cissp (@cissp) — Telegram-канал | Telegram Dialogs
Telegram Dialogs — логотип
Все каналы
cissp

cissp

@cissp

16.1K подписчиков даркнет 💬 Комментарии открыты

@cissp International channel 4 Transmission Knowledge In the Field of Cyber Security with a Focus on the Content of the CISSP-ISC2 Course - - - - - - - - - - +also group: https://t.me/cisspgroup ————————— @alirezaghahrood

Последние публикации

cissp
21.08.2026 06:51 · 👁 655
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) 1. Scope & Applicability Which regulated entities are covered by the framework. 2. New Definitions Introduction and clarification of cybersecurity terminology. 3. Inventory Management Stronger requirements for identifying and managing technology assets. 4. Designated Officers Enhanced cybersecurity roles, responsibilities, and accountability. 5. Operational Resilience A shift from concentration-risk thinking toward broader operational resilience. 6. Log Management Requirements for collecting, managing, retaining, and protecting logs. 7. Data Localization & Retention Rules governing where data is stored and how long it must be retained. 8. Self-Certification Certification requirements relating to internally developed software products. 9. Security Audits Requirements for cybersecurity audits and auditing organizations. 10. Incident Response Cyber incident reporting, response, escalation, and communication. 11. Data & Device Security Security controls for organizational data and devices. 12. Third-Party Responsibility Greater accountability for cybersecurity risks arising from vendors and service providers. From a CISO perspective The important point is that this framework is not simply about implementing more security controls. Its direction is closer to: Cybersecurity Governance Risk Management Operational Resilience Executive Accountability A mature CISO function therefore needs to demonstrate: What assets do we have? What risks affect them? What controls mitigate those risks? Are those controls actually effective? How do we respond and recover from incidents? How are third-party risks governed? Can critical business services continue during a cyber disruption? Cybersecurity is no longer only about preventing incidents. It is about ensuring that the organization can withstand, respond to, recover from, and continue operating through cyber disruption. –Security you can rely on– 2026.08.21 ———————————————— #CISO #CyberSecurity #CyberResilience #OperationalResilience #CyberRisk #SecurityGovernance #RiskManagement #GRC #InformationSecurity #ThirdPartyRisk #IncidentResponse #SEBI #CSCRF #BusinessContinuity #CyberSecurityGovernance https://www.linkedin.com/posts/diyako-secure-bow_sebi-cyber-security-cyber-resiliency-framework-activity-7496453850745417728-gn0k
cissp
14.08.2026 22:14 · 👁 1.1K
Attackers are already probing an unpatched GeoServer zero-day. The SQL injection flaw drew hundreds of attempts within hours of disclosure and, under certain configurations, can lead to remote code execution. No patch is available yet. Read the details: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html — CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.08.15 https://www.linkedin.com/posts/alirezaghahrood_attackers-are-already-probing-an-unpatched-share-7494154096929677313-hXKY
cissp
02.08.2026 11:34 · 👁 1.5K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) Executive Insights from the CyberEdge Cyberthreat Defense Report 2026 based on insights from more than 1,200 IT security decision-makers and practitioners across 17 countries and 19 industries, provides one of the most comprehensive views of today's cybersecurity landscape. After reviewing this year's report, one message stands out: Organizations are more confident in their security capabilities than ever before yet they are simultaneously more concerned about the future than at any point in recent years. This is not a contradiction. It reflects the reality of today's cyber battlefield. Over the past few years, organizations have significantly invested in technologies such as Zero Trust, XDR, SIEM, SOAR, and AI-driven security operations. These investments have improved overall security maturity and strengthened defensive capabilities. However, threat actors have evolved just as rapidly. Artificial Intelligence is reshaping offensive cyber operations by enabling highly personalized phishing campaigns, faster vulnerability discovery, more convincing social engineering, automated reconnaissance, and increasingly sophisticated attack techniques. One of the report's most significant findings is that phishing and spear phishing have overtaken malware as the cybersecurity threat of greatest concern among security professionals. This marks a fundamental shift in the threat landscape. Cyberattacks are no longer focused solely on exploiting technical vulnerabilities they increasingly target human behavior, digital identities, and trust relationships. Identity is no longer just an IT function it has become the foundation of modern cybersecurity. As organizations continue expanding across cloud environments,, APIs, and AI-powered services, identity has become the new security perimeter. At the same time, while organizations report stronger security postures in cloud infrastructure and core IT systems, they continue to struggle with areas such as security awareness, third-party risk management, and securing AI-powered applications. These remain among the weakest links in enterprise cybersecurity and the very areas where attackers are increasingly concentrating their efforts. Another encouraging finding is the continued increase in cybersecurity investment. Nearly nine out of ten organizations expect their cybersecurity budgets to grow, demonstrating that cybersecurity is increasingly viewed as a strategic business investment rather than an operational expense. The future of cybersecurity will not be determined by who owns the most technology but by who can integrate technology, people, governance, and Artificial Intelligence into a unified cyber defense strategy. Cybersecurity is no longer a technology challenge. It is a business resilience strategy. Special Thanks to Google Cloud Security ISC2 Rubrik SentinelOne 👌❤️ –Security you can rely on– 2026.08.02 ———————————————— #CyberSecurity https://www.linkedin.com/posts/diyako-secure-bow_annual-cdr-report-cybersecurity-2026-activity-7489643618182340608-rl-G?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAXwLuQBD9tBET0AAFOnGrOQNaM1EWhmgM8
cissp
23.07.2026 13:21 · 👁 1.7K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) The cybersecurity market is entering a new phase. After reviewing several 2025/26 industry reports, one trend is unmistakable: organizations are no longer asking "Which security product should we buy?" They are asking "How do we reduce cyber risk while enabling business growth?" This shift marks the evolution of cybersecurity from a technology function to a business governance discipline. The strongest investments in 2025/26 are focused on: • Identity-first security architectures • AI-driven threat detection and response • SaaS and cloud security governance • Cyber resilience and business continuity • Security automation and exposure management Yet, technology alone is not the differentiator. Organizations continue to struggle with fragmented security architectures, disconnected tools, alert fatigue, skills shortages, and the absence of measurable cyber risk governance. From a CISO perspective, the competitive advantage is no longer determined by the size of the security stack it is determined by the maturity of governance, visibility, and decision-making. Cybersecurity leaders must transition from operating security controls to managing cyber risk as a strategic business function. Executive Conclusion The future belongs to organizations that integrate cybersecurity into corporate strategy, operational resilience, and executive decision-making. In 2025/26, cybersecurity maturity not technology acquisition will define sustainable business resilience and competitive advantage. –Security you can rely on– 2026.07.23 ———————————————— #CyberSecurity #CISO #CyberRisk #CyberResilience #Governance #SecurityLeadership #DigitalTransformation #RiskManagement #ZeroTrust #AI #ExecutiveLeadership #DiyakoSecureBow https://www.linkedin.com/posts/diyako-secure-bow_cybersecurity-202526-activity-7486040226495377408-CwqF
cissp
17.07.2026 09:36 · 👁 1.5K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) Why Every Security Team Should Know Osquery: Modern cybersecurity is no longer limited to firewalls, EDR, and SIEM platforms. The real challenge is obtaining accurate, real-time visibility into what is actually happening across endpoints. Osquery addresses this challenge by transforming operating systems into relational databases. Instead of relying on proprietary agents or platform specific scripts, security teams can query endpoints using standard SQL to retrieve information about: • Running processes and services • Active network connections • Installed software and patches • User accounts and privileges • Startup persistence mechanisms • Scheduled tasks and cron jobs • USB devices and hardware inventory • Browser extensions • File integrity changes • System configuration and security posture Why Osquery Matters?! Organizations often struggle with fragmented visibility across Windows, Linux, and macOS. Osquery provides a unified telemetry layer that enables defenders to collect normalized data regardless of the operating system. This significantly improves: * Threat Hunting * Digital Forensics * Incident Response * Asset Inventory * Vulnerability Validation * Compliance Monitoring * Security Baseline Assessment Beyond Asset Management One of Osquery’s greatest strengths is its ability to support hypothesis-driven investigations. For example, during an incident responders can quickly answer questions such as: * Which hosts executed PowerShell with suspicious arguments? * Which endpoints contain an unexpected local administrator? * Which systems have unsigned binaries running from temporary directories? * Which devices established outbound connections to a suspicious IP? * Which persistence mechanisms appeared after a specific date? All through SQL-based queries executed at scale. Integration with Modern SOC Osquery becomes even more powerful when integrated with security ecosystems such as: * FleetDM * Velociraptor * Elastic * Splunk * Microsoft Sentinel * Wazuh * TheHive * SOAR platforms This enables continuous monitoring and automated threat detection rather than relying solely on periodic scans. Final Thoughts Osquery is not an EDR replacement. It is a high-value telemetry and visibility platform that complements existing security controls by providing deep endpoint intelligence, accelerating investigations, and enabling proactive threat hunting. In mature cybersecurity programs, visibility is not a luxury it is the foundation of effective defense. Special Thanks to Uptycs 🙏♥️☺️ –Security you can rely on– 2026.07.17 ———————————————— #CyberSecurity #ThreatHunting #Osquery #DFIR #IncidentResponse #SOC #BlueTeam #ThreatDetection #DigitalForensics #Linux #Windows #macOS #SecurityOperations #EndpointSecurity #DiyakoSecureBow https://www.linkedin.com/posts/guide-2-osquery-2026-ugcPost-7483816364323868672-gPqF
cissp
14.07.2026 10:25 · 👁 1.4K
Cybersecurity is an evolving discipline, and maintaining professional competence requires continuous learning. I'm pleased to have completed additional ISACA Continuing Professional Education (CPE) requirements as part of my ongoing commitment to professional excellence and internationally recognized best practices. Special Thanks to 👍💕👌 ISACA ISACA Foundation ISACA UAE — CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.07.14 #ISACA #CPE #InformationSecurity #CyberSecurity #Governance #RiskManagement #ProfessionalDevelopment https://www.linkedin.com/posts/alirezaghahrood_isaca-cpe-ghahrood-2026-ugcPost-7482686338081751040-Y1Wf
cissp
07.07.2026 12:15 · 👁 1.6K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) 🔐 Cybersecurity is not just about technology it starts with people, processes, and governance. Many organizations invest in security tools but still struggle to build a structured cybersecurity program. A practical roadmap and security fundamentals are often more valuable than deploying another security solution. One useful resource in this area is the Cybersecurity Handbook for Civil Society Organizations, published by NDI. Although it is designed for civil society organizations, many of its recommendations are equally applicable to SMEs, NGOs, and organizations looking to improve their cybersecurity maturity. The handbook covers topics such as: ✅ Building a cybersecurity plan ✅ Governance and security responsibilities ✅ Securing accounts and endpoints ✅ Data protection and secure communications ✅ Safe internet and email usage ✅ Physical security considerations ✅ Incident response fundamentals ✅ Security awareness and organizational culture At Diyako Secure Bow, we believe that effective cybersecurity is built on a combination of governance, risk management, secure architecture, continuous assessment, and user awareness not technology alone. If your organization is looking to establish or improve its cybersecurity program, our team can help through assessments, consulting, technical security reviews, GRC, vCISO services, security architecture, and specialized cybersecurity training. 📖 Recommended reading for security leaders, IT managers, and anyone responsible for improving organizational cyber resilience. What do you think is the biggest challenge organizations face when building an effective cybersecurity program? Special Thanks to 😇♥️🙏 National Democratic Institute (NDI) –Security you can rely on– 2026.07.07 ———————————————— #CyberSecurity #InformationSecurity #CyberResilience #GRC #vCISO #RiskManagement #SecurityAwareness #SOC #CyberDefense #DiyakoSecureBow https://www.linkedin.com/posts/diyako-secure-bow_cybersecurity-handbook-cso-activity-7480232620900114432-AOge
cissp
25.06.2026 15:03 · 👁 1.7K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) 🔎 Digital Forensics in the Cloud Is No Longer Optional As organizations continue migrating critical workloads to the cloud, Digital Forensics and Incident Response (DFIR) must evolve beyond traditional on-premise approaches. A recent research paper titled: “Digital Forensics and Incident Response in the Cloud: Addressing GCP Challenges” highlights an important reality: Cloud-native investigations introduce challenges that conventional forensic methodologies were never designed to address. Some of the key challenges include: 🔹 Limited access to underlying infrastructure 🔹 Volatile cloud artifacts and ephemeral resources 🔹 Multi-tenant environments 🔹 Centralized logging dependency 🔹 Identity and IAM complexity 🔹 Evidence preservation and chain of custody 🔹 Regulatory and cross-border compliance considerations The research also emphasizes that effective cloud DFIR requires organizations to adopt a forensics by design approach rather than treating incident response as an afterthought. At Diyako Secure Bow (DSB), we believe cloud security must extend beyond preventive controls. Building resilient cloud environments requires integrating: ✅ Cloud Security Architecture ✅ Incident Response Readiness ✅ Digital Forensics Preparedness ✅ Cloud Logging & Monitoring Strategy ✅ Identity-Centric Security ✅ Governance, Risk & Compliance (GRC) Security is no longer just about preventing attacks it’s about being prepared to investigate, respond, recover, and continuously improve. –Security you can rely on– 2026.06.25 ———————————————— #CyberSecurity #CloudSecurity #DFIR #DigitalForensics #IncidentResponse #GoogleCloud #GCP #CloudForensics #ThreatDetection #SOC #CloudIncidentResponse #SecurityArchitecture #GRC #ZeroTrust #DiyakoSecureBow https://www.linkedin.com/posts/diyako-secure-bow_dfir-in-the-cloud-2026-activity-7475911738014498816-bDFx
cissp
24.06.2026 17:06 · 👁 1.4K
#DiyakoSecureBow ———————————— CISO as a Service (vCISO) 🔐 10 Golden Rules for Cybersecurity: Simple, Yet Critical Many cybersecurity incidents are not caused by sophisticated attacks. They happen because basic security practices are overlooked. Experience shows that a significant number of data breaches, ransomware infections, account compromises, and operational disruptions could be prevented by implementing a few fundamental security controls. The 10 Golden Rules for Cybersecurity highlight essential practices that every organization and individual should follow: ✅ Use strong and unique passwords ✅ Enable Multi-Factor Authentication (MFA)🤙🏾 ✅ Keep systems and software up to date ✅ Stay alert to phishing and suspicious messages ✅ Regularly back up critical data ✅ Apply the principle of least privileg🤙🏾 ✅ Secure devices and endpoints ✅ Use trusted and secure networks🤙🏾 ✅ Report suspicious activities promptly ✅ Continuously improve cybersecurity awareness Cybersecurity is not just about technology. It is a combination of people, processes, and security controls working together to protect the organization. At Diyako Secure Bow, we believe that building a strong security culture is the first and most effective line of defense against cyber threats. At Diyako Secure Bow, we help organizations transform cybersecurity from a reactive necessity into a strategic advantage. Special Thanks to🙏♥️😇 Centre for Cybersecurity Belgium –Security you can rely on– 2026.06.24 ———————————————— #CyberSecurity #InformationSecurity #CyberAwareness #SecurityCulture #CyberResilience #CyberRiskManagement #DataProtection #CyberDefense #SecurityFirst #DiyakoSecureBow https://www.linkedin.com/posts/diyako-secure-bow_10-golden-rules-4-cybersec-2026-activity-7475594827875876866-E4h5
cissp
21.06.2026 17:43 · 👁 1.4K
ThreatResearch Ghost-Sender Universal Email Spoofing against Exchange Online https://labs.infoguard.ch/posts/ghost-sender Using Exchange Online (or on-premises exchange in hybrid mode) in combination with an external MX record, such as a third-party email server or spam protection solution, can allow the spoofing of emails from any sender to any recipient in the target tenant. Hardening Whitepaper Know Your Blind Spots: Better Visibility Through EDR Policy Hardening 2026. EDR tools identify, detect, and respond to anomalous behavior. They assist blue teams, incident response operations, and threat hunting. However, an EDR is only as effective as the events it can detect. Alerts and actions depend on the tool's detections, which in turn depend on visibility within the environment. — CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.06.21 https://www.linkedin.com/posts/alirezaghahrood_edr-policy-hardening-2026-ugcPost-7474517183457525760-rWsE
Чат поддержки
Ответим здесь же, обычно быстро
Здравствуйте! Напишите ваш вопрос — оператор ответит в этом чате.