Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Exam prep
Exam-prep training that counts toward CySA+ renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 60 CEUs CySA+ requires every 3 years — without re-keying each entry into CompTIA's portal.
45 results mapped to CySA+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
In the last year alone, the number of supply chain attacks has grown exponentially as they offer threat actors stealthy, scalable, and privileged access to your organization’s on-premises, cloud, and hybrid environment. Addressing supply chain attacks requires a multi-layered defense strategy in which third-party integrations are audited, endpoints are monitored for post-compromise actions, and an Incident Response plan that considers supply risks is put in place to minimize the overall impact to your organization. On May 10, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Sumo Logic share insights from original threat research and supply chain attacks to demonstrate how multi-signal investigations can effectively secure your organization against supply chain attacks. Key takeaways from the webinar include: • The three primary attack vectors that cybercriminals rely on to launch supply chain attacks against organizations • The challenges that organizations face related to supply chain risk (e.g., technical complexity, access requirements, stealth of cyberattacks) and how they impact business operations • Tactical and high-level strategic recommendations on how your organization can minimize supply chain risk and reduce the attacker dwell times and impact • How 24/7 log monitoring and management can improve cyber resilience and prevent zero-day threats • A case study on how original research and curated threat intelligence conduct stronger post-exploitation investigations.
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
In recent months, major incidents such as the attack related to SolarWinds has led organizations to reevaluate their cyber security strategy. Governments and municipalities in particular, who are facing threats from increasingly professional threat-actors, need robust and adaptive defenses to secure critical data and infrastructure. While traditional tools rely on rules and signatures to spot signs of known threats, cyber-criminals continue to innovate and circumvent these defenses with new tools, techniques, and procedures. For this reason Cyber AI is becoming increasingly critical for its ability to understand ‘normal’, and detect and respond to subtle deviations indicative of a cyber-threat. Join Darktrace and (ISC)2 on July 27, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Darktrace’s Director of Strategic Threat, Marcus Fowler explores: o The unique challenges facing the digital infrastructures of cities and nations o Top cyber incidents of 2021 and what they show us about government cyber-risk o Case studies of Darktrace municipal customers
Responding to an incident takes more than theoretical knowledge. To effectively detect, investigate, and mitigate a live incident requires strong knowledge, technical skills, and practical experience, many of which current cyber pros are missing. Join Cyberbit and (ISC)2 on November 23, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific to experience a live incident response, simulated on the cyber range included in Cyberbit’s cyber team preparedness platform. Here’s the twist: you, as the audience, are in control. You will vote to control the actions taken by the responder and see how quickly the audience can resolve the attack!
No doubt, you’ve seen it, the threat landscape is evolving year over year. How do you fine tune your defenses against an ever-changing adversary? On August 18, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific join F5 Labs and (ISC)² for a multifaceted analysis of the application security threat landscape based on F5 Labs’ 2022 Application Protection Report. The report analyzes nearly 1,000 data breaches from 2021, focusing on three specific threats: ransomware, which played a role in nearly half of the successful attacks in 2021; formjacking attacks like Magecart; and data exfiltration, which was featured in nearly 80% of breaches. F5 Labs and will share additional perspectives of the threat landscape, with a look at cloud risks, cryptocurrency theft, and some case studies about well-resourced attackers. The session will conclude with recommended best practices using prioritization methods for different scenarios.
Vulnerability management has been a staple of security teams for decades. But if you haven’t noticed, this space has evolved considerably over the last half decade. Long gone are the days of lengthy, hard-to-digest vulnerability scanning reports often created to check the PCI compliance checkbox. These days, smart IT security teams are investing in risk-based vulnerability management (RBVM) technologies and best practices to help prioritize which vulnerabilities to remediate first based on a variety of internal and external factors. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps the evolution from VA, to VM, to RBVM - Defines key elements of modern-day RBVM solutions - Reviews internal and external factors to help prioritize vulnerability remediation - Describes what to look for when evaluating best-of-breed RBVM offerings - Summarizes the extraordinary benefits derived from RBVM deployments
Cybercriminals use an ever-increasing array of DDoS attack vectors to target business and governments. Today, the question isn’t if, but when, you will be a target. Knowing your adversary's latest tactics and techniques are key to your defense. Join NETSCOUT and (ISC)² to explore the findings and trends from the latest NETSCOUT DDoS Threat Intelligence Report. • Global and regional DDoS attacks stats (e.g. size, frequency, vectors.) • How attackers are getting more sophisticated in their DDoS attack techniques, and the most common attack vectors. • The relationship between DDoS attacks and geopolitical events. • The increasing number and size of botnets that are being used to launch DDoS attacks. • Best practices in DDoS attack defense and suppression.
With successful cyber-attacks and breaches at an all-time high, a continually increasing cybersecurity workforce gap, and the specter of the “great resignation,” organizations are finding it increasingly difficult to hire and retain sufficiently experienced cybersecurity professionals. When faced with a dwindling giant panda population in the late 1900s, conservationists the world over poured their time and effort into restoring the population from its critical lows. The use of artificial environments gave the pandas the stimulation and experience necessary to return their species from the brink of extinction. Similarly, our industry faces a species on the brink, the cyber unicorn. They are under threat from burnout, headhunters, and other natural and artificial phenomena. On September 27, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific we will explore real-world case studies on how large organizations are using cyber ranges to combat team burnout, build practical expertise, and assess readiness. Topics covered include Red-, Blue-, and Purple-team events, automated user behavior, and threat presentation - manual and automated.
DDoS (distributed denial of service) attacks continue to increase in frequency and sophistication as attackers innovate with new adaptive DDoS attack tactics and techniques. Dive into NETSCOUT’s latest DDoS Threat Intelligence Report that reveals multiple noteworthy findings and trends followed by a simulated DDoS attack against stateful devices. Join NETSCOUT and (ISC)2 on December 1, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific us as we explore the report and recommend best practices in adaptive DDoS defense: - Global and regional DDoS attack stats and trends. - DDoS attacks are increasing being linked to worldwide geopolitical events (e.g., the Russian-Ukraine war.) - Attackers are conducting more pre-attack reconnaissance to determine attack vectors, avoid detection, and maximize impact on targets. - Attackers are moving away from reflection/amplification attacks towards direct path, state exhausting attacks that target stateful devices like firewalls and load balancers.
Ransomware continues to dominate the headlines with a wide range of organizations impacted. Part of its staying power is that ransomware threat actors tackle the attack chain with the specialization and organization of a business, with different groups tasked with different roles and responsibilities. Join us for this Proofpoint and (ISC)2 webinar March 28, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn how threat actors are adapting to maintain their business model, and what organizations can do in response. We’ll discuss best practices to: - Minimize the probability and impact of ransomware incidents by focusing on the entire attack chain - Minimize the damage when ransomware incidents do occur by detecting and limiting the action of compromised identities - Minimize recovery time by protecting the primary target of ransomware attacks, your data
The 2022 cyber threat landscape was one of persistence, increased scope, and relentless determination. As businesses began to ease pandemic-driven operating environments and adjust to geopolitical shifts—as well as growing economic hardships—adversaries supporting nation-state, eCrime, and hacktivist motivations started the year with a relentless show of effort that ultimately defined 2022. Join CrowdStrike and (ISC)2 March 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for an in-depth review of how the cyber threat landscape has evolved over the last year, including notable threats, events and trends outlined and explained in the CrowdStrike 2023 Global Threat Report. In this session, we’ll discuss: • The most relevant threat issues that organizations face today • New adversaries uncovered in 2022 and their growing speed and sophistication • Useful best practices in how you can combat the modern-day threat
The Domain Name System (DNS) is essentially the central nervous system of the internet—everyone needs it to work because without DNS services, digital business could come to a halt. Cybercriminals know this too, and exploit DNS services to launch their attacks while simultaneously attacking the DNS services of their targets. Therefore, it’s not only important to protect your organization’s DNS service, but also to use the data available from DNS services to more rapidly detect and surgically block threat activity such as phishing, DNS tunneling-based data exfiltration, and ransomware. On March 2, 2023 join Infoblox and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear best practices for an effective DNS security architecture.
The ransomware scourge continues to plague the cybersecurity industry. To help ensure you and your company are better prepared, we will share insights and lessons learned from ransomware case studies. In this session, on September 12, 2023 at 1:00 p.m./ 10:00 a.m. Pacific IANS and (ISC)2 will lead you through: • What went right (and wrong) in these examples and how best to incorporate that experience into your defenses and program • Threat actor behavior and how to take advantage of their internal processes to thwart them • TTPs used in various ransomware operations • Alert monitoring – from investigating to remediating • The reality and best practices around backups and recovery
Changes in how we design, build, run and secure information systems have also changed how we look at authentication and access control. The emerging concept of identity is transforming the ways that humans and non-human actors alike make use of data and compute power. At the same time, the emergence of identity as a focus for organizations also means that it has become a focus for attackers. To assess the ways that old and new attacks are targeting digital identities, F5 Labs is presenting findings from our 2023 Identity Threat Report: The Unpatchables. On September 19, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific this session will focus on credential stuffing. This will be the first of two sessions. We will quantify its prevalence, explore targeting trends such as attackers’ choice of industries and endpoints, and outline credential stuffing tactics, techniques and procedures (TTPs). We will also take a deeper look into some case studies, with a particular focus on the differences between basic and sophisticated attacks. This talk will also assess the stolen credentials supply chain before focusing on mitigation strategies for combating credential stuffing.
Vulnerability management has been a staple of security teams for decades. But if you haven’t noticed, this space has evolved considerably in recent years. Long gone are the days of lengthy, hard-to-digest vulnerability scanning reports often created to check the PCI compliance checkbox. These days, smart IT security teams are investing in exposure management platforms and embracing best practices to help prioritize which vulnerabilities to remediate first based on a variety of internal and external factors. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps the evolution from VA, to VM, to RBVM, to exposure management - Defines key elements of modern-day exposure management platforms - Reviews internal and external factors to help prioritize vulnerability remediation - Summarizes the extraordinary benefits derived from exposure management deployments - Describes what to look for when evaluating best-of-breed exposure management offerings
Brace yourself for agentic AI ransomware – a terrifying fusion of cutting-edge tech and malicious intent that's set to redefine cyber threats as we know them. Unlike traditional ransomware, which follows pre-programmed rules, agentic AI ransomware can adapt its behavior in real-time based on its environment and the defenses it encounters. Is your organization prepared? Join KnowBe4 and ISC2 on May 8, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this mind-blowing webinar where Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist, pulls back the curtain on the looming threat of AI-powered ransomware. Don't let your organization become a case study in what NOT to do when faced with this new breed of ransomware! In this webinar you’ll discover: - Agentic AI and why it's keeping cybersecurity experts up at night. - A glimpse into the future: what Agentic AI malware looks like and how it operates - The terrifying mechanics behind Agentic AI Ransomware Battle-tested strategies to fortify your defenses against this AI-driven attack - How to stay one step ahead with next-generation defense tactics against evolving AI threats Don't be caught with your defenses down. Join us and arm yourself with strategies you need to protect your organization in this new era of AI-powered cyber warfare.
Legacy vulnerability management approaches often struggle to keep pace with today’s dynamic threat landscape. Maximizing the value of your vulnerability management program requires moving beyond outdated practices to adopt a proactive and risk-based approach. Join Steve Piper, CEO of CyberEdge and Editor-in-Chief of Security Buzz, as he shares strategies for transforming legacy vulnerability management systems into efficient, leading-edge cyber exposure programs that prioritize high-risk vulnerabilities, streamline workflows, and reduce attack surfaces. Gain insights into leveraging automation, integrating threat intelligence, and driving measurable improvements in your organization’s security posture.
The cybersecurity landscape is evolving at an unprecedented pace, and organizations must ensure their Security Information and Event Management (SIEM) solutions don’t merely keep up with emerging threats and compliance requirements but also provide room to adapt and grow. In this exclusive webinar, Sumo Logic will share insights on navigating SIEM implementation and optimization in a growing, cloud-first world. Learn why a modern SIEM is the cornerstone of an effective security practice, how to log critical data efficiently, and what’s the horizon for security operations. Key Takeaways: - Essential SIEM capabilities to secure your organization from evolving cyber threats. - Strategies to increase fidelity, scale security operations, and improve resilience. - How to streamline security monitoring and compliance reporting.
As cloud adoption surges, so does the speed and sophistication of attacks. Traditional static detection and response can’t keep up in today’s fast-moving, multi-cloud environments. Join Palo Alto Networks and ISC2 June 24, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific to explore actionable best practices for modern cloud detection, investigation, and response (CDR). We’ll cover how security teams are leveraging CDR to keep up with the speed and diversity of cloud-native attacks. In this session, you'll learn: - Lessons from real-world multi-cloud incidents - Why cloud security must start with prevention, not just detection - How to cut through the noise and focus on what really matters - Key capabilities to demand in a CDR solution — and red flags to avoid - How to ready your SecOps team for cloud-native response
As cyber threats grow more advanced, many organizations are still relying on fragmented tools and manual processes to identify and remediate vulnerabilities—leaving critical gaps in their security posture. In this webinar, join NinjaOne and ISC2 July 10, 2025 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a forward-looking discussion on how IT and security teams can modernize their approach to vulnerability management. We’ll explore strategies for reducing complexity, closing exposure windows faster, and building a more proactive security framework across your entire endpoint environment. Key takeaways will include: -How to automate and prioritize vulnerability data using risk-based intelligence (e.g., CVE, CVSS) -Tactics for accelerating patch deployment to minimize risk and reduce response times -The role of AI and sentiment analysis in evaluating patch relevance and risk Best practices for tracking remediation outcomes to ensure vulnerabilities are fully addressed Whether you’re looking to strengthen your current security operations or rethink your patching strategy, this session will offer practical insights you can apply immediately.
Cybercriminals are using AI to outsmart traditional defenses, making the world more dangerous for the rest of us. They're deploying AI-generated deepfake videos to impersonate executives and using AI-powered chatbots to mimic trusted colleagues in sophisticated social engineering attacks. But as an IT professional, you have the power to turn the tables. Now is the time to leverage the power of AI to protect your organization and gain a critical edge in cybersecurity. On July 17, 2025 join KnowBe4 and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a session where we will discuss how your organization can harness AI-powered agents for real-time threat detection, predictive analytics and automated training. You'll learn: - Jaw-dropping examples of hyper-personalized phishing and shape-shifting malware attacks - New strategies to deploy AI and autonomous agents as your 24/7 cyber guardians - How to harness predictive analytics to stay two steps ahead of evolving threats - About the ethical minefield of AI in cybersecurity and how to navigate it safely - Practical, actionable steps to leverage AI in your human risk management strategy. Attend this webinar to arm yourself with the knowledge and strategies you need!
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.