Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISC2 · Webinars
Live and recorded webinars that count toward CISSP renewal — vendor sessions, community talks, and conference replays we've indexed for CE credit. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 120 CPEs CISSP requires every 3 years — without re-keying each entry into ISC2's portal.
596 results mapped to CISSP, soonest first.
To understand where you’re going, you must first know where you are. But in the world of cloud-native security, where technologies and best practices seem to change by the month, finding your baseline can sometimes feel impossible—let alone benchmarking your peers. To help organizations find their way, the team at Prisma Cloud has put together the second annual State of Cloud-Native Security report, a survey of 3,000 professionals across five countries that helps answer the question What’s happening in cloud-native security today, and what are successful organizations doing right. On January 25, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Palo Alto Networks, Prisma Cloud, and (ISC)², as we reveal for the first time the trends that are driving the world’s most successful cloud security programs, analyze the best practices that help leading enterprises excel, and demystify the evolving cloud security landscape.
“Identity Security is the foundation for Zero Trust”. This statement has been widely accepted within the cyber-security industry since most breaches result from weak credentials and unmanaged accounts. Identity is the foundation by which you assert your relationship with an organization. How you justify the applications and data, you should be allowed to access and what you can do with it. Join SailPoint and Optiv, along with (ISC)2 for a discussion on why Identity Security is decidedly the foundation for Zero Trust, how it enables the other Zero Trust pillars, and how to set the foundation for your entire Zero Trust journey.
Cloud adoption — especially software-as-a-service (SaaS) — is showing no signs of slowing down. SaaS models are already a go-to for many organizations — and consumption will only increase as more businesses shift to remote and hybrid work. While the growth of SaaS offers many positives, it also drives an exponential increase in IT, security, and business complexity. Shadow users, data sprawl, misconfigurations, and excessive spending are just a few examples of the challenges SaaS applications pose. Join Axonius and (ISC)2 on February 24, 2022 at 1:00 p.m. Eastern as we examine the relationship between SaaS apps and IT and security teams, along with the challenges at hand and several actionable solutions. Through a renewed focus on SaaS security posture management, we’ll share how you can: • Discover both known and unknown SaaS apps • Uncover and mitigate various security risks that put sensitive customer and business data at risk — including identifying misconfigured SaaS settings and suspicious or malicious behavior • Deliver the insights on user access and app utilization needed for better IT management and cost optimization across all SaaS apps
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
Two years into the global pandemic and the stakes for remote work security have never been higher. Even as ransomware, phishing, and shadow IT reach all-time highs, admins must ensure users stay safe and productive across all devices, apps, and locations. As work-from-home flexibility settles in as the new normal, Cloudflare has seen organizations start to re-evaluate the temporary IT scaffolding they put in place in early 2020. For many, this has meant taking steps towards more sustainable and secure Internet-native Zero Trust architectures. Join Cloudflare, (ISC)2 and special guest OneTrust on March 3, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific as they share lessons learned evolving their remote work security over the past two years. Tune in to learn how organizations: · Prioritize starting points to address remote work security problems · Balance user experience with more rigorous security · Motivate Zero Trust initiatives within their organization
A recent research study published by (ISC)2 provides insights for cybersecurity professionals into the minds of C-suite executives and how they perceive their organizations’ readiness for ransomware attacks. This data underscores the need for clearer and more frequent communications between cybersecurity teams and executives and offers best practices security leaders should implement to improve those interactions. Join (ISC)2 CISO Jon France on February 22, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he guides attendees through a summary of the data, discusses what we can learn from it and answer questions about ransomware topics.
Last year was a record-breaking year for data breaches. What can we learn from this growing trend? On March 17, 2022 at 1:00 p.m. Eastern/10:00 am Pacific join F5 Labs and (ISC)² as they share findings in a hot-off-the-presses report exploring those trends. This discussion will analyze the continuing growth of malware, the threat that Magecart and similar web attacks pose to e-commerce, business email compromise, and more. As in the 2021 report, they will use MITRE’s ATT&CK framework to visualize attack chains at large scale to explore the relationships between attacker behaviors. The talk will conclude with a discussion of different mitigation strategies so that organizations can tune their defenses to adapt to the latest in attacker trends.
Zero-day exploits serve as a master key for cybercriminals to launch crippling cyberattacks which are only increasing in frequency. In fact, research from Google's Project Zero shows that as of November 2021, a total of 57 zero-day exploits in the wild have been discovered, compared to an average of 22 exploits in past years. In the past year, eSentire’s Threat Response Unit (TRU) detected and responded to a significant increase in zero-day exploit activity in client environments that included defending against critical Exchange vulnerabilities ProxyLogon, ProxyShell, the REvil attack against Kaseya and most recently, mass exploitation of Log4j vulnerabilities. Join eSentire and (ISC)2 on March 22, 2022 at 1:00p.m. Eastern/10:00a.m. Pacific as key findings from new research on zero-day attack patterns are shared including how to triage vulnerabilities, and the response capabilities needed to effectively tackle future zero-day attacks. We’ll also examine: • Factors contributing to the rise of zero-day attacks • Notable Vulnerability analysis of SolarWinds, ProxyLogon, ProxyShell, and Kaseya VSA • Opportunity windows for zero-day exploits (n-day attacks) • Recommendations on how you can defend against zero-day exploits
The cloud has become the primary location for businesses to store data. As usage of the cloud has grown, many organizations simply try to lift and shift their tools to the cloud, unaware that better, more tailored and cost-effective cloud-native solutions exist. On April 5, 2022 at 1:00 p.m. Eastern/10:00a.m. Pacific, join IANS and (ISC)² to hear: • Which AWS/Azure/GCP cloud-native tools to consider • Which cloud-native tools aren’t quite ready • When and how to use cloud-native firewalls, vulnerability scanners, DLP and incident response tools for a more scalable, cost-effective and secure environment.
51% of businesses have experienced a third-party data breach. In other words, there’s a one-in-two chance a vendor will expose your sensitive data. Practically every company relies on third parties to provide critical services or software to their business. But while you can outsource processes, you can’t outsource the associated risks. Knowing who your vendors are, how they manage their risks and their potential impacts on your company is a crucial piece of your InfoSec program. However, contracting is often overlooked from a security perspective, and it shouldn’t be. An effective vendor risk management program can minimize the impact of disruptive events and reduce a company’s overall risk exposure. In this webinar, Jose Costa, Chief Information Security Officer at Tugboat Logic, and Zach Payne, Senior Corporate Counsel at OneTrust, will deep dive into: - How to build an ideal vendor management framework - The issue with vendor contracts and how to overcome common pitfalls - Practical advice to streamline complex client and vendor points of view - Liability limitations, intellectual property, and confidential information.
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join this webinar featuring CrowdStrike Director of Strategic Threat Advisory Group, Jason Rivera, as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond.
As multi-cloud adoption accelerates, security teams are navigating the delta between each cloud provider’s native capabilities and comprehensive protection from bad actors. Understanding cloud terminology, principles, and security issues is critical. Join (ISC)² and Sysdig March, 29, 1:00 p.m., Eastern/10:00 a.m. Pacific to understand the fundamentals on cloud categories and terms like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform), etc. so you can move past the acronyms and onto implementing them as best practices. In this session we will: • Debunk new industry acronyms and explain how they fit into your overall cloud security strategy • Explain why native cloud provider tools aren’t always sufficient • Provide CSPM best practices: Detecting misconfigurations, excessive permissions and suspicious activity • Showcase how open-source Falco can be used to detect cloud threats in real-time
Phishing attacks have come a long way from the spray-and-pray emails of just a few decades ago. Now they’re more targeted, more cunning and more dangerous. And this enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Join (ISC)² and KnowBe4 March 31, 2022 at 1:00 p.m., Eastern and 10:00 a.m. Pacific to hear Roger Grimes, KnowBe4’s Data-Driven Defense Evangelist, share a comprehensive strategy for phishing mitigation. With 30+ years experience as a computer security consultant, instructor, and award-winning author, Roger has dedicated his life to making sure you’re prepared to defend against ever-present IT security threats like phishing. In this webinar you’ll learn: How to develop a comprehensive defense-in-depth plan for phishing mitigation Ideas for security policies you can implement now Technical controls all organizations should consider Gotchas to watch out for with cybersecurity insurance Why it’s critical to develop your organization’s human firewall
The security threat landscape is evolving fast and continues to be challenging for defenders. Even though more sophisticated approaches using Machine Learning (ML) are growing in importance, they are difficult for non-experts to adapt to their particular use case and require sufficient training data. There is growing reliance on inflexible analytics and ML tools and the burden grows on security analysts to be data scientists. This (ISC)² and Sumo Logic webinar on April 12, 2022 at 1:00 p.m. Eastern/10:00 a.m., Pacific will cover: • How can non-experts leverage and benefit from using ML in security • Leveraging ML for security services that address the expertise problem by adapting ML to security use cases • Solving the data problem by pooling or crowdsourcing across the customer base • How to use Cloud MLOps with Cloud SIEM to help address current and emerging threats.
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join our webcast featuring CrowdStrike SVP of Intelligence Adam Meyers as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond. Highlights include: • Ransomware and the ever-adaptable adversary • Iran and the new face of disruptive operations • The emergence of China as leader in vulnerability exploitation • Log4Shell sets the internet on fire • Increasing threats to cloud environments
When it comes to keeping up with an organization’s critical threats, it’s important to have visibility into your third parties. Traditionally, organizations have relied on risk ratings to keep track of the security posture across their shared third-party network, and identify where they may be most vulnerable. Useful as they are, however, risk ratings have their limitations. Users have difficulty deploying and wrapping an efficient process around them. Just trying to keep up with vendors and services in-house is time and resource intensive. So how do you effectively “get good” at risk scores and extract the real value behind them for your business? Enter the Risk Operations Center (ROC). Similar to the model that’s long been used by security teams via Security Operations Centers, a ROC is staffed with cyber security experts who continuously monitor and curate alerts to evaluate potential risks to your third-party ecosystems. Unfortunately, ROCs are difficult to create and maintain, which is why enterprise solutions have been created to lower the barrier to entry for organizations that want to leverage these benefits. In Part one of this series, we'll explore how a Risk Operation Center effectively operationalizes security rating by: ● Creating and utilizing ratings for continuous monitoring ● Validating ratings with expert oversight ● Modifying ratings based on an organization's tailored risk appetite ● Refining ratings with automated tools and techniques to scale approach
No matter how much security technology we purchase, we still face a fundamental security problem: people. This (ISC)² and KnowBe4 webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding. On May 5, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific, join Erich Kron, Security Awareness Advocate for KnowBe4 as he provides fun and engaging examples of mental manipulation in everyday life: from the tactics used by oily car dealers, to sophisticated social engineering and online scams. Additionally, we’ll look at how to ethically use the very same levers when educating our users. Key Takeaways: • The Perception Vs. Reality Dilemma • Understanding the OODA (Observe, Orient, Decide, Act) Loop • How social engineers and scam artists achieve their goals by subverting OODA Loop's different components • How we can defend ourselves and our organizations
Getting asset visibility and insights into exposures, such as what services or ports might be exposed to the internet, is great. But should you start closing all those ports or shutting down risky services? How do you know what actions to take next? This is where layering threat intelligence onto your attack surface can help prioritize actions or response from your security team. This kind of actionable intelligence can support a wide range of cybersecurity activities, from cyber hygiene and patching to optimizing threat hunting operations. In this session, Looking Glass and (ISC)² will discuss: • How threat intelligence can be applied to your attack surface to prioritize action • Real-world examples of organizations effectively using intelligent attack surface insights to improve their cybersecurity program
It’s what keeps many of us awake at night-- knowing that a cyberattack is inevitable. Still there are things you can do to help strengthen your security posture. Join NETSCOUT and (ISC)² on May 4, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a discussion that will expose critical factors in understanding the global threat landscape as Dr. Eric Cole, Founder, and CEO of Secure Anchor Consulting, sheds light on cyber vulnerabilities that organizations are currently ignoring and outline strategies to reduce cyber risk. Paul Barrett, CTO for NETSCOUT, will unpack strategies to minimize the risk through network visibility. Presenters will also share regional examples from North America and expand upon the highly correlated risk reduction factors associated with network visibility in cyber.
Your cybersecurity teams are overwhelmed managing dozens of security tools and dealing with hundreds or thousands of alerts every day. That’s why organizations need a modern approach to total enterprise security to be able to automate manual processes and build a security ecosystem for a faster and more coordinated response to threats. Integrating DNS security with your existing SIEM/SOAR, Threat Intelligence, Vulnerability Management, NAC, NGFW, EDR, etc. could help the security operations team gain better visibility and context around threats for a prioritized security response. Join Infoblox and (ISC)² on March 15, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn some key tips and benefits of an efficient cybersecurity ecosystem: • How to get 360° view of all the assets on your network • How to overcome the challenge of working with siloed security tools • Decrease time to remediation by using network and threat context • Automatically trigger response to events detected by DNS security
As more companies undergo digital transformation and software is released more frequently, application security is moving from an opportunity to an imperative. However, AppSec as a process requires cooperation with software developers - a team whose time is heavily in demand from every customer-facing part of the organization. How do security teams improve AppSec without slowing down business and finding themselves at odds with the rest of the organization? For DevSecOps to succeed it must take cues from the DevOps revolution that came before it. Teams need to learn new tools that address the new problems that arise from the evolution of IT. Smart use of automation can create transparent processes that handle routine work between teams without creating friction. And most importantly, adopting a supportive, rather than authoritative, mindset makes it possible for teams to move quickly together while achieving their respective missions. On April 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, ShiftLeft and (ISC)² will provide an overview of application security that covers key tools, best practices, and a primer on working effectively with your colleagues in AppDev and DevOps in order to make modern software more secure.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
The nonprofit Open Web Application Security Project (OWASP) works to improve the security of software, web applications, and APIs. Since 2003, the OWASP Top 10 has raised awareness of the most critical security risks to web applications. The latest Top 10 list, released in late 2021, includes significant updates from previous lists. For nearly 20 years the top risks remained largely unchanged, but modern application architectures have shifted the calculus—bringing a new wave of risk to web applications. Join F5 and (ISC)2 on April 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore: • Key changes in the 2021 OWASP Top 10 including alignment of symptoms to root causes and new risk categories • Ways to use the OWASP Top 10 as a foundation to protect applications • How F5 solutions can help mitigate critical risks with effective and easy-to-operate security
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.