Knowledge

Articles by tag "digital-edge"

11/10/2021 Compliance

NYS Department of Financial Services – Serious MFA Requirements

One regulation we help clients with is the New York State DFS 23 NYCRR Part 500 compliance.
 
Who does DFS regulate?

According to its website: “DFS is the primary regulator for all state-licensed and state-chartered banks, credit unions, and mortgage bankers and brokers. All mortgage loan servicers doing business in New York State must be registered or licensed by DFS. The Department also oversees all of the insurance companies operating in New York, licenses all of the budget planners, finance agencies, check cashers, money transmitters, and virtual currency businesses operating in New York.”
 
The requirements of part 500 are generally nothing out of the ordinary, or rather, nothing more than what is already considered good practice in the cybersecurity world.

 

11/6/2021 Compliance

Michael Petrov provided his recommendation for risk assessment methodology – CIS RAM 2.0

POSITION ON RISK

  1. Initial risk is 100% (99.9%). I argue, if you deploy a system without any controls and connect it to the internet, it will be hacked multiple times in a year.
  2. Risk = 100% - control mitigation + destabilizing events (zero days, new vulnerabilities).
  3. We may calculate control mitigation but cannot predict those destabilizing events, and this is the nature of the business, and this is why we cannot precisely measure risks. So we don't have to; we can just assess.
  4. Mitigation is NOT lowering the impact but lowering LIKELIHOOD. When there is a cybersecurity breach, it is easier to predict maximum impact, which depends on the time of detection (controls - destabilizing). I would argue that within some short time, the impact could be the cost of the business. 
  5. My biggest problem with current frameworks is that they all concentrate on initial assessment, not the continuous process.
  6. Risk has to be re-assessed yearly, and the methodology is more important for re-assessment compared to the initial assessment.
  7. Incidents should be used to adjust risks as it is real-life data for statistical analysis for the given client. Incidents should be used to re-assess likelihood, and each incident must be bound to a risk and effect KPI.
  8. Methodology should suggest KPI assignment. 

This is the big picture. All I see today is ISO-like risks analyses that are initially made based on industrial risks. The mentality should be changed, and I don't know if it is too big of a shift from the current approach.

11/2/2021 Edgy News

Digital Edge in World's Greatest

12/1/2020 Newsletters

"Standards vs Hackers and Lawmakers" Webinar

5/27/2020 Videos

CEO Message Part 1

Michael Petrov has started a series discussing the values and beliefs of Digital Edge. In this first part, he speaks about the importance of being a perfectionist as well as the three levels of knowledge in regards to technology. 

5/27/2020 Videos

CEO Message Part 2

In the second part of his series, Michael Petrov discusses the importance of trust with a client as well as the different stages of trust you can build with a client. 

7/8/2019 Edgy News

"Digital Edge created a product for Panama Maritime Authority. This product revolutionizes the way ships are regulated."

by: Konstantin Mozgovoy

7/1/2019 Presentations

Digital Edge SOC Overview

7/1/2019 Presentations

Digital Edge Security Frameworks

7/1/2019 Presentations

Digital Edge Security Services