top of page
Search


What is cybersecurity risk management, and why does it matter?
đ What is cybersecurity risk management, and why does it matter? In a world where threats evolve daily, cybersecurity risk management helps organizations prioritize what really matters: protecting the systems, data, and operations that drive the business. In this quick video, TBDCyber's senior partner, Graeme Payne, breaks down what cybersecurity risk management means and how it drives security. đĽ Tune in to hear. At TBDCyber, we help organizations build security programs t
Sep 23, 20251 min read


Entra ID P2 Secure Your Admin Accounts Now!
đ Admin Accounts Deserve Extra Protection In this short clip, TBDCyber's Microsoft trusted advisor, Chris Goosen, explains why organizations should consider enabling Entra ID P2 licensingâespecially for administrator accounts. đŹ Key takeaway: Instead of always-on admin privileges, Entra ID P2 allows just-in-time access through Privileged Access Management (PAM). That means: âď¸ Admin accounts start with zero privileges by default âď¸ Elevated access is granted only when need
Sep 23, 20251 min read


Incident Response in Cybersecurity: A Strategic Approach
In todayâs cyber landscape, threats arenât a matter of if or whenâthey are impacting organizations right now. From ransomware attacks and data breaches to insider threats, every business is a potential target. The stakes are high: according to IBMâs 2024 Cost of a Data Breach Report, the average global cost of a breach reached $4.9 million, with most incidents taking more than 200 days to detect and contain. Why Incident Response Matters A well-structured Incident Response (I
Aug 26, 20252 min read


What actually makes a data security program effective?
What actually makes a data security program effective? Itâs not just about inventories or visibility dashboardsâitâs about reducing real-world risk. In this quick video, Zach Luze from TBDCyber breaks down the core outcomes every data security initiative should drive: â
Minimizing inappropriate access â
Detecting and preventing data loss â
Rendering data useless to attackers If your current strategy doesnât support these goals in tactical, measurable ways, it might be time to
Jul 22, 20251 min read


OT Security: Safeguarding Critical Infrastructure in a Connected World
OT Security: Safeguarding Critical Infrastructure in a Connected World As IT and OT systems continue to converge, new cybersecurity challenges emerge. Traditional OT environments werenât built with security in mind, making them vulnerable as they integrate with IT networks. Protecting critical infrastructure is non-negotiable. Watch TBDCyber's Bahaa Kutub, CISSP speak on the fundamentals of OT cybersecurity and how organizations can fortify their environments.
Jul 22, 20251 min read


The Future of Third-Party Risk Management: AI & Automation
The Future of Third-Party Risk Management: AI & Automation Third-party risk programs are evolvingâfast. AI is no longer just a buzzword; itâs reshaping how organizations manage vendor risks. In this video, Joe Mendygral, Senior Director at TBDCyber, breaks down the latest trends in AI-driven automation for third-party risk management. â
More vendors, less manual work â AI-driven platforms now analyze surveys, policies, and compliance reports automatically. â
Risk scoring & re
Jul 22, 20251 min read


Insider Threat Management - Where to Begin?
In this short video, Justin Barnett breaks down three essential steps to help organizations build a strong foundation for their Insider Risk Management (IRM) program: 1ď¸âŁ Identify Key Use Cases Start with your existing policiesâacceptable use, data classification, and user conduct. These guide your priorities for addressing insider threats like data leaks, IP theft, and misuse of resources. 2ď¸âŁ Establish Stakeholders IRM isnât just a security function. HR, Legal, and GRC play
Jul 22, 20251 min read


Is your cybersecurity program actually protecting what matters most?
Is your cybersecurity program actually protecting what matters most? In this short video, TBDCyber's Alexandra Reibel explains why a risk-focused cybersecurity program is the smartest, most effective approach for todayâs threat landscape. Too many organizations fall into the trap of chasing the latest threats or checking compliance boxes â but thatâs not where true resilience comes from. â A threat-focused approach keeps you in constant reaction mode. â A compliance-focused p
Jul 22, 20251 min read


Is your Security Operations Center truly prepared for todayâs evolving threats?
Is your Security Operations Center (SOC) truly prepared for todayâs evolving threats? A well-functioning SOC is more than just the latest SIEM or SOAR toolâitâs about people, processes, and playbooks working together seamlessly. At TBDCyber, we help organizations evaluate and enhance their SOC programs to ensure compliance, efficiency, and resilience against cyber threats. In this video, Kyle Shubin, Senior Manager at TBDCyber, walks through key areas of a SOC assessment: â
Jul 22, 20251 min read


Security shouldnât be an afterthought in your SDLC
Security shouldnât be an afterthought. Today in this short video, Bahaa Kutub, CISSP, Director at TBDCyber, breaks down why secure software development is critical in todayâs threat landscapeâand how you can build security in from the start. Too often, organizations scramble to fix vulnerabilities after releaseâwasting time, money, and risking reputation. But thereâs a better way. âď¸ Threat modeling âď¸ Secure coding practices âď¸ Security testing âď¸ Code reviews When these ele
Jul 22, 20251 min read


Scaling Your TPRM Program
Struggling to scale your third-party risk management program without blowing your budget? In this video, Joe Mendygral, who leads Third-Party Risk at TBDCyber, shares how we helped an organization boost analyst productivity by 250%âwithout compromising risk insight. How? đš Smarter use of security monitoring tools đš Streamlined surveys for inherent risk + security controls đš Thoughtful automation through existing platforms If youâre trying to assess thousands of vendors eff
Jul 22, 20251 min read


Have you considered outsourcing Third-Party Risk Management?
Most organizations outsource IT services or MSSPsâbut third-party risk often gets overlooked. In this quick video, Joe Mendygral, who leads our TPRM services at TBDCyber, shares how we help clients: â
Assess vendors â
Identify and remediate risk â
Provide clear, actionable reporting â
Scale from 10 to 100,000 vendors â
Tailor programs to your security framework or unique needs
Jul 17, 20251 min read


Rethinking Data Security: The Power of DSPM & Vulnerability Management
In this short video, our CISO, Zach Luze, breaks down how DSPM: Maps your sensitive data across repositories Connects with vulnerability management tools to pinpoint high-risk assets Provides leadership with clear expectations and insights for better decision-making
Jul 17, 20251 min read


How CISOs Can Navigate Digital Transformation & Cyber Risk
Graeme Payne, Co-Founder and Senior Partner at TBDCyber, shares his thoughts on how CISOs can navigate digital transformation and cyber risk in this short video.
Jul 10, 20251 min read


Thinking About DSPM? 8 Crucial Considerations Before You Buy
Author: Zach Luze, TBDCyber CISO and Director of Data and Security Architecture Data Security Posture Management (DSPM) is generating buzz with its scalability, advanced classification, and broad coverage. But buying a DSPM solution isnât a plug-and-play decisionâit requires careful evaluation. Hereâs what I tell clients to consider before investing. 1. Know what DSPM doesâ and doesnâtâ do DSPM identifies where sensitive data lives, highlights vulnerabilities, and prioritize
Feb 3, 20253 min read


Post-Incident Response: Learning and Adapting
Author: Kyle Shubin, Senior Manager TBDCyber Introduction Effective incident management doesn't end with resolving a security breach. It involves a crucial phase known as post-incident response, where organizations reflect on the incident experience and adapt their strategies to improve future defenses. This phase plays a significant role in building organizational resilience. This article underscores the necessary steps organizations should take after resolving a security
Jun 12, 20243 min read
bottom of page