Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Webinars
Live and recorded webinars that count toward CySA+ renewal — vendor sessions, community talks, and conference replays we've indexed for CE credit. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 60 CEUs CySA+ requires every 3 years — without re-keying each entry into CompTIA's portal.
265 results mapped to CySA+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
Last year was a record-breaking year for data breaches. What can we learn from this growing trend? On March 17, 2022 at 1:00 p.m. Eastern/10:00 am Pacific join F5 Labs and (ISC)² as they share findings in a hot-off-the-presses report exploring those trends. This discussion will analyze the continuing growth of malware, the threat that Magecart and similar web attacks pose to e-commerce, business email compromise, and more. As in the 2021 report, they will use MITRE’s ATT&CK framework to visualize attack chains at large scale to explore the relationships between attacker behaviors. The talk will conclude with a discussion of different mitigation strategies so that organizations can tune their defenses to adapt to the latest in attacker trends.
Zero-day exploits serve as a master key for cybercriminals to launch crippling cyberattacks which are only increasing in frequency. In fact, research from Google's Project Zero shows that as of November 2021, a total of 57 zero-day exploits in the wild have been discovered, compared to an average of 22 exploits in past years. In the past year, eSentire’s Threat Response Unit (TRU) detected and responded to a significant increase in zero-day exploit activity in client environments that included defending against critical Exchange vulnerabilities ProxyLogon, ProxyShell, the REvil attack against Kaseya and most recently, mass exploitation of Log4j vulnerabilities. Join eSentire and (ISC)2 on March 22, 2022 at 1:00p.m. Eastern/10:00a.m. Pacific as key findings from new research on zero-day attack patterns are shared including how to triage vulnerabilities, and the response capabilities needed to effectively tackle future zero-day attacks. We’ll also examine: • Factors contributing to the rise of zero-day attacks • Notable Vulnerability analysis of SolarWinds, ProxyLogon, ProxyShell, and Kaseya VSA • Opportunity windows for zero-day exploits (n-day attacks) • Recommendations on how you can defend against zero-day exploits
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join this webinar featuring CrowdStrike Director of Strategic Threat Advisory Group, Jason Rivera, as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond.
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join our webcast featuring CrowdStrike SVP of Intelligence Adam Meyers as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond. Highlights include: • Ransomware and the ever-adaptable adversary • Iran and the new face of disruptive operations • The emergence of China as leader in vulnerability exploitation • Log4Shell sets the internet on fire • Increasing threats to cloud environments
No matter how much security technology we purchase, we still face a fundamental security problem: people. This (ISC)² and KnowBe4 webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding. On May 5, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific, join Erich Kron, Security Awareness Advocate for KnowBe4 as he provides fun and engaging examples of mental manipulation in everyday life: from the tactics used by oily car dealers, to sophisticated social engineering and online scams. Additionally, we’ll look at how to ethically use the very same levers when educating our users. Key Takeaways: • The Perception Vs. Reality Dilemma • Understanding the OODA (Observe, Orient, Decide, Act) Loop • How social engineers and scam artists achieve their goals by subverting OODA Loop's different components • How we can defend ourselves and our organizations
Getting asset visibility and insights into exposures, such as what services or ports might be exposed to the internet, is great. But should you start closing all those ports or shutting down risky services? How do you know what actions to take next? This is where layering threat intelligence onto your attack surface can help prioritize actions or response from your security team. This kind of actionable intelligence can support a wide range of cybersecurity activities, from cyber hygiene and patching to optimizing threat hunting operations. In this session, Looking Glass and (ISC)² will discuss: • How threat intelligence can be applied to your attack surface to prioritize action • Real-world examples of organizations effectively using intelligent attack surface insights to improve their cybersecurity program
It’s what keeps many of us awake at night-- knowing that a cyberattack is inevitable. Still there are things you can do to help strengthen your security posture. Join NETSCOUT and (ISC)² on May 4, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a discussion that will expose critical factors in understanding the global threat landscape as Dr. Eric Cole, Founder, and CEO of Secure Anchor Consulting, sheds light on cyber vulnerabilities that organizations are currently ignoring and outline strategies to reduce cyber risk. Paul Barrett, CTO for NETSCOUT, will unpack strategies to minimize the risk through network visibility. Presenters will also share regional examples from North America and expand upon the highly correlated risk reduction factors associated with network visibility in cyber.
Your cybersecurity teams are overwhelmed managing dozens of security tools and dealing with hundreds or thousands of alerts every day. That’s why organizations need a modern approach to total enterprise security to be able to automate manual processes and build a security ecosystem for a faster and more coordinated response to threats. Integrating DNS security with your existing SIEM/SOAR, Threat Intelligence, Vulnerability Management, NAC, NGFW, EDR, etc. could help the security operations team gain better visibility and context around threats for a prioritized security response. Join Infoblox and (ISC)² on March 15, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn some key tips and benefits of an efficient cybersecurity ecosystem: • How to get 360° view of all the assets on your network • How to overcome the challenge of working with siloed security tools • Decrease time to remediation by using network and threat context • Automatically trigger response to events detected by DNS security
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
Increasing efforts to modernize and digitally transform business operations means it’s easy for organizations to lose track of their assets, or not know about assets acquired by business or operating units (“shadow IT”). But how can you protect what you don’t know about? That’s why understanding your attack surface is critical. In this session, Looking Glass cybersecurity expert, Cody Pierce, will discuss what an “attack surface” is, how to determine your digital footprint, and why your organization’s attack surface is likely growing rapidly. He will also share how managing your attack surface by taking the adversary’s view – a different perspective than most cyber defense strategies – is critical to identifying assets, maintaining effective inventory, and prioritizing mitigations. In this session, you’ll learn: • What attack surface management is and why it’s important • How attack surface management can fit into your existing cybersecurity program • Use cases where attack surface management can inform, optimize, and enhance a variety of cyber operations
Ransomware readiness is the #1 board-level directive when it comes to cyber security. Join Cyberbit and (ISC)2 on April 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we prepare information security executives and incident responders for ransomware by running a live simulation of a corporate ransomware crisis. You will be presented with an unfolding cyberattack scenario, confronting you with critical decisions ranging from the C-Level to the SOC manager level. We will then shift gears to the cyber range, which will emulate a real-world SOC and demonstrate how IR experts can successfully investigate and eradicate a ransomware attack. The session will combine the C-level, decision-making challenges encountered in a ransomware crisis with a hands-on, ransomware investigation simulated in a cyber range. The simulation allows you, as the audience, to impact the flow of the scenario by providing your suggested actions while our experienced instructor will provide you with helpful tips.
In the last year alone, the number of supply chain attacks has grown exponentially as they offer threat actors stealthy, scalable, and privileged access to your organization’s on-premises, cloud, and hybrid environment. Addressing supply chain attacks requires a multi-layered defense strategy in which third-party integrations are audited, endpoints are monitored for post-compromise actions, and an Incident Response plan that considers supply risks is put in place to minimize the overall impact to your organization. On May 10, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and Sumo Logic share insights from original threat research and supply chain attacks to demonstrate how multi-signal investigations can effectively secure your organization against supply chain attacks. Key takeaways from the webinar include: • The three primary attack vectors that cybercriminals rely on to launch supply chain attacks against organizations • The challenges that organizations face related to supply chain risk (e.g., technical complexity, access requirements, stealth of cyberattacks) and how they impact business operations • Tactical and high-level strategic recommendations on how your organization can minimize supply chain risk and reduce the attacker dwell times and impact • How 24/7 log monitoring and management can improve cyber resilience and prevent zero-day threats • A case study on how original research and curated threat intelligence conduct stronger post-exploitation investigations.
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
Cybersecurity teams are fighting a losing battle trying to keep up with complex business requirements and the expanding attack surface. Although traditional security controls and MSSPs (managed security service providers) were once effective, they are no match for the growing speed and sophistication of modern threats. Unfortunately, you can’t protect your organization from cyber threats if you don’t have complete visibility across your attack surface. Even if your team utilizes a global threat hunting and threat intelligence team, they must be armed with data correlation and contextualization capabilities across multiple signals (e.g., endpoint, log, network, cloud) to effectively contain and remediate advanced persistent threats. Join eSentire and (ISC)² May 19, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific to hear how threat intelligence teams can use data from multiple signal sources for enhanced threat detection, investigation, and response. Learn more about: • What multi-signal data correlation and contextualization means in the context of threat intelligence and threat hunting • Mapping tactics and techniques threat actors use to fulfill their objectives back to each phase of the overall attack workflow • Deep dive into how eSentire’s Threat Response Unit (TRU) used data from log, endpoint, and network to build detection content for threats like Log4j and Cobalt Strike • How threat intelligence teams can adopt a multi-signal approach to enrich their detection engineering content
As the old adage goes “an ounce of prevention is worth a pound of cure.” A holistic application security (AppSec) program is essential for validating your applications’ security. AppSec experts perform a variety of security assessments that identify your software’s flaws and vulnerabilities. These bugs are then prioritized for remediation according to their severity and in accordance with your unique risk profile. In this webinar May 24, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Synopsys and (ISC)² will focus on how you can mature your AppSec program with the Payment Card Industry Data Security Standard (PCI DSS) in mind. You will learn how to • Establish an AppSec program that meets or exceeds PCI requirements • Leverage the OWASP and NIST frameworks • Perform thorough code review, pen testing, and vulnerability assessments
Denial of service attacks became larger and more complex in 2021 with peak attack bandwidth now more than five times larger than it was in 2020. From disgruntled customers, to organized cybercrime and even modern day cyber warfare, DDoS attacks are still a go-to for many threat actors with effects of successful denial of service attacks ranging from temporary disruption of an online event to outages of critical infrastructure. Increasingly, DDoS attacks also used by cybercrime gangs to coerce payments of ransomware demands. While DDoS mitigation services are getting better at deflecting large volumetric DDoS attacks, the shift in tactics to focus on protocol and application DDoS makes mitigation a more complex task. On June 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and F5 Labs discuss the F5 DDoS Trends report which analyzed thousands of attacks over the past two years to uncover how DDoS attacks are changing. We will showcase which industry sectors are most frequently attacked, which suffer the largest and most complex attacks, and some of the relevant security controls which can be employed to counter the growing threat. Join this webinar to learn: -What the most common forms of DDoS attacks are -Which industries are most effected -How attackers are building botnets and changing tactics -How to use the MITRE ATT&CK framework to map effective security controls
Maintaining security consistency across our own data center and public cloud environments, along with the use of multiple cybersecurity controls are major challenges that organizations face today that not only increase costs and complexity, but also create silos, leaving major security gaps. Join Doug Cahill, VP of Analyst Services and Sr. Analyst at ESG, and David Puzas, Sr. Product Marketing Manager at CrowdStrike in a webcast discussion. This CrowdCast will cover: • Current security challenges • The different attack types • How to leverage visibility and threat intelligence to achieve security consistency from endpoint to workloads, and everywhere in between
Identity is the front line in the battle against modern cyber threats. Nearly 80% of cyberattacks leverage compromised credentials to gain access and evade detection. These attacks often come in via unmanaged or rogue endpoints, legacy systems, supply chain vendors or other attack vectors that are outside the scope of endpoint-centric security controls. Join CrowdStrike experts as they will unpack the current state of identity-based threats and how Falcon Complete managed detection and response is changing the game for security teams. In this webcast, you’ll hear: • Insights from Falcon OverWatch elite threat hunters, who’ll share trends and stories about how today’s attackers are obtaining and abusing credentials, and. blending in with day-to-day activity • How the Falcon Complete team of security analysts are leveraging identity threat protection to keep ahead of the evolving threats • Guidance you can use to protect your own organization from identity-based threats
Having a strongly aligned and integrated ecosystem of cyber tech and tools is required to protect and preserve the business in today’s digital infrastructures. Over the last several years, more and more traffic has migrated from plaintext protocols to encrypted protocols. While this provides better privacy and security, it also makes it more difficult to troubleshoot this traffic when problems inevitably arise. Although security and network monitoring tools can still analyze some encrypted traffic without decryption, lots of details cannot be analyzed adequately. This session, sponsored by Netscout and hosted by (ISC)² on July 26, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, will show how integrating decryption with NDR solutions can provide an even more robust monitoring experience. To further the dialogue regarding a healthy cybersecurity solution ecosystem, this session will also explore the critical aspects to integrating NDR with EDR, SIEM and SOAR technologies.
Cyberattacks continue to challenge many organizations. With a growing attack surface, limited access to expensive security talent, frustration with managed security service providers (MSSPs), and constrained budgets, leading security and IT leaders are looking for alternatives like managed detection and response (MDR) services to help reduce their risks. There are many options for security service providers, and with all the options, it may be hard to choose the best for your needs. Join Pondurance’s Chief Strategy Officer, Lyndon Brown, as he clears the fog around MDR and will discuss: -The biggest cybersecurity challenges for mid-market and enterprise organizations. -The difference between a SIEM, MSSP, XDR, MDR and Modern MDR Components of MDR and how to choose the right provider for your organization.
The Manufacturing industry is one of the most highly targeted industries, both from a nation state and ecrime perspective. The often-critical nature of manufacturing operations and the valuable data that many manufacturing businesses hold make them an enticing target for adversary groups seeking to extract value and further their strategic objectives. Join us for this session with Scott Jarkoff, CrowdStrike’s Director, Strategic Threat Advisory Group for APJ & EMEA where he will discuss trends across 2021 and attacks targeting manufacturing, as well as ways to proactively defend your mission critical assets from being breached. Agenda: - Introductions - Manufacturing at a glance - Adversaries & Threat trends - The Emerging Threat
Découvrez les composantes essentielles d'une cyberdéfense efficace et comment offrir une protection optimale à votre entreprise. Faire la une des journaux à la suite d'une cyberattaque de grande envergure n'est pas un sort réservé aux grandes entreprises. Les petites et moyennes entreprises sont elles aussi dans la ligne de mire des cyberadversaires. En effet, leurs défenses étant souvent plus fragiles, elles constituent des cibles de choix pour les ransomwares et autres menaces avancées. Ce webcast explique comment assurer la protection de votre PME, même si vous n'avez pas d'équipe de cybersécurité à disposition. Fabrice Elzière, Manager Sales Engineers de CrowdStrike passera en revue les cybermenaces qui visent les PME en s'appuyant sur des cas clients concrets. Il détaillera également les composantes essentielles d'une cyberdéfense efficace et vous donnera quelques conseils pratiques pour protéger au mieux votre entreprise. Au sommaire de ce webcast: Les mythes les plus courants en matière de cybersécurité concernant les PME Cas concrets de cyberintrusions et comment celles-ci auraient pu être évitées Structure de base d'un programme de cybersécurité efficace (techniques de prévention de nouvelle génération, chasse aux menaces, investigations et intervention en temps réel) Comment, en tant que petite entreprise, utiliser les services managés pour détecter, bloquer et neutraliser les cyberattaquants déterminés, sans avoir à élaborer et gérer un programme de cybersécurité
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.