Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISC2 · Exam prep
Exam-prep training that counts toward CISSP renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 120 CPEs CISSP requires every 3 years — without re-keying each entry into ISC2's portal.
147 results mapped to CISSP, soonest first.
To understand where you’re going, you must first know where you are. But in the world of cloud-native security, where technologies and best practices seem to change by the month, finding your baseline can sometimes feel impossible—let alone benchmarking your peers. To help organizations find their way, the team at Prisma Cloud has put together the second annual State of Cloud-Native Security report, a survey of 3,000 professionals across five countries that helps answer the question What’s happening in cloud-native security today, and what are successful organizations doing right. On January 25, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Palo Alto Networks, Prisma Cloud, and (ISC)², as we reveal for the first time the trends that are driving the world’s most successful cloud security programs, analyze the best practices that help leading enterprises excel, and demystify the evolving cloud security landscape.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
A recent research study published by (ISC)2 provides insights for cybersecurity professionals into the minds of C-suite executives and how they perceive their organizations’ readiness for ransomware attacks. This data underscores the need for clearer and more frequent communications between cybersecurity teams and executives and offers best practices security leaders should implement to improve those interactions. Join (ISC)2 CISO Jon France on February 22, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he guides attendees through a summary of the data, discusses what we can learn from it and answer questions about ransomware topics.
51% of businesses have experienced a third-party data breach. In other words, there’s a one-in-two chance a vendor will expose your sensitive data. Practically every company relies on third parties to provide critical services or software to their business. But while you can outsource processes, you can’t outsource the associated risks. Knowing who your vendors are, how they manage their risks and their potential impacts on your company is a crucial piece of your InfoSec program. However, contracting is often overlooked from a security perspective, and it shouldn’t be. An effective vendor risk management program can minimize the impact of disruptive events and reduce a company’s overall risk exposure. In this webinar, Jose Costa, Chief Information Security Officer at Tugboat Logic, and Zach Payne, Senior Corporate Counsel at OneTrust, will deep dive into: - How to build an ideal vendor management framework - The issue with vendor contracts and how to overcome common pitfalls - Practical advice to streamline complex client and vendor points of view - Liability limitations, intellectual property, and confidential information.
As multi-cloud adoption accelerates, security teams are navigating the delta between each cloud provider’s native capabilities and comprehensive protection from bad actors. Understanding cloud terminology, principles, and security issues is critical. Join (ISC)² and Sysdig March, 29, 1:00 p.m., Eastern/10:00 a.m. Pacific to understand the fundamentals on cloud categories and terms like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform), etc. so you can move past the acronyms and onto implementing them as best practices. In this session we will: • Debunk new industry acronyms and explain how they fit into your overall cloud security strategy • Explain why native cloud provider tools aren’t always sufficient • Provide CSPM best practices: Detecting misconfigurations, excessive permissions and suspicious activity • Showcase how open-source Falco can be used to detect cloud threats in real-time
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
As more companies undergo digital transformation and software is released more frequently, application security is moving from an opportunity to an imperative. However, AppSec as a process requires cooperation with software developers - a team whose time is heavily in demand from every customer-facing part of the organization. How do security teams improve AppSec without slowing down business and finding themselves at odds with the rest of the organization? For DevSecOps to succeed it must take cues from the DevOps revolution that came before it. Teams need to learn new tools that address the new problems that arise from the evolution of IT. Smart use of automation can create transparent processes that handle routine work between teams without creating friction. And most importantly, adopting a supportive, rather than authoritative, mindset makes it possible for teams to move quickly together while achieving their respective missions. On April 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, ShiftLeft and (ISC)² will provide an overview of application security that covers key tools, best practices, and a primer on working effectively with your colleagues in AppDev and DevOps in order to make modern software more secure.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
In the last year alone, the number of supply chain attacks has grown exponentially as they offer threat actors stealthy, scalable, and privileged access to your organization’s on-premises, cloud, and hybrid environment. Addressing supply chain attacks requires a multi-layered defense strategy in which third-party integrations are audited, endpoints are monitored for post-compromise actions, and an Incident Response plan that considers supply risks is put in place to minimize the overall impact to your organization. On May 10, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Sumo Logic share insights from original threat research and supply chain attacks to demonstrate how multi-signal investigations can effectively secure your organization against supply chain attacks. Key takeaways from the webinar include: • The three primary attack vectors that cybercriminals rely on to launch supply chain attacks against organizations • The challenges that organizations face related to supply chain risk (e.g., technical complexity, access requirements, stealth of cyberattacks) and how they impact business operations • Tactical and high-level strategic recommendations on how your organization can minimize supply chain risk and reduce the attacker dwell times and impact • How 24/7 log monitoring and management can improve cyber resilience and prevent zero-day threats • A case study on how original research and curated threat intelligence conduct stronger post-exploitation investigations.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Effectively managing and mitigating cyber risk in your supply chain today means moving away from trust-based approaches and investing in a more proactive third-party risk program. A variety of factors from global digitalization to geopolitical conditions have drawn more reliance on and attention to supply chain connections, and threat actors are more motivated than ever to exploit these connections as attack vectors. Mitigating these threats requires overcoming both external cooperative and internal organizational challenges. This highly pertinent webinar will share insights on these challenges as well as best practices for evolving your third-party risk management program to keep up with an evolving supply chain-focused threat landscape. This webinar will explore: • The current challenges facing organizations in keeping up with and managing evolving cyber risk in constantly expanding supply chains • Differences in traditional and more adaptive, SOC-inspired approaches to third-party cyber risk and what programmatic strategies work best for modern organizations • How to improve your organization’s overall security posture by adopting a proactive risk reduction strategy in managing your vendor ecosystem
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
The very activities that cybersecurity teams do to make their organizations safe can create additional risk for the organization. Defenders can unintentionally create new ways for attackers to target their organization through inadvertently introducing new vulnerabilities, placing too much trust in their security strategy, ignoring alert fatigue, and by making their mitigation activities too predictable. During this session, we will: • Explore why blindly applying vendor patches may not always be the best strategy. • See examples of how overconfidence in any single line of defense can be dangerous. • Identify opportunities to streamline incident alerts and monitoring so critical notifications are not missed. • Learn why following an incident response playbook may not always be in your best interest. Join us on June 30, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific when SimSpace and (ISC)² will discuss the four types of second-order cyber risk and offer practical advice on best practices that form a continuous improvement approach to improve overall cyber hygiene while minimizing second-order cyber risks.
Accidents and attacks can happen – no matter how airtight your security practices are. As ransomware threats continue to surge, businesses struggle to manage data security and associated costs. Recovering from a ransomware attack, in particular, is often a costly endeavor, with victims scrambling to minimize downtime, revenue loss, and reputation damage. When things go wrong, the organization needs a comprehensive disaster recovery plan in place to restore all data and resume normal operations. Join Synology and (ISC)² on July 7, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webcast where we will examine the fundamental elements of a complete disaster recovery plan, such as endpoint and cloud backup, off-site failover, and remote archives. In this session, we will also walk through several case studies identifying opportunities to enhance restoration efficiency and minimize work disruptions.
With the current push for digital business transformation, organizations are increasingly dependent on external parties, increasing their vulnerability to vendor cyber risk. Because many vendor risk management programs are developed as tactical responses to ensure compliance with a growing list of data privacy and cybersecurity regulations, they often result in labor-intensive and inefficient processes that deliver marginal value. Industry best practices for effective Third-Party Cyber Risk Management can improve your program and may provide cyber defense for your third parties. In this webinar, July 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, BlueVoyant and (ISC)² will discuss: • Industry recognized best practices for an effective TPRM program • How to transform your TPRM program with continuous monitoring and active risk identification and mitigation • Ways to solve your toughest TPRM challenges
This session will focus on methods for security teams to better monitor and secure hybrid cloud environments while logging compliance data. Learn best practices to analyze, prioritize, and investigate security alerts within cloud resources faster and more accurately through a variety of cloud-agnostic security strategies while reducing downtime and security incidents. On July 28, 2022 at 1:00 p.m. Eastern/10:00 am. Pacific Sumo Logic and (ISC)² will: • Discuss business motivations for cloud migration. • Identify common challenges while monitoring applications throughout the migration. • Explore solutions for typical security operations constraints during the migration.
In recent months, major incidents such as the attack related to SolarWinds has led organizations to reevaluate their cyber security strategy. Governments and municipalities in particular, who are facing threats from increasingly professional threat-actors, need robust and adaptive defenses to secure critical data and infrastructure. While traditional tools rely on rules and signatures to spot signs of known threats, cyber-criminals continue to innovate and circumvent these defenses with new tools, techniques, and procedures. For this reason Cyber AI is becoming increasingly critical for its ability to understand ‘normal’, and detect and respond to subtle deviations indicative of a cyber-threat. Join Darktrace and (ISC)2 on July 27, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Darktrace’s Director of Strategic Threat, Marcus Fowler explores: o The unique challenges facing the digital infrastructures of cities and nations o Top cyber incidents of 2021 and what they show us about government cyber-risk o Case studies of Darktrace municipal customers
Clar Rosso, CEO of (ISC)2 shares the latest insights on what’s happening at our association. Join us for this quarterly update where we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. Joining Clar this quarter is Dr. Casey Marks, chief product officer and VP of (ISC)2, to discuss the latest in Exams and certifications.
Responding to an incident takes more than theoretical knowledge. To effectively detect, investigate, and mitigate a live incident requires strong knowledge, technical skills, and practical experience, many of which current cyber pros are missing. Join Cyberbit and (ISC)2 on November 23, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to experience a live incident response, simulated on the cyber range included in Cyberbit’s cyber team preparedness platform. Here’s the twist: you, as the audience, are in control. You will vote to control the actions taken by the responder and see how quickly the audience can resolve the attack!
With hybrid workplaces now the new norm and supply chain attacks on the rise, there’s an increased exposure to cyber-attacks, which can cause substantial disruption to any organization or industry. This increased exposure is forcing companies to not only invest and improve their own cybersecurity posture, but also manage third party risk and protect against cyber risks with cyber insurance. Certain best practices and technologies help reduce your risk and improve your security score while helping to keep insurance premium costs low. DNS security is one such approach that provides extended visibility, protection and security automation to improve a company’s security posture. Join Infoblox and (ISC)2 November 11th, at 1 p.m., ET/ 10 a.m. PT for this webinar to learn more about: o Why organizations invest in cyber insurance o Getting the most out of cyber insurance o How DNS security improves security scores and reduces cyber insurance premiums
When you tell people you’re thinking about CISSP, you’ve probably been told: • CISSP is globally renowned - those holding it are highly sought-after. • Achieving certification means you get paid more. • CISSP is HARD to earn. • It’s a LONG exam. But what you probably haven’t heard are the unexpected surprises along the way CISSPs never imagined in their certification journey. For example, learning that CISSP is a broad certification that focuses on governance: Do you understand the technology? The people? The management? Join us for a panel discussion as CISSP-certified members share their personal stories and the unanticipated ways certification continues to benefit their careers. After all is said, you’ll be amazed at what CISSP can do for you in your professional growth and career. Hear expert insights from: AJ Yawn, Jerome Leach and Angus Macrae
Building a strong cybersecurity team takes grit. The best results don’t always come at the first pass. When BT, a world-leading communications provider headquartered in London with offices globally, tasked CSIRT Training Specialist Jonathan Kilgannon with raising the bar for success among the company’s CISSP candidates, he delivered. Average exam pass rates jumped to 90% percent — a 40% increase — following the changes he implemented in the training process. Find out how identifying the right candidates, preparing them in advance and (ISC)2 Official In-Person Team Training made all the difference.
SIEM systems are pivotal to IT organization’s security operations. Many companies are adopting a hybrid cloud model, and cloud-based SIEMs are becoming common as a result. Regardless of on-prem or cloud deployments, the challenges around SIEM remain the same, from data overload, lack of contextual information, to high costs. Security best practices in deploying SIEMs also remain unchanged, which include establishment of use cases, data ingestion types and development of parsers for various tool vendors. On March 9, 2021 at 1:00pm Eastern, Gigamon and (ISC)2 will present a webinar that will cover solutions to these challenges such as Gigamon’s Application Metadata Intelligence as well as various smart filtering techniques.
Firewalls, VPN concentrators, IDS/IPS, load balancers, etc., all have one thing in common. They are stateful devices. That makes them very susceptible to DDoS attacks – more specifically, state exhaustion attacks. To protect these devices from DDoS attacks, you need dedicated, stateless DDoS attack protection technology deployed in front of your stateful infrastructure. Join Netscout and (ISC)2 on December 6, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we examine: · Why stateful devices like firewalls are susceptible to DDoS attacks. · Why industry best practices (and firewall vendors) suggest deploying stateless DDoS protection in front of your firewall to protect it and other stateful devices. · How and why organizations should prepare and defend around the first and last line of network perimeter defense to protect the availability and performance of firewalls and other stateful infrastructure from cyber threats.
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.