Skip to content
Home
Services
Fractional CISO – Cybersecurity Leadership
Fractional CTO – Application Development Leadership
Automation
Ransomware Cost Estimator
Customer Success Stories
BUCS: Automation Success
ISSA Cybersecurity
Bear Analytics
Inteleos
MovementX: Automation Transformation
Resources
Publications
Papers
Newsletter
About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
Linkedin-in
Home
Services
Fractional CISO – Cybersecurity Leadership
Fractional CTO – Application Development Leadership
Automation
Ransomware Cost Estimator
Customer Success Stories
BUCS: Automation Success
ISSA Cybersecurity
Bear Analytics
Inteleos
MovementX: Automation Transformation
Resources
Publications
Papers
Newsletter
About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
Linkedin-in
Logo-cyber with three tag words 4000w
Home
Services
Fractional CISO – Cybersecurity Leadership
Fractional CTO – Application Development Leadership
Automation
Ransomware Cost Estimator
Customer Success Stories
BUCS: Automation Success
ISSA Cybersecurity
Bear Analytics
Inteleos
MovementX: Automation Transformation
Resources
Publications
Papers
Newsletter
About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
  • Home
  • Services
    • Fractional CISO – Cybersecurity Leadership
    • Fractional CTO – Application Development Leadership
    • Automation
    • Ransomware Cost Estimator
  • Customer Success Stories
    • BUCS: Automation Success
    • ISSA Cybersecurity
    • Bear Analytics
    • Inteleos
    • MovementX: Automation Transformation
  • Resources
    • Publications
    • Papers
    • Newsletter
  • About
Linkedin-in

Welcome to v061 : New Year’s Resolution: Strengthen Cybersecurity, Protect Missions.

  • January 8, 2025

News: Canada Orders TikTok to Shut Down Canadian Operations Over Security Concerns

The Canadian government on Wednesday ordered ByteDance-owned TikTok to dissolve its operations in the country, citing national security risks, but stopped short of instituting a ban on the popular video-sharing platform.

 

News: 5 Ways Behavioral Analytics is Revolutionizing Incident Response

Behavioral analytics, long associated with threat detection (i.e. UEBA or UBA), is experiencing a renaissance. Once primarily used to identify suspicious activity, it’s now being reimagined as a powerful post-detection technology that enhances incident response processes.

 

Breach: HIBP notifies 57 million people of Hot Topic data breach

Have I Been Pwned warns that an alleged data breach exposed the personal information of 56,904,909 accounts for Hot Topic, Box Lunch, and Torrid customers.

 

Cyber Savvy AI Antics

New Year’s Cybersecurity Resolutions

This year I vow, with firm intent,
To guard the data my mission’s lent.
No threat too small, no risk too slight,
I’ll strengthen my systems, day and night.

First, I’ll train my team with care,
On phishing scams and threats out there.
Passwords strong, two-factor too,
To lock the gates from those who pursue.

I’ll audit policies, review the past,
Ensure my defenses are built to last.
Backups stored in a safe, dry space,
Ready to act if breaches take place.

Vendors and partners, I’ll vet them tight,
To ensure our network stays secure and right.
From emails to endpoints, vigilance stays,
To keep the bad actors out of our maze.

With board support and budget aligned,
This nonprofit’s safety will be redefined.
For those we serve, we’ll stay steadfast,
Cybersecurity first, from now to the last.

A resolution made, not just for show,
To keep our mission’s heart aglow.
This year I commit, I take the lead,
Cyber resilience is the creed.

 

News: Comprehensive Guide to Building a Strong Browser Security Program

The rise of SaaS and cloud-based work environments has fundamentally altered the cyber risk landscape. With more than 90% of organizational network traffic flowing through browsers and web applications, companies are facing new and serious cybersecurity threats. These include phishing attacks, data leakage, and malicious extensions. As a result, the browser also becomes a vulnerability that needs to be protected.

 

Phishing: New Phishing Tool GoIssue Targets GitHub Developers in Bulk Email Campaigns

Cybersecurity researchers are calling attention to a new sophisticated tool called GoIssue that can be used to send phishing messages at scale targeting GitHub users.

 

Privacy: Privacy Tennessee Information Protection Act

The Tennessee Information Protection Act (TIPA), effective July 1, 2025, is a state-level data privacy law that regulates how companies manage and protect consumers’ personal data within Tennessee.

 

News: Zoom addressed two high-severity issues in its platform

Zoom addressed six flaws, including two high-severity issues that could allow remote attackers to escalate privileges or leak sensitive information.

 

AI: Elon Musk’s AI turns on him, labels him ‘one of the most significant spreaders of misinformation on X’

Elon Musk’s Grok AI has called him out for spreading misinformation.

 

AI: Fake AI video generators infect Windows, macOS with infostealers

Fake AI image and video generators infect Windows and macOS with the Lumma Stealer and AMOS information-stealing malware, used to steal credentials and cryptocurrency wallets from infected devices.

 

Breach: T-Mobile confirms it was hacked in recent wave of telecom breaches

T-Mobile confirms it was hacked in the wave of recently reported telecom breaches conducted by Chinese threat actors to gain access to private communications, call records, and law enforcement information requests.

 

Cybercrime: Fraud network uses 4,700 fake shopping sites to steal credit cards

A financially motivated Chinese threat actor dubbed “SilkSpecter” is using thousands of fake online stores to steal the payment card details of online shoppers in the U.S. and Europe.

 

News: Gmail’s New Shielded Email Feature Lets Users Create Aliases for Email Privacy

Google appears to be readying a new feature called Shielded Email that allows users to create email aliases when signing up for online services and better combat spam.

 

Phishing: Phishing emails increasingly use SVG attachments to evade detection

Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection.

 

News: Privileged Accounts, Hidden Threats: Why Privileged Access Security Must Be a Top Priority

Privileged accounts are well-known gateways for potential security threats. However, many organizations focus solely on managing privileged access—rather than securing the accounts and users entrusted with it. This emphasis is perhaps due to the persistent challenges of Privileged Access Management (PAM) deployments. Yet, as the threat landscape evolves, so must organizational priorities. To prevent trust from becoming a liability, the next step in securing privileged access must become a critical focus.

 

News: Microsoft Launches Windows Resiliency Initiative to Boost Security and System Integrity

Microsoft has announced a new Windows Resiliency Initiative as a way to improve security and reliability, as well as ensure that system integrity is not compromised.

 

Vulnerability Vortex

The ASA flaw CVE-2014-2120 is being actively exploited in the wild

Cisco warns customers that a decade-old ASA vulnerability, tracked as CVE-2014-2120, is being actively exploited in the wild.

 

New Windows zero-day exposes NTLM credentials, gets unofficial patch

A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer.

 

Microsoft December 2024 Patch Tuesday addressed actively exploited zero-day

Microsoft December 2024 Patch Tuesday security updates addressed 71 vulnerabilities including an actively exploited zero-day.

 

Hunk Companion WordPress plugin exploited to install vulnerable plugins

Hackers are exploiting a critical vulnerability in the “Hunk Companion” plugin to install and activate other plugins with exploitable flaws directly from the WordPress.org repository.

 

Over 25,000 SonicWall VPN Firewalls exposed to critical flaws

Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports.

 

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools

A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect.

 

Sophos discloses critical Firewall remote code execution flaw

Sophos has addressed three vulnerabilities in its Sophos Firewall product that could allow remote unauthenticated threat actors to perform SQL injection, remote code execution, and gain privileged SSH access to devices.

 

CVE-2024-12828 (CVSS 9.9): Webmin Vulnerability Leaves a Million Servers Exposed to RCE

The popular web-based system administration tool, Webmin, has been found to harbor a critical security vulnerability (CVE-2024-12828) that could allow attackers to seize control of servers. With an estimated one million installations worldwide, the impact of this vulnerability could be widespread.

 

Dozens of Chrome Extensions Hacked, Exposing Millions of Users to Data Theft

A new attack campaign has targeted known Chrome browser extensions, leading to at least 35 extensions being compromised and exposing over 2.6 million users to data exposure and credential theft.

 

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure.

 

 

Read also

Welcome to V068: They let the hackers in through the ‘cloud’ – whatever that is.

Read newsletter

Welcome to V067: THIS. IS. MARCH CYBER MADNESS

Read newsletter

Welcome to v066 : Jibber Jabber Cyberwocky

Read newsletter

Welcome to v065 : Just when you thought it couldn’t get crazier…

Read newsletter

Welcome to v064: A cybersecurity pro and a business executive walk into a bar….

Read newsletter

Welcome to v063: I can remember all my passwords!

Read newsletter

Welcome to v062 : Roses are red, violets are blue, cyber-hackers are waiting for you

Read newsletter

Welcome to v060 : Dashing through the net, in a cloud-based CMS

Read newsletter

Welcome to v059 : It’s Cyber Budget Time

Read newsletter

Welcome to v058 : Cyber Fright Night

Read newsletter

Welcome to v057 : Happy Cybersecurity Awareness Month!

Read newsletter

Welcome to v056 : What is your Neurocyberpathology?

Read newsletter

Welcome to v055: It’s Time to Get Cyber-tastic!

Read newsletter

Welcome to v054 : How to Phish an Association Exec

Read newsletter

Welcome to v053 : Hot Out of the Oven: American Phish Pie

Read newsletter

Welcome to v052 : Quantum Toaster Breaches: Coffee Appoints New CIO

Read newsletter

Welcome to v051: Be thankful you’re not Crowdstrike!

Read newsletter

Welcome to v050 : We’re at v050 and kicking cyber-ass!!!

Read newsletter

Welcome to v049 : Watch Over Your Tech

Read newsletter

Welcome to v048 : BEC is DOA

Read newsletter

Welcome to v047 : Insurance Future: Coverage Linked to Cyber Hygiene

Read newsletter

Welcome to v046 : One Phish, Two Phish, Red Team, Blue Team

Read newsletter

Welcome to v045 : Quantum Humor: Relatively Fun, Universally Secure

Read newsletter

Welcome to v044 : Tongue Twisting Today’s Top Tech Terms

Read newsletter

Welcome to v043 : Where Firewalls Whisper and Passwords Giggle

Read newsletter

Welcome to v042 : Swap Suits for Codes and Be Heroes

Read newsletter

Welcome to v041 : Sweet Security Insights, Slice by Slice

Read newsletter

Welcome to v040 : Staff slip, skip strict security steps

Read newsletter

Welcome to v039: Rockin’ Cyber News

Read newsletter

v038: Choose Your CyberNews

Read newsletter

v037: Cybercrime is as Cybercrime Does

Read newsletter

v036: News You Can’t Refuse

Read newsletter

v035: Have Some Views of Cyber-News

Read newsletter

v034: The Double-Edged Sword in 2024 Cybersecurity Landscape

Read newsletter

v033: Cyber News to Use so You Don’t Lose

Read newsletter

v032: Cybercrime all the time

Read newsletter

V031: Cyber News for Chews

Read newsletter

V030: Cybercrime is a Tasty Wave

Read newsletter
About Us
businessman developing strategic plans, evaluating technology

Developing cybersecurity plans, evaluating and implementing technology, building effective software, and executing strategic initiatives.

Let’s Socialize

Popular Post

Welcome to V068: They let the hackers in through the ‘cloud’ – whatever that is.

April 23, 2025

Welcome to V067: THIS. IS. MARCH CYBER MADNESS

April 3, 2025
About

Reduce cybersecurity risk, maintain compliance, develop strategic plans, and create custom software.

Services
  • Fractional CISO – Cybersecurity Leadership
  • Fractional CTO – Application Development Leadership
  • Automation
  • Ransomware Cost Estimator
Quick Links
  • Latest Publications
  • Testimonials
  • Customer Use Cases
Logo-cyber with three tag words 4000w

Do you want a free sketch for your homepage? Visit Weblify.se

Linkedin-in

Why you need a vCIO?

While CEOs and presidents grapple with the complexities of business, marketplace, industry, strategy, and their board and stakeholders, they are left with little time or inclination to deal with the details of the incredibly dynamic technology landscape. Keeping one’s eye on the myriad of technology changes and how they can and will affect the business takes a specialized, dedicated, and experienced professional. That is exactly the role of the virtual CIO or CTO.
Download

20 Years of CIO Experience

Tracks trends, market direction and customer needs to plan the future of technology.  Recruits high performing team members and develops their skills by providing decision-making ownership and collaborative engagement.  Able to initiate culture change, lead by example, and get buy-in at all levels.  Known for facilitating energizing brainstorming sessions that generate actionable insights and create new revenue opportunities.

In 2000, Brian was introduced to the exhibitions and events industry when he joined 3rd Millennium Communications as Manager of Software Development for a Virtual Tradeshow Product.  That company was acquired by Galaxy Information Services and through additional acquisitions later became Experient.

As CIO of Experient, Brian oversaw the replacement and upgrade of every piece of legacy proprietary systems that supported the registration, housing, and lead retrieval services.  He also oversaw the transition from a paper-based and manual business operations to an entirely online and mobile app-based model.  Brian oversaw the strategy and operations of the Experient data center including their recent adoption and migration to cloud-based hosting to enhance availability, reliability, scalability, and recoverability.

Brian led the product development strategy and spearheaded several product concepts including eventBit™ which was granted a US patent in 2019 (Patent Number: US 10,311,267 B2).  He was also instrumental in the evolution of lead retrieval products from hardware-based units to smart phone-based mobile app technology.

Brian oversaw the cyber-security position for Experient including compliance to the Payment Card Industry Data Security Standard (PCI DSS), SSAE-18 SOC 1 Type II, and internal corporate security standards audits. Security scope included a 400-server data center, 700 end user devices, and credit card data environment, and a data center holding thousands of databases of customer data. Under Brian’s leadership, Experient successfully met or exceeded requirements for PCI since its introduction in 2005.

Brian’s business philosophy is rooted in a belief in the power of high performing teams, the necessity of self-disruption, the focus on the client’s perspective, the criticality of speed of change, and the utility of lean and agile development and operational processes.

Brian has the honor of being the first technology professional to participate as a director on the Board of Directors for the International Association of Exhibitions and Events® (IAEE). Organized in 1928 as the National Association of Exposition Managers to represent the interests of trade show and exposition managers, the International Association of Exhibitions and Events® is the leading association for the global exhibition industry. Today IAEE represents over 12,000 individuals in 50 countries who conduct and support exhibitions around the world. Being a data-centric leader, Brian is also proud to serve on the board of CEIR, the Center for Exhibition Industry Research.

Brian also believes that in today’s competitive employee market, the most successful companies must find ways to create enjoyable and engaged workplace environments. No stranger to performance, Brian was frequently seen on stage in front of the Experient organization delivering educational messages (such as not clicking on links within phishing emails) or just poking fun at his peers within the leadership team through music.

Brian is a Tennessee Volunteer at heart and his blood runs deep orange due to his undergraduate studies at the University of Tennessee, Knoxville where he received his Bachelors of Science in Electrical Engineering with Honors.  He also earned a Masters of Science in Technology Management from the University of Maryland Global Campus.  His personal passions include his wife and two sons, music, and fitness.  He is a 30-year veteran of live music performance, a published musical play composer, and a recording studio engineer and producer.  When he’s not in the studio, you’ll find him out on his bike climbing the local hills.

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.I agree