Top Fractional CISO Blogs of 2020

Share this post

It’s officially the last week of 2020. Another year is in the books, and everyone on Planet Earth is looking forward to a 2021 that will hopefully be better than 2020.

That said, we were incredibly fortunate at Fractional CISO to have a positive year. We managed to grow our business and hire three new employees. We opened a scholarship, started producing videos, and published more content to this blog than ever before. 

We thought it would be a fun end-of-year exercise to take a look back at our hits and misses for the year. 

Garmin Ransonware

6. Scariest Breach: Garmin Ransomware

Okay, Garmin Ransomware doesn’t exactly rank on the list of scariest breaches with the flurry of big attacks we’ve seen towards the end of this year – the SolarWinds attack represents nation-state attackers making attacks that threaten national security – but the Garmin Ransomware attack is the scariest breach we covered here and cybercriminals in it for the money are much more likely to be the ones attacking any given American business. 

Ransomware is an especially dangerous attack for small and medium-sized businesses. It will completely stop operations and they may not have the cash to stay in business after paying off the ransomers.

Should you pay off a ransomware attack? Maybe, but you should definitely have a plan for one if it happens. 

5. Most Regrets: Zoom Bombs

I know I can’t prove it to you, but I promise I was working on a post about Zoom’s security shortcomings before Zoom bombing blew up (pun intended) this year. I wasn’t at all surprised when I saw the headlines rolling in, and really wished I would have gotten an article out in-front of the event. 

Anyways, I predicted that Zoom would improve its security. Has it?

Zoom faced an incredible amount of public and market pressure to improve its security features and it has acted swiftly. Zoom might fit the bill for your business needs – just be sure to use all the security features at your disposal. Most of them are optional and need to be turned on. 

4. Favorite Infographic: Enjoyment from Hot Dogs

I wrote the third in my series of posts about being a Virtual CISO for other cybersecurity professionals who are interested in becoming Virtual CISOs themselves. 

It’s important to have some sort of plan to market your services, and at first I focused heavily on LinkedIn. While I still focus on LinkedIn, there is such a thing as too much LinkedIn. The same can be said for hot dogs. 

My favorite part about LinkedIn is how easy it makes staying in front of your network. You don’t need to post every day to reap the biggest benefit: reminding your professional contacts that you exist and could solve their problem. 

Drawing of man sitting at desk with laptop, SOC 2 is above his head with question marks.

3. Most Educational: SOC 2 Compliance

Credit for this one goes to RJ Russell, one of the aforementioned new hires who I brought onto the team to serve as another vCISO.

SOC 2 compliance is confusing to many business leaders at first. Most compliance standards are prescriptive – they tell you what you need to do, and you do it. SOC 2 is different: you determine what security-conscious practices are appropriate for your business and execute on those. 

This is why it’s incredibly helpful to have someone like a CISO in a leadership role to help manage the compliance process – it requires a holistic approach to security. 

Elon Musk Cybersecuritys Iron Man Tesla

2. Hottest on Social: Elon Musk

There is no universal formula as to what makes a social media post go viral and get attention. There are best practices and best guesses, but nothing is a guarantee.

Well, except this: Elon Musk gets clicks. 

Elon had a close call this year when Russian hackers offered an employee a $1 million bribe to plant malware in Tesla’s computers. The fact that hackers had to resort to recruiting an insider speaks volumes about Tesla’s security. If they could have gotten in without risking an in-person visit, they almost certainly would have done so. 

WhatsApp vs Signal vs Telegram Security

1. Most Popular: Signal vs. Whatsapp vs. Telegram 

Competition is heating up in the encrypted messaging market. The three big players are Signal, Whatsapp, and Telegram. This post, written by Fractional CISO Cybersecurity Analyst, Chinmayee Paunikar, compares the features, security, and privacy elements of each of the three applications.

This is by far the most popular post on our website, drawing in the most traffic every single day. Hopefully it helps readers decide which app they should be using! Encrypted messaging apps should play an important role in communications at all businesses. They are especially useful for sending secrets.

Happy New Year!

Whether you’ve been reading our humble blog for years or minutes, thank you for stopping by! 

Rob Black
Rob founded Fractional CISO in 2017 and has helped dozens of mid-size SaaS and technology companies improve their security posture as a vCISO. He consults, speaks, and writes on IoT and security. Rob has held product security and corporate security leadership positions at PTC ThingWorx, Axeda and RSA Security. He received his MBA from the Kellogg School of Management and holds two Bachelor of Science degrees from Washington University in St. Louis in Computer Science and System Science and Engineering. He is also a Certified Information Systems Security Professional (CISSP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales