network transformation projects are always daunting – especially when you can never know exactly what your business will need tomorrow. New risks to mitigate, standards to comply with, and use cases to scale will inevitably emerge. Join (ISC)² and Cloudflare April 20, 2022 at 2:00 p.m. Eastern, 11 a.m. Pacific to hear Cloudflare Field Technologist, Trey Guinn share perspectives on how to both fast-track and future-proof your security approach. He has seen organizations commit to network and security architectures that were complex and costly to keep changing to adapt to future needs. Trey will advise us on the most important principles to evaluate new technology platforms with confidence that it’ll enable your organization to evolve and innovate faster than ever before. In this webinar you’ll also hear about: • The most pressing business and IT drivers of digital transformation • The emergence of the Internet as the new corporate network • The key criteria to evaluate Zero Trust security and SASE networking investments
Your enterprise network relies on a vast assortment of security devices and solutions, each generating their own alerts. More often than not, security teams don’t have the resources to address every one of them in a timely manner. According to a 2017 EGS report, keeping up with the enormous volume of security alerts and a lack of integration are the biggest network security challenges enterprise's face. Join Infoblox, their special guest Optiv and (ISC)2 on February 7, 2019 at 1:00PM Eastern , for a live discussion on how organizations can leverage ecosystem integrations to bridge islands of security, while automating incident response through automation and orchestration.
Analyst reports are increasingly emphasizing that NetOps and SecOps teams with little to no integration fall short in areas of operational efficiency and the agility to respond to business needs. Security is challenged by increasingly advanced threats driven by nation-state and organized criminals. And networking teams struggle to fully embrace multi-cloud, hybrid work, and other initiatives. The good news is that these same reports are highlighting how increased communication, cooperation and integration of NetOps and SecOps can address a multitude of challenges, making each organization more effective and efficient, and while supporting a more flexible, agile business environment. On June 27, 2023 at 1:00 p.m. Eastern/10:00am Pacific, join Infoblox and (ISC)2 to discover how NetOps and SecOps teams can align their operations to help each achieve goals more efficiently. Discussion topics include: -Nine common challenges for NetOps and SecOps -Tips to make more efficient use of limited resources -5 key areas where seemingly different objectives connect -Making compliance easier to do, and demonstrate to auditors -How tighter NetOps/SecOps integration improves visibility for all
It’s not a question of IF your network will be breached, but WHEN. News broadcasts for the last several years have shown that most enterprise networks will be hacked at some point. In addition, the time it takes for most IT departments to notice the intrusion usually takes months—over six months according to the Ponemon Institute. This gives hackers plenty of time to find what they want and exfiltrate whatever information they want. There are some clear things that you can do to minimize your corporate risk and the potential costs of a breach. One new approach is to create a resilient security architecture model. The intent of this model is to create a solution that gets the network back up and running after a breach has occurred, as fast as possible. While prevention should always be a key security architecture goal, a resilient architecture goal focusses on recognizing the breach, investigating the breach, and then remediating the damage as quickly as possible. Join Keysight and (ISC)2 for an examination of what network security resilience is, the benefits of such and examples of the visibility and security solutions that can be implemented to reduce the time to remediation.
Want to know which IT security technologies are hot and which ones are not? Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP), as he reviews key purchase insights from the 2024 Cyberthreat Defense Report. Specifically, Steve will examine which security technologies are most widely deployed and most planned for acquisition in 2024 so you can benchmark your company’s current and planned investments against your peers. Steve will review purchase intent across five key security technology categories, including: - Network security - Endpoint security - Application and data security - Security management and operations - Emerging security technologies
Want to know which IT security technologies are hot and which ones are not? Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP), and (ISC)2 as Steve reviews key purchase insights from the 2021 Cyberthreat Defense Report. Specifically, this webcast will identify those security technologies most widely deployed and most planned for acquisition in 2021 so you can benchmark your company’s current and planned investments against your peers. We'll review adoption rates of emerging technologies, such as ZTNA and SASE, and examine purchase intent across five key security technology categories, including: • Network security • Endpoint security • Application and data security • Security management and operations • Identity and access management
Explore network traffic filtering with Network Security Group, set up Microsoft Defender for Cloud, create a Log Analytics workspace, configure Log Analytics agent integration, Azure Key Vault networking, and connect an Azure SQL server using Azure Private Endpoint in the Azure portal. Enhance cloud security effectively. (SC-5002)
Strengthen your command over securing network access for AI workloads in Azure. This learning path is tailored for Cloud Administrators and IT professionals looking to enforce precise access controls and ensure isolation of sensitive AI resources. Learn how to implement private endpoints, configure virtual networks, and restrict exposure of Azure AI services and Azure Machine Learning workspaces. Whether you're designing robust hybrid networks or hardening cloud-native architectures, this path empowers you with practical skills to safeguard your AI infrastructure in today's security-first digital landscape.
Today, most security teams struggle to identify and locate threats in their networks. Without the ability to find the bad actors in the network, security teams are unable to be effective in their roles. Organizations need tools to link intelligence about threats in the wild, threats in your network, and understand unique signals from both. In this webcast, we’ll examine the latest trends and downfalls in this space, and how Chronicle, an Alphabet company, is looking to solve them at a global scale with a focus on speed and efficacy. We’ll also have a demo of the Chronicle security platform, Backstory and how it can help streamline your security.
You know that metadata helps you separate signal from noise, reduce time-to-threat-detection and improve overall security efficacy. But did you know that application metadata helps you monitor user experience, troubleshoot problematic apps, understand “Shadow IT” usage and improve security posture within your organization? Join Gigamon and (ISC)² on August 22, 2019 at 1:00 PM Eastern as we discuss the growing need for application-aware network operations and how Gigamon Application Metadata Intelligence provides the deep application visibility needed to rapidly pinpoint performance bottlenecks and potential network security risks. You’ll see how next-gen network packet brokers enhance metadata with intelligence and insights from traffic flows and discover how to understand the performance and control of hundreds of critical apps.
Want to know which IT security technologies are hot and which ones are not? 2020 has thrown many purchasing and deployment plans into a state of flux and your organization has probably been caught up in this. Join Steve Piper, Founder & CEO of CyberEdge (and a proud CISSP) and (ISC)2 on Tuesday, July 28, 2020 at 1:00PM Eastern as Steve reviews key purchase insights from the 2020 Cyberthreat Defense Report. Specifically, this webcast will examine which security technologies are most widely deployed and most planned for acquisition in 2020 so you can benchmark your company’s current and planned investments against your peers. Purchase intent across five key security technology categories will be focused on including: •Network security •Endpoint security •Application and data security •Security management and operations •Identity and access management
The building blocks of traditional WAN architectures are showing their age. MPLS is expensive and has painfully slow deployment times. Broadband Internet does not deliver the millisecond performance and constant reliability needed for most business applications today. And neither infrastructure was designed with security in mind. Compounding matters further, the surge in remote work and increased cloud adoption is straining traditional WAN architectures. WAN-as-a-service is a cloud-based WAN architecture that offers global scale, integrated enterprise network security functions, and direct, secure connectivity to remote users. Join Cloudflare and (ISC)2 on May 13, 2021 at 1:00PM Eastern for an examination on how WAN-as-a-Service can increase operational agility and lower total costs of ownership and solve the inherent challenges associated with MPLS and broadband Internet. We’ll also cover: · What is WAN-as-a-service and what are its advantages over traditional WAN architectures · How can enterprises build and deploy a successful WAN strategy with fast connectivity and robust security built-in · How enterprises can increase your operational agility with easy deployment and management of network services
This course is designed for intermediate-level learners who want to enhance their security skills in Android development. Participants will analyze the structure of Android memory and evaluate its defenses against exploitation, including understanding pointers and their role in buffer overflow exploits. The course covers various types of overflows, mitigation techniques, and specific vulnerabilities such as the Stagefright buffer overflow. In addition to exploitation techniques, learners will explore secure data storage practices within the Android file system, implement cryptography concepts, and securely manage credentials using the Android Keystore. The course also addresses password security through hashing and salting techniques, common data risks, and secure storage practices to protect data at rest. Finally, participants will gain insights into network security, data protection in transit, and securing inter-process communications and webviews in Android applications.
The beauty of the internet is that when users access content, they don’t actually care about the exact physical location of the “hardware” that is ultimately fetching the information. Users primarily care about how quickly they can get the information and how secure they are while doing it. To ensure business continuity, organizations deploy highly distributed but interconnected networks to ensure faster and efficient internet delivery. This webinar highlights some of the challenges you face while deploying distributed infrastructure and validation solutions to ensure high performance and security. - Overview of technologies like software-defined wide area network (SD-WAN) and contend delivery network (CDN) that leverage distributed topologies - Common challenges of deploying such technologies - Performance and security issues during deployment and post deployment of distributed networks
This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. In this course, you'll embark on a journey through the world of Linux, gaining foundational knowledge to navigate and manage Linux operating systems. From understanding the history and usage of Linux to mastering essential command-line operations, this course will provide you with a strong base to begin your Linux journey. You'll also dive into Linux distributions, comparing popular versions like Ubuntu, CentOS, and Debian, and learn the nuances of installing and configuring them. As you progress, you'll explore using Linux’s powerful CLI (Command Line Interface) for tasks such as file management, software installation, networking, and scripting. You’ll learn how to manage networks, secure systems, and administer user accounts, empowering you to configure, manage, and secure Linux systems with confidence. The course is designed for beginners who want to start from the basics, progressing to more advanced Linux administration tasks. Whether you’re interested in IT, system administration, or development, this course will provide a solid foundation for managing Linux environments. No prior experience with Linux is required.
Zero Trust has generated a great deal of “buzz” in the last few years. Many solution providers tout the benefits of Zero Trust, but the approach may not be a fit for you and your organization. Join iboss and (ISC)2 on May 4, 2021 at 1:00PM Eastern as we explore the evolution of network security design principles in order to gain a deeper understanding of how technology can be leveraged to meet evolving user needs and the behavioral and technological direction behind SASE and Zero Trust.
Today’s network environment can feel like a Cold War-era novel, full of who’s watching whom scenarios and heavily protected intelligence communications. Visibility is critical to an organization’s security posture, and encrypted channel communications can become an obstacle to it when gets to the wrong eyes. Decryption can illuminate what is hidden and restores the advantage you need to see what’s lurking in the shadows. Join Gigamon and (ISC)2 on September 5, 2019 at 1PM Eastern for an examination of decryption best practices, a review of encryption methodologies, the obstacles that impact security, resources and regulatory compliance and what’s changed with TLS 1.3 and how this newer protocol impacts visibility.
As your infrastructure has grown to include a mix of physical, virtual and cloud environments with increased network speeds and volume of data, so have the threats increased to your attack surface with more vectors to breach your organization. This challenges your network and security operation teams and tour traditional network packet broker needs to evolve from providing network visibility to also helping strengthen your security posture. Join Gigamon and (ISC)2 on October 18, 2018 at 1:00PM Eastern where we will examine the acquisition and aggregation of data from your physical, virtual and cloud infrastructure, filtering of traffic to provide the right data to the right tools, transforming your data with masking, header stripping and SSL decryption (TLS1.3) to ensure compliance, threat prioritization by providing context and bridging the gap between NetOps and SecOps.
Updated in May 2025. This course now features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. In this course, you’ll gain the foundational knowledge needed to respond effectively to cybersecurity incidents. You will be introduced to the key elements of identifying and analyzing cyber threats, attacks, and vulnerabilities. Throughout the course, you'll develop the skills to assess the security posture of a network and prepare a response to potential incidents. By the end, you'll have a comprehensive understanding of the cybersecurity landscape, empowering you to safeguard and protect organizational systems. The course begins with an in-depth exploration of the different types of cyber threats and actors, as well as the common attack vectors they use. You will learn how attacks are structured, their motives, and the impact they may have on businesses and individuals. In addition to understanding the threats, you'll delve into tools and techniques for vulnerability scanning, penetration testing, and network and system reconnaissance, all critical for identifying weaknesses before an attack happens. As you progress, the course will focus on gaining access through various attack techniques, including web app scanning, social engineering, and wireless attacks. You will also dive deeper into post-exploitation tactics such as data exfiltration, pivoting, lateral movement, and maintaining persistence. Equipped with these skills, you'll be able to recognize when an attack is underway and respond appropriately. This course is ideal for aspiring cybersecurity professionals or those looking to enhance their skills in incident response. It’s designed for individuals with a basic understanding of IT concepts, and while no advanced technical knowledge is required, familiarity with networking and security basics will hel
Securing your infrastructure can sometimes feel like navigating a ship at night in a storm, with pirates attacking. An occasional flash of lightning allows a quick glimpse of the intruders, but you never really know when or from where the next attack is coming. What if you could illuminate the best path forward? A centralized platform gives you a single window with pervasive visibility into all network traffic – both north-south and east-west which allows improvement to the effectiveness and efficiency of all your security tools and better manage SSL decryption as well as NetFlow generation. Join Gigamon and (ISC)2 on May 2, 2019 at 1:00PM for a discussion on how to discover applications on your network you didn’t know where there, spotting potential security vulnerabilities before they become a problem and see a live demo of how you can optimize security and network performance.
Recent research shows that more than 85% of web traffic is comprised of cloud services. The rapid adoption of cloud and mobile is fundamentally changing network traffic patterns and the movement of data, rendering existing network and security models obsolete. This shift is resulting in enterprise security teams supplementing next-gen firewalls (NGFWs), secure web gateways (SWGs), and VPNs with cloud access security brokers (CASBs). While CASBs address a key set of cloud-specific use cases tied to visibility, data security, compliance, and threat protection, your dissolving corporate perimeter is also forcing security teams to rethink their entire legacy security stack. After all, if most of your web traffic is comprised of cloud services, why does most of your security spend on security tools that are not effective in this new world? Join Netskope for Part 1 of this 3-part series to discover new blind spots that exist with legacy security tools, why simply moving legacy security tools to the cloud is not enough, top cloud security use cases driving the need for a new perimeter and the essential requirements for a new, more effective perimeter.
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us for this live replay session as Zscaler and (ISC)² discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us July 12, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific when Zscaler and (ISC)² 's webinar session will discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
The security winds are rapidly shifting from "trust but verify" models to ones that assume that every activity is insecure until proven otherwise. In an age of high-profile security attacks, increasingly sophisticated phishing schemes, and ransomware threats run amok, organizations of all shapes and sizes are urgently seeking new ways to protect their workforce, their finances, their reputations, and their business operations. On September 26, 2023 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, hear how security and networking teams today are avoiding the latest attacks and nullify exploits by choosing the right cloud-delivered technologies that enforce zero trust for global secure access. In this session you will hear: • Why organizations around the globe are prioritizing the implementation of a SASE framework, specifically with SSE • How SSE can enforce zero trust access to help protect access to Private apps, SaaS apps, and the open internet, all in a single solution.
CyberEdge’s annual Cyberthreat Defense Report (CDR) has become a staple for assessing organizations’ security postures, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. It incorporates dozens of insights from 1,200 security professionals from 17 countries and 19 industries. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he reviews key findings from CyberEdge’s 2025 CDR, including: - The percentage of organizations victimized by cyber attacks - The percentage of organizations victimized by ransomware attacks - The health of IT security budgets - The hottest security technologies planned for acquisition - Adoption of best practices for securing modern networks
DNS has always seemed to have a “last mile” security issue. Communications from a local DNS served to a client are typically unencrypted and not secure, leaving this traffic vulnerable to spoofing, hijacking and more. But privacy standards and protocols are emerging which are helping to encrypt this traffic. Join Infoblox and (ISC)2 on October 3, 2019 at 1:00PM Eastern for an examination of DNS over TLS (DoT) and DNS over HTTPS (DoH). The discussion will include the pros and cons of the two protocols, what option might make sense for your security & risk requirements and simple ways to secure your network and DNS.
F5 Labs, one of F5 Networks’ information security research teams, publishes the Application Protection Report to help bridge the divide between tactics and strategy in information security. Join F5 Labs and (ISC)2 on November 4, 2021 at 1:00p.m. Eastern as we will share the findings from the 2021 Application Protection Report, which covers the explosion of ransomware in 2021, formjacking attacks such as Magecart, API security, and cloud misconfigurations, among others. We will wrap up by recommending mitigations for the most frequently observed attack vectors, as well as some strategic insights on the direction of information security as a whole.
Having a strongly aligned and integrated ecosystem of cyber tech and tools is required to protect and preserve the business in today’s digital infrastructures. Over the last several years, more and more traffic has migrated from plaintext protocols to encrypted protocols. While this provides better privacy and security, it also makes it more difficult to troubleshoot this traffic when problems inevitably arise. Although security and network monitoring tools can still analyze some encrypted traffic without decryption, lots of details cannot be analyzed adequately. This session, sponsored by Netscout and hosted by (ISC)² on July 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, will show how integrating decryption with NDR solutions can provide an even more robust monitoring experience. To further the dialogue regarding a healthy cybersecurity solution ecosystem, this session will also explore the critical aspects to integrating NDR with EDR, SIEM and SOAR technologies.
Zero trust network access (ZTNA) has been one of the most widely discussed and debated security technology categories in recent years. While most enterprise IT security teams have already started drinking the zero trust Kool-Aid, there are still some skeptics who are hesitant to embrace zero trust architectures for a variety of reasons. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he debunks five common zero trust security myths so you can distinguish between fact and fiction.
Cybersecurity professionals have endured many challenges this year, including record-setting ransomware attacks, expanded attack surfaces, and shortages of skilled IT security personnel. However, we’ve seen security budgets rebound, increased reliance on cloud security deployments, and increased adoption of promising security technologies, such as zero trust network access (ZTNA), API security, and network/endpoint deception. So, what does next year have in store for the cybersecurity industry? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2023.
This year was particularly challenging for IT security professionals. For a short while, we thought we finally had this pandemic kicked. Then the Delta variant came along, further extending the work-from-home movement and its associated cybersecurity risks. Meanwhile, we saw record-setting ransomware attacks, including high-profile attacks on critical infrastructure, while the shortage of IT security talent worsened. On a brighter note, we saw increased adoption of promising security technologies, such as zero trust network access (ZTNA) and secure access service edge (SASE). So, what does next year have in store for the cybersecurity industry? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he shares his top five cybersecurity predictions for 2022.
Full cloud native security requires more than application security testing and network monitoring. It requires a concerted approach to vulnerability management within CI/CD pipelines, in pre-production testing, and at runtime. Join Aqua Security and (ISC)2 on April 22, 2021 at 1:00PM Eastern for an examination on how to secure applications in complex cloud native ecosystems, including: · Detecting vulnerabilities and exploits in container images, VMs, and serverless functions · Prioritizing and triaging security risks to accelerate remediation · Uncovering hidden malware and attack kill chains before they’re executed in production
Join (ISC)² Chief Operating Officer, Wesley Simpson for a lively and informative panel discussion on the many new features and offerings provided at the 2020 virtual Security Congress! Security Congress veterans and session panelists, Brandon Dunlap, James McQuiggan, & Sharon Smith will share how to leverage many of the unique features of the virtual Security Congress, guide you through the various educational, networking and engaging social activities driving the 2020 (ISC)² Security Congress experience. Whether it's your first Security Congress or 10th, there's something here for everyone. Key topics discussed: - What makes Security Congress is the marquee security conference of the year: - Content quality, notable speakers, & keynotes - Network with thousands of professionals from around the globe & career coaching opportunities - Ability to obtain up to 45 CPE Link to event page in the attachments. (ISC)² is an international, nonprofit membership association for information security leaders like you. We’re committed to helping our members learn, grow and thrive. More than 150,000 certified members strong, we empower professionals who touch every aspect of information security. (ISC)² Security Congress brings together industry colleagues, offers educational and thought- leadership sessions, and fosters collaboration with other forward-thinking companies. The goal of our annual global cybersecurity conference is to advance security leaders by arming them with the knowledge, tools and expertise to protect their organizations.
The CISO’s job now includes much more than just securing an organization’s internal network. The evolving cyber threat landscape has security teams scrambling to respond to an onslaught of attacks from all angles. Between sophisticated phishing kits used by even novice hackers, to vulnerabilities across the global supply chain, and the sheer volume of emerging attack vectors. Enter external cyber defense. By combining the most comprehensive digital risk protection (DRP) solution with cutting-edge third-party cyber risk management, you can extend visibility outside your perimeter to identify, validate, and shut down cyber threats as they emerge in the darkest corners of the internet and across your vendor ecosystem. Join BlueVoyant and (ISC)² on November 10, 2022 1p.m. Eastern/ 10am Pacific to learn how our solution can help your security team: • Advance from a reactive to proactive security posture to thwart attacks at the source • Identify and remediate risks across the entire third-party vendor and partner ecosystem • Scale threat response regardless of organization size and improve patch time for identified vulnerabilities
Your cybersecurity teams are overwhelmed managing dozens of security tools and dealing with hundreds or thousands of alerts every day. That’s why organizations need a modern approach to total enterprise security to be able to automate manual processes and build a security ecosystem for a faster and more coordinated response to threats. Integrating DNS security with your existing SIEM/SOAR, Threat Intelligence, Vulnerability Management, NAC, NGFW, EDR, etc. could help the security operations team gain better visibility and context around threats for a prioritized security response. Join Infoblox and (ISC)² on March 15, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn some key tips and benefits of an efficient cybersecurity ecosystem: • How to get 360° view of all the assets on your network • How to overcome the challenge of working with siloed security tools • Decrease time to remediation by using network and threat context • Automatically trigger response to events detected by DNS security
In the current environment, many legacy VPN and remote access solutions are being overwhelmed, and organizations are reacting with ‘band aid’ fixes. The goal is to enable business critical users with cloud-based private access as quickly as possible with the least amount of friction. Strategically, this will mean combining a cloud-based Next Gen Secure Web Gateway (providing cloud and web inline security) and a zero trust network access (ZTNA) solution (providing scalable and fast remote access) as part of your SASE architecture. Here are five areas to consider when updating your blueprint for remote access security: 1. Most legacy VPNs were deployed to handle around a third an organization’s workforce, but they are being pushed to handle two-thirds or more in the current crisis. The poor performance and user experience of overloaded VPNs can be easily replaced with cloud-enabled private access - for critical business use cases. 2. Shift your remote access strategy from VPNs providing network access, with the opportunity for lateral movement by malicious insiders and compromised accounts, to secure, cloud-enabled, zero trust application access. 3. ZTNA maintains the traditional remote access features of device posture checking and strong authentication, but improves the security of data centers and public cloud environments by not exposing any IPs, ports or services to the public internet. 4. The deployment of legacy VPNs to multiple data centers and multi-cloud environments can be complex for IT and users. Cloud-enabled ZTNA seamlessly and transparently provides access to hybrid IT environments with high performance, global scale, and much less complexity.
Information security and incident response teams are often hampered by an inability to see what is happening on the network. That lack of visibility mean they cannot confidently detect threats or respond quickly and effectively. A new approach that consolidates fundamental network detection and response capabilities using enriched metadata collected from sensors in physical, virtual and cloud environments is helping security teams minimize mean-time-to-detection and response. How can you achieve accelerated threat detection and response through broad situational awareness fueled by real-time access to historical metadata? Join Gigamon and (ISC)2 on July 11, 2019 at 1PM Eastern as we dive into metadata’s critical role in incident detection and response strategies and how to best use metadata to focus incident response efforts through data correlation and enrichment.
APIs make the world go round. 58% of dynamic HTTP traffic on the Cloudflare network is API-related. Security and IT leaders have to balance securing their APIs and their customers’ sensitive data, without slowing down innovation while maintaining customer trust. On November 28, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join us as Cloudflare and ISC2 discuss the best practices to automate your API security with a focus on small security teams. In this webinar, you will: * Explore today’s complex API ecosystem of new APIs, diverse users, and sophisticated attackers * Experience the problems with patchwork and DIY approaches to API security * See an example of optimal API security workflow * Observe ways an API security tool enables you to automate your API security processes * Simplify compliance with ever growing requirements: PCI, HIPAA, FHIR, Open Banking Initiative, Financial Data Exchange etc.
This course is designed to demystify Zero Trust security and guide learners through practical implementation. Based on the principle of “never trust, always verify,” this course explains what Zero Trust is, why it matters, and how organizations can begin their Zero Trust journey. Key topics include network, endpoint, and cloud security, starting with foundational concepts and addressing misconceptions—highlighting that Zero Trust is not achieved by simply deploying technologies. Real-world use cases, assessment methodologies, and maturity ranking techniques help participants create a customized Zero Trust strategy for their business. The curriculum explores modern Zero Trust standards and frameworks, such as NIST and the Open Group, moving from principles to architectural design. With a focus on practical application and strategic planning, this course is ideal for anyone responsible for organizational security seeking to enhance their defense strategy using Zero Trust.
During 2020, the worldwide shift to remote work led to a staggering rise in cybercrime, as criminals targeted gaps in previously secure on-site networks. With over 50% of employers expecting to keep employees working remotely, and payments for a ransomware attacks averaging $100,000, businesses must work proactively to protect their data. It is essential for business to have an effective plan in place to protect at-risk systems, detect and mitigate ransomware attacks in real time, and quickly restore affected systems. Join Synology and (ISC)2 on September 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. as we discuss actionable strategies for ransomware preparedness and look at real-world examples and case studies. Key takeaways include: Actionable ransomware preparedness tips Protecting PC data and the elements of a robust ransomware recovery plan Why and how to backup Microsoft 365 & Google Workspace data Setting up remote backup to a secondary server or cloud
Recruiting and retaining qualified IT security talent is a never-ending challenge. Seven in eight organizations are experiencing a shortfall, according to CyberEdge’s annual Cyberthreat Defense Report. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can smart security organizations do to mitigate the effects of this talent shortage? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Examines the shortage of IT security personnel by job role - Proposes creative ways for recruiting new security talent - Suggests clever ways for retaining the talent you already have - Identifies technologies and services that enable security teams to do more with less
Recruiting and retaining qualified IT security talent has never been more challenging. Seven in eight organizations are experiencing a shortfall, according to CyberEdge’s 2022 Cyberthreat Defense Report. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can smart security organizations do to mitigate the effects of this talent shortage? Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Examines the shortage of IT security personnel by job role - Proposes creative ways for recruiting new security talent - Suggests clever ways for retaining the talent you already have - Identifies technologies and services that enable security teams to do more with less
How well is your remote workforce secured against Ryuk and other ransomware – or will you find out once they return to the office? How businesses are protecting employee endpoints, on or off the corporate network, as we shift to a hybrid work model? Join Illumio and (ISC)2 on July 29, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to find out how to benchmark your own IT efforts to prevent mass infections, and learn how to achieve Zero Trust for the endpoint, with default containment to stop the spread before it starts. We will also cover: · What security visibility and control does IT have into endpoints on ungoverned home networks? · How can businesses prevent the spread of ransomware like Ryuk to avoid mass endpoint infections? · How can Zero Trust security support a hybrid model as employees – and their endpoints – start returning to the office?
Organizations across all sectors have long relied on risk ratings or in-house risk management programs to keep track of the security posture across their shared third-party network and identify where there may be vulnerabilities in their vendor ecosystem. However, a growing focus on supply chain security requires a more comprehensive and advanced approach to third-party risk management. In this webinar, Cybersecurity Assurance Manager, Richard Furze of Lloyd’s Bank, will facilitate a highly apt discussion on the need for organizations to evolve their vendor risk management programs and the experience of doing so. This webinar will explore: • What challenges and pitfalls an organization can face utilizing traditional risk management methods or in-house programs • How an organization can go about transitioning their risk management program • How continuous monitoring can improve relationships with suppliers, incident management, and risk remediation • Major lessons learned from the evolution of a third-party risk management program
Palo Alto Networks Unit 42 cloud threat researchers wanted to understand how supply chain attacks occur in the cloud native applications. To gain insight into this growing threat, they analyzed data from a variety of public data sources around the world. Additionally, they executed a red team exercise at the request of a large SaaS provider against their cloud-based software development environment. Unit 42’s findings indicate that many organizations are still have a long way to go in achieving supply chain security in the cloud. Join Palo Alto Network and (ISC)2 on November 16, 2021 at 1:00p.m. Eastern for the Unit 42 Cloud Threat Report and how supply chain attacks in the cloud can occur and provide actionable recommendations organizations can adopt to protect their cloud native supply chains.
There is much talk in the Industry with regards to Zero Trust Networking (ZTN) - but what does it involve and what does this mean for Network Visibility? In this Webinar we will explore the reason for ZTN, some of the current ideas surrounding the implementations of ZTN and where Network Visibility plays a key role in securing such environments. With one of the key concepts of ZTN being the encryption and authentication of data in motion, we will also discuss the need for Metadata and why this can be an advantage over traditional methods of monitoring. Join Gigamon and (ISC)2 on August 13, 2020 at 1:00PM Eastern for an examination of: - Understanding the ZTN trust model at a high level - See which components are important within ZTN and why - Understand why the perimeter is changing and why the need for segementation goes beyond physical devices - How Metadata can play a key role in understanding the activity of applications on your network
When it comes to keeping up with an organization’s critical threats, it’s important to have visibility into your third parties. Traditionally, organizations have relied on risk ratings to keep track of the security posture across their shared third-party network, and identify where they may be most vulnerable. Useful as they are, however, risk ratings have their limitations. Users have difficulty deploying and wrapping an efficient process around them. Just trying to keep up with vendors and services in-house is time and resource intensive. So how do you effectively “get good” at risk scores and extract the real value behind them for your business? Enter the Risk Operations Center (ROC). Similar to the model that’s long been used by security teams via Security Operations Centers, a ROC is staffed with cyber security experts who continuously monitor and curate alerts to evaluate potential risks to your third-party ecosystems. Unfortunately, ROCs are difficult to create and maintain, which is why enterprise solutions have been created to lower the barrier to entry for organizations that want to leverage these benefits. In Part one of this series, we'll explore how a Risk Operation Center effectively operationalizes security rating by: ● Creating and utilizing ratings for continuous monitoring ● Validating ratings with expert oversight ● Modifying ratings based on an organization's tailored risk appetite ● Refining ratings with automated tools and techniques to scale approach
Defending against advanced threats requires advanced insights from the three foundational data sources for security operations: endpoint data, log data, and the network. In the first part of a three-part series, we'll discuss: ·advanced threat behaviors, how they gain access to the network through both commonplace and sophisticated means, how they act once they're inside. ·how to leverage the three foundational data sources, integrated into a best-of-breed XDR approach to detect and investigate advanced threats like supply chain attacks, insider threats, and more ·how to rapidly respond to minimize the blast radius and reduce business impact when an advanced threat gets inside.
Cloud-native workloads such as virtual machines (VMs), containers, and serverless functions are foundational building blocks of applications. With the rise of hybrid and multi-cloud environments, ensuring the security of cloud workloads has become more challenging than ever. But fear not! We are here to guide you through best practices for securing these resources throughout their lifecycle. Join Prisma Cloud/Palo Alto Networks and (ISC)2 May 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a webinar on how to build a comprehensive strategy that fits your unique cloud environment. We will cover topics such as: • Agentless vs. agent-based deployment options • Understanding risk and prioritizing risks in your environment • Remediation strategies for runtime protection Gain valuable insights on how to effectively secure your cloud resources and protect yourself from potential threats.
Today, many legacy VPN solutions are overwhelmed. The solution is SASE: enabling employees to work from anywhere with a cloud-based combination of Zero Trust Network Access (scalable and fast remote access) and NG SWG (inline cloud and web security). Here are five areas to consider when transforming security to enable working from anywhere: •Fixing the poor user experience caused by overloaded VPNs. •Preventing lateral movement of malicious actors over VPNs. •Using ZTNA to avoid exposing private servers to the Internet. •Reducing the complexity of remote access to hybrid cloud. •Combining NG SWG with ZTNA to deliver SASE for remote workers.
Never Trust, Always Verify. Cloud workloads are constantly evolving and changing. Third-party providers operate outside of company networks. With data in various places, companies can't keep up with who and what have access, and they don't know how critical data might be being exploited. Now you can take an evolutionary step in security with a Zero Trust framework that eliminates implied trust with continuous validation at every stage of a digital interaction, enables developer teams to modernize applications with cloud native development, allows security teams to strengthen defenses across the application lifecycle. On September 28, 2022 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, join Palo Alto Networks and (ISC)² to learn how you can apply an enterprise-wide Zero Trust strategy with integrated capabilities for complete cloud native application protection in your organization. You’ll also find out why organizations that tightly integrate DevSecOps principles into their development lifecycles are: - Over 7X more likely to have strong or very strong security postures - 9X more likely to have low levels of security friction
To understand where you’re going, you must first know where you are. But in the world of cloud-native security, where technologies and best practices seem to change by the month, finding your baseline can sometimes feel impossible—let alone benchmarking your peers. To help organizations find their way, the team at Prisma Cloud has put together the second annual State of Cloud-Native Security report, a survey of 3,000 professionals across five countries that helps answer the question What’s happening in cloud-native security today, and what are successful organizations doing right. On January 25, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Palo Alto Networks, Prisma Cloud, and (ISC)², as we reveal for the first time the trends that are driving the world’s most successful cloud security programs, analyze the best practices that help leading enterprises excel, and demystify the evolving cloud security landscape.
Transformations are disruptive by nature driving the need to review the challenges for cloud and web use in our organizations. Secure web gateways (SWGs) are also part of the disruptive transformation cycle we are all experiencing and becoming the core of SASE architecture to provide vital content and context for granular policy controls. Here are five areas to consider when updating your blueprint for securing web and cloud use. 1. The web is no longer just web, over half of secure web gateway (SWG) sessions are now cloud apps where the average organization uses 2,415 cloud apps and 89% of users are active in the cloud. Adding more fuel, over 98% of cloud apps are unmanaged by IT and freely adopted by business units and users. 2. Web content and filtering needs to advance to decoding cloud app traffic inline, or SWGs will remain blind to cloud content and context for real-time threat and data protection where 44% of threats were cloud-enabled in 2019. 3. The general allow/block model no longer works for cloud. Allow now requires granular controls such as understanding cloud app instances and activity to detect cloud phishing or cloud-enabled threats using trusted domains and valid certificates to evade legacy defenses. 4. Appliance limitations are being replaced with cloud native platforms with on-demand performance and global scale. These microservice designed platforms are enabling an integrated SASE architecture with an understanding of data context and expanding capabilities to end appliance sprawl. 5. SWG control points for main and remote offices now must include a growing base of remote workers. For cloud SWG optimization, they require a hyperscale carrier grade access network providing the fastest round trip time possible. This eliminates the performance versus security trade-off and the uncertainties of the internet.
Artificial intelligence (AI) is no longer science fiction. Software vendors have been integrating AI into products for years, which has led to innovations such as improved threat detection and training opportunities. But the emergence of newer technologies has raised new questions about the real threats AI poses. In this presentation on April 6 at 1:00 p.m. ET / 10:00 a.m. PT, KnowBe4 and (ISC)² will discuss the benefits of AI, the potential threats, and strategies you can use to protect your network today and in the future. You’ll learn: · The key benefits and uses of AI for cybersecurity. · How AI could put your organization at risk. · Strategies for integrating AI into your cybersecurity defenses. · Why security awareness training is your best, last line of defense. Get the information you need now to protect your network!
Recruiting and retaining qualified IT security talent has never been more challenging. Nearly nine in 10 organizations are experiencing a shortfall, according to CyberEdge’s 2021 Cyberthreat Defense Report. That’s up from eight in 10 organizations just three years ago. This weighs heavily on the minds of IT security managers as ‘lack of skilled personnel’ is consistently rated as one of the top inhibitors to successfully defending networks against cyberthreats. So, what can organizations do to mitigate the effects of this talent shortage? Well, if you’re willing to ‘think outside the box,’ there is hope. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: Examines the shortage of IT security personnel by job role Proposes creative ways for recruiting new security talent Suggests clever ways for retaining the talent you already have Identifies technologies that enable security teams to do more with less
Join thousands of cybersecurity professionals at all levels for three days of industry discussion, continuing education and networking, November 16 – 18. Get your passes at: https://securitycongress.brighttalk.live/passes/
A vendor-led learning path on Cisco's SSE and ZTNA stack, including ISE policy design and Umbrella DNS security. Three modules, hands-on with dCloud labs.
Implement security controls across Azure application platform services—from container workloads to the API layer. Configure Microsoft Defender for Containers, secure Azure Kubernetes Service (AKS), Azure Container Registry (ACR), Container Instances, and Container Apps. Then apply authentication, network access, and policy controls across Azure Function apps, Logic apps, App Services, Web Application Firewall, and Azure API Management.
Implement a defense-in-depth security strategy for Azure Storage. Harden storage accounts, govern access with Microsoft Entra ID and stored access policies, enforce network perimeter controls using firewall rules and private endpoints, and enable Microsoft Defender for Storage to detect threats from malicious uploads and compromised AI agent credentials.
Having access to new technology and intelligence to allow proactive response to the threats will change the way teams protect their environments. Harness the massive computing power of Backstory integrated with the powerful insights from VirusTotal to process petabytes worth of data in almost real-time. Watch a step-by-step demo of how Chronicle's security solutions, working with partners like Tenable, can help your organization be better prepared and connected for what comes onto your network.
Showing 72 of 84
Load more →