Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Exam prep
Exam-prep training that counts toward Security+ renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 50 CEUs Security+ requires every 3 years — without re-keying each entry into CompTIA's portal.
87 results mapped to Security+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
Firewalls, VPN concentrators, IDS/IPS, load balancers, etc., all have one thing in common. They are stateful devices. That makes them very susceptible to DDoS attacks – more specifically, state exhaustion attacks. To protect these devices from DDoS attacks, you need dedicated, stateless DDoS attack protection technology deployed in front of your stateful infrastructure. Join Netscout and (ISC)2 on December 6, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we examine: · Why stateful devices like firewalls are susceptible to DDoS attacks. · Why industry best practices (and firewall vendors) suggest deploying stateless DDoS protection in front of your firewall to protect it and other stateful devices. · How and why organizations should prepare and defend around the first and last line of network perimeter defense to protect the availability and performance of firewalls and other stateful infrastructure from cyber threats.
Did you know that 86% of organizations experienced a successful attack in 2021? Up from 81% the prior year, the largest year-over-year increase in six years. CyberEdge’s 2021 Cyberthreat Defense Report (CDR) has become the de facto standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals, and for ascertaining current and planned investments in IT security infrastructure. Now in its eighth year, the 2021 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on May 11, 2021 at 1:00 pm ET/10 am PT for highlights of the results and get key insights including: - The chronic shortage of IT security skilled staff is still prevalent; hiring gaps exist across all major IT security roles - Lack of skilled personnel is the #2 obstacle to effective defense against cyberthreats - The fastest and most economical solution is to train existing IT members to fill security positions - IT security professionals see personal and organization-wide benefits of cybersecurity certifications, especially for cloud security, software security, security administration, and management - And more!
No doubt, you’ve seen it, the threat landscape is evolving year over year. How do you fine tune your defenses against an ever-changing adversary? On August 18, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific join F5 Labs and (ISC)² for a multifaceted analysis of the application security threat landscape based on F5 Labs’ 2022 Application Protection Report. The report analyzes nearly 1,000 data breaches from 2021, focusing on three specific threats: ransomware, which played a role in nearly half of the successful attacks in 2021; formjacking attacks like Magecart; and data exfiltration, which was featured in nearly 80% of breaches. F5 Labs and will share additional perspectives of the threat landscape, with a look at cloud risks, cryptocurrency theft, and some case studies about well-resourced attackers. The session will conclude with recommended best practices using prioritization methods for different scenarios.
The OWASP® Foundation works to improve the security of software through its community-led open source software projects and is the de facto authority on bots and malicious automation. Join this webinar to dive into the OWASP Automated Threats (OAT) project and get important guidance that you can immediately put into practice. We will dive into the ontology and countermeasures of the OAT, discuss example scenarios, and get real on some widely deployed security controls (apologies in advance to any CAPTCHA fans). Learn the importance of mitigating attacks like credential stuffing, which is a part of the OWASP Automated Threats project, and is a top software security risk as detailed in the OWASP Top 10.
Nearly 70% of organizations host more than half their workloads in the cloud, which has more than doubled since 2020. There’s a dangerous pothole on the fast track to cloud migration, and it grows larger the longer it’s ignored: application development security. The good news is that wherever you are on the journey, you can rethink your cloud native development strategy and confidently steer clear of damage. Our webinar “Top 5 Cloud-Native Risks” is a smart place to start. Join Palo Alto and (ISC)² September 8, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to see the latest research, insights and recommendations from pros in security, DevOps technical, and line of business leadership. Learn how to balance the benefits of cloud native development with new best practices for protecting applications, and ensure that your environment stays resilient, flexible and secure.
Cybercriminals use an ever-increasing array of DDoS attack vectors to target business and governments. Today, the question isn’t if, but when, you will be a target. Knowing your adversary's latest tactics and techniques are key to your defense. Join NETSCOUT and (ISC)² to explore the findings and trends from the latest NETSCOUT DDoS Threat Intelligence Report. • Global and regional DDoS attacks stats (e.g. size, frequency, vectors.) • How attackers are getting more sophisticated in their DDoS attack techniques, and the most common attack vectors. • The relationship between DDoS attacks and geopolitical events. • The increasing number and size of botnets that are being used to launch DDoS attacks. • Best practices in DDoS attack defense and suppression.
The pace of new software releases has grown rapidly since the shift to DevOps, which in turn has created a dynamic attack surface in need of immediate protection: the development environments in your software supply chain. Attackers are compromising your source code management systems, build servers, and artifact registries in your CI/CD pipelines. As seen in the recent LastPass security incident, a compromise of one development system led to business interruption and the exfiltration of LastPass’s source code and proprietary data. Join Legit Security and (ISC)² October 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we discuss techniques you can use to effectively harden your developer environments. In this webinar you will also learn: • How to prevent your business from falling victim to the type of attack that recently compromised LastPass • Methods for security practitioners to secure decentralized developer environments at scale • Best practices to reduce the likelihood of lateral movement in the event of a compromised developer environment
Today, web apps and APIs are the most common medium for sharing and modifying data. The boom in cloud-native architecture has led to increased economies of scale and the ability to speed the delivery of services like never before. But as web applications continue to evolve, so does your attack surface, creating new complexities and vulnerabilities. The bottom line: If you’re not protecting your web apps and APIs, you’re not adequately protecting your valuable data. So what do you do? Join Palo Alto and (ISC)² November 3, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific to learn 5 best practices to help you secure your critical web applications, APIs and ALL data on ANY cloud-native architecture.
DDoS (distributed denial of service) attacks continue to increase in frequency and sophistication as attackers innovate with new adaptive DDoS attack tactics and techniques. Dive into NETSCOUT’s latest DDoS Threat Intelligence Report that reveals multiple noteworthy findings and trends followed by a simulated DDoS attack against stateful devices. Join NETSCOUT and (ISC)2 on December 1, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific us as we explore the report and recommend best practices in adaptive DDoS defense: - Global and regional DDoS attack stats and trends. - DDoS attacks are increasing being linked to worldwide geopolitical events (e.g., the Russian-Ukraine war.) - Attackers are conducting more pre-attack reconnaissance to determine attack vectors, avoid detection, and maximize impact on targets. - Attackers are moving away from reflection/amplification attacks towards direct path, state exhausting attacks that target stateful devices like firewalls and load balancers.
Join us for a deep dive into Certified in Cybersecurity (CC), the new entry-level credential from (ISC)², creator of the CISSP®. Cyberthreats continue to escalate worldwide, and the need for cybersecurity experts is critical. But talent is scarce. Research shows the workforce needs an influx of 3.4 million cybersecurity professionals to meet global demand. (ISC)² seeks to help close the skills gap with CC by opening opportunities in the industry to a new pool of professionals. With no experience required, it creates a clear pathway and breaks down traditional barriers to entry, enabling candidates to build confidence and enter their first cybersecurity role ready for what’s next. You’ll learn about: • Career opportunities in cybersecurity • Recommended core skills • Three ways to train for the exam • What to expect on exam day • And much more! Save your spot now. Presenters: Adesoji Ogunjobi, CISSP-ISSAP, CCSP, CSSLP Chad Kliewer, CISSP-ISSMP, CCSP, Professional Development Content Manager, (ISC)² Janet Gray, CC Moderator: Brandon Dunlap
Join us for a deep dive into Systems Security Certified Practitioner (SSCP), the security operations and network security credential from ISC2, creator of the CISSP. As organizations continue to pursue digital transformation initiatives, the threat landscape is always expanding. Yet cybersecurity leadership talent is scarce. That’s where SSCP from ISC2 comes in — to help fill the gap. Once certified, the opportunities for certified professionals are near limitless. The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It shows you have the advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures. In this 60-minute live virtual session, you’ll learn: - If SSCP is right for you - How Official ISC2 Training flexes with your learning style - What to expect on exam day - How to become endorsed and maintain your certification - Plus, more! Plus! Get answers to your SSCP questions during the Q&A section. Register now and begin your SSCP certification journey today!
Discover the integrated approach to network security and efficiency in our upcoming webinar, where we unravel the synergy between Security Service Edge (SSE), Software-Defined Wide Area Network (SD-WAN), and Secure Access Service Edge (SASE). This session will illuminate how the convergence of these technologies creates a robust, scalable, and agile framework for businesses navigating the complexities of digital transformation. Join HPE and ISC2 as we discuss practical insights on leveraging SSE and SD-WAN as foundational blocks to transition towards a comprehensive SASE model, ensuring end-to-end security and optimal network performance. This webinar will provide actionable strategies to enhance your business’s security posture and network management in the cloud era.
It is difficult to go anywhere in the security profession these days without the topics of artificial intelligence (AI) and API Security coming up. Like many popular topics, there is quite a bit of buzz and hype which creates quite a bit of fog around the topics. In particular, it can be difficult to understand when AI can add value. How can we know when AI is being leveraged in a useful way to creatively solve problems? AI works best when applied to specific problems and needs to be carefully, strategically, and methodically leveraged in order to tackle certain problems that suit it. While there are many such problems, API security is one such problem that I’ve experienced AI producing good results for. Join F5 and ISC2 April 11, 2024 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a session on applying AI to API Security. We'll also share 10 best practices around API Security that you won’t want to miss!
A record 73% of organizations were compromised by ransomware last year. However, the percentage of respondents who expect a successful cyberattack in the coming year declined by 4%, from 76% to 72%. Has cybersecurity turned a corner? CyberEdge’s Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its tenth year, the 2023 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join ISC2 (a sponsor of this year’s study) and CyberEdge for highlights and key insights of the results, including: • 85% of organizations suffered at least one successful cyberattack last year • Double and triple extortion ransomware attacks are now the norm • Overall concern for cyberthreats ticked down for the second straight year, the first multi-year decline in CDR history
The 2022 cyber threat landscape was one of persistence, increased scope, and relentless determination. As businesses began to ease pandemic-driven operating environments and adjust to geopolitical shifts—as well as growing economic hardships—adversaries supporting nation-state, eCrime, and hacktivist motivations started the year with a relentless show of effort that ultimately defined 2022. Join CrowdStrike and (ISC)2 March 23, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific for an in-depth review of how the cyber threat landscape has evolved over the last year, including notable threats, events and trends outlined and explained in the CrowdStrike 2023 Global Threat Report. In this session, we’ll discuss: • The most relevant threat issues that organizations face today • New adversaries uncovered in 2022 and their growing speed and sophistication • Useful best practices in how you can combat the modern-day threat
Cybercriminals continue to rely on proven attack methods while developing new ways to infiltrate digital environments and break through your human defense layer. But how can you reduce your organization’s attack surface? KnowBe4 looked at 12.5 million users across 35,681 organizations to find out. In this webinar on July 13, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific, KnowBe4 and (ISC)2 take a look at the 2023 Phishing By Industry Benchmarking Study findings and best practices. You will learn more about: • New phishing benchmark data for 19 industries • Understanding who’s at risk and what you can do about it • Actionable tips to create your “human firewall” • The value of new-school security awareness training Do you know how your organization compares to your peers? Watch this webinar to find out!
The Domain Name System (DNS) is essentially the central nervous system of the internet—everyone needs it to work because without DNS services, digital business could come to a halt. Cybercriminals know this too, and exploit DNS services to launch their attacks while simultaneously attacking the DNS services of their targets. Therefore, it’s not only important to protect your organization’s DNS service, but also to use the data available from DNS services to more rapidly detect and surgically block threat activity such as phishing, DNS tunneling-based data exfiltration, and ransomware. On March 2, 2023 join Infoblox and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear best practices for an effective DNS security architecture.
The ransomware scourge continues to plague the cybersecurity industry. To help ensure you and your company are better prepared, we will share insights and lessons learned from ransomware case studies. In this session, on September 12, 2023 at 1:00 p.m./ 10:00 a.m. Pacific IANS and (ISC)2 will lead you through: • What went right (and wrong) in these examples and how best to incorporate that experience into your defenses and program • Threat actor behavior and how to take advantage of their internal processes to thwart them • TTPs used in various ransomware operations • Alert monitoring – from investigating to remediating • The reality and best practices around backups and recovery
Microsoft 365 is a mission critical tool for organizations facilitating global collaboration, remote work, and cloud computing. While Microsoft provides native email security capabilities via Exchange Online Protection (EOP) and through additional security tools like Microsoft Defender for Office 365, organizations needs to augment these defenses in order to protect against modern sophisticated email threats such as business email compromise (BEC), advanced phishing, and account takeover. With over 88% of productivity software market share, Microsoft is the primary target of choice for threat actors. In 2022, cyber criminals sent more than 30 million messages that abused the Microsoft brand and products. On September 21, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific join Proofpoint and ISC2 for a live webinar with threat experts and learn how to break the attack chain and stop advanced email threats. Join the webinar to hear: • Why threat actors are targeting your Microsoft 365 environment • Why industry analysts recommend supplementing native Microsoft 365 capabilities • What key areas you need to augment in your Microsoft 365 platform • Best practices for strengthening your Microsoft 365 security.
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.