Orion Secure

Insights

What we’re seeing.And what to do about it.

Regulatory changes, findings from the field, and the monthly cybersecurity briefing our clients read.

RSS feed

Original articles

  • Getting the Most Out of Your KnowBe4 Subscription

    When organizations invest in KnowBe4, they're often focused on phishing simulations and security awareness training. While those are foundational components, they represent…

  • Cyber Defense Institute is now Orion Secure!

    We are very excited to share some exciting news we've been working on for a while: as of December 30, Cyber Defense Institute will officially transition to a new name, Orion…

  • Navigating the Challenges of SSPR: A Balanced View on the DFS Industry Letter

    The realm of information security is complex, especially for small businesses operating with limited resources. The New York State Department of Financial Services (DFS)'s…

  • Don't Get Breached: How the DFS Part 500 Amendment Strengthens Insurance & Finance Resilience

    Remember the chaos of 2020 when COVID-19 swept across the globe? For many insurance and finance companies, it wasn't just a health crisis; it was a painful reminder that even…

  • Cybersecurity for Small Businesses

    I was asked to speak at the 2023 Rochester Security Summit on the topic of "Cybersecurity for Small Businesses". Below is the YouTube recording of that presentation. I hope…

  • DFS 500 Second Amendment Implementation Dates

    Today I attended a presentation by the superintendant and deputy superintendent of New York State Department of Financial Services. A lot of infomration was provided and we…

  • Navigating the Latest Updates to the New York State Department of Financial Services (NYS DFS) Cybersecurity Regulations: Impact on Covered Entities

    In the ever-evolving landscape of cybersecurity, regulatory bodies continually refine and enhance standards to address emerging threats. The New York State Department of…

  • Common Pen Test Findings That Are Easy to Fix

    We do a lot of penetration tests for a wide range of clients; whether they be healthcare, retail, nonprofit, insurance, banks, industrial or anything in between. Even though…

  • How to (better) Protect Email

    Last week we alerted our insurance colleagues to multiple instances of spear-phishing as they relate to a new trend toward using OneDrive as a means of spreading phishing…

  • OneDrive Phishing Scam Details

    We recently alerted our insurance industry colleagues of an active phishing campaign that had compromised multiple accounts at multiple insurance industry companies in the…

  • OneDrive Insurance Phishing Scam

    This Friday (4/26/19) we investigated a phishing campaign for one of our insurance clients and we learned quickly that it spanned at least two other CNY area insurance…

  • Check your Antivirus

    We've been involved with multiple organizations in the past three weeks that have responded to a serious security incident that was exacerbated by a lack of up to date anti…

  • Hurricane Florence and Disaster Recovery Planning

    As Hurricane Florence is set to smash into the Carolinas today, it may have you thinking about how your business might fare an unexpected disaster. Even if it didn't, it sure…

  • PCI-DSS 3.2.1 is Here

    Recently, the Payment Card Industry (PCI) released an update to their Data Security Standard (DSS) that is used by anyone that accepts credit cards within their organization.…

  • Policies and your Information Security Program

    Regulations and standards almost universally require an "information security policy," which would make us believe they must be rather important. For example, New York's…

Monthly briefing

One email a month: the security and compliance news that actually affects regulated organizations, written in plain language.