<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Articles &#8211; GuardStreet</title>
	<atom:link href="https://guardstreet.com/category/articles/feed/" rel="self" type="application/rss+xml" />
	<link>https://guardstreet.com</link>
	<description></description>
	<lastBuildDate>Mon, 20 Jul 2026 22:20:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>
	<item>
		<title>CMMC Phase 2 Is Paused. Your Obligations Are Not.</title>
		<link>https://guardstreet.com/cmmc-phase-2-is-paused-your-obligations-are-not/</link>
					<comments>https://guardstreet.com/cmmc-phase-2-is-paused-your-obligations-are-not/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 22:20:18 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3651</guid>

					<description><![CDATA[On July 13, the Department of War suspended CMMC Phase 2. The third-party audits that were set to become requirements in November are on hold while a new CMMC Reform Task Force reviews the program, with recommendations due back in 60 days. Plenty of contractors read that news as breathing room. We read it as  [...]]]></description>
										<content:encoded><![CDATA[<p>On July 13, the Department of War suspended CMMC Phase 2. The third-party audits that were set to become requirements in November are on hold while a new CMMC Reform Task Force reviews the program, with recommendations due back in 60 days.</p>
<p>Plenty of contractors read that news as breathing room. We read it as a warning.</p>
<h4>The signature just got heavier</h4>
<p>Nothing about the pause touches the annual affirmation. A senior official at your company still signs it every year, attesting that you meet all 110 requirements of NIST SP 800-171. What changed is that no third-party auditor stands behind that signature anymore. Your own self-assessment is the only thing under it.</p>
<p>The Department has said plainly that it is not relaxing standards. And the False Claims Act enforcement that produced multiple DOJ settlements over inaccurate self-attestations is exactly where it was in June. The pause removed the deadline. It did not remove the exposure.</p>
<h4>Everything else is still in force</h4>
<p>NIST SP 800-171 remains the standard for protecting Controlled Unclassified Information. DFARS 252.204-7012 remains in every applicable contract you hold. Level 1 and Level 2 self-assessments are still required, along with a current SPRS score. And primes can still make compliance a condition of award, whatever the Department does with its own timeline.</p>
<h4>Don’t coast through the review</h4>
<p>The task force is reviewing how compliance gets verified. The standard it verifies against comes from DFARS and NIST 800-171, and nothing in the review suspends it. Whatever model emerges in September will sit on top of the same 110 requirements, and a company that lets its posture slide carries legal exposure the whole time it waits to find out.</p>
<p>If you already have a C3PAO audit scheduled, it’s a good idea to keep it. A completed audit is independently verifiable proof of your posture at a moment when most of the Defense Industrial Base is self-attesting, and that carries weight with contracting officers and teaming partners alike.</p>
<h4>Put your two cents in by August 14</h4>
<p>Alongside the suspension, the Department issued a Request for Information asking contractors what CMMC actually costs, where the administrative burden sits, and which controls deliver real security instead of paperwork. The task force will build its recommendations partly from those responses. If the</p>
<p>current model has been pricing you out or burying your team in documentation, this is your chance to say so on the record and help the process. Responses are due August 14.</p>
<h4>Keep two things current</h4>
<p>The affirmation your leadership signs covers the whole year, so two things need to hold up year-round. The first is security operations, the monitoring, detection, and response that satisfy Level 2 requirements on an ordinary Tuesday, not just in the weeks before an assessment. The second is documentation. Your System Security Plan, your POA&amp;M, and the evidence behind them are what give the person signing something defensible to stand on.</p>
<h4>Where Guard Street fits</h4>
<p>Guard Street has helped the Defense Industrial Base meet Department of War cyber requirements since 2020. We have watched frameworks pause, restart, and change shape, and our mission does not move: protect the systems.</p>
<p>For a clear read on where your posture stands before the task force reports, reach out at https//guardstreet.com/connect</p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/cmmc-phase-2-is-paused-your-obligations-are-not/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Mid-Market Businesses Get Wrong About Vendor Risk</title>
		<link>https://guardstreet.com/what-mid-market-businesses-get-wrong-about-vendor-risk/</link>
					<comments>https://guardstreet.com/what-mid-market-businesses-get-wrong-about-vendor-risk/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 28 May 2026 16:47:42 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3646</guid>

					<description><![CDATA[Most of the breaches we see at mid-sized companies don’t start with the company itself. They start with somebody the company decided to trust. Payroll. The marketing automation tool. The IT shop with a VPN tunnel into the network. Once in a while it’s something stranger, like the HVAC contractor with a login to the  [...]]]></description>
										<content:encoded><![CDATA[<p>Most of the breaches we see at mid-sized companies don’t start with the company itself. They start with somebody the company decided to trust. Payroll. The marketing automation tool. The IT shop with a VPN tunnel into the network. Once in a while it’s something stranger, like the HVAC contractor with a login to the building management portal that happens to share a network segment with finance.</p>
<p>This is vendor risk, and most mid-market companies are doing it wrong. Not because they’re careless. Often it’s because the program they’re running was built either for an enterprise with a thirty-person risk team or for a five-person shop with three vendors. The middle inherits the worst pieces of both, and that’s where things break.</p>
<p>A few patterns we see often.</p>
<h4>Vendor risk has become a procurement task.</h4>
<p>In a lot of mid-market companies, vendor risk lives inside procurement. A questionnaire goes out with the contract. The vendor fills it in. Somebody saves it in a SharePoint folder nobody opens again. Deal closes. Box checked.</p>
<p>The trouble is that the questionnaire describes the vendor on the day they signed. Two years later, after a private equity buyout, two rounds of layoffs, a new platform, and an engineer who left her AWS keys in a public repo over a long weekend, that questionnaire is a museum piece.</p>
<p>You bought a product. You didn’t buy a guarantee that the company selling it would still look the same eighteen months in.</p>
<h4>SOC 2 is being read as a verdict.</h4>
<p>A SOC 2 Type II report is useful. It doesn’t tell you the vendor is safe to plug into your business, but that’s how a lot of buyers treat it.</p>
<p>Two issues. First, the vendor writes the scope. We’ve reviewed plenty of clean Type II reports that, when you actually read them, exclude the integration the client is using. Second, the report measures whether controls exist and operate against a set of criteria. It doesn’t measure how those controls would hold up against somebody who’s actually trying to get in.</p>
<p>If a vendor’s whole answer to “how do you handle security” is the SOC 2 logo at the bottom of their website, you don’t have an answer. You have marketing.</p>
<h4>The big vendors get the attention, the small ones get the access.</h4>
<p>Programs at this size tend to be top-heavy. The biggest contracts get the most diligence. Everyone else gets the short questionnaire, or nothing.</p>
<p>Attackers don’t really care about your contract values. They care about which door is unlocked. The Target breach famously came through an HVAC contractor. SolarWinds came through a build server most of its customers didn’t know existed. Kaseya rolled downhill through MSPs into thousands of small businesses that had never heard the name. The small specialty vendor is often the way in.</p>
<p>Try this exercise. Make a list of every vendor that holds customer data, financial data, employee data, or has any kind of access to your network. Now mark which ones have a security program you’ve actually looked at. For most mid-market businesses we work with, the second list is much shorter than the first.</p>
<h4>An assessment is not a program</h4>
<p>A questionnaire is a snapshot. A vendor risk program is what happens after the snapshot.</p>
<p>Most companies stop at the snapshot. There’s a folder of questionnaires, some from three or four years ago, and the assumption is that the work is done. Meanwhile two of those vendors have had public incidents, one was acquired and migrated its data to a different cloud, and a fourth quietly subcontracted part of its operation overseas without telling anybody.</p>
<p>You don’t need an expensive monitoring platform for this. Often it’s a calendar entry, a few news alerts on the vendor names, and somebody whose job it is to ask a follow-up question when something hits the news.</p>
<h4>You probably don’t know what data your vendors actually have.</h4>
<p>This is the one that catches owners off guard.</p>
<p>Most companies cannot tell you, with any precision, what’s sitting where. Marketing uploaded a customer export to an email tool last spring. Finance hooked up the bank to a forecasting app. HR is using a recruiting platform that has a year’s worth of resumes, including the W9s with SSNs for contract workers. Each of these decisions made sense to the person making it. Nobody mapped any of it.</p>
<p>When something breaks, the first question from your lawyer, your insurer, and any regulator who shows up is: what did they have? “We’ll have to find out” is not a great answer in that moment.</p>
<h4>What we’d recommend:</h4>
<p>The fix isn’t complicated. Most of it is process. Tools come later, if at all.</p>
<p>Inventory everything. Not the procurement list, the actual list. Every tool, service, and contractor that touches your data or your network, including the ones some manager spun up on a corporate card last quarter.</p>
<p>Sort by risk. Most vendors are not equal. The ones holding sensitive data or with privileged access are tier one. The plant watering service is not. Put the effort where it earns its keep.</p>
<p>Re-review the top tier annually at minimum. Make it a calendar event so it actually happens. Tie it to budget cycles if that’s what it takes to get it on the schedule.</p>
<p>Write down what data each vendor has. Keep it current. If somebody asked tomorrow morning, you should be able to answer in five minutes.</p>
<p>Plan how the data comes back, or gets destroyed, when the relationship ends. We’ve seen breach disclosures involve a vendor a company stopped working with three years ago.</p>
<p>That’s most of it. Mid-market vendor risk usually isn’t a problem of awareness. The owners we talk to generally know they should be doing more. It’s a problem of where the program lives, what it actually covers, and who’s on the hook for keeping it current.</p>
<p>If you’re not sure where your business stands on that, we’d rather talk through it now than after something happens.</p>
<h4>How Guard Street can help.</h4>
<p>Guard Street assists companies in creating their vendor risk assessments and management strategy.  We provide an ongoing management service to identify the vendor changes, security risks and remediation plans specific to your key vendors.</p>
<p>Visit <a href="http://www.guardstreet.com/connect">www.guardstreet.com/connect</a> to discuss your business’ vendor risk needs and how to address them.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/what-mid-market-businesses-get-wrong-about-vendor-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Is a Letter of Attestation, and Why Does Your Business Need One?</title>
		<link>https://guardstreet.com/what-is-a-letter-of-attestation-and-why-does-your-business-need-one/</link>
					<comments>https://guardstreet.com/what-is-a-letter-of-attestation-and-why-does-your-business-need-one/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 30 Apr 2026 00:57:03 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3630</guid>

					<description><![CDATA[You are closing a deal with an enterprise client. The procurement team sends over a security questionnaire and buried in the list of requirements is a request for a Letter of Attestation for your penetration test. Maybe you have seen this before. Maybe it is the first time. Either way, you need to know what it is, what it should say and how  [...]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">You are closing a deal with an enterprise client. The procurement team sends over a security questionnaire and buried in the list of requirements is a request for a Letter of Attestation for your penetration test. Maybe you have seen this before. Maybe it is the first time. Either way, you need to know what it is, what it should say and how to get one without holding up the deal.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="auto">We’ll break it down in plain terms.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="1"><b><span data-contrast="none">What Is a Letter of Attestation?</span></b><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:160}"> </span></h4>
<p><span data-contrast="auto">A Letter of Attestation (LoA) is a formal document issued by an independent cybersecurity firm confirming that a security control has been pursued and typically it demonstrates proof that a professional penetration test was conducted on your systems. It is written for external audiences including the client reviewing your vendor application, the auditor checking your compliance posture and the insurer evaluating your risk profile.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="auto">It confirms that a qualified third party tested your systems, what standards governed that testing and that findings were addressed. The full technical report stays internal. The LoA is what you share externally.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="2"><b><span data-contrast="none">Who Is Asking for This?</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:120}"> </span></h4>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Enterprise clients vetting vendors before signing contracts.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Healthcare and financial sector partners requiring compliance proof.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">SOC 2, ISO 27001 and several other audit frameworks.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Government contractors and procurement offices.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Cyber insurers assessing risk before issuing or renewing a policy.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<h4 aria-level="1"><b><span data-contrast="none">What a Letter of Attestation Includes</span></b><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:160}"> </span></h4>
<p><span data-contrast="auto">If someone is asking you for an LoA for a penetration test, here is what a legitimate one contains. This is also useful to know when evaluating whether what you have already received from a testing firm is complete:</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><b><span data-contrast="auto">Final Statement: </span></b><span data-contrast="auto">A formal declaration that penetration testing was performed by a qualified third party.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="7" data-aria-level="1"><b><span data-contrast="auto">Scope of Testing: </span></b><span data-contrast="auto">The scope of what was tested, including systems, applications, and networks covered.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="8" data-aria-level="1"><b><span data-contrast="auto">Methodology: </span></b><span data-contrast="auto">The methodology used, such as OWASP Top 10, NIST SP 800-115, or PTES.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="9" data-aria-level="1"><b><span data-contrast="auto">Finding Summary: </span></b><span data-contrast="auto">Depending on the purpose (for example if requested by an auditor), a high-level summary of findings categorized by severity: Critical, High, Medium, and Low.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="10" data-aria-level="1"><b><span data-contrast="auto">Remediation Confirmation: </span></b><span data-contrast="auto">Confirmation that critical and high findings were remediated prior to issuance.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="11" data-aria-level="1"><b><span data-contrast="auto">Signature and Firm Credentials: </span></b><span data-contrast="auto">A formal signature from the testing firm, establishing accountability.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<h3 aria-level="1"></h3>
<h4 aria-level="1"><b><span data-contrast="none">Why There Is No Letter Grade</span></b><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:160}"> </span></h4>
<p><span data-contrast="auto">A question that comes up frequently is “Why does an LoA not just give a score or a grade?” If a penetration test was performed, why not summarize it as a B+ or an 87 out of 100 and call it a day?</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="auto">The short answer is that a grade would actually make the document less useful and more dangerous. Here is why.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="2"><b><span data-contrast="none">A Grade Does Not Reflect What Was Actually Tested</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:120}"> </span></h4>
<p><span data-contrast="auto">Every penetration test is bound by time and agreed-upon scope. A three-day test of one application looks the same on a graded scale as a three-week test of your full infrastructure. The grade removes that context, and without context, it is misleading to anyone reading it.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="2"><b><span data-contrast="none">A Grade Can Create Problems for You</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:120}"> </span></h4>
<p><span data-contrast="auto">If your LoA shows a B+ and a breach occurs later, that grade becomes a liability. Stakeholders may point to it as evidence that you represented your security as stronger than it was. A penetration test is a point-in-time assessment and framing it as a score implies something closer to a certification, which it is not.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="2"><b><span data-contrast="none">The Industry Measures Risk by Severity, Not Score</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:120}"> </span></h4>
<p><span data-contrast="auto">Security findings are categorized as Critical, High, Medium or Low based on how exploitable they are and what the business impact would be. That framework is precise and consistent. A Remote Code Execution vulnerability is Critical regardless of who assesses it. A grade introduces subjectivity where there should not be any.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="2"><b><span data-contrast="none">The LoA and the Technical Report Serve Different Purposes</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:120}"> </span></h4>
<p><span data-contrast="auto">The LoA is a clean external document. The technical report is the detailed internal record. Putting a grade on the LoA blurs that line and risks surfacing internal details in a document that was never meant to carry them.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="auto">Your clients and auditors are not looking for a score. They want confirmation that real testing happened and that problems were fixed. A well-written LoA does that more clearly than any grade could.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<h4 aria-level="1"><b><span data-contrast="none">When Should You Get One?</span></b><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:160}"> </span></h4>
<p><span data-contrast="auto">Any time a client, auditor, or insurer needs proof that security testing happened, an LoA is what they are asking for. The most common triggers:</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="12" data-aria-level="1"><span data-contrast="auto">A client or prospect requires security documentation as part of vendor onboarding.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="13" data-aria-level="1"><span data-contrast="auto">You are pursuing SOC 2, ISO 27001, or a similar compliance certification.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="14" data-aria-level="1"><span data-contrast="auto">A past security incident requires documented proof of remediation.</span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="15" data-aria-level="1"><span data-contrast="auto">Company leadership / board requires one each year. </span><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:80}"> </span></li>
</ul>
<h4 aria-level="1"><b><span data-contrast="none">How Guard Street Can Help</span></b><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:160}"> </span></h4>
<p><span data-contrast="auto">If a client or partner is asking for a Letter of Attestation and you are not sure where to start, or if you want to make sure your security program is documented in a way that holds up to real scrutiny, Guard Street can help.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
<p><span data-contrast="auto">Visit </span><a href="http://www.guardstreet.com/connect"><span data-contrast="none">www.guardstreet.com/connect</span></a><span data-contrast="auto"> to discuss what your business needs and how to get there.</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:160}"> </span></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/what-is-a-letter-of-attestation-and-why-does-your-business-need-one/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The LiteLLM Compromise: What the Biggest AI Supply Chain Attack of 2026 Means for Your Business</title>
		<link>https://guardstreet.com/the-litellm-compromise-what-the-biggest-ai-supply-chain-attack-of-2026-means-for-your-business/</link>
					<comments>https://guardstreet.com/the-litellm-compromise-what-the-biggest-ai-supply-chain-attack-of-2026-means-for-your-business/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 16 Apr 2026 17:12:02 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3625</guid>

					<description><![CDATA[On the morning of March 24th, tens of thousands of developers building AI-powered applications went about their normal routines. They pulled software packages, ran builds, and shipped code. What most of them did not realize was that one of the most widely used tools in the AI ecosystem had been quietly weaponized overnight. LiteLLM is  [...]]]></description>
										<content:encoded><![CDATA[<p>On the morning of March 24th, tens of thousands of developers building AI-powered applications went about their normal routines. They pulled software packages, ran builds, and shipped code. What most of them did not realize was that one of the most widely used tools in the AI ecosystem had been quietly weaponized overnight.</p>
<p>LiteLLM is an open-source Python library that acts as a universal gateway to over 100 large language model providers, including OpenAI, Anthropic, Google, and Amazon. On March 24th, a threat group called TeamPCP used stolen credentials to upload two poisoned versions of the package to PyPI (Python Package Index), the public repository that developers worldwide depend on. Those compromised versions sat there for roughly three hours before anyone caught it.</p>
<p>Three hours does not sound like much. But for a package with an estimated 95 million monthly downloads, that window was more than enough to cause serious damage.</p>
<h3>Why This One Is Different</h3>
<p>LiteLLM is not some obscure utility buried deep in a codebase. Its entire purpose is to sit between your applications and your AI providers and manage the API keys, credentials and access tokens for all of them in one place. Compromising LiteLLM does not give an attacker one key. It gives them <em>every</em> key.</p>
<p>The malware embedded in the compromised versions was engineered to sweep up the entire credential surface of a modern AI deployment: cloud provider keys for AWS, GCP and Azure; SSH keys; Docker configurations; CI/CD tokens; database credentials; and even cryptocurrency wallets. All of it was encrypted before being shipped to an attacker-controlled server.</p>
<p>In plain terms: if your organization was running one of the affected versions, the attackers potentially walked away with the keys to your entire digital infrastructure. Not just your AI tools, but everything connected to them.</p>
<h3>The Lucky Break</h3>
<p>The attack was not discovered by a monitoring system or a security audit. It was thankfully caught because of a bug in the malware itself. A researcher named Callum McMahon was testing an unrelated tool that happened to pull in LiteLLM automatically as a hidden dependency. The malicious code had a flaw that caused it to spawn processes uncontrollably until it consumed all available memory and crashed his machine.</p>
<p>McMahon investigated the crash, traced it to LiteLLM, and reported it. Within hours, the compromised packages were pulled. But as AI researcher Andrej Karpathy pointed out publicly: if the attackers had not made that coding mistake, the malware could have run undetected for weeks, silently collecting credentials from organizations around the world.</p>
<p>The difference between a contained incident and a prolonged credential harvest across the global AI development community came down to sloppy code written by the attackers themselves.</p>
<h3>The Ripple Effect</h3>
<p>What makes this especially alarming is that LiteLLM is not just installed directly by developers. It gets pulled in automatically as a hidden dependency by a large number of major AI frameworks. Projects including Microsoft GraphRAG, Google ADK, DSPy, MLflow, CrewAI, and OpenHands all depended on LiteLLM. Over 600 public repositories had unprotected LiteLLM dependencies at the time of the compromise.</p>
<p>Consequently, organizations using those tools may have been exposed without anyone on their team ever directly installing LiteLLM. If your company runs AI workloads of any kind, there is a real chance that LiteLLM is somewhere in your software supply chain whether your team put it there or not.</p>
<h3>What This Means for Your Organization</h3>
<p>You do not need to be a technology company to be affected by this. If your organization uses AI-powered tools, chatbots, automation, analytics, or any application that connects to large language models, you are part of the ecosystem that was just compromised. A few questions worth asking:</p>
<p><strong>Do you know what your AI tools depend on? </strong>Most organizations have adopted AI tooling quickly without applying the same supply chain scrutiny they would to other critical software. If you cannot answer the question &#8220;what open-source packages does our AI stack rely on,&#8221; that is a gap that needs attention.</p>
<p><strong>Are your software dependencies locked to verified versions? </strong>The difference between installing a package with an open version range and locking it to a specific, reviewed version is the difference between a door with a deadbolt and a door propped open with a brick.</p>
<p><strong>How are credentials managed across your AI infrastructure? </strong>Tools like LiteLLM concentrate API keys and cloud credentials into a single point. If that point is compromised, the blast radius extends across every provider and system those credentials touch.</p>
<p><strong>Are your own security tools introducing risk? </strong>This entire chain of events started with a compromised security scanner. The tools your team relies on to protect your environment can themselves become the entry point if they are not properly verified and maintained.</p>
<h3>The Bigger Picture</h3>
<p>The era of blindly trusting open-source AI infrastructure is over. Organizations everywhere have rushed to adopt AI tools, and in that rush, many have skipped the supply chain diligence they would apply to any other critical piece of software. That gap is now being actively exploited by sophisticated threat actors who understand exactly where the weak points are.</p>
<p>At Guard Street, we have been having these conversations with business and technology leaders for months. The rapid adoption of AI has created entirely new categories of risk that most existing security programs were not built to handle. If your organization is treating AI infrastructure like any other software dependency, without dedicated scrutiny, it is time for a reassessment.</p>
<p>The LiteLLM compromise is a wake-up call. Whether your organization responds to it now or learns the lesson the hard way is a decision that is being made today, whether anyone in the room realizes it or not.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/the-litellm-compromise-what-the-biggest-ai-supply-chain-attack-of-2026-means-for-your-business/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Russian Military Hackers Just Hijacked 18,000 Routers. Is Yours One of Them?</title>
		<link>https://guardstreet.com/russian-military-hackers-just-hijacked-18000-routers-is-yours-one-of-them/</link>
					<comments>https://guardstreet.com/russian-military-hackers-just-hijacked-18000-routers-is-yours-one-of-them/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Wed, 15 Apr 2026 19:14:15 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3620</guid>

					<description><![CDATA[On April 7th, over 18,000 home and small business routers in 120 countries were penetrated by a Russian military intelligence operation, which the FBI, NSA, Department of Justice, and law enforcement partners from 15 nations declared they had stopped on April 7. Codenamed Operation Masquerade, the operation targeted infrastructure under the control of APT28, a  [...]]]></description>
										<content:encoded><![CDATA[<p>On April 7th, over 18,000 home and small business routers in 120 countries were penetrated by a Russian military intelligence operation, which the FBI, NSA, <a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4453919/nsa-supports-fbi-in-highlighting-russian-gru-threats-against-routers/">Department of Justice, and law enforcement partners from 15 nations declared they had stopped on April 7.</a> Codenamed Operation Masquerade, the operation targeted infrastructure under the control of APT28, a Russian GRU hacking outfit that has been operational for more than 20 years. They may also go by the titles Forest Blizzard or Fancy Bear.</p>
<p>Malware in the conventional sense was not installed by the attackers. They altered the DNS settings of the devices by taking use of known flaws in consumer-grade TP-Link routers. They were able to covertly reroute internet traffic from all of the network&#8217;s devices through servers under their control thanks to that one modification. They then collected emails, passwords, login tokens, and other private information. The end user did not need to interact with the assault. The majority of victims were unaware that something was amiss.</p>
<p>Microsoft found that the campaign affected 5,000 individual devices and more than 200 organizations. Governmental organizations, military personnel, defense contractors, operators of vital infrastructure, and telecom companies in North America, Europe, Africa, Central America, and Southeast Asia were among the targets. After casting a broad net, the GRU filtered for intelligence targets with high value.</p>
<p>In order to prevent the attackers from regaining access, the FBI responded by issuing court-authorized commands to hacked routers located within the United States to reset their DNS settings. The operation did not gather user data or interfere with regular router operation. However, the fact that the FBI had to remotely intervene in devices sitting in American homes and offices should tell you something about the scale of the problem.</p>
<h3>Why Routers Are the Weakest Link</h3>
<p>Home routers have been attacked by nation-states before, and this won&#8217;t be the last. A Chinese botnet that had taken control of hundreds of similar devices was stopped by the FBI in 2024. It was the Cyclops Blink botnet in 2022. VPNFilter in 2018 came before that. Because routers are the most overlooked component of security infrastructure in the majority of households and companies, the trend continues to recur.</p>
<p>This continues to occur for several reasons:</p>
<p><strong>Firmware updates are manual and invisible. </strong>Most routers don&#8217;t update automatically, in contrast to your laptop or phone. Most users have never seen the admin panel they must log into in order to update. Automatic updates are rarely released by manufacturers, and many older devices no longer receive any updates at all.</p>
<p><strong>Default credentials are everywhere. </strong>How many users have altered the default admin password on their router? Every study that has ever been done on the subject has found that the response is far from sufficient.  Many routers still ship with credentials like &#8220;admin/admin&#8221; or publicly documented defaults that attackers can look up in seconds.</p>
<p><strong>Remote management is often enabled by default. </strong>Anybody can try to access the admin panel from anywhere in the globe because some routers come with remote administration interfaces that are open to the internet. The majority of users are unaware that this feature even exists, much less that it need to be disabled.</p>
<p><strong>Nobody monitors router activity. </strong>Laptops and servers are safeguarded by endpoint security technologies. Inboxes are protected by email security measures. However, very few people are keeping an eye on what the router is doing. There was no alarm when APT28 altered DNS settings on hacked routers. All of the network&#8217;s devices were silently affected by the modification.</p>
<p><strong>End-of-life devices stay in service for years. </strong>Unlike phones, which are replaced every few years, routers are not. Hardware that was long since discontinued by the manufacturer is still in use in many homes and businesses. These devices continue to be linked to the internet and trusted to manage all network traffic, but they will never get another security patch.</p>
<h3>The Remote Work Problem</h3>
<p>This issue has significantly worsened due to the transition to remote and hybrid work. Prior to 2020, corporate networks with specialized firewalls, intrusion detection systems, and IT professionals keeping an eye on traffic handled the majority of sensitive business data. Nowadays, a large amount of that same data passes through consumer-grade routers that staff members purchased from a big-box retailer and mindlessly plugged in.</p>
<p>This is particularly mentioned in the NSA&#8217;s advice, which advises companies that use telework to examine their policies for employee access to sensitive data, including the usage of VPNs and hardened application setups. The reason for this suggestion is that the agency recognizes what this attack showed: when a home router is compromised, the attacker does not simply see the router. They perceive everything that is related to it. The fraudulent DNS settings are passed down to any device connected to that Wi-Fi network. Every email, file transfer, and login from every device in the house passes through infrastructure under the attacker&#8217;s control.</p>
<p>This implies that your security perimeter now encompasses each employee&#8217;s home network if your company employs remote workers. Additionally, you typically have little visibility into what&#8217;s going on there.</p>
<h3>What You Should Do</h3>
<p>The good news is that self-defense measures are simple. Unfortunately, the majority of individuals and institutions have not adopted them. Here are our recommendations based on the FBI, NSA, and CISA guidelines:</p>
<ol>
<li><strong>Change your router’s admin credentials. </strong>If your router’s login is still set to the factory default, change it immediately. Use a strong, unique password. This is the single most impactful step you can take.</li>
<li><strong>Update your router’s firmware. </strong>Log into your router’s admin panel and check for available updates. If you do not know how, your manufacturer’s website will have instructions. If your router is no longer receiving updates from the manufacturer, it is time to replace it.</li>
<li><strong>Disable remote management. </strong>Unless you have a specific reason to manage your router from outside your network, turn this feature off. It is one of the primary ways attackers gain initial access.</li>
<li><strong>Replace end-of-life hardware. </strong>If your router is old enough that the manufacturer has stopped issuing security updates, it is a liability. No amount of configuration hardening can protect a device with known, unpatched vulnerabilities.</li>
<li><strong>Pay attention to certificate warnings. </strong>The NSA specifically flagged this. If your browser or email client starts showing certificate warnings that it did not show before, do not ignore them. A DNS hijacking attack can trigger these warnings because traffic is being routed through an untrusted server.</li>
<li><strong>Review your remote work policies. </strong>If your organization has employees working from home, you need to address the security of their home networks. At a minimum, require VPN usage for accessing sensitive systems. Better yet, provide guidance or support for employees to secure their home routers.</li>
</ol>
<h3>The Bigger Picture</h3>
<p>Since 2018, the FBI has now carried out four significant operations to combat nation-state router breaches. Every time, the assailants broadened their scope and changed their strategies. Unmanaged, unmonitored, unpatched consumer networking equipment at the edge of networks handling sensitive data was the underlying vulnerability in each case.</p>
<p>These hazards are not hypothetical. Before this operation was stopped, Russian military intelligence secretly collected credentials from infected routers for at least two years. Over 200 organizations and 120 countries were impacted by the program. And this is the only one that we are aware of.</p>
<p>&nbsp;</p>
<p>At Guard Street, we collaborate with companies to find and fill precisely these kinds of gaps. One of the most neglected aspects of most security programs is router and edge device protection, and events like Operation Masquerade serve as a reminder that the dangers are genuine, active, and aimed at companies of all sizes.</p>
<p>The FBI advises getting in touch with your local field office or submitting a report to the Internet Crime Complaint Center at ic3.gov if you think your router has been compromised.</p>
<p><em><strong>Guard Street</strong> provides cybersecurity advisory, threat intelligence, and strategic risk management for organizations navigating an evolving threat landscape. To learn how we can help your organization assess and strengthen its security posture, visit guardstreet.com.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/russian-military-hackers-just-hijacked-18000-routers-is-yours-one-of-them/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Iranian Cyberattacks Are Here. Is Your Organization Next? </title>
		<link>https://guardstreet.com/iranian-cyberattacks-are-here-is-your-organization-next/</link>
					<comments>https://guardstreet.com/iranian-cyberattacks-are-here-is-your-organization-next/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Mon, 16 Mar 2026 01:28:17 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3608</guid>

					<description><![CDATA[Last week, Stryker, one of the world's largest medical device companies with over $25 billion in revenue and operations in 61 countries was hit with a cyberattack.   The Iran-linked hacktivist group Handala claimed responsibility, alleging they wiped data from more than 200,000 systems and servers, forcing Stryker's offices across 79 countries to shut down. Investigators believe the attackers gained access to Stryker's Microsoft  [...]]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Last week, Stryker, one of the world&#8217;s largest medical device companies with over $25 billion in revenue and operations in 61 countries was hit with a cyberattack. </span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">The Iran-linked hacktivist group Handala claimed responsibility, alleging they wiped data from more than 200,000 systems and servers, forcing Stryker&#8217;s offices across 79 countries to shut down. Investigators believe the attackers gained access to Stryker&#8217;s Microsoft Intune management console, then used it to wipe corporate devices back to factory settings. A devastating result that required no ransomware, no malware. Just administrative access turned against the company itself.</span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><b><span data-contrast="auto">This is what modern nation-state warfare looks like.</span></b><span data-ccp-props="{&quot;335559739&quot;:280}"> </span></p>
<h3 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"></h3>
<h4 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"><b><span data-contrast="none">The Threat Is Escalating Fast</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:140,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></h4>
<p><span data-contrast="auto">Iran has historically relied on cyber operations as a primary tool of retaliation, precisely because it lacks the conventional military reach to strike back symmetrically against the United States and Israel. Since the U.S.-Israel military campaign began in late February, that calculus has shifted dramatically.</span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">Multiple Iranian state-aligned groups have formed under a coordinated &#8220;Electronic Operations Room,&#8221; with Handala, linked directly to Iran&#8217;s Ministry of Intelligence and Security, claiming attacks against energy companies, payment systems, and now American critical infrastructure.</span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">The Stryker attack is not an isolated incident, but the first of likely many. This is a signal to the US.</span><span data-ccp-props="{&quot;335559739&quot;:280}"> </span></p>
<h3 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"></h3>
<h4 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"><b><span data-contrast="none">Who Needs to Be on Guard</span></b><span data-ccp-props="{&quot;335559738&quot;:280,&quot;335559739&quot;:140,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></h4>
<p><span data-contrast="auto">Threat analysts and ratings agencies are warning that the current environment puts local governments, critical infrastructure providers, and major U.S. companies at heightened risk. Attacks range from DDoS to financially motivated intrusions to full data-wiping operations. Currently, the sectors with the greatest exposure include:</span><span data-ccp-props="{&quot;335559739&quot;:160}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="none">Healthcare and medical technology</span></b><span data-contrast="none"> &#8212; as Stryker demonstrates, patient-care disruptions create maximum pressure.</span><span data-ccp-props="{&quot;335559739&quot;:120,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="none">Energy and utilities</span></b><span data-contrast="none"> &#8212; Iranian state-sponsored actors have repeatedly targeted water and energy sector networks and industrial control systems.</span><span data-ccp-props="{&quot;335559739&quot;:120,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="none">Financial services</span></b><span data-contrast="none"> &#8212; U.S. security officials have specifically warned that the financial sector has historically been a target for Iranian-aligned groups during periods of elevated tension.</span><span data-ccp-props="{&quot;335559739&quot;:120,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="none">Defense and aerospace</span></b><span data-contrast="none"> &#8212; defense industrial base companies, particularly those with ties to Israeli research and defense firms, are at increased risk</span><span data-ccp-props="{&quot;335559739&quot;:120,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><b><span data-contrast="none">Every U.S. multinational</span></b><span data-contrast="none"> &#8212; as one former CIA official put it plainly: every American company operating internationally should be briefing its overseas personnel right now</span><span data-ccp-props="{&quot;335559739&quot;:280,&quot;335572071&quot;:0,&quot;335572072&quot;:0,&quot;335572073&quot;:4278190080,&quot;335572075&quot;:0,&quot;335572076&quot;:0,&quot;335572077&quot;:4278190080,&quot;335572079&quot;:0,&quot;335572080&quot;:0,&quot;335572081&quot;:4278190080,&quot;335572083&quot;:0,&quot;335572084&quot;:0,&quot;335572085&quot;:4278190080,&quot;335572087&quot;:0,&quot;335572088&quot;:0,&quot;335572089&quot;:4278190080,&quot;469789798&quot;:&quot;nil&quot;,&quot;469789802&quot;:&quot;nil&quot;,&quot;469789806&quot;:&quot;nil&quot;,&quot;469789810&quot;:&quot;nil&quot;,&quot;469789814&quot;:&quot;nil&quot;}"> </span></li>
</ul>
<h3 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"></h3>
<h4 data-ccp-border-between="0px none #000000" data-ccp-padding-between="0px" aria-level="2"><strong>What This Means for Your Organization </strong></h4>
<p><span data-contrast="auto">The Stryker attack succeeded not because of exotic zero-day exploits, but because of access. Specifically, privileged administrative access to a device management platform. This is a pattern we see repeatedly with Iranian threat actors: they find the door you left unlocked, walk in, and use your own tools against you.</span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">The fundamentals matter now more than ever: hardened identity and access management, endpoint visibility, rapid detection of abnormal administrative activity, and a tested incident response plan. Nation-state actors do not announce themselves. By the time you know they are in, the damage is often already done.</span><span data-ccp-props="{&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">At Guard Street, we work with organizations every day who believe a sophisticated attack will not happen to them, until it does. The Stryker breach is a reminder that no sector, no size, and no geography makes you immune. The question is not whether you are a target. The question is whether you are ready.</span><span data-ccp-props="{&quot;335559739&quot;:280}"> </span></p>
<p><b><span data-contrast="auto">Ready to assess your exposure? Let&#8217;s talk.</span></b></p>
<p><strong>Visit </strong><strong><a href="https://guardstreet.com/connect">https://guardstreet.com/connect</a> </strong>or<strong> call 1-800-811-9130 </strong>to talk with our experts about building a strategic security plan for your organization.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/iranian-cyberattacks-are-here-is-your-organization-next/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Rising Cost of Ransomware in 2026: Real-World Impact and Prevention Strategies</title>
		<link>https://guardstreet.com/the-rising-cost-of-ransomware-in-2026-real-world-impact-and-prevention-strategies/</link>
					<comments>https://guardstreet.com/the-rising-cost-of-ransomware-in-2026-real-world-impact-and-prevention-strategies/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 22 Jan 2026 06:21:28 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3590</guid>

					<description><![CDATA[Ransomware continues to be one of the most persistent and costly threats facing organizations. In 2026, mid-market companies (typically 100 to1,000 employees) are seeing average recovery costs climb into the $200,000 to $2.5 million range per incident, often driven more by extended downtime and operational disruption than by ransom payments themselves. While the numbers can  [...]]]></description>
										<content:encoded><![CDATA[<p>Ransomware continues to be one of the most persistent and costly threats facing organizations. In 2026, mid-market companies (typically 100 to1,000 employees) are seeing average recovery costs climb into the $200,000 to $2.5 million range per incident, often driven more by extended downtime and operational disruption than by ransom payments themselves.</p>
<p>While the numbers can feel daunting, the good news is that ransomware is increasingly preventable and manageable with the right preparation. This article outlines the current landscape of ransomware costs, what drives those figures and practical steps organizations can take to reduce both likelihood and impact.</p>
<p>&nbsp;</p>
<h4>Why Ransomware Costs Keep Rising</h4>
<p>Several trends are pushing costs higher in 2026:</p>
<ol>
<li><strong>Double and Triple Extortion Tactics:</strong> Attackers don’t just encrypt data, they exfiltrate it first, then threaten public release or contact customers directly. This multi-layered pressure increases negotiation complexity and reputational risk.</li>
<li><strong>Targeting of Backups and Recovery Systems:</strong> Sophisticated groups now specifically seek out and encrypt or delete backups. When recovery takes longer, business interruption costs (lost revenue, employee idle time, customer impact) skyrocket.</li>
<li><strong>Supply Chain and Third-Party Entry Points:</strong> A single compromised vendor can lead to widespread infection. Mid-market firms often lack the resources to fully vet every partner, creating hidden vulnerabilities.</li>
<li><strong>Regulatory and Insurance Fallout:</strong> Stricter incident reporting rules (e.g., SEC requirements, state laws) and cyber insurance carriers demanding higher deductibles or denying coverage for unprepared organizations add financial strain.</li>
</ol>
<p>&nbsp;</p>
<h4>Quantifying the Real Impact</h4>
<p>A useful framework for understanding ransomware risk is Annualized Loss Expectancy (ALE):</p>
<p>● <strong>Single Loss Expectancy (SLE):</strong> Estimated cost of one successful incident (downtime, recovery, legal, PR, etc.)</p>
<p>● <strong>Annual Rate of Occurrence (ARO):</strong> How often you expect an incident in a given year (e.g., 0.1 = once every 10 years)</p>
<p>● <strong>ALE = SLE × ARO</strong></p>
<p>For many mid-market organizations, even a conservative estimate shows ALE in the hundreds of thousands to millions annually, making proactive investment in prevention and resilience far more cost-effective than reacting after an attack.</p>
<p>&nbsp;</p>
<h4>Practical Prevention and Resilience Strategies</h4>
<p>Here are actionable steps that mid-market teams can implement without massive budgets or overhauls:</p>
<ol>
<li><strong>Implement the 3-2-1 Backup Rule (and Test It)</strong>:
<ul>
<li>Three copies of data</li>
<li>On two different media types</li>
<li>One copy offsite and immutable test monthly restores—unverified backups are a common failure point.</li>
</ul>
</li>
<li><strong>Segment Networks Aggressively:</strong> Isolate critical systems (finance, HR, customer data) so that one compromised endpoint cannot spread laterally. Use micro-segmentation where possible.</li>
<li><strong>Adopt Multi-Factor Authentication (MFA) Everywhere:</strong> Prioritize hardware keys or biometrics for admin accounts and remote access. Phishing resistant MFA blocks the majority of initial entry points.</li>
<li><strong>Run Regular Incident Response Tabletop Exercises:</strong> Simulate a ransomware scenario with your leadership team quarterly. These sessions clarify roles, reduce panic, and uncover gaps in communication and decision-making—often more valuable than technology alone.</li>
<li><strong>Conduct an Independent Quantified Risk Assessment Annually:</strong> A knowledgeable cybersecurity company understand the right questions to ask to address changes in your environment (technically and non-technically) and can update the risk quantification for your organization. This is essential in helping prioritize your focus and spending (e.g., spending $40K on better backups and training could reduce ALE by $300K).</li>
</ol>
<p>&nbsp;</p>
<h4>Looking Ahead with Confidence</h4>
<p>Ransomware in 2026 is serious, but it is not inevitable. Organizations that prepare thoughtfully, quantify their risks and focus on resilience rather than reaction are far better positioned to weather incidents with minimal disruption.</p>
<p>As a cybersecurity boutique, Guard Street specializes in a tailored approach with quantification and AI strategic considerations to deliver vulnerability assessments, tabletop exercises, and compliance guidance as your dedicated cybersecurity partner. Connect with us for a complimentary consultation to map these strategies to your environment.</p>
<p>We’d be happy to discuss how these approaches could apply to your organization. Feel free to reach out for a complimentary conversation.</p>
<p><em><strong><a href="http://guardstreet.com/connect">Connect with Guard Street</a></strong></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/the-rising-cost-of-ransomware-in-2026-real-world-impact-and-prevention-strategies/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2026 Cybersecurity Landscape: Key Threats and Proactive Strategies</title>
		<link>https://guardstreet.com/2026-cybersecurity-landscape-key-threats-and-proactive-strategies/</link>
					<comments>https://guardstreet.com/2026-cybersecurity-landscape-key-threats-and-proactive-strategies/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 15 Jan 2026 18:44:52 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3569</guid>

					<description><![CDATA[The new year brings a cybersecurity environment shaped by rapid technological advances and persistent, evolving risks. For mid-market organizations, the focus remains on practical measures that deliver meaningful protection without unnecessary complexity. This overview highlights four key threats anticipated in 2026 and actionable strategies to address them, grounded in current trends and real-world data.    [...]]]></description>
										<content:encoded><![CDATA[<p>The new year brings a cybersecurity environment shaped by rapid technological advances and persistent, evolving risks. For mid-market organizations, the focus remains on practical measures that deliver meaningful protection without unnecessary complexity. This overview highlights four key threats anticipated in 2026 and actionable strategies to address them, grounded in current trends and real-world data.</p>
<p>&nbsp;</p>
<h4>1. AI-Enhanced Social Engineering and Phishing</h4>
<p>AI tools are enabling attackers to craft highly personalized phishing emails, deepfake voice calls and videos, and adaptive malware that evades traditional detection. Reports indicate a 30-50% rise in AI-assisted phishing attempts in late 2025, targeting supply chains and remote workers.</p>
<p><strong>Proactive Steps:</strong></p>
<ul>
<li>Implement multi-factor authentication (MFA) across all accounts, prioritizing hardware keys or biometrics for high-risk users.</li>
<li>Conduct monthly phishing simulations with immediate, non-punitive feedback to build team awareness.</li>
<li>Use AI-powered email filters that analyze behavioral patterns, not just signatures, for early anomaly detection.</li>
</ul>
<p>These steps create a human-technical hybrid defense, reducing breach likelihood by up to 99% according to recent NIST guidelines.</p>
<p>&nbsp;</p>
<h4>2. Ransomware Targeting Backup and Recovery Systems</h4>
<p>Ransomware groups continue to evolve, with 2025 seeing increased attacks on cloud backups and immutable storage. Mid-market firms face average recovery costs of $200K-$2.5M per incident, often driven by downtime rather than ransom payments.</p>
<p>Proactive Steps:</p>
<ul>
<li>Maintain 3-2-1 backups: three copies, two media types, one offsite/immutable, tested monthly for restorability.</li>
<li>Perform annualized loss expectancy (ALE) calculations to quantify ransomware impact.
<ul>
<li>Multiply single loss expectancy (SLE) by annual rate of occurrence (ARO) for prioritized budgeting.</li>
</ul>
</li>
<li>Segment networks to limit lateral movement, ensuring critical systems remain isolated during an attack.</li>
</ul>
<p>Preparation like this minimizes disruption, allowing most organizations to recover in hours rather than days.</p>
<p>&nbsp;</p>
<h4>3. Supply Chain and Third-Party Vulnerabilities</h4>
<p>Interconnected ecosystems amplify risks, as seen in 2025 supply chain breaches affecting thousands of mid-market vendors. Weak access controls in SaaS tools and unpatched third-party APIs remain common entry points.</p>
<p><strong>Proactive Steps:</strong></p>
<ul>
<li>Adopt a zero-trust model: Verify every access request with least-privilege principles, regardless of user location.</li>
<li>Review vendor contracts quarterly for shared security responsibilities, focusing on SOC2 Type II reports and incident response SLAs.</li>
<li>Map your supply chain digitally and run automated scans for known exploited vulnerabilities (e.g., via tools aligned with CISA&#8217;s KEV catalog).</li>
</ul>
<p>This approach extends your security perimeter effectively, without requiring a full infrastructure overhaul.</p>
<p>&nbsp;</p>
<h4>4. Evolving Compliance and Regulatory Pressures</h4>
<p>Frameworks like SOC2, CMMC, PCI, and cyber insurance mandates are tightening, with Q4 renewals driving 40% of mid-market audits. Non-compliance risks include 20-30% premium hikes or coverage denials.</p>
<p><strong>Proactive Steps:</strong></p>
<ul>
<li>Create a compliance roadmap aligning NIST CSF 2.0 with your industry (e.g., CMMC Level 2 for DoD contractors, HIPAA for healthcare-adjacent firms).</li>
<li>Automate control evidence collection for audits, focusing on high-impact areas like data encryption and incident logging.</li>
<li>Schedule annual gap assessments to track maturity, turning compliance into a competitive edge for insurance negotiations.</li>
</ul>
<p>Forward planning here not only avoids penalties but strengthens overall resilience.</p>
<p>&nbsp;</p>
<h4>Moving Forward Thoughtfully</h4>
<p>Cybersecurity in 2026 rewards organizations that prioritize preparation over reaction. By quantifying risks through models like ALE, layering defenses thoughtfully, and aligning with compliance realities, mid-market teams can protect operations with confidence.</p>
<p>As a cybersecurity boutique, Guard Street specializes in a tailored approach with quantification and AI strategic considerations to deliver vulnerability assessments, tabletop exercises, and compliance guidance as your dedicated cybersecurity partner. Connect with us for a complimentary consultation to map these strategies to your environment.</p>
<p><em><strong><a href="http://guardstreet.com/connect">Connect with Guard Street</a></strong></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/2026-cybersecurity-landscape-key-threats-and-proactive-strategies/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Ghost in the Inbox: Why Phishing Attacks Still Haunt Businesses Despite Training</title>
		<link>https://guardstreet.com/the-ghost-in-the-inbox-why-phishing-attacks-still-haunt-businesses-despite-training/</link>
					<comments>https://guardstreet.com/the-ghost-in-the-inbox-why-phishing-attacks-still-haunt-businesses-despite-training/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 21 Aug 2025 03:12:46 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3421</guid>

					<description><![CDATA[In the realm of cybersecurity, real-world incidents often highlight vulnerabilities that theoretical knowledge alone cannot address. Consider a recent case from an IT professional: An employee in the marketing department received an email sharing what seemed to be a project update from an unfamiliar collaborator. The message was crafted to appear as if it came  [...]]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;">In the realm of cybersecurity, real-world incidents often highlight vulnerabilities that theoretical knowledge alone cannot address. Consider a recent case from an IT professional: An employee in the marketing department received an email sharing what seemed to be a project update from an unfamiliar collaborator. The message was crafted to appear as if it came from a co-worker, urging the recipient to open the attached PDF for details.</span></p>
<p><span style="font-weight: 400;">The unsettling detail? The impersonated co-worker had passed away nearly a year earlier.</span></p>
<p><span style="font-weight: 400;">This was no ordinary email—it was a sophisticated phishing attack, leveraging social engineering to mimic internal communications and exploit trust. Scans of the employee&#8217;s computer and the network fortunately detected no malware or breaches. However, the risk was significant: Potential deployment of malicious software, theft of sensitive data, or even a ransomware outbreak.</span></p>
<p><span style="font-weight: 400;">Compounding the concern, the organization had required all staff to complete cybersecurity training just a month prior. Employees reviewed modules on identifying phishing attempts, avoiding dubious attachments, and escalating suspicions. Yet, this near-miss demonstrates a persistent truth: Awareness does not always translate to action.</span></p>
<p>&nbsp;</p>
<h2><b>The Persistent Threat of Phishing</b></h2>
<p><span style="font-weight: 400;">Phishing continues to be a leading cyber threat, with reports indicating that it initiates over 90% of successful data breaches. Modern attackers refine their methods, using psychological tactics to create convincing forgeries. Impersonating a deceased colleague, as in this example, adds emotional manipulation, making recipients less likely to scrutinize the message.</span></p>
<p><span style="font-weight: 400;">Key indicators of such attacks include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Unexpected updates or shares from unrecognized sources.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Demands for urgent review without standard verification.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Attachments in common formats like PDFs that may conceal harmful code.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Subtle discrepancies in sender information, such as altered email domains.</span></li>
</ul>
<p><span style="font-weight: 400;">The fallout can be severe: Monetary losses, harm to reputation, and compliance violations. For businesses of any size, one breach can prove devastating.</span></p>
<p>&nbsp;</p>
<h2><b>Why Traditional Training Falls Short</b></h2>
<p><span style="font-weight: 400;">While mandatory online training provides foundational knowledge, it is frequently passive and easily forgotten. Participants navigate through content, complete assessments, and resume normal duties—without deeply embedding the principles. In creative roles like marketing, where ideas flow rapidly and collaborations are constant, instinctive reactions prevail, leading to risky decisions like opening unverified attachments.</span></p>
<p><span style="font-weight: 400;">This incident illustrates that intellectual understanding differs from behavioral change. Under pressure, even trained individuals may revert to habits, revealing that some lessons require more than repetition to take hold.</span></p>
<p>&nbsp;</p>
<h2><b>The Power of Tabletop Exercises: Hands-On Defense</b></h2>
<p><span style="font-weight: 400;">Tabletop exercises offer a proactive, interactive alternative to conventional training. These simulations convene teams—either in person or virtually—to enact cyber scenarios, debate strategies, and pinpoint deficiencies in a controlled setting.</span></p>
<p><span style="font-weight: 400;">Envision a session modeling the &#8220;ghost co-worker&#8221; phishing ploy:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Team members encounter simulated emails and evaluate responses.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Group discussions expose issues, such as obsolete directories or inadequate checks.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Participants rehearse protocols, from alerting IT to containing threats.</span></li>
</ul>
<p><span style="font-weight: 400;">Advantages include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Enhanced Engagement and Memory</b><span style="font-weight: 400;">: Practical involvement reinforces concepts far beyond passive learning.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Collaborative Strength</b><span style="font-weight: 400;">: Involving multiple departments builds unity and collective vigilance.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Vulnerability Detection</b><span style="font-weight: 400;">: Identify and address weaknesses preemptively, like flaws in filtering systems.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Tailored Relevance</b><span style="font-weight: 400;">: Adapt exercises to specific sectors, focusing on collaboration-related phishing for relevant teams.</span></li>
</ul>
<p><span style="font-weight: 400;">Research indicates that companies employing tabletop exercises experience up to a 50% drop in phishing successes, as staff cultivate instinctive, secure responses.</span></p>
<p>&nbsp;</p>
<h2><b>Don&#8217;t Let Phishing Ghosts Haunt Your Business</b></h2>
<p><span style="font-weight: 400;">This example serves as a stark reminder: Cyber adversaries target human elements, undeterred by prior trainings. True resilience demands cultivating habits via immersive, practical preparation.</span></p>
<p><span style="font-weight: 400;">Prepared to fortify your defenses? Contact Guard Street Cybersecurity for robust, hands-on tabletop trainings customized to your needs. Our specialists ensure your organization is equipped to handle the unforeseen. Email us at info@guardstreet.com or visit https://guardstreet.com/connect/ to arrange a session. Secure your future today.</span></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/the-ghost-in-the-inbox-why-phishing-attacks-still-haunt-businesses-despite-training/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why Prevention Starts With Your People</title>
		<link>https://guardstreet.com/why-prevention-starts-with-your-people/</link>
					<comments>https://guardstreet.com/why-prevention-starts-with-your-people/#respond</comments>
		
		<dc:creator><![CDATA[Peter Mazza]]></dc:creator>
		<pubDate>Thu, 31 Jul 2025 03:55:54 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://guardstreet.com/?p=3407</guid>

					<description><![CDATA[In today’s digital threat landscape, ransomware continues to rank among the most costly and disruptive cyber threats facing businesses. In 2025, global ransomware damages are projected to exceed $57 billion, with U.S. enterprises disproportionately targeted due to the sensitive data they hold and the high likelihood they can pay up. Despite rising awareness, many organizations  [...]]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;">In today’s digital threat landscape, ransomware continues to rank among the most costly and disruptive cyber threats facing businesses. In 2025, global ransomware damages are projected to exceed </span><b>$57 billion</b><span style="font-weight: 400;">, with U.S. enterprises disproportionately targeted due to the sensitive data they hold and the high likelihood they can pay up.</span></p>
<p><span style="font-weight: 400;">Despite rising awareness, many organizations still approach ransomware as an inevitable technical issue—one best left to antivirus software or IT departments. But the truth is, </span><b>most ransomware attacks begin with a human click</b><span style="font-weight: 400;">, not a machine vulnerability. And that’s where the real opportunity for prevention lies.</span></p>
<h3><b>The True Cost of Ransomware vs. Training</b></h3>
<p><span style="font-weight: 400;">The average cost of a ransomware payment on a mid-sized business exceeds </span><b>$5 million</b><span style="font-weight: 400;">, factoring in downtime, ransom payments, data loss, legal fees, and reputational damage. And the longer it takes to detect and respond to an attack, the more expensive it becomes.</span></p>
<p><span style="font-weight: 400;">Compare that to the cost of proactive, high-quality employee cybersecurity training. A typical program ranges from </span><b>$50 to $300 per employee per year</b><span style="font-weight: 400;">. Even with robust training solutions and tabletop simulations, the total investment is a fraction of what a single attack could cost.</span></p>
<p><span style="font-weight: 400;">The numbers speak for themselves: </span><b>It’s not just more effective to train—it’s significantly more affordable.</b></p>
<h3><b>Understanding Ransomware Tactics</b></h3>
<p><span style="font-weight: 400;">Ransomware isn’t just one-size-fits-all. It comes in many forms, and each is designed to exploit the people and processes within an organization:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Locker Ransomware</b><span style="font-weight: 400;">: Denies access to systems or devices entirely.</span><span style="font-weight: 400;"><br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Crypto Ransomware</b><span style="font-weight: 400;">: Encrypts files and demands payment for the decryption key.</span><span style="font-weight: 400;"><br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Double Extortion</b><span style="font-weight: 400;">: Attackers steal data before encrypting it, threatening to release it if the ransom isn’t paid.</span><span style="font-weight: 400;"><br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Ransomware-as-a-Service (RaaS)</b><span style="font-weight: 400;">: Pre-packaged kits that allow even non-technical criminals to launch sophisticated attacks.</span><span style="font-weight: 400;">
<p></span></li>
</ul>
<p><span style="font-weight: 400;">But the method of entry is almost always the same: </span><b>social engineering.</b></p>
<p><span style="font-weight: 400;">Attackers impersonate trusted sources—CEOs, vendors, IT staff—and use urgency, fear, or curiosity to trick employees into clicking a link, opening an attachment, or sharing credentials. A single moment of distraction can open the door.</span></p>
<h3><b>Training That Actually Works</b></h3>
<p><span style="font-weight: 400;">To prevent ransomware, you don’t just need annual slide decks and checkbox compliance. You need </span><b>training that sticks</b><span style="font-weight: 400;">, training that replicates real-world conditions, and training that evolves alongside the tactics of threat actors.</span></p>
<p><span style="font-weight: 400;">Effective programs include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Training Modules</b><span style="font-weight: 400;">: At one and ideally two short training videos per month that include the foundational topics for a strong cyber posture with quizzes are essential.  People learn through frequency and repetition of a pre-planned curriculum. </span></li>
<li style="font-weight: 400;" aria-level="1"><b>Ongoing Phishing Simulations</b><span style="font-weight: 400;">: Realistic, targeted tests that help employees recognize suspicious messages.  This should be performed in conjunction with the training modules above.</span><span style="font-weight: 400;"><br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Role-Based Education</b><span style="font-weight: 400;">: Tailored training for finance teams, HR, executives, and other high-risk roles.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Onsite or Video Conference Training</b><span style="font-weight: 400;">: This approach reinforces the above training and goes a step further with questions and answers.  It facilitates engagement which is an important aspect of training and retention.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Incident Response Drills</b><span style="font-weight: 400;">: Practice runs that simulate a live ransomware attack and stress-test decision-making.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Tabletop Exercises</b><span style="font-weight: 400;">: Team-based sessions where departments walk through hypothetical scenarios—what they’d see, who they’d alert, and how they&#8217;d respond.</span><span style="font-weight: 400;">
<p></span></li>
</ul>
<h3><b>Where Guard Street Comes In</b></h3>
<p><span style="font-weight: 400;">Guard Street specializes in </span><b>essential cyber training, incident response drills</b><span style="font-weight: 400;">, </span><b>realistic, high-impact tabletop exercises</b><span style="font-weight: 400;"> that go beyond theory. Our simulations aren’t generic—they’re built around your actual environment, risk profile, and common attack vectors. We design experiences that expose gaps, surface unspoken assumptions, and equip your people to recognize and react to ransomware attacks.</span></p>
<p><span style="font-weight: 400;">From IT teams to front-line employees, we help organizations turn human vulnerability into a human firewall.</span></p>
<p><span style="font-weight: 400;">While ransomware attacks may be inevitable—falling for them doesn’t have to be.</span></p>
]]></content:encoded>
					
					<wfw:commentRss>https://guardstreet.com/why-prevention-starts-with-your-people/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
