Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Exam prep
Exam-prep training that counts toward Security+ renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 50 CEUs Security+ requires every 3 years — without re-keying each entry into CompTIA's portal.
114 results mapped to Security+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
Since the initial disclosure of Log4j, the OverWatch team, CrowdStrike’s elite team of threat hunters, has maintained around-the-clock vigilance, tracking the evolution of the Log4j threat, and developing techniques to uncover stealthy attempts to exploit it. Join our OverWatch experts for a summary of the team’s threat hunting insights. You’ll get a real-world view from the experts on the front lines and gain insights you can use to kickstart your own Log4j threat hunting efforts. Join this CrowdCast to hear more about: • A look at the Log4j vulnerability through the eyes of elite threat hunters • Case studies providing insights into how adversaries are carrying out their campaigns in the wild • Ideas for suggested threat hunting techniques you can put into action in your own environment
The COVID-19 pandemic has caused dramatic increases in remote workforces and BYOD policy adoptions, making it more challenging than ever to secure company applications and data. Now that organizations have increased their remote access capacities, it’s now time to explore ways to help secure these remote managed and unmanaged devices to help mitigate the elevated risks of ransomware, data breaches, and other cyberattacks. Join Steve Piper, Founder & CEO of CyberEdge (and proud CISSP), as he: - Recaps key findings from a recent COVID-19 impact study - Examines the challenges facing today’s IT security teams - Suggests ways to invest more in your human firewalls - Explores current and emerging security technologies
Did you know that 81% of organizations reported that they suffered a successful cyber-attack in 2019? CyberEdge’s 2020 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. The 2020 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 12, 2020 at 1:00PM Eastern for highlights of the results and get key insights including: A record 62% of organizations were compromised by ransomware last year 58% of ransomware victims paid ransoms last year, but a third failed to recover their encrypted data Malware, spear-phishing, and ransomware cause the most headaches while zero-day attacks are of least concern Lack of skilled personnel and low employee awareness inhibit IT security’s success 85% of organizations are experiencing a shortfall of skilled IT security personnel
Ransomware attacks are a lucrative business for threat actors. These attacks create chaos to organisations, and cause a rippling effect to their customers, or even worse, critical infrastructure or supply chains. Let’s unite to study these adversaries, their tactics, and learn from front line responders how you can best defend, respond, and recover from a ransomware attack. Please join CrowdStrike to deep-dive into active and notorious eCrime actors in the Ransomware space CrowdStrike tracks as Wizard Spider, Carbon Spider, and Pinchy Spider.
Firewalls, VPN concentrators, IDS/IPS, load balancers, etc., all have one thing in common. They are stateful devices. That makes them very susceptible to DDoS attacks – more specifically, state exhaustion attacks. To protect these devices from DDoS attacks, you need dedicated, stateless DDoS attack protection technology deployed in front of your stateful infrastructure. Join Netscout and (ISC)2 on December 6, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we examine: · Why stateful devices like firewalls are susceptible to DDoS attacks. · Why industry best practices (and firewall vendors) suggest deploying stateless DDoS protection in front of your firewall to protect it and other stateful devices. · How and why organizations should prepare and defend around the first and last line of network perimeter defense to protect the availability and performance of firewalls and other stateful infrastructure from cyber threats.
Did you know that 86% of organizations experienced a successful attack in 2021? Up from 81% the prior year, the largest year-over-year increase in six years. CyberEdge’s 2021 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. Now in its eighth year, the 2021 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 11, 2021 at 1:00 pm ET/10 am PT for highlights of the results and get key insights including: - The chronic shortage of IT security skilled staff is still prevalent; hiring gaps exist across all major IT security roles - Lack of skilled personnel is the #2 obstacle to effective defense against cyberthreats - The fastest and most economical solution is to train existing IT members to fill security positions - IT security professionals see personal and organization-wide benefits of cybersecurity certifications, especially for cloud security, software security, security administration, and management - And more!
Today’s network environment can feel like a Cold War-era novel, full of who’s watching whom scenarios and heavily protected intelligence communications. Visibility is critical to an organization’s security posture, and encrypted channel communications can become an obstacle to it when gets to the wrong eyes. Decryption can illuminate what is hidden and restores the advantage you need to see what’s lurking in the shadows. Join Gigamon and (ISC)2 on September 5, 2019 at 1PM Eastern for an examination of decryption best practices, a review of encryption methodologies, the obstacles that impact security, resources and regulatory compliance and what’s changed with TLS 1.3 and how this newer protocol impacts visibility.
It's now widely recognized that traditional security solutions are insufficient to protect organizations from advanced threats and targeted attacks. To fight back you need your own unified plan of attack so that you can better sense malicious activity and take preventive action that will crush attackers and keep your environment safe Join Brett Williams, Senior Security Engineer for Carbon Black on March 23, 2016 at 1PM (GMT+8; Hong Kong, Singapore, Beijing) for an overview of how organizations are moving from a passive to proactive defense on the end point. This webinar will cover: * End point security challenges organizations face today * Why using a trusted security model on the endpoint is essential * The importance of choosing the right solution and integration with your existing security investments * Example of Ransomware detection and protection using proactive defense. * Best practices learned from successful deployments
Though most reporting on cyberattacks focuses on the impacts to large companies, the truth is that small businesses are not immune. eCrime groups know that small businesses rarely have the resources to defend themselves in the same way as large enterprises, which can make them lucrative targets for ransomware and cyber extortion. The threats are real, and the days of protecting your organisation with simple antivirus and a firewall are gone. What can you do when you lack a full staff of cybersecurity experts to defend your business? In this webinar, CrowdStrike’s Patrick Magat will: - Examine the cyber threats that target small businesses. - Share real-world examples plucked from the CrowdStrike case files. - Advice on how to build the blocks of a successful cyber defence. - Practical guidance for defending your business.
NOWHERE TO HIDE: KEY INSIGHTS FROM CROWDSTRIKE'S FALCON OVERWATCH TEAM Insights from the CrowdStrike OverWatch Threat Hunting Team [Americas] Falcon OverWatch™, CrowdStrike’s elite team of threat hunters, has the unparalleled ability to see and stop the most sophisticated threats, leaving adversaries with nowhere to hide. Join our OverWatch experts for a summary of the team’s threat hunting insights from the last 12 months. They’ll review intrusion trends, share insights into current adversary tactics and deliver highlights of notable intrusions identified by expert OverWatch threat hunters. You’ll get a real-world view from the experts at the front lines and gain insights that can inform your security strategies in the months ahead. In this webcast, you will hear: • A new look at the most common tactics, techniques and procedures (TTPs) used by adversaries, as well as those OverWatch believes defenders should have on their radar. • An analysis of intrusions by vertical — including a special focus on the telecommunications vertical, which saw intrusions double this past year. • Detailed case studies providing insights into how adversaries are carrying out their campaigns in the wild. • Recommendations for defenders looking to better protect their organization from current and emerging threats.
Account Takeover (ATO) attacks are on the rise. Not only are they hard to detect, they have consequences far beyond compromised PII and stolen goods. Stopping such ATO attacks is critical for any company engaged in online commerce. Join PerimeterX and (ISC)2 on May 7, 2020 at 1:00PM Eastern time as we highlight the top five ways to identify automated bot attacks to your website. We’ll cover: ● Real use cases - attacks that happened in the real world ● Practical strategies for identifying automated attacks ● Best practices for addressing and blocking bot attacks ● ATO attack trends during COVID19 pandemic
The financial losses associated with Business Email Compromise (BEC) and Email Account Compromise (EAC) continue to rise. The FBI reported losses of almost $1.7B in 2019 alone. While BEC and EAC start to become one of CISO’s top concerns, there are still a lot of confusion regarding the terms. In addition, many organizations are struggling to identify the scope of the problem regarding BEC/EAC. So how can you better manage this billion-dollar problem in your organization? Join Proofpoint and (ISC)2 for a deep dive into how best manage the BEC and EAC issues and problems they can bring. We’ll discuss: - What is BEC and EAC - What do they have in common and how are they different - Why is it difficult to prevent BEC/EAC - What are the best practices to help you mitigate BEC/EAC risks
Cyberattacks continue to threaten online digital experiences. Automated bots and compromised third-party code outsmart existing defenses and compromise the integrity of your websites and mobile apps. This impacts an organization’s ability to be effective in conducting and securing online business. In this webcast, we’ll examine the top five security threats to online business, how to stay ahead of these attacks and proactively address client-side vulnerabilities and the practical strategies needed to protect customers, online revenue and company reputation.
The future of work remains unpredictable and uncertain. More than ever before, business leaders need to remain confident that their operations can continue securely. However, 94% of cyber-threats still originate in the inbox, and ‘Impersonation attacks’ that expertly mimic the writing style of trusted contacts and colleagues are on the rise. Humans can no longer distinguish real from fake on their own – businesses are increasingly turning to AI to distinguish friend from foe and fight back with autonomous response. . Join Darktrace and (ISC)² on September 24, 2020, at 1:00 p.m. Eastern for expert insight into how cyber AI is the only tool that can keep pace with the rapidly evolving threat landscape facing organization’s inboxes every day. The webcast will examine: · Exploration of the most recent email threat trends and statistics · Overview of Darktrace’s latest developments to secure the email environments of the dynamic workforce · Case studies and use cases from industry leading customers
Security teams face increasing challenges from lack of visibility, complex solutions and sophisticated attacks. CrowdStrike can help organizations achieve visibility across their entire AWS footprint, while securing their workloads and leveraging automation best practices for scale, consistency and speed. Key Takeaways: - How CrowdStrike integrations with AWS solutions can help organizations - Where CrowdStrike and AWS work together - The Shared Responsibility Model - Resources to get started with CrowdStrike and AWS today
Ransomware attacks are a lucrative business for threat actors. These attacks wreak havoc on organizations, and cause a rippling effect to their customers, or even worse, critical infrastructure or supply chains. Please join CrowdStrike to deep-dive into active and notorious eCrime actors in the Ransomware space CrowdStrike tracks as Wizard Spider, Carbon Spider, and Pinchy Spider. Study these adversaries, their tactics, and learn from front line responders how you can best defend, respond, and recover from a ransomware attack. This webinar will be delivered by CrowdStrike security experts. This experienced team will discuss: • Briefing of eCrime actors Wizard Spider, Carbon Spider, and Pinchy Spider • How CrowdStrike Incident Response (IR) and Endpoint Recovery Services (ERS) optimize a ransomware investigation, getting you secure and back to business faster • Ransomware preparation – best practices for an organization’s Business Continuity, Disaster Recovery, and IR planning
With the increased adoption of cloud across nearly every industry, security teams must do more with less and adapt to new infrastructure technologies and threats. Add to that, the growth in organisations moving to DevOps to accelerate app deployment, many security teams have chosen to take a “shift left” approach to improving the security posture of applications throughout the CI/CD pipeline. In theory it means shifting responsibility for security and compliance to developers. In practice, it means enriching CI/CD processes to detect threats and vulnerabilities before they reach production. Although these improvements have improved protection of apps, security is still too often overlooked and addressed only at runtime. Join this webinar roundtable to see how you can incorporate comprehensive security throughout your entire CI/CD pipeline. You’ll hear from industry experts as they discuss - How security teams can enable DevOps teams with the tools needed to add security into the CI/CD pipeline. - The benefits of scanning IaC templates (Terraform® and AWS CloudFormation™) - How to improve the security posture of cloud native apps through continuous CI/CD security including container images and registries in the build-and-deploy phase. - And how to best instill a culture of DevSecOps
Before the rise of cloud computing, enterprises could expect to be responsible for securing the systems in their data centers, their applications — everything. Because of the complexities of the threat landscape and organizational environments, security and DevSecOps teams have struggled to stay ahead. Today, more and more organizations are migrating systems in part or wholly to the cloud, and cloud service providers are ready, willing and able to ease the security burden through the shared responsibility model. We welcome you to come learn the best practices for securing your cloud in this CrowdCast with CrowdStrike and AWS. Attend this webcast to: • Understand the composition of cloud environments and the technologies that are driving adoption • Take a deep dive into the challenges of moving to the cloud and having a cloud infrastructure • Learn key best practices to secure your organization’s public cloud platforms • Find out how automation of DevSecOps processes and controls can help keep pace with the security you need
No doubt, you’ve seen it, the threat landscape is evolving year over year. How do you fine tune your defenses against an ever-changing adversary? On August 18, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific join F5 Labs and (ISC)² for a multifaceted analysis of the application security threat landscape based on F5 Labs’ 2022 Application Protection Report. The report analyzes nearly 1,000 data breaches from 2021, focusing on three specific threats: ransomware, which played a role in nearly half of the successful attacks in 2021; formjacking attacks like Magecart; and data exfiltration, which was featured in nearly 80% of breaches. F5 Labs and will share additional perspectives of the threat landscape, with a look at cloud risks, cryptocurrency theft, and some case studies about well-resourced attackers. The session will conclude with recommended best practices using prioritization methods for different scenarios.
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.