AttackIQ Blog

    Risky Biz Soap Box: Mapping NIST 800-53 to MITRE ATT&CK

    January 11, 2021
    Read More

    Lions and Tigers and a December Full of Adversary Activity – Oh My!

    December 23, 2020
    Defensive technologies can provide meaningful capabilities to isolate the adversary from compromised systems as defenders and threat hunters inspect their networks, preventing further reconnaissance and lateral movement, but only if their effectiveness is tested and validated.
    Read More

    “In God we trust. All others must bring data.”

    December 16, 2020
    Read More

    Grandpa’s New Shoes—or How Compliance Learned to Love Adversary Emulation

    December 15, 2020
    The alignment of NIST 800-53 and MITRE ATT&CK creates a unique opportunity for red, blue, and white teams to understand each other—and how they can work together to build a fully compliant and mature cybersecurity program.
    Read More

    Innovating During COVID-19 to Improve Security Effectiveness

    December 1, 2020
    Read More

    Five ways to lock down security control validation

    November 12, 2020
    Simple and important steps to make your cybersecurity program more efficient and effective.
    Read More

    AttackIQ Threat Informed Defense, Vol. 3

    October 26, 2020
    Read More

    AttackIQ Named one of the 2020 Best Small & Medium Workplaces™ by Great Place to Work® and Fortune

    October 16, 2020
    Read More

    Time to prepare for increased U.S.-China tensions in cyberspace 

    October 5, 2020
    Last week, the U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA) issued an alert to critical infrastructure owners and operators across the United States to be vigilant for potential Chinese cyberspace operations given heightened tensions between the two countries. What does the CISA alert recommend, and why is it important to follow it? 
    Read More

    This election year, the health of the Union depends in part on how we safeguard our information 

    September 23, 2020
    Cybersecurity does not exist in a vacuum and current socio-economic pressures make the United States more vulnerable to cyberattacks of all kinds. With the U.S. presidential election underway, Americans need to take practical steps to defend our democratic processes, online and off. This essay outlines some of the issues facing the United States in advance of the election, shares insights from AttackIQ’s recent podcast with leaders of Harvard’s Defending Digital Democracy project, and offers specific steps to manage the cybersecurity challenges of this moment.
    Read More

    A historic plan, built for the public.

    September 15, 2020
    Read More

    Episode 4: FIN6 MITRE Emulation Plan

    September 15, 2020
    Read More