Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Webinars
Live and recorded webinars that count toward Security+ renewal — vendor sessions, community talks, and conference replays we've indexed for CE credit. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 50 CEUs Security+ requires every 3 years — without re-keying each entry into CompTIA's portal.
305 results mapped to Security+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
Last year was a record-breaking year for data breaches. What can we learn from this growing trend? On March 17, 2022 at 1:00 p.m. Eastern/10:00 am Pacific join F5 Labs and (ISC)² as they share findings in a hot-off-the-presses report exploring those trends. This discussion will analyze the continuing growth of malware, the threat that Magecart and similar web attacks pose to e-commerce, business email compromise, and more. As in the 2021 report, they will use MITRE’s ATT&CK framework to visualize attack chains at large scale to explore the relationships between attacker behaviors. The talk will conclude with a discussion of different mitigation strategies so that organizations can tune their defenses to adapt to the latest in attacker trends.
Zero-day exploits serve as a master key for cybercriminals to launch crippling cyberattacks which are only increasing in frequency. In fact, research from Google's Project Zero shows that as of November 2021, a total of 57 zero-day exploits in the wild have been discovered, compared to an average of 22 exploits in past years. In the past year, eSentire’s Threat Response Unit (TRU) detected and responded to a significant increase in zero-day exploit activity in client environments that included defending against critical Exchange vulnerabilities ProxyLogon, ProxyShell, the REvil attack against Kaseya and most recently, mass exploitation of Log4j vulnerabilities. Join eSentire and (ISC)2 on March 22, 2022 at 1:00p.m. Eastern/10:00a.m. Pacific as key findings from new research on zero-day attack patterns are shared including how to triage vulnerabilities, and the response capabilities needed to effectively tackle future zero-day attacks. We’ll also examine: • Factors contributing to the rise of zero-day attacks • Notable Vulnerability analysis of SolarWinds, ProxyLogon, ProxyShell, and Kaseya VSA • Opportunity windows for zero-day exploits (n-day attacks) • Recommendations on how you can defend against zero-day exploits
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join this webinar featuring CrowdStrike Director of Strategic Threat Advisory Group, Jason Rivera, as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond.
Phishing attacks have come a long way from the spray-and-pray emails of just a few decades ago. Now they’re more targeted, more cunning and more dangerous. And this enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Join (ISC)² and KnowBe4 March 31, 2022 at 1:00 p.m., Eastern and 10:00 a.m. Pacific to hear Roger Grimes, KnowBe4’s Data-Driven Defense Evangelist, share a comprehensive strategy for phishing mitigation. With 30+ years experience as a computer security consultant, instructor, and award-winning author, Roger has dedicated his life to making sure you’re prepared to defend against ever-present IT security threats like phishing. In this webinar you’ll learn: How to develop a comprehensive defense-in-depth plan for phishing mitigation Ideas for security policies you can implement now Technical controls all organizations should consider Gotchas to watch out for with cybersecurity insurance Why it’s critical to develop your organization’s human firewall
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join our webcast featuring CrowdStrike SVP of Intelligence Adam Meyers as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond. Highlights include: • Ransomware and the ever-adaptable adversary • Iran and the new face of disruptive operations • The emergence of China as leader in vulnerability exploitation • Log4Shell sets the internet on fire • Increasing threats to cloud environments
No matter how much security technology we purchase, we still face a fundamental security problem: people. This (ISC)² and KnowBe4 webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding. On May 5, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific, join Erich Kron, Security Awareness Advocate for KnowBe4 as he provides fun and engaging examples of mental manipulation in everyday life: from the tactics used by oily car dealers, to sophisticated social engineering and online scams. Additionally, we’ll look at how to ethically use the very same levers when educating our users. Key Takeaways: • The Perception Vs. Reality Dilemma • Understanding the OODA (Observe, Orient, Decide, Act) Loop • How social engineers and scam artists achieve their goals by subverting OODA Loop's different components • How we can defend ourselves and our organizations
Getting asset visibility and insights into exposures, such as what services or ports might be exposed to the internet, is great. But should you start closing all those ports or shutting down risky services? How do you know what actions to take next? This is where layering threat intelligence onto your attack surface can help prioritize actions or response from your security team. This kind of actionable intelligence can support a wide range of cybersecurity activities, from cyber hygiene and patching to optimizing threat hunting operations. In this session, Looking Glass and (ISC)² will discuss: • How threat intelligence can be applied to your attack surface to prioritize action • Real-world examples of organizations effectively using intelligent attack surface insights to improve their cybersecurity program
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
The nonprofit Open Web Application Security Project (OWASP) works to improve the security of software, web applications, and APIs. Since 2003, the OWASP Top 10 has raised awareness of the most critical security risks to web applications. The latest Top 10 list, released in late 2021, includes significant updates from previous lists. For nearly 20 years the top risks remained largely unchanged, but modern application architectures have shifted the calculus—bringing a new wave of risk to web applications. Join F5 and (ISC)2 on April 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore: • Key changes in the 2021 OWASP Top 10 including alignment of symptoms to root causes and new risk categories • Ways to use the OWASP Top 10 as a foundation to protect applications • How F5 solutions can help mitigate critical risks with effective and easy-to-operate security
Recently, we saw the disastrous effects of numerous far-reaching supply chain breaches and third-party code vulnerabilities, including SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. Unfortunately, we can expect to see more of the same in 2022 and beyond. When we consider these latest cyber events, it’s important to prepare—with the right people, processes, and tools—for what’s unquestionably yet to come. This is why every organization must be sure to have a robust third-party security risk strategy in place. Join Panorays Co-Founder and CTO, Demi Ben-Ari as he shares tips on how to best reduce supply chain risk and contain attacks. Plus he’ll discuss: 1. Why supply chain security is critically important right now 2. What actually happened with SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. 3. How to take action when a supply chain attack happens, and how to minimize the blast radius.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
As the old adage goes “an ounce of prevention is worth a pound of cure.” A holistic application security (AppSec) program is essential for validating your applications’ security. AppSec experts perform a variety of security assessments that identify your software’s flaws and vulnerabilities. These bugs are then prioritized for remediation according to their severity and in accordance with your unique risk profile. In this webinar May 24, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Synopsys and (ISC)² will focus on how you can mature your AppSec program with the Payment Card Industry Data Security Standard (PCI DSS) in mind. You will learn how to • Establish an AppSec program that meets or exceeds PCI requirements • Leverage the OWASP and NIST frameworks • Perform thorough code review, pen testing, and vulnerability assessments
Denial of service attacks became larger and more complex in 2021 with peak attack bandwidth now more than five times larger than it was in 2020. From disgruntled customers, to organized cybercrime and even modern day cyber warfare, DDoS attacks are still a go-to for many threat actors with effects of successful denial of service attacks ranging from temporary disruption of an online event to outages of critical infrastructure. Increasingly, DDoS attacks also used by cybercrime gangs to coerce payments of ransomware demands. While DDoS mitigation services are getting better at deflecting large volumetric DDoS attacks, the shift in tactics to focus on protocol and application DDoS makes mitigation a more complex task. On June 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and F5 Labs discuss the F5 DDoS Trends report which analyzed thousands of attacks over the past two years to uncover how DDoS attacks are changing. We will showcase which industry sectors are most frequently attacked, which suffer the largest and most complex attacks, and some of the relevant security controls which can be employed to counter the growing threat. Join this webinar to learn: -What the most common forms of DDoS attacks are -Which industries are most effected -How attackers are building botnets and changing tactics -How to use the MITRE ATT&CK framework to map effective security controls
No doubt, you’ve heard the buzz about zero trust. Zero trust isn’t a product but rather a journey. While the end goal is worthwhile, like most things in security, getting there won’t be fast or easy. In this live session, June 28, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific IANS Faculty and (ISC)² discuss: • Exactly what a strong zero trust architecture requires • Concrete steps to take and products to consider to that help keep you moving on the right path • Ways to measure progress, set realistic milestones and ensure goals are obtainable
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us July 12, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific when Zscaler and (ISC)² 's webinar session will discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
“SMS-based phishing attempts doubled in the U.S. year over year”-- that is just one key finding in Proofpoint’s 2022 Human Factor Threat Report. The report is the culmination of a year’s worth of threat research and insights drawn from more than 5 billion email messages, 35 billion URLs, 200 million attachments, 35 million cloud accounts and 1.7 billion suspicious SMS messages. It reveals surprising trends and offers actionable insight that sheds light on the nature of today’s cyber threats. Join us July 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Proofpoint and (ISC)² take a deep dive into: • The developing relationship between cyber-criminal groups and what it means for the rest of us • How the most critical variable, people, can help mitigate attacks and manage privilege • The threats detected, mitigated and resolved during 2021 and our deployments
Maintaining security consistency across our own data center and public cloud environments, along with the use of multiple cybersecurity controls are major challenges that organizations face today that not only increase costs and complexity, but also create silos, leaving major security gaps. Join Doug Cahill, VP of Analyst Services and Sr. Analyst at ESG, and David Puzas, Sr. Product Marketing Manager at CrowdStrike in a webcast discussion. This CrowdCast will cover: • Current security challenges • The different attack types • How to leverage visibility and threat intelligence to achieve security consistency from endpoint to workloads, and everywhere in between
Identity is the front line in the battle against modern cyber threats. Nearly 80% of cyberattacks leverage compromised credentials to gain access and evade detection. These attacks often come in via unmanaged or rogue endpoints, legacy systems, supply chain vendors or other attack vectors that are outside the scope of endpoint-centric security controls. Join CrowdStrike experts as they will unpack the current state of identity-based threats and how Falcon Complete managed detection and response is changing the game for security teams. In this webcast, you’ll hear: • Insights from Falcon OverWatch elite threat hunters, who’ll share trends and stories about how today’s attackers are obtaining and abusing credentials, and. blending in with day-to-day activity • How the Falcon Complete team of security analysts are leveraging identity threat protection to keep ahead of the evolving threats • Guidance you can use to protect your own organization from identity-based threats
The Manufacturing industry is one of the most highly targeted industries, both from a nation state and ecrime perspective. The often-critical nature of manufacturing operations and the valuable data that many manufacturing businesses hold make them an enticing target for adversary groups seeking to extract value and further their strategic objectives. Join us for this session with Scott Jarkoff, CrowdStrike’s Director, Strategic Threat Advisory Group for APJ & EMEA where he will discuss trends across 2021 and attacks targeting manufacturing, as well as ways to proactively defend your mission critical assets from being breached. Agenda: - Introductions - Manufacturing at a glance - Adversaries & Threat trends - The Emerging Threat
Découvrez les composantes essentielles d'une cyberdéfense efficace et comment offrir une protection optimale à votre entreprise. Faire la une des journaux à la suite d'une cyberattaque de grande envergure n'est pas un sort réservé aux grandes entreprises. Les petites et moyennes entreprises sont elles aussi dans la ligne de mire des cyberadversaires. En effet, leurs défenses étant souvent plus fragiles, elles constituent des cibles de choix pour les ransomwares et autres menaces avancées. Ce webcast explique comment assurer la protection de votre PME, même si vous n'avez pas d'équipe de cybersécurité à disposition. Fabrice Elzière, Manager Sales Engineers de CrowdStrike passera en revue les cybermenaces qui visent les PME en s'appuyant sur des cas clients concrets. Il détaillera également les composantes essentielles d'une cyberdéfense efficace et vous donnera quelques conseils pratiques pour protéger au mieux votre entreprise. Au sommaire de ce webcast: Les mythes les plus courants en matière de cybersécurité concernant les PME Cas concrets de cyberintrusions et comment celles-ci auraient pu être évitées Structure de base d'un programme de cybersécurité efficace (techniques de prévention de nouvelle génération, chasse aux menaces, investigations et intervention en temps réel) Comment, en tant que petite entreprise, utiliser les services managés pour détecter, bloquer et neutraliser les cyberattaquants déterminés, sans avoir à élaborer et gérer un programme de cybersécurité
Since the initial disclosure of Log4j, the OverWatch team, CrowdStrike’s elite team of threat hunters, has maintained around-the-clock vigilance, tracking the evolution of the Log4j threat, and developing techniques to uncover stealthy attempts to exploit it. Join our OverWatch experts for a summary of the team’s threat hunting insights. You’ll get a real-world view from the experts on the front lines and gain insights you can use to kickstart your own Log4j threat hunting efforts. Join this CrowdCast to hear more about: • A look at the Log4j vulnerability through the eyes of elite threat hunters • Case studies providing insights into how adversaries are carrying out their campaigns in the wild • Ideas for suggested threat hunting techniques you can put into action in your own environment
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.