Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISACA · Exam prep
Exam-prep training that counts toward CISM renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 120 CPEs CISM requires every 3 years — without re-keying each entry into ISACA's portal.
88 results mapped to CISM, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
IT security is a highly rewarding, impactful, and profitable profession – but it’s one that faces a massive talent gap that’s been plaguing the industry for years. According to the annual (ISC)2 Cybersecurity Workforce Study, there are currently 2.72 million unfilled cybersecurity job openings. While that number finally seems to be declining as the benefits of these roles continue to gain popularity, it’s still one that’s cause for concern. How has the industry gotten to this point? Considered the pinnacle position in the field – the Chief Information Security Officer (CISO) – has a notoriously high turnover rate. Some may view the position as a “turnoff” and perceive this security leader role to be “Chief Scapegoat”. But that’s all changing. In fact, the CISO role has evolved into one that is integral to the fabric of the business and accelerating it by protecting productivity. Join Jack Miller of Menlo Security and Brandon Dunlap on February 15, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific as two former CISO have a fireside chat to discuss their career journeys: paradigm shifts, highlights and how best to chase your passion for security
A recent research study published by (ISC)2 provides insights for cybersecurity professionals into the minds of C-suite executives and how they perceive their organizations’ readiness for ransomware attacks. This data underscores the need for clearer and more frequent communications between cybersecurity teams and executives and offers best practices security leaders should implement to improve those interactions. Join (ISC)2 CISO Jon France on February 22, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he guides attendees through a summary of the data, discusses what we can learn from it and answer questions about ransomware topics.
51% of businesses have experienced a third-party data breach. In other words, there’s a one-in-two chance a vendor will expose your sensitive data. Practically every company relies on third parties to provide critical services or software to their business. But while you can outsource processes, you can’t outsource the associated risks. Knowing who your vendors are, how they manage their risks and their potential impacts on your company is a crucial piece of your InfoSec program. However, contracting is often overlooked from a security perspective, and it shouldn’t be. An effective vendor risk management program can minimize the impact of disruptive events and reduce a company’s overall risk exposure. In this webinar, Jose Costa, Chief Information Security Officer at Tugboat Logic, and Zach Payne, Senior Corporate Counsel at OneTrust, will deep dive into: - How to build an ideal vendor management framework - The issue with vendor contracts and how to overcome common pitfalls - Practical advice to streamline complex client and vendor points of view - Liability limitations, intellectual property, and confidential information.
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
In the last year alone, the number of supply chain attacks has grown exponentially as they offer threat actors stealthy, scalable, and privileged access to your organization’s on-premises, cloud, and hybrid environment. Addressing supply chain attacks requires a multi-layered defense strategy in which third-party integrations are audited, endpoints are monitored for post-compromise actions, and an Incident Response plan that considers supply risks is put in place to minimize the overall impact to your organization. On May 10, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Sumo Logic share insights from original threat research and supply chain attacks to demonstrate how multi-signal investigations can effectively secure your organization against supply chain attacks. Key takeaways from the webinar include: • The three primary attack vectors that cybercriminals rely on to launch supply chain attacks against organizations • The challenges that organizations face related to supply chain risk (e.g., technical complexity, access requirements, stealth of cyberattacks) and how they impact business operations • Tactical and high-level strategic recommendations on how your organization can minimize supply chain risk and reduce the attacker dwell times and impact • How 24/7 log monitoring and management can improve cyber resilience and prevent zero-day threats • A case study on how original research and curated threat intelligence conduct stronger post-exploitation investigations.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Effectively managing and mitigating cyber risk in your supply chain today means moving away from trust-based approaches and investing in a more proactive third-party risk program. A variety of factors from global digitalization to geopolitical conditions have drawn more reliance on and attention to supply chain connections, and threat actors are more motivated than ever to exploit these connections as attack vectors. Mitigating these threats requires overcoming both external cooperative and internal organizational challenges. This highly pertinent webinar will share insights on these challenges as well as best practices for evolving your third-party risk management program to keep up with an evolving supply chain-focused threat landscape. This webinar will explore: • The current challenges facing organizations in keeping up with and managing evolving cyber risk in constantly expanding supply chains • Differences in traditional and more adaptive, SOC-inspired approaches to third-party cyber risk and what programmatic strategies work best for modern organizations • How to improve your organization’s overall security posture by adopting a proactive risk reduction strategy in managing your vendor ecosystem
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
While understaffing and low budgets have always been challenges for any team, security teams face many unique roadblocks that divert attention from working on higher-impact projects that contribute to their organization's security posture. On May 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Tines discuss the learnings of security leaders who have found a way to free their teams from manual tasks and remove the barriers so they can focus on high-value strategic work that truly matters. We'll distill their best practices and leave attendees with actionable insights that they can immediately put to work with their team, including: • What to look for when choosing a security tool. • What security leaders are doing to address burnout and mental health issues within their teams. • How to make security roles more accessible via Diversity, Equity, and Inclusion. • What endpoint hygiene means and lessons they learned while working at multinational corporations.
The very activities that cybersecurity teams do to make their organizations safe can create additional risk for the organization. Defenders can unintentionally create new ways for attackers to target their organization through inadvertently introducing new vulnerabilities, placing too much trust in their security strategy, ignoring alert fatigue, and by making their mitigation activities too predictable. During this session, we will: • Explore why blindly applying vendor patches may not always be the best strategy. • See examples of how overconfidence in any single line of defense can be dangerous. • Identify opportunities to streamline incident alerts and monitoring so critical notifications are not missed. • Learn why following an incident response playbook may not always be in your best interest. Join us on June 30, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific when SimSpace and (ISC)² will discuss the four types of second-order cyber risk and offer practical advice on best practices that form a continuous improvement approach to improve overall cyber hygiene while minimizing second-order cyber risks.
Accidents and attacks can happen – no matter how airtight your security practices are. As ransomware threats continue to surge, businesses struggle to manage data security and associated costs. Recovering from a ransomware attack, in particular, is often a costly endeavor, with victims scrambling to minimize downtime, revenue loss, and reputation damage. When things go wrong, the organization needs a comprehensive disaster recovery plan in place to restore all data and resume normal operations. Join Synology and (ISC)² on July 7, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webcast where we will examine the fundamental elements of a complete disaster recovery plan, such as endpoint and cloud backup, off-site failover, and remote archives. In this session, we will also walk through several case studies identifying opportunities to enhance restoration efficiency and minimize work disruptions.
With the current push for digital business transformation, organizations are increasingly dependent on external parties, increasing their vulnerability to vendor cyber risk. Because many vendor risk management programs are developed as tactical responses to ensure compliance with a growing list of data privacy and cybersecurity regulations, they often result in labor-intensive and inefficient processes that deliver marginal value. Industry best practices for effective Third-Party Cyber Risk Management can improve your program and may provide cyber defense for your third parties. In this webinar, July 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, BlueVoyant and (ISC)² will discuss: • Industry recognized best practices for an effective TPRM program • How to transform your TPRM program with continuous monitoring and active risk identification and mitigation • Ways to solve your toughest TPRM challenges
This session will focus on methods for security teams to better monitor and secure hybrid cloud environments while logging compliance data. Learn best practices to analyze, prioritize, and investigate security alerts within cloud resources faster and more accurately through a variety of cloud-agnostic security strategies while reducing downtime and security incidents. On July 28, 2022 at 1:00 p.m. Eastern/10:00 am. Pacific Sumo Logic and (ISC)² will: • Discuss business motivations for cloud migration. • Identify common challenges while monitoring applications throughout the migration. • Explore solutions for typical security operations constraints during the migration.
Responding to an incident takes more than theoretical knowledge. To effectively detect, investigate, and mitigate a live incident requires strong knowledge, technical skills, and practical experience, many of which current cyber pros are missing. Join Cyberbit and (ISC)2 on November 23, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to experience a live incident response, simulated on the cyber range included in Cyberbit’s cyber team preparedness platform. Here’s the twist: you, as the audience, are in control. You will vote to control the actions taken by the responder and see how quickly the audience can resolve the attack!
With hybrid workplaces now the new norm and supply chain attacks on the rise, there’s an increased exposure to cyber-attacks, which can cause substantial disruption to any organization or industry. This increased exposure is forcing companies to not only invest and improve their own cybersecurity posture, but also manage third party risk and protect against cyber risks with cyber insurance. Certain best practices and technologies help reduce your risk and improve your security score while helping to keep insurance premium costs low. DNS security is one such approach that provides extended visibility, protection and security automation to improve a company’s security posture. Join Infoblox and (ISC)2 November 11th, at 1 p.m., ET/ 10 a.m. PT for this webinar to learn more about: o Why organizations invest in cyber insurance o Getting the most out of cyber insurance o How DNS security improves security scores and reduces cyber insurance premiums
SIEM systems are pivotal to IT organization’s security operations. Many companies are adopting a hybrid cloud model, and cloud-based SIEMs are becoming common as a result. Regardless of on-prem or cloud deployments, the challenges around SIEM remain the same, from data overload, lack of contextual information, to high costs. Security best practices in deploying SIEMs also remain unchanged, which include establishment of use cases, data ingestion types and development of parsers for various tool vendors. On March 9, 2021 at 1:00pm Eastern, Gigamon and (ISC)2 will present a webinar that will cover solutions to these challenges such as Gigamon’s Application Metadata Intelligence as well as various smart filtering techniques.
Did you know that 86% of organizations experienced a successful attack in 2021? Up from 81% the prior year, the largest year-over-year increase in six years. CyberEdge’s 2021 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. Now in its eighth year, the 2021 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 11, 2021 at 1:00 pm ET/10 am PT for highlights of the results and get key insights including: - The chronic shortage of IT security skilled staff is still prevalent; hiring gaps exist across all major IT security roles - Lack of skilled personnel is the #2 obstacle to effective defense against cyberthreats - The fastest and most economical solution is to train existing IT members to fill security positions - IT security professionals see personal and organization-wide benefits of cybersecurity certifications, especially for cloud security, software security, security administration, and management - And more!
Cybersecurity is about priorities, but the challenge is knowing what works and what doesn’t. What if you could learn from thousands of peers, around the globe, about how they’re succeeding? You can. Cisco recently commissioned the Security Outcomes Study, outlining which security best practices lead to the most impactful results. Join Cisco and (ISC)2 on April 6, 2021 at 1:00PM Eastern for a discussion that will cover: · The business outcomes that cyber professionals are working to achieve · The specific security practices that contribute the most · How to use their advice to improve your cyber program today
The 2021 Cloud Security Report, sponsored by (ISC)2, explores current cloud security trends and challenges, how organizations are responding to security threats in the cloud and reveals tools and best practices organizations are considering. Based on a comprehensive survey of 783 cybersecurity professionals conducted in early 2021 to uncover how cloud user organizations are responding to security threats in the cloud, and what training, certifications and best practices IT cybersecurity leaders are prioritizing in their move to the cloud. Join (ISC)2 on July 21, 2021 at 1:00PM Eastern for highlights of the results and to get key insights including: •A majority of cybersecurity professionals (96%) confirm they are at least moderately concerned about public cloud security, a small increase from last year’s survey. •For the second year in a row, the key barrier to cloud adoption, organizations mention was a lack of qualified staff (39%) as the biggest impediment to faster adoption. •More than half of organizations (57%) expect their cloud budgets to increase over the next 12 months. •When asked how organizations rate their overall security readiness, 73% rate their team’s security readiness average or below average. Of those, 78% believe their teams would benefit from cloud security training and/or certification.
Cybersecurity is always evolving. The 2021 (ISC)2 Cybersecurity Workforce Study has found how the profession has evolved and matured with respect to risk and governance as well. Join (ISC)2 on December 16, 2021 at 11:00am Eastern/8:00am Pacific and learn how organizations and professionals are evolving from: · "How secure are we?" to "What's our security-related risk, and is it acceptable to the business?" · Risk as a purely technical issue to risk as a key business issue · Subject-matter experts to both subject-matter experts and trusted advisors
During 2020, the worldwide shift to remote work led to a staggering rise in cybercrime, as criminals targeted gaps in previously secure on-site networks. With over 50% of employers expecting to keep employees working remotely, and payments for a ransomware attacks averaging $100,000, businesses must work proactively to protect their data. It is essential for business to have an effective plan in place to protect at-risk systems, detect and mitigate ransomware attacks in real time, and quickly restore affected systems. Join Synology and (ISC)2 on September 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. as we discuss actionable strategies for ransomware preparedness and look at real-world examples and case studies. Key takeaways include: Actionable ransomware preparedness tips Protecting PC data and the elements of a robust ransomware recovery plan Why and how to backup Microsoft 365 & Google Workspace data Setting up remote backup to a secondary server or cloud
Does your organization rely heavily on SaaS solutions like Microsoft 365 and Google Workspace? That critical data may be at more risk than you realize. There are hidden risks with compliance issues associated with SaaS solutions and other concerns. Join Synology and (ISC)2 on January 20, 2022 at 1:00 p.m. Eastern as we examine the importance of Cloud backup and the practical strategies that can protect your organization from detrimental data loss. Additionally, we will discuss real-life case studies that exemplify the importance of SaaS backup and walk through the elements of their backup strategies that made them so successful.
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.