ידע ששווה
קריאה.
מאמרים קצרים וישירים על CISO as a Service, פרטיות, תקינה ואבטחת AI - מה שמנהלים בישראל צריכים לדעת.
Worth
reading.
Short, direct articles on CISO as a Service, privacy, compliance, and AI security - what Israeli executives need to know.
התיבה צריכה להתרוקן. שיקול הדעת לא.
חוזרים לשגרה עם תיבה מלאה. איך מאמתים בקשות דחופות, שינוי פרטי בנק וקישורי התחברות לפני שפועלים.
לקריאת המאמר ←פחות רישום לא אומר פחות אחריות
תיקון 13 צמצם רישום מאגרים, לא את האחריות למידע אישי. מה בודקים בפועל, ומתי צריך ממונה הגנת פרטיות.
לקריאת המאמר ←בבחירות, קול מוכר הוא לא הוכחה
דיפפייק בבחירות ובארגון: למה קול או סרטון אינם הוכחה, ואיך מאמתים מקור בערוץ נפרד לפני שפועלים.
לקריאת המאמר ←מודעות לסייבר צריכה לעבוד גם אחרי אוקטובר
חודש מודעות הוא התחלה. דיווח פשוט על פישינג, MFA עמיד לפישינג וטיפול בדיווחים צריכים לעבוד כל השנה.
לקריאת המאמר ←ב-ISO 27001, נוהל הוא רק תחילת השיחה
ביקורת ISO 27001 לא נגמרת בנהלים. הרשאות, שחזור גיבויים ודיווחי אירועים צריכים להשאיר ראיות לעבודה ולשיפור.
לקריאת המאמר ←ההתקפה על הבחירות לא חייבת לפרוץ לקלפי
פריצות, הדלפות ומבצעי השפעה זרה לא נועדו רק לשנות קולות. הן עלולות לערער את האמון שלנו בתוצאות. מה אפשר לעשות בישראל?
לקריאת המאמר ←האם המדינה באמת מגינה על המשק ממתקפות סייבר?
כן, אבל לא במקום הארגון. מה משתנה במתקפות מדינתיות בין מלחמה לשקט, מה מערך הסייבר עושה ומה לא, וחמישה דברים שכל ארגון צריך להתחיל בהם.
לקריאת המאמר ←עוד מערכת אבטחה? לא בטוח שזה מה שחסר לכם.
לפני שקונים עוד כלי אבטחה, שווה לעצור: למפות סיכונים, לבחור שלושה דברים שחשובים עכשיו, לתת אחראי ותאריך. ברוב המקרים לא חסרה עוד מערכת. חסר סדר.
לקריאת המאמר ←כמה עולה CISO as a Service?
אין מחיר אחיד - והנה למה. הגורמים שקובעים את העלות, שלושה מודלי התקשרות נפוצים, כמה עולה לא להוביל אבטחה אחרי תיקון 13, ואיך להשוות הצעות בלי ליפול.
לקריאת המאמר ←Clear the inbox, not your judgment
Read the original Hebrew post on verifying urgent requests after the holidays.
Read the post →Less registration does not mean less responsibility
Read the original Hebrew post on privacy duties beyond database registration.
Read the post →In elections, a familiar voice is not proof
Read the original Hebrew post on checking sources before acting.
Read the post →Cybersecurity awareness should work after October too
Awareness month is a start. Simple phishing reports, phishing-resistant MFA and responses to reports should work all year.
Read article →For ISO 27001, a policy is only the start of the conversation
An ISO 27001 audit does not end with policies. Access reviews, backup restores and incident reports should leave evidence of work and improvement.
Read article →An attack on elections need not breach the ballot box
Hacks, leaks and foreign influence operations can undermine trust in elections without changing a single ballot. What should Israel do?
Read the article →Does the state really protect the economy from cyberattacks?
Yes, but not instead of your organization. What changes in state-backed attacks between war and quiet times, what the national cyber directorate does and does not do, and five things every organization should start with.
Read the article →Another security tool? That may not be what you are missing.
Before buying another security tool, stop: map the risks, pick the three things that matter now, give each an owner and a date. Most of the time you are not missing a system. You are missing order.
Read the article →How much does CISO as a Service cost?
There is no single price, and here is why. The factors that set the cost, three common engagement models, the cost of not leading security after Amendment 13, and how to compare proposals without falling.
Read the article →