Welcome to RecertHero!
Submit bugs, feature requests, and feedbackCompTIA · Free
Free continuing-education opportunities that count toward Security+ renewal — vendor webinars, community talks, and free courses. RecertHero estimates the CEU value of every opportunity, so you can plan toward the 50 CEUs Security+ requires every 3 years — without re-keying each entry into CompTIA's portal.
237 results mapped to Security+, soonest first.
According to Ponemon's 2022 Cost of Insider Threats Report, insider threats cost organizations $15.4 million, up 34% from 2020 and have increased in frequency by 44% in the same period. Insider risk and data loss prevention (DLP) are a top concern for organizations today. And it makes sense, with a distributed and revolving workforce, and increasing reliance on technology. That’s because data loss begins with people, whether careless, compromised, or malicious insiders. So how do you better protect your organization? Join Proofpoint and (ISC)2 on March 10, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for a lively discussion on why organizations need to take a modern, people-centric approach that provides visibility and context into content, user behavior, and threat insights - to help you to mitigate this risk. We’ll also examine: • The importance of looking beyond only content awareness to understand people risk • How to better understand and respond to people-led data breaches • Real-world examples of insider threat scenarios • Best practices to improve your data and user security
Last year was a record-breaking year for data breaches. What can we learn from this growing trend? On March 17, 2022 at 1:00 p.m. Eastern/10:00 am Pacific join F5 Labs and (ISC)² as they share findings in a hot-off-the-presses report exploring those trends. This discussion will analyze the continuing growth of malware, the threat that Magecart and similar web attacks pose to e-commerce, business email compromise, and more. As in the 2021 report, they will use MITRE’s ATT&CK framework to visualize attack chains at large scale to explore the relationships between attacker behaviors. The talk will conclude with a discussion of different mitigation strategies so that organizations can tune their defenses to adapt to the latest in attacker trends.
Zero-day exploits serve as a master key for cybercriminals to launch crippling cyberattacks which are only increasing in frequency. In fact, research from Google's Project Zero shows that as of November 2021, a total of 57 zero-day exploits in the wild have been discovered, compared to an average of 22 exploits in past years. In the past year, eSentire’s Threat Response Unit (TRU) detected and responded to a significant increase in zero-day exploit activity in client environments that included defending against critical Exchange vulnerabilities ProxyLogon, ProxyShell, the REvil attack against Kaseya and most recently, mass exploitation of Log4j vulnerabilities. Join eSentire and (ISC)2 on March 22, 2022 at 1:00p.m. Eastern/10:00a.m. Pacific as key findings from new research on zero-day attack patterns are shared including how to triage vulnerabilities, and the response capabilities needed to effectively tackle future zero-day attacks. We’ll also examine: • Factors contributing to the rise of zero-day attacks • Notable Vulnerability analysis of SolarWinds, ProxyLogon, ProxyShell, and Kaseya VSA • Opportunity windows for zero-day exploits (n-day attacks) • Recommendations on how you can defend against zero-day exploits
For security teams on the front lines and those of us in the business of stopping breaches, 2021 provided no rest for the weary. In the face of the massive COVID-driven social, economic and technological shifts of 2020, adversaries again refined their tradecraft to become even more sophisticated and brazen. Understanding the 2021 dynamics of adversary tactics is critical for staying ahead of today’s threats. This is the context that the CrowdStrike 2022 Global Threat Report delivers. Join this webinar featuring CrowdStrike Director of Strategic Threat Advisory Group, Jason Rivera, as he examines the notable threats, events and trends in the 2022 report. Receive pragmatic recommendations to help you better defend against cyberattacks in 2022 and beyond.
Phishing attacks have come a long way from the spray-and-pray emails of just a few decades ago. Now they’re more targeted, more cunning and more dangerous. And this enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Join (ISC)² and KnowBe4 March 31, 2022 at 1:00 p.m., Eastern and 10:00 a.m. Pacific to hear Roger Grimes, KnowBe4’s Data-Driven Defense Evangelist, share a comprehensive strategy for phishing mitigation. With 30+ years experience as a computer security consultant, instructor, and award-winning author, Roger has dedicated his life to making sure you’re prepared to defend against ever-present IT security threats like phishing. In this webinar you’ll learn: How to develop a comprehensive defense-in-depth plan for phishing mitigation Ideas for security policies you can implement now Technical controls all organizations should consider Gotchas to watch out for with cybersecurity insurance Why it’s critical to develop your organization’s human firewall
As of July 31, 2021, the FBI’s Internet Crime Complaint Center saw a 62% increase in reported ransomware incidents and a 20% increase in reported losses, compared with the same time frame in 2020. Ransomware is a masterful crime that cybercriminals cannot get enough of and organizations continue to be ever more challenged by this reality. However, ransomware does not appear out of thin air. Join Lumu Technologies and (ISC)2 on April 7, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we take a deep dive into: - The vicious cycle that enables complex ransomware schemes. - The common denominators of ransomware incidents. - Practical advice to stop ransomware in its tracks regardless of your vertical or resources. - Best practices on containing its impact via real-life examples.
No matter how much security technology we purchase, we still face a fundamental security problem: people. This (ISC)² and KnowBe4 webinar will explore the different levers that social engineers and scam artists pull to make us more likely to do their bidding. On May 5, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific, join Erich Kron, Security Awareness Advocate for KnowBe4 as he provides fun and engaging examples of mental manipulation in everyday life: from the tactics used by oily car dealers, to sophisticated social engineering and online scams. Additionally, we’ll look at how to ethically use the very same levers when educating our users. Key Takeaways: • The Perception Vs. Reality Dilemma • Understanding the OODA (Observe, Orient, Decide, Act) Loop • How social engineers and scam artists achieve their goals by subverting OODA Loop's different components • How we can defend ourselves and our organizations
Getting asset visibility and insights into exposures, such as what services or ports might be exposed to the internet, is great. But should you start closing all those ports or shutting down risky services? How do you know what actions to take next? This is where layering threat intelligence onto your attack surface can help prioritize actions or response from your security team. This kind of actionable intelligence can support a wide range of cybersecurity activities, from cyber hygiene and patching to optimizing threat hunting operations. In this session, Looking Glass and (ISC)² will discuss: • How threat intelligence can be applied to your attack surface to prioritize action • Real-world examples of organizations effectively using intelligent attack surface insights to improve their cybersecurity program
As discussed throughout this series, attack surface management can support several cybersecurity use cases, from finding unpatched or vulnerable assets to optimizing threat hunting. With this kind of flexibility, there are also many approaches to implementing attack surface management. In this final session, we’ll discuss tips for implementing attack surface management. We will also share best practices for organizations using attack surface management to monitor themselves and third parties or suppliers. Participants will walk away with a checklist to successfully leverage when implementing attack surface management.
The nonprofit Open Web Application Security Project (OWASP) works to improve the security of software, web applications, and APIs. Since 2003, the OWASP Top 10 has raised awareness of the most critical security risks to web applications. The latest Top 10 list, released in late 2021, includes significant updates from previous lists. For nearly 20 years the top risks remained largely unchanged, but modern application architectures have shifted the calculus—bringing a new wave of risk to web applications. Join F5 and (ISC)2 on April 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we explore: • Key changes in the 2021 OWASP Top 10 including alignment of symptoms to root causes and new risk categories • Ways to use the OWASP Top 10 as a foundation to protect applications • How F5 solutions can help mitigate critical risks with effective and easy-to-operate security
Recently, we saw the disastrous effects of numerous far-reaching supply chain breaches and third-party code vulnerabilities, including SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. Unfortunately, we can expect to see more of the same in 2022 and beyond. When we consider these latest cyber events, it’s important to prepare—with the right people, processes, and tools—for what’s unquestionably yet to come. This is why every organization must be sure to have a robust third-party security risk strategy in place. Join Panorays Co-Founder and CTO, Demi Ben-Ari as he shares tips on how to best reduce supply chain risk and contain attacks. Plus he’ll discuss: 1. Why supply chain security is critically important right now 2. What actually happened with SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. 3. How to take action when a supply chain attack happens, and how to minimize the blast radius.
A record 71% of organizations were compromised by ransomeware last year with 63% of ransomware victims paying ransoms, encouraging cybercriminals to increase their attacks. CyberEdge’s 2022 Cyberthreat Defense Report (CDR) has become the standard for assessing organizations’ security posture, for gauging perceptions of IT security professionals and for ascertaining current and planned investments in IT security infrastructure. Now in its ninth year, the 2022 CDR assesses the views of 1,200 IT security professionals representing 17 countries and 19 industries. It’s the most geographically comprehensive view of IT security perceptions in our industry. Join (ISC)2 (a sponsor of this year’s study) and CyberEdge on Wednesday, May 25, 2022 at 1:00PM Eastern for highlights and key insights of the results, including: • Lack of skilled personnel and low security awareness inhibit IT security’s success • 84% of organizations are experiencing a shortfall of skilled IT personnel; IT security administrators, analysts and architects are in shortest supply • Nearly all respondents (99%) agreed that achieving a specialty cybersecurity certification would help their careers; the top choices were cloud security, software security and security administration
Cyber-attacks continue to plague the healthcare industry as threat actors leverage new trends and evolve their attack surface. Their primary focus is still attacking messaging tools with obtaining user credentials being the nirvana state for would be threat actors. Once the credentials are obtained, the attack options are numerous with ransomware, imposter email, supply chain fraud, and data extraction being the primary area of focus. On May 18, 2022 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific, Proofpoint and (ISC)² discuss how these exploits are currently impacting healthcare, the favored attacks being deployed by threat actors, and outline practical mitigating strategies healthcare institutions can implement to optimally defend themselves.
As the old adage goes “an ounce of prevention is worth a pound of cure.” A holistic application security (AppSec) program is essential for validating your applications’ security. AppSec experts perform a variety of security assessments that identify your software’s flaws and vulnerabilities. These bugs are then prioritized for remediation according to their severity and in accordance with your unique risk profile. In this webinar May 24, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, Synopsys and (ISC)² will focus on how you can mature your AppSec program with the Payment Card Industry Data Security Standard (PCI DSS) in mind. You will learn how to • Establish an AppSec program that meets or exceeds PCI requirements • Leverage the OWASP and NIST frameworks • Perform thorough code review, pen testing, and vulnerability assessments
Denial of service attacks became larger and more complex in 2021 with peak attack bandwidth now more than five times larger than it was in 2020. From disgruntled customers, to organized cybercrime and even modern day cyber warfare, DDoS attacks are still a go-to for many threat actors with effects of successful denial of service attacks ranging from temporary disruption of an online event to outages of critical infrastructure. Increasingly, DDoS attacks also used by cybercrime gangs to coerce payments of ransomware demands. While DDoS mitigation services are getting better at deflecting large volumetric DDoS attacks, the shift in tactics to focus on protocol and application DDoS makes mitigation a more complex task. On June 14, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific (ISC)² and F5 Labs discuss the F5 DDoS Trends report which analyzed thousands of attacks over the past two years to uncover how DDoS attacks are changing. We will showcase which industry sectors are most frequently attacked, which suffer the largest and most complex attacks, and some of the relevant security controls which can be employed to counter the growing threat. Join this webinar to learn: -What the most common forms of DDoS attacks are -Which industries are most effected -How attackers are building botnets and changing tactics -How to use the MITRE ATT&CK framework to map effective security controls
No doubt, you’ve heard the buzz about zero trust. Zero trust isn’t a product but rather a journey. While the end goal is worthwhile, like most things in security, getting there won’t be fast or easy. In this live session, June 28, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific IANS Faculty and (ISC)² discuss: • Exactly what a strong zero trust architecture requires • Concrete steps to take and products to consider to that help keep you moving on the right path • Ways to measure progress, set realistic milestones and ensure goals are obtainable
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us July 12, 2022 at 1:00 p.m., Eastern/10:00 a.m. Pacific when Zscaler and (ISC)² 's webinar session will discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
“SMS-based phishing attempts doubled in the U.S. year over year”-- that is just one key finding in Proofpoint’s 2022 Human Factor Threat Report. The report is the culmination of a year’s worth of threat research and insights drawn from more than 5 billion email messages, 35 billion URLs, 200 million attachments, 35 million cloud accounts and 1.7 billion suspicious SMS messages. It reveals surprising trends and offers actionable insight that sheds light on the nature of today’s cyber threats. Join us July 21, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as Proofpoint and (ISC)² take a deep dive into: • The developing relationship between cyber-criminal groups and what it means for the rest of us • How the most critical variable, people, can help mitigate attacks and manage privilege • The threats detected, mitigated and resolved during 2021 and our deployments
Supply Chain attacks, Zero-Days, and Advanced Persistent Threats (APTs) are effective because they target the trust models traditional security products were built on. The result is a post-compromise world where traditional IDS technology is looking in the wrong direction based on outdated assumptions to detect and stop modern attacks. Join John Oltsik from ESG and ExtraHop experts to learn how machine learning NG-IDS gives you back the edge against Advanced Threats : · Why Advanced Threats require a post-compromise posture · How time has been unkind to that noisy 90s IDS · How to fill IDS compliance gaps and increase security efficacy · How NG-IDS stops Advanced Threats before they do real damage
F5 Labs, one of F5 Networks’ information security research teams, publishes the Application Protection Report to help bridge the divide between tactics and strategy in information security. Join F5 Labs and (ISC)2 on November 4, 2021 at 1:00p.m. Eastern as we will share the findings from the 2021 Application Protection Report, which covers the explosion of ransomware in 2021, formjacking attacks such as Magecart, API security, and cloud misconfigurations, among others. We will wrap up by recommending mitigations for the most frequently observed attack vectors, as well as some strategic insights on the direction of information security as a whole.
Cyber attacks are at an all-time high and threat actors are becoming more sophisticated in their attempts. When considering today’s trends (and threats) in the industry, three recurring themes often come up amongst Cybersecurity professionals: the continued growth of ‘double extortion’ ransomware attacks, the increased risk that employee identity theft poses to organizations, and the additional fallout from supply chain attacks. Join Aura, NXTsoft, and (ISC)2 on April 15, 2021 at 1:00 PM Eastern as we discuss these three cyber threat trends and different ways you can address them within your organization.
Security and compliance frameworks from CIS, NIST, and PCI SSC point to long lists of must-have technology to build secure and compliant defenses. But they don’t tell us which ones to do first or how to allocate our limited budgets. Advanced Threats follows a land and pivots toward your valuables workflow. This knowledge gives you a roadmap to prioritize investments while leaving others as “good enough” that fit your budget and time constraints. Join ExtraHop experts to get insights into building effective layered defenses that prioritize your budget: - How the “Defender’s Dilemma” should guide your investments at the edge - How “Intruder’s Dilemma” sets the network trap for intruders and advanced threats - Why your IDS needs a next-gen upgrade against advanced threats - See how NG-IDS stops advanced threats (demonstration)
The majority of crippling cyberattacks begin with a simple phishing email. And while most companies provide some form of annual training, they focus on overly simplistic lures taken from public events that fail to represent the real danger of targeted criminal campaigns. Join eSentire and (ISC)2 on September 14, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as they explore how to build a comprehensive training and testing program that leverages realistic threat scenarios to foster context-relevant security awareness that drives behavioral change: · Use risk management data and accurate phishing lures to build comprehensive awareness training · Maximize your resources and programs to increase return on investment · Conduct testing that improves resilience · Meet regulatory requirements and demonstrate program success to your leadership
Everyone knows that multi-factor authentication (MFA) is more secure than a simple login name and password, but too many people think that MFA is a perfect, unhackable solution. It isn't! Join Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist, and security expert with over 30-years experience, and (ISC)2 on October 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. Pacific as he explores the many ways hackers can and do get around your favorite MFA solution. This webinar includes a (pre-filmed) hacking demo by KnowBe4's Chief Hacking Officer Kevin Mitnick, and real-life successful examples of every attack type. It will end by telling you how to better defend your MFA solution so that you get maximum benefit and security. We’ll also examine the good and bad of MFA and how to become a better computer security defender in the process, including: · Ways hackers get around multi-factor authentication · How to defend your multi-factor authentication solution · The role humans play in a blended-defense strategy
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.