It’s happening right now in clandestine labs around the world: an old warehouse in an abandoned industrial park in Russia, a government-supported facility in North Korea, maybe even the basement
Exercise is a Must
What is in your plan? Who developed your plan? How did you exercise your plan? Have you updated your plan? Why do you even have a plan? Have you ever
Conducting Realistic Exercises: Test the Plan vs. Plan the Test
One of my favorite subjects to discuss and write about is the issue of realistic testing when conducting an exercise. While the subject of this article might seem like a
Penetration Testing: An Effective Weapon Against Cyber-Attacks
With the increasing volume of malicious files being detected and the number of attacks growing year after year, it seems that today’s cyber attackers are winning. While cyber professionals cannot
Testing Your Disaster Recovery Plan in the Cloud
You’ve moved your disaster recovery operation to the cloud and now it’s time to test it. That’s essential because it’s the only way to guarantee your plan works and that
Security Controls, Self-Audit, and Testing
As the digital ecosystem within enterprises proliferate, so do the cybersecurity risks and vulnerabilities. Before organizations look outside for effective governance, risk and compliance, and business continuity tools to manage
Continuity Plans Can You Actually Use Them?
At this time of year, many of us are scrambling to get plans exercised to meet a calendar year commitment or deadline, so I’d like to explore the issue of
Beware of Artificial Readiness
Everyone loves good news and hates the bad. Hearing “yes” is great, hearing “no” is not so great. Desiring to hear “you will be getting all you asked” is human