Black Kite Blog
Have You Built a Password Fortress? – Risky Passwords of 2022
Each year, password lists are published by various companies looking to highlight the frequent, weak passwords of the last 12 months. Is yours on the list?
Jul 6, 2022Due Diligence 5-step Checklist
Third-party due diligence in 5 steps: a working checklist from Black Kite Research covering scoping, evidence, scoring, sign-off, and continuous review.
Jun 28, 2022What Should Cyber Security’s Role in Sourcing and Procurement Be?
When SPVM teams and security teams work together when assessing vendors, risk is properly accounted for and all parties involved are informed.
Jun 15, 2022Prioritizing Third Party Risk Intelligence in a Managed Services Package
Modern cybersecurity programs are complex and MSSPs must include a third-party risk intelligence solution in their service offering.
Jun 3, 2022Third-party Risk Management: a Tool or a Process?
Within Enterprise Risk Management, Third-party risk has taken a new level of importance in the world of mitigation and risk processes.
May 31, 2022Seven Questions to Ask When Assessing Security Rating Services
Thinking about exploring security ratings services, but not sure where to start? We've got you covered with our SRS assessment checklist.
May 12, 2022Strong Cybersecurity Talent: the Biggest Need for Companies in 2022
As the hiring market for cybersecurity talent grows and adapts to worldwide changes, companies can adjust tactics to discover candidates in new places.
Apr 21, 2022The Cia Triad: a Key Part of Your Cyber Security Program
Confidentiality, Integrity, and Availability are the key principles of the CIA triad, the basis for maintaining robust information security procedures.
Apr 7, 2022Third-party Risk Management & Cyber News
Stay up-to-date in the industry by reading our weekly bites of cyber news by Jeffrey Wheatman & Bob Maley.
Apr 1, 2022New Federal Cybersecurity Legislation Aimed at Protecting Critical Infrastructure
New requirements for reporting data breaches and ransomware attacks aim to protect critical infrastructure and national public safety.
Mar 18, 2022Controls Without Enforcement: Is Zero Trust Possible?
Without alignment on standards, Zero Trust architecture has the potential to discourage gradual growth into compliance due to the daunting ask.
Mar 4, 2022Understanding the Nist 800-160 Sp 1.1 Draft
Will NIST 800-160 SP v1.1 help federal security engineers protect against national cyber attack? Time tells all– but here’s what to know now.
Feb 25, 2022