Skip to main content

Cybersecurity Quarterly Winter 2025/26

Page 1

A PUBLICATION FROM

The Journey to Greater Security

Winter 2025/26 Fostering Collaboration and Shared Defense Amongst the Nation's SLTT Organizations Making Security an Integral Part of the Software Development Process Helping Small and Medium-Sized Businesses Navigate the Complexities of Cyber Insurance Why Regularly Assessing Your Organization's Cyber Risk is Key to a Strong Cyber Defense Program

For every organization, the journey to becoming more cyber secure looks different. Regardless of their resources, capabilities, or hurdles, the Center for Internet Security is committed to helping organizations large and small navigate the path to maturing their cybersecurity program.


Cloud security automation is easier than ever. Placement New CISAd hardening components available in EC2 Image Builder on AWS.

GET STARTED


Contents Featured Articles

Quarterly Regulars Cybersecurity Quarterly is published and distributed in March, June, September, and December. Founded MMXVII. Published by Center for Internet Security, 31 Tech Valley Drive, East Greenbush, New York 12061 For questions or information concerning this publication, contact CIS at learn@cisecurity. org or call 518.266.3460 © 2025 Center for Internet Security. All rights reserved.

The MS-ISAC: Strengthening Collective SLTT Cyber Defense Even in light of recent changes, the MS-ISAC continues to foster collaboration and communication among the nation's state, local, tribal, and territorial government organizations to improve their cyber defense

3

How Secure by Design Helps Developers Build Secure Software Collaborating with SAFECode to provide practical guidance to ensure security is built into the software development process

6

The Importance of Conducting Risk Assessments: It’s a Journey, not a Destination Why establishing an effective, and regularly-occurring, risk assessment process in your organization is key to a strong cybersecurity posture

8

Control Assist: A Path to Cyber Insurance Readiness for SMBs New guidance, developed in collaboration with CyberAcuView, to help small and medium-sized businesses utilize the CIS Controls to navigate the complex path to securing cyber insurance

11

Simplify CIS Benchmarks Implementation With a 100-Day Plan How to create a clear roadmap to implementing the CIS Benchmarks in your organization as part of its cybersecurity journey

14

Quarterly Update with John Gilligan

1

News Bits & Bytes

2

Cyberside Chat

16

Event Calendar

18

Winter 2025/26 Volume 9 Issue 4 Editor-in-Chief

Michael Mineconzo Managing Editor

Jay Billington Copy Editors

David Bisson Autum Pylant

Staff Contributors

Jay Billington Stephanie Gass Patrick Johnston Phyllis Lee Robin Regnier Karen Sorady

Winter 2025/26

i


Ad Placement

www.sans.org/partnerships/sltt


QuarterlyUpdate

with John Gilligan

“Every organization has a different journey from having little or no security to a fully robust security program" It is mid-December and the snow is already falling in the area of Washington, D.C. Winter has indeed arrived. In the last issue of Cybersecurity Quarterly, I noted the transition of the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) to a fee-based membership model. We have made amazing progress in just a few months. We now have 23 states and one territory that are on board or in the process of onboarding a state membership. Of that group, 16 states and one territory have signed up for a State/Territory-Wide membership. Approximately 30,00 local organizations from these states and territory are now eligible to join the MS-ISAC. The remaining seven states have opted for the StateLevel (Transitional) membership, which does not include membership for local organizations but does include all organizations at the state level such as legislatures, judicial branches, and independent state-level agencies. For these states and territory, the MS-ISAC is starting to work with each to define activities to improve security across the entire state or territory. We're referring to this as implementing a "whole of state" approach. Each whole-of-state effort is a partnership between the state/ territory and the MS-ISAC to engage every local entity to improve its security resilience through education and training, relevant best practices, tailored policies, common risk management practices, and effective use of defensive tools. Each state/territory will have a unique implementation plan based on its progress to date and its unique priorities. The whole-of-state effort is a vital part of the MS-ISAC’s efforts to improve the collective defense posture of the nation in response to increasing threats from hostile foreign powers, cartels, and criminal gangs. In the coming Cybersecurity Quarterly issues, we will report on progress in implementing whole-ofstate efforts with these states and territory as well as the onboarding of additional states and territories. The theme for this quarter’s issue is the cybersecurity journey. It has become a focus at the Center for Internet Security® (CIS®), as we recognize that every organization has a different journey from having little or no security to a fully robust security program. Moreover, the actions and

support that are required to mature an organization differ depending on the stage of an organization’s journey. This focus has helped us identify practices, processes, and tools that are relevant for small, so-called "cyber underserved" organizations, as well as those that are relevant for large organizations such as a state government. In this issue of Cybersecurity Quarterly, Karen Sorady, CIS’s Vice President of MS-ISAC Strategy and Plans, discusses the national imperative of strengthening collective cyber defense and how the MS-ISAC is working with U.S. State, Local, Tribal, and Territorial (SLTT) organizations toward that goal. Meanwhile, Phyllis Lee, CIS’s VP of Security Best Practice Content Development, describes a recent publication developed with SAFECode.org that takes the concept of secure by design and prioritizes actions that developers of software should take to ensure resilient software. The recent guide also provides specific metrics that must be satisfied for each prioritized action. In a second article, Lee provides an update on CIS’s work with insurance companies, specifically helping them to simplify cyber insurance underwriting for small and medium-sized businesses. Shehzad Mirza, Director of Operations at CyberWA, writes on the importance of conducting risk assessments on a continuing basis, while our partners at SteelCloud examine how to develop a plan for implementing CIS Benchmarks® in your organization. Finally, Stephanie Gass, CIS’s Senior Director for Information Security, outlines practical steps for improving cybersecurity policies and procedures in the new year. I hope you enjoy this quarter’s issue. Stay warm! Best Regards,

John M. Gilligan President & Chief Executive Officer Center for Internet Security Winter 2025/26

1


NewsBits&Bytes CIS Announces Built-In Linux Benchmarks Now Available on Microsoft Azure The Center for Internet Security® (CIS®) has collaborated with Microsoft to bring industry-standard security guidance into Microsoft Azure as a built-in capability by embedding CIS Benchmarks® for all available Azure-endorsed Linux distributions; this brings secure-by-design principles to the operating system level and enables organizations to automatically apply trusted, audit-ready security configurations across cloud and hybrid environments without manual setup, customization, or guesswork. This integration is powered by Azure Machine Configuration and the new azure-osconfig compliance engine, allowing organizations to implement compliance as code at scale while strengthening their overall security posture. It marks a strategic shift in how enterprises approach cloud-native compliance. Learn more about our collaboration here.

CIS Launches New CIS SecureSuite Platform Thousands of CIS SecureSuite® Members rely on CIS tools and resources to simplify the process for implementing the secure recommendations of the CIS Benchmarks®. With the release of our CIS SecureSuite Platform, it's now even easier for Members to harden their systems. The CIS SecureSuite Platform brings trusted guidance from CIS into one unified experience. Built exclusively for CIS SecureSuite Members, the Platform consolidates tools — specifically, CIS CSAT Pro and CIS-CAT® Pro Dashboard — into a single interface, making security management scalable and actionable. Learn more about the CIS SecureSuite Platform here.

CIS Controls Central to Ohio’s New Cybersecurity Law for Political Subdivisions CIS played a key role in Ohio’s new cybersecurity law through the inclusion of its CIS Critical Security Controls® (CIS Controls®) in House Bill 96 (HB 96) signed by Governor Mike DeWine. The law requires political subdivisions — including counties, municipalities, and townships — to begin implementing cybersecurity measures based on the CIS Controls and the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF). Political subdivisions may choose to align with either the NIST CSF, CIS Controls, or a combination of both. By incorporating CIS Controls, the law ensures that public entities have access to prioritized, actionable safeguards tailored to their operational needs. Learn more about the legislation here.

2

Cybersecurity Quarterly

CIS, Astrix, and Cequence Unite to Deliver Actionable Guidance for Securing AI Environments The Center for Internet Security® (CIS®), Astrix Security, and Cequence Security have announced a strategic partnership to develop new cybersecurity guidance tailored to the unique risks of artificial intelligence (AI) and agentic systems. This collaborative initiative builds on the globally-recognized CIS Critical Security Controls® (CIS Controls®), extending its principles into AI environments where autonomous decision‑making, tool and API access, and automated threats introduce new challenges. The intent of the partnership includes developing two CIS Controls companion guides: one for AI agent environments, which will focus on securing the agent system lifecycle; the other for Model Context Protocol (MCP) environments. Together, these guides will provide targeted safeguards for organizations operating in environments where MCP agents, tools, and registries interact dynamically with enterprise systems. Learn more about the partnership here.


The MS-ISAC: Strengthening Collective SLTT Cyber Defense For state, local, tribal, and territorial (SLTT) organizations, defending against the ever-growing threat of cyber attacks can be daunting, especially when resources are limited. That's why leaning on the collective knowledge and strength of the larger SLTT community is critical to developing a strong cyber defense strategy.

By Karen Sorady Not long ago, a mid-sized county faced a critical moment: a phishing campaign targeting its public safety systems threatened to disrupt emergency services and compromise sensitive data. Alone, the county’s IT team would have struggled to detect and contain the attack before damage occurred. However, it wasn't alone. It was part of the Multi-State Information Sharing and Analysis Center® (MS-ISAC®). The MS-ISAC exists for moments like this. Built on the principle of collective defense, it transforms isolated cybersecurity efforts into a unified, nationwide network of U.S. State, Local, Tribal, and Territorial (SLTT) government organizations working together. Through real-time collaboration, shared learning, and coordinated response, the MS-ISAC helps communities turn intelligence into action when it matters most.

Built on the principle of collective defense, the MS-ISAC transforms isolated cybersecurity efforts into a unified, nationwide network of U.S. State, Local, Tribal, and Territorial (SLTT) government organizations working together. Through real-time collaboration, shared learning, and coordinated response, the MS-ISAC helps communities turn intelligence into action when it matters most. Unmatched Strength Through Numbers The phishing campaign was identified early because of the MS-ISAC’s scale and reach. Thousands of U.S. SLTT organizations contribute telemetry and insights, creating a powerful early-warning system. When indicators of compromise (IOCs) appeared in one jurisdiction, alerts were shared across the network, giving others the chance to block the threat before it spread. What could have been days of downtime and costly recovery became a minor incident mitigated in hours. This is the strength of collective defense. Today, entire states and territories are embracing whole-of-state Winter 2025/26

3


cybersecurity through State/Territory-Wide membership, which affords the full benefits of MS-ISAC membership to every public sector organization in the state or territory, including public K-12 schools, power or water utilities, hospitals, libraries, and law enforcement agencies. With the current states and territories committed to State/Territory-Wide membership, our eligible member population now exceeds 27,000 U.S. SLTT organizations — far surpassing our historical peak of just under 19,000 member organizations under the previous no-cost membership.

Intelligence that Makes a Difference At its core, the MS-ISAC is an information sharing and analysis center, designed for collaboration across all hazards. Its intelligence goes beyond generic feeds, delivering U.S. SLTT-specific, multidimensional threat alerts enriched with federal and commercial data. From ransomware and phishing to emerging risks like AI-driven attacks and supply chain vulnerabilities, this multidimensional threat intelligence helps leaders

Unlock Premium Cyber Defense The MS-ISAC’s low-cost, U.S. SLTT-tailored cybersecurity tools and services enable states to extend affordable, scalable capabilities across agencies and communities, reducing cyber risk and minimizing service disruptions. U.S. SLTTs whose states haven’t signed up for State/ Territory-Wide membership can also sign up for a Single Organization membership — including at low- or even no-cost to organizations with the smallest budgets — to receive the same protection. Membership benefits include: •

Advanced Threat Intelligence: Deeper insights into emerging threats and vulnerabilities

•

Priority Incident Response: Faster, dedicated support during critical events

•

Customized Security Services: Tailored assessments and recommendations for U.S. SLTT organizations

•

Exclusive Reports and Briefings: Strategic intelligence for executives and decision-makers.

4

Cybersecurity Quarterly

prioritize resources and align response strategies before threats escalate.

Who We Serve: Beyond Just Cyber and IT The MS-ISAC isn’t just for cybersecurity and IT professionals. It’s for every U.S. SLTT leader with a stake in protecting their community. We provide tailored intelligence and resources for every level of leadership, from governors shaping statewide policy to school superintendents responsible for safeguarding student data, from law enforcement executives defending public safety systems to owners and operators managing critical infrastructure. Whether it’s strategic briefings for decision-makers or hands-on support for technical teams, the MS-ISAC ensures that all stakeholders have the tools they need to act confidently against cyber threats. From small towns to large states, this community-driven approach scales protection without leaving anyone behind. Karen Sorady is the Vice President of the MS-ISAC Strategy and Plans division at the Center for Internet Security® (CIS®). In this role, Sorady's focus is on establishing relationships with key member segments, including the MS-ISAC Executive Committee, external association partners, and the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, to develop strategies and plans to provide solutions and best practices which positively impact the cybersecurity interests of our U.S. SLTT members. Sorady has a wealth of experience in cybersecurity and information technology having retired as New York State’s Chief Information Security Officer after a more than 30-year public sector career. Her background includes executive cyber and information technology leadership, governance, strategic planning, risk management, security outreach and awareness, threat and vulnerability management, and incident response. Sorady holds a Master of Business Administration from the University of Albany, NY, and a Bachelor of Arts in Psychology from the State University College at Oneonta, NY. She holds certifications as an Information Systems Security Professional (CISSP), in Risk and Information Security Controls (CRISC), and in Strategic Planning, Policy and Leadership (GSTRT).


Benefits SLTTs Gain From MS-ISAC Membership The MS-ISAC helps SLTT teams stay ahead of threats, respond faster, and protect the communities they serve.

1 3 5

Statewide Insight into Cybersecurity Progress

2

Faster Advanced Warning of Verified Cyber Threats

Ad Placement 24x7x365 Expert Cybersecurity Support for Public Organizations

Secure Information Sharing across Agencies & Communities

4 6

Cross-Sector Coordination that Builds Resilience

Time-Saving Tools and Resources for Every Public Entity

LEARN MORE


How Secure by Design Helps Developers Build Secure Software In today's world, security can no longer be an afterthought. It is crucial that a strong security foundation is built into the software development process. That's why CIS and SAFECode worked together to provide practical guidance to integrate security into every step of the software development lifecycle.

By Phyllis Lee Security isn’t just a feature; it’s a foundation. As cyber threats grow more sophisticated and regulations tighten, developers are being asked to do more than just write clean code. They’re being asked to build software that’s secure by design throughout its lifetime. To help developers meet this challenge, the Center for Internet Security® (CIS®) and the Software Assurance Forum for Excellence in Code (SAFECode) released Secure by Design: A Guide to Assessing Software Security Practices. This guide offers practical, risk-based strategies for integrating security into every phase of the software development lifecycle — tailored to real-world development environments.

Why Secure by Design Matters The Secure by Design initiative, launched by the Cybersecurity and Infrastructure Security Agency (CISA) in 2023, urges technology vendors to prioritize customer security and reduce exploitable flaws at the source. But with fragmented guidance across frameworks like the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF),

As cyber threats grow more sophisticated and regulations tighten, developers are being asked to do more than just write clean code. They’re being asked to build software that’s secure by design throughout its lifetime. 6

Cybersecurity Quarterly

Building Security in Maturity Model (BSIMM), and SAFECode’s own practices, developers have lacked a unified path forward — until now. This guide bridges that gap by aligning with NIST’s SSDF, mapping practices to the CIS Critical Security Controls® (CIS Controls®) and adapting recommendations to different organizational maturity levels using SAFECode’s Development Groups (DGs) model.

Six Secure by Design Considerations Every Developer Should Know The guide breaks Secure by Design into six essential areas. Here’s what developers need to focus on: 1. Secure Software Design Start with clear security objectives and a threat model. Whether you’re building for a niche application or a


your security standards. And if they don’t, fill the gaps with scans, tests, and feedback loops. 5. Code Integrity Security isn’t just about writing good code; it’s about ensuring the code you ship is the code you intended. Use version control, code signing, and change tracking to prevent tampering. Configure your development environment with least privilege and zero trust principles. And secure your tools, as they’re part of your attack surface. 6. Vulnerability Remediation No software is perfect. Accept vulnerability reports, investigate them, and fix the issues. Sponsor bug bounties, publish advisories using standards like the Common Security Advisory Framework (CSAF), and provide context on severity and exploitability. And critically important, use root cause analysis to improve your tools, training, and threat models. If you rely on external tools, give feedback to help them evolve. broad user base, your architecture must reflect the risks your software is expected to resist. Threat modeling isn’t optional; it’s your blueprint for resilience and needs to be maintained as the software and its use change. 2. Secure Development Coding, testing, deployment, and maintenance are where most vulnerabilities emerge. Align your practices with NIST SSDF and tailor them to your tools, languages, and platforms. Whether you’re working in containers, mobile apps, or embedded systems, the principles remain: validate inputs, manage secrets, and automate security checks. 3. Secure Default Configuration Most users stick with default settings, so make them secure. Disable unnecessary features, restrict access, and minimize the attack surface. If 80% of users don’t need a feature, it should be off by default. This offers more than just good hygiene; it provides a frontline defense. 4. Supply Chain Security Third-party code is everywhere, and it’s a risk. Vet, monitor, and manage the components you didn’t write and ensure that their security is maintained over time. Use contracts, audits, and internal reviews. If you rely on open-source or commercial tools, make sure they meet

Built for Developers, Not Just Auditors Secure by Design: A Guide to Assessing Software Security Practices goes beyond just telling you what to do; it also helps you understand why it matters and how to tailor it to your organization’s maturity level. Using SAFECode’s DGs model, this guide helps you prioritize high-value activities whether you’re a lean startup or a large enterprise. And it provides guidance that helps you understand the implications of artificial intelligence and machine learning for the security of your software. Security is a continuous process. But with the right framework, you can build software that’s secure by design, not just by accident. Level up your secure development practices and build with confidence. Phyllis Lee is the Vice President of SBP Content Development at the Center for Internet Security (CIS). She has over 25 years of experience in information assurance and has performed vulnerability assessments, virtualization research, and worked in security automation. Prior to joining CIS, Lee worked at the National Security Agency (NSA) focusing on the intersection between malware and virtualization, which included collaboration with MIT Lincoln Labs. Lee also participated in a variety of security automation standardization efforts and led the security automation strategy for the NSA Information Assurance Directorate (IAD). She graduated from Johns Hopkins University with a master of science in computer science.

Winter 2025/26

7


The Importance of Conducting Risk Assessments: It’s a Journey, not a Destination Your security team can't defend against risks it doesn't know exist. In a constantly evolving threat landscape, your organization not only needs to perform risk assessments, but do so regularly to track progress and reevaluate threats.

By Shehzad Mirza In today’s fast-moving business environment, every organization, whether a nonprofit, startup, government entity, or global corporation, faces the same and ever-increasing risks. These risks can threaten operations, reputations, finances, employees, or customers. The ability to recognize and address such threats before they materialize is critical for a company. That is why performing ongoing risk assessments is not just a regulatory requirement or a best practice. They are a strategic necessity. Risk assessments are a structured process used to identify potential hazards, evaluate how likely they are to occur, and determine the impact they could have on an organization. Once these risks are understood,

These risks can threaten operations, reputations, finances, employees, and/ or customers. The ability to recognize and address such threats before they materialize is critical for a company. That is why performing ongoing risk assessments is not just a regulatory requirement or a best practice. They are a strategic necessity. organizations can prioritize actions to be taken to reduce the likelihood of these risks and minimize the potential damage from the risk. Risks can come from anywhere: cyber threats, supply chain disruptions, natural disasters, employee misconduct, or outdated technology. The goal of a risk assessment is to uncover these potential hazards and build in layers of defense before they become a crisis.

Protecting Assets Every organization has valuable assets, including intangible assets like data, brand reputation, customer relationships, and physical property such as equipment

8

Cybersecurity Quarterly


or buildings. A risk assessment helps map out which threats could harm these assets and how damaging the consequences could be. The risk assessment will help to identify sensitive systems, evaluate their vulnerabilities, and recommend stronger safeguards that could reduce or even prevent damages/losses.

Ensuring Operational Continuity Continuous business operation is essential to ensure trust and reliability. However, many organizations fail to prepare for disruptions until one actually occurs. A risk assessment should help to expose how certain processes could be interrupted, for instance, if key employees suddenly leave, if a critical system is being exploited, or if a natural disaster shuts down facilities. Knowing the value of what is at risk is essential to protecting it. With this knowledge, organizations can create contingency plans such as backup suppliers, emergency staffing arrangements, or data recovery procedures. These proactive steps help ensure that, even in the face of unexpected events, the organization can continue functioning with minimal interruption.

Enhancing Legal Compliance and Reducing Liability Regulatory requirements are increasing across almost every industry. Privacy laws like GDPR and California Privacy Rights Act (CPRA), financial and health compliance standards, and environmental rules all require that organizations take responsibility for managing risks. Conducting a risk assessment not only helps to meet these legal requirements; it can also reduce liability by proving that an organization took reasonable steps to reduce the risks.

When employees see that leadership prioritizes risk management, they are more likely to report issues, follow policies, and play an active role in safety and security. This collective awareness strengthens the organization at every level. Failing to comply can lead to fines, lawsuits, and damage to corporate reputation. A documented, ongoing risk assessment process demonstrates due diligence and protects organizations against claims of negligence or misconduct.

Safeguarding Employees Risk assessments also protect a company’s most valuable asset, its people. Employees need a safe environment to work effectively. By identifying workplace hazards such as unsafe equipment, poor building infrastructure, harassment risk, overworked staff, and mental health challenges, organizations can take proactive steps to prevent accidents, burnout, or toxic work environments. Risk assessments can foster a culture of responsibility and transparency. When employees see that leadership prioritizes risk management, they are more likely to report issues, follow policies, and play an active role in safety and security. This collective awareness strengthens the organization at every level.

A Proactive Path Toward Organizational Success Once a risk assessment is completed, it will lead to development, improvement, and/or implementation of appropriate policies and procedures. With the results of the risk assessment, you should have an appropriate or improved business continuity plan, acceptable use policy, employee handbook, information security policy, etc. An organization will have the risks documented in a risk register, which should be reviewed on a quarterly basis with executive staff and board members. A risk register is a document that identifies and prioritizes current and potential risks for the organization. Each risk will have details such as a description of the risk, the likelihood of the risk occurring, the impact on the organization, the strategy to mitigate the risk (or business case to accept the risk), and the party responsible for mitigating the risk. Winter 2025/26

9


The true value of a risk assessment lies in its proactive nature. We do not live in a static environment; therefore, it is critical to periodically measure in order to track progress as well as emerging threats. This documentation will serve as a due diligence document to better protect the organization. There are many tools (such as CyberWA Cyber Audit Platform), techniques, and resources (NIST and Center for Internet Security® (CIS®) guidelines) that can be used to get started with a risk assessment. Make sure that the appropriate stakeholders are involved to help cover all aspects of the organization. Start with the basics and then work up to more complex areas to lead to the final risk register. The true value of a risk assessment lies in its proactive nature. We do not live in a static environment; therefore, it is critical to periodically measure in order to track progress as well as emerging threats. It shifts organizations away from reacting to a crisis and toward anticipating and preventing them. Through risk assessments, organizations can protectively safeguard their assets, comply with regulations, protect employees, and maintain business continuity. Effective risk management should not be seen as a cost burden but rather as a strategic investment that protects enterprise value, safeguards employees, and ensures the organization can grow even in unpredictable environments. Regardless of the tools or methodologies employed, risk assessments, along with their findings and mitigation strategies, serve as critical elements of an organization’s overall business strategy. The assessment lifecycle requires the continual identification of both existing and emerging risks, followed by their measurement and ongoing monitoring, to ensure the implementation of appropriate and effective organizational responses. Shehzad Mirza serves as Chief Security Officer and VP of Organizational Services at CyberWA, where he is responsible for the company’s strategic and operational cyber security objectives and the senior executive lead on developing and implementing CyberWA’s organizational security services.

10

Cybersecurity Quarterly

Shehzad Mirza was the former Director of IT & Security Operations for Global Cyber Alliance (GCA), a not-forprofit organization whose mission is to eliminate cyber risks around the globe. Additionally, he was the product owner for three projects. Those projects were the DMARC project, GCA Toolkit v2, and the GCA AIDE (IoT) project. Prior to joining GCA, Mizra was a manager in the Advisory Services practice, as part of the security monitoring group, of Ernst & Young LLP. He also served as Senior Director of Security Operations at CIS, where he was responsible for managing security operations, which included the 24x7x365 CIS Security Operations Center (SOC) consisting of security analysts and intel analysts providing cybersecurity and detection/notification services to all state and local governments across the United States for the Multi-State Information Sharing and Analysis Center® (MS-ISAC®). Mizra started his career in cybersecurity as a consultant with Symantec working and managing a 24x7 SOC for the State of New York. He started as an analyst and within four years managed the SOC.


Control Assist: A Path to Cyber Insurance Readiness for SMBs Many organizations are looking to integrate cyber insurance into their overall cyber defense strategy. Especially for small and medium-sized businesses, navigating the complex application process can be a challenge. Control Assist offers these organizations a clearer path to meeting the necessary requirements.

By Phyllis Lee Small and medium-sized businesses (SMBs) are increasingly exposed to cyber threats, yet many struggle to secure cyber insurance due to the complexity of the application process and uncertainty around what insurers expect. To address this challenge, the Center for Internet Security® (CIS®) and CyberAcuView have partnered to launch Control Assist™, a groundbreaking initiative designed to simplify cyber insurance and strengthen cybersecurity for SMBs.

Bridging the Gap Between Cybersecurity and Insurance Control Assist is a strategic framework that connects two traditionally disconnected domains: cybersecurity and insurance underwriting. At its core, Control Assist aligns Implementation Group 1 (IG1) of the CIS Critical Security Controls® (CIS Controls®), a globally recognized standard for essential cyber hygiene, with the most common questions found in cyber insurance applications. This alignment creates a shared language that enables SMBs to clearly demonstrate their cybersecurity posture, insurers to assess risk with greater precision, and vendors to showcase how their technologies support insurance readiness. The result is a more transparent, efficient, and resilient cyber insurance ecosystem.

SMBs and the Cyber Risk Gap SMBs face three significant challenges when it comes to managing cyber risk: constrained budgets and staffing, lower levels of cyber maturity, and increasingly sophisticated attackers targeting smaller organizations.

Recent data paints a stark picture. According to the 2025 Verizon Data Breach Investigations Report, the majority of ransomware attacks now target SMBs, with extortion malware appearing in 88% of SMB breach incidents — more than double the rate at larger enterprises. Recent data paints a stark picture. According to the 2025 Verizon Data Breach Investigations Report, the majority of ransomware attacks now target SMBs, with extortion malware appearing in 88% of SMB breach incidents — more than double the rate at larger enterprises. Ransomware has become one of the most common and costly cyber threats facing SMBs today. For many SMBs, the path to obtaining cyber insurance remains confusing and resource-intensive. They often struggle to interpret insurers’ security questionnaires, identify which controls matter most, and prove that they’ve implemented effective safeguards. The result is a disconnect. Businesses are eager to manage cyber risk but are uncertain how to demonstrate readiness, while insurers are eager to underwrite policies but are facing inconsistent, unstandardized information. That gap is exactly where Control Assist steps in.

Winter 2025/26

11


Why Control Assist Matters Many SMBs lack the internal expertise or resources to navigate the insurance process or prioritize cybersecurity investments effectively. Control Assist offers a practical, actionable roadmap that connects security controls to insurance requirements. By translating technical cybersecurity practices into terms familiar to insurers, Control Assist reduces confusion, accelerates coverage decisions, and empowers SMBs to take meaningful steps toward both stronger security and smoother insurance access.

Key Benefits Across the Ecosystem Control Assist delivers tangible benefits to all stakeholders involved in the cyber insurance process: •

Simplifies the cyber insurance application process by mapping technical security controls to familiar insurance questions

•

Reduces risk of misinterpretation or missing information that can lead to delayed or denied claims

•

Guides SMBs toward the most critical investments for defending against common cyber attacks

•

Gives insurers standardized, verifiable evidence of an organization’s security maturity

•

Enables security vendors to demonstrate how their products support insurance readiness

This shared framework fosters collaboration, trust, and transparency across the cybersecurity and insurance

By translating technical cybersecurity practices into terms familiar to insurers, Control Assist reduces confusion, accelerates coverage decisions, and empowers SMBs to take meaningful steps toward both stronger security and smoother insurance access. industries, driving better outcomes for SMBs and the broader digital economy.

Industry Collaboration and Technical Validation To maximize the impact of Control Assist, CIS and CyberAcuView collaborated with eight leading cybersecurity and technology companies: Amazon Web Services (AWS), CrowdStrike, SentinelOne, FirstWatch Technologies, Safe Security, Spektrum Labs, Palo Alto Networks, and one additional industry partner. These partners mapped their products to the Control Assist question set, identifying which CIS Controls can be automatically validated based on the technology in use. This mapping allows SMBs to leverage existing tools to verify their security posture, reducing the burden of manual documentation and accelerating the insurance process. The mapping highlights which controls can be technically confirmed using these solutions. Importantly, the absence of a validated answer does not imply that a control is missing; it may simply require manual confirmation. Control Assist is more than a one-time mapping exercise; it's a foundation for future innovation across the cyber insurance and cybersecurity ecosystem. Some of the opportunities we see on the horizon include:

12

Cybersecurity Quarterly

•

Expanded mappings: Extending beyond IG1 to include IG2 and IG3, providing a maturity roadmap for SMBs ready to go further

•

Insurance innovation: Enabling new insurance products and faster underwriting processes for companies that demonstrate IG1 alignment, potentially even new incentives or premium reductions

•

Vendor alignment: Encouraging security providers to design “insurance-ready” products that naturally fulfill IG1 safeguards, helping SMBs meet both security and compliance needs simultaneously


•

Ecosystem collaboration: Bringing together brokers, insurers, MSPs, and vendors around a shared framework, creating a unified language for cybersecurity assurance

We are deeply grateful to our participating vendor partners for helping make Control Assist a reality. Their commitment demonstrates a shared belief that aligning cybersecurity frameworks with insurance processes is not just possible; it’s essential.

Building a More Resilient Cyber Insurance Market Control Assist is a foundational step toward a more standardized and resilient cyber insurance market. By linking proven cybersecurity practices to the insurance process, CIS and CyberAcuView are helping to reduce friction, improve transparency, and promote stronger risk management across the board. The CIS Controls are already trusted by tens of thousands of organizations worldwide. Control Assist builds on this legacy by offering SMBs a clear, credible path to cyber maturity and insurance readiness. It also supports insurers in making more informed decisions and helps vendors demonstrate the real-world impact of their solutions.

Supported by Industry Leaders CyberAcuView is backed by a coalition of leading cyber insurance underwriters, including AIG, AXIS, Beazley, Chubb, The Hartford, Liberty Mutual Insurance, and Travelers. These organizations are committed to improving the cyber insurance experience for policyholders and strengthening the overall resilience of the digital economy. All CyberAcuView activities are conducted under strict antitrust review and guidance to ensure fair and competitive practices.

By aligning the CIS Controls with insurance underwriting questions, this initiative empowers SMBs to confidently demonstrate their cybersecurity posture, prioritize meaningful investments, and reduce the friction often associated with applying for coverage.

Control Assist marks a pivotal advancement in making cyber insurance more accessible, understandable, and actionable for SMBs. By aligning the CIS Controls with insurance underwriting questions, this initiative empowers SMBs to confidently demonstrate their cybersecurity posture, prioritize meaningful investments, and reduce the friction often associated with applying for coverage. It also equips insurers with clearer, standardized data to assess risk and supports technology vendors in showcasing the insurance-readiness of their solutions. As cyber threats continue to evolve, initiatives like Control Assist are essential for building a more resilient and collaborative cyber insurance ecosystem where security and coverage go hand in hand. With support from leading insurers and cybersecurity providers, Control Assist offers a practical path forward for SMBs seeking both protection and peace of mind. Phyllis Lee is the Vice President of SBP Content Development at the Center for Internet Security (CIS). She has over 25 years of experience in information assurance and has performed vulnerability assessments, virtualization research, and worked in security automation. Prior to joining CIS, Lee worked at the National Security Agency (NSA) focusing on the intersection between malware and virtualization, which included collaboration with MIT Lincoln Labs. Lee also participated in a variety of security automation standardization efforts and led the security automation strategy for the NSA Information Assurance Directorate (IAD). She graduated from Johns Hopkins University with a master of science in computer science.

Winter 2025/26

13


Simplify CIS Benchmarks Implementation With a 100-Day Plan The CIS Benchmarks and their consensus-based configuration guidance offer a clear path to a more secure organization. But following that path requires a wellconstructed roadmap to implement their recommendations effectively.

By Tony Caputo Organizations tasked with implementing the CIS Benchmarks®, consensus-based secure configuration guidelines developed by the Center for Internet Security® (CIS®) and referenced by frameworks like NIST SP 800-53, often feel daunted by the scale of the challenge. Full implementation of a CIS Benchmark can sometimes involve thousands of detailed steps. It is understandable to question whether your team has the time, skills, or capacity to deliver, especially if your organization is under-resourced, such as a U.S. State, Local, Tribal, or Territorial (SLTT) government or small to medium-sized business (SMB). CIS anticipated these concerns when it created CIS CyberMarket®. This dedicated marketplace connects organizations, particularly U.S. SLTTs, with trusted vendors offering everything from enhanced DNS security to automation platforms that deliver end-to-end CIS Benchmarks automation and continuous compliance.

A 100-Day Path to CIS Benchmarks and NIST SP 800-53 Alignment With automation, organizations can achieve compliance with CIS Benchmarks and alignment with NIST SP 800-53 in just 100 days. Manual methods often take six months or longer and frequently produce incomplete results. By contrast, automation provides a faster, more reliable path that reduces stress on internal teams while enabling continuous compliance through regular updates. Success begins with careful preparation. Implementation of the CIS Benchmarks is an enterprise-wide effort that requires input from IT, engineering, compliance, and risk leaders as well as application and infrastructure owners.

14

Cybersecurity Quarterly

Full implementation of a CIS Benchmark can sometimes involve thousands of detailed steps. It is understandable to question whether your team has the time, skills, or capacity to deliver, especially if your organization is under-resourced, such as a U.S. State, Local, Tribal, or Territorial (SLTT) government or small to medium-sized business (SMB). Together, these stakeholders can build a realistic plan that includes: •

The “Why”: Establish a clear rationale that aligns stakeholders, justifies the investment, and sets the strategic posture for the initiative.

•

Scope: Define the number of endpoints, unique app stacks, and tools to secure along with the timing for doing it.

•

Benchmarking: Choose the appropriate level of implementation. Many organizations target Level 2 for comprehensive security. Consider whether to implement CIS Benchmarks for operating systems


only or expand your hardening efforts to browsers, databases, and applications. •

Tooling: Identify automation options, from point tools to unified platforms, that provide scanning, remediation, reporting, monitoring, and updates from a single dashboard.

•

Timeframes: Account for project start and end dates, resource availability, budget constraints, and audit deadlines.

•

Maintenance: Build in a process to address CIS Benchmark updates and manage drift over time.

The plan should be communicated in terms relatable to different audiences. Executives want to understand risk reduction and audit readiness. End users want clarity on how the changes will affect their daily routines. Appointing a project leader and assigning task ownership improves accountability and drives progress.

Starting the 100-Day Journey To implement CIS Benchmarks or NIST SP 800-53 in 100 days, automation is not optional. Once your plan is complete, automation tools help establish baselines, enforce policies, and maintain the level of security appropriate for your organization. A recommended first step is to secure a Windows Server environment. These servers typically have fewer CIS Benchmarks recommendations than workstations and are often easier to configure than Linux systems. Achieving this milestone quickly provides an early win that demonstrates progress and builds momentum across the project team.

No single organization holds all the answers. That is why a standardized solution such as the CIS Benchmarks, reinforced by automation, is an effective path to resilient, enterprise-grade cybersecurity.. The first phase of the 100-day journey lays the foundation for long-term success. While the CIS Benchmarks will always require maintenance, the right automation strategy ensures your organization stays aligned with updates and resilient against system drift. Among the solutions available through the CIS CyberMarket, SteelCloud’s ConfigOS unifies scanning, remediation, monitoring, reporting, and ongoing compliance into a single purpose-built solution. A unified platform minimizes rework, streamlines processes, and ensures every component is fully integrated. For a detailed roadmap, its free 100 Days to CIS Benchmarks Implementation eBook provides 42 pages of guidance on planning, execution, and sustaining continuous compliance. Cyber threats are advancing every day. The CIS Benchmarks represent consensus-driven recommendations from global experts who have experienced and/or considered the full spectrum of attacks and defenses. No single organization holds all the answers. That is why a standardized solution such as the CIS Benchmarks, reinforced by automation, is an effective path to resilient, enterprise-grade cybersecurity. Tony Caputo brings nearly 30 years of entrepreneurial and technology leadership in private, public, and early-stage companies to his role as SteelCloud’s CEO. This includes deep experience in sales strategies, tactical execution plans, product development, strategic alliances, and leading teams to achieve exponential revenue growth in the legal, GRC, and cybersecurity industries.

Winter 2025/26

15


CybersideChat Kickstarting Cybersecurity in 2026: A Professional's New Year Playbook By Stephanie Gass, Senior Director of Information Security, CIS The beginning of the year is more than a fresh calendar. It’s a strategic pivot point for cybersecurity leaders. Threat actors don’t take holidays, and neither should our vigilance. January is the ideal moment to reset, reassess, and reallocate resources for maximum impact. Here’s how to make the first 90 days count.

Review and Reflect: Turn Lessons Into Leverage Look back on last year. Aggregate incident response data, audit findings, tabletop exercise (TTX) outcomes, control performance, and security key performance indicators. Look for patterns like repeated vulnerabilities, delayed detection, noisy alerting, vendor-related weaknesses, and gaps in backup integrity. Compare SLAs to actuals and assess your

Threat actors don’t take holidays, and neither should our vigilance. January is the ideal moment to reset, reassess, and reallocate resources for maximum impact. . 16

Cybersecurity Quarterly

threat modeling assumptions against what happened. Ask: •

Which controls delivered measurable risk reduction? Which were costly but low-yield?

•

Where did we depend on manual workflows that should be automated?

•

What compensating controls are becoming business unit standards? Fix root causes.

From there, turn insights into decisions. Retire tools that don’t deliver, invest in telemetry where coverage is thin, and document where architecture modernization could eliminate chronic risk debt.

Update Policies and Frameworks: Keep the Guardrails Current Policies are not one and done; they are living documents. Refresh incident response plans, access control standards, secure SDLC guidance, and third-party risk procedures. Validate that onboarding/offboarding flows reflect your current identity stack. Adjust data-handling policies to align with the organization's evolving use of AI, SaaS, and data sharing.

Review framework alignment and ensure your control objectives and metrics are mapped correctly. If your organization is subject to sector-specific regulations, confirm that reporting workflows, playbooks, and logging meet requirements and are testable. Finally, close the loop by updating runbooks, notify control owners, and schedule attestation.

Prioritize Threat Intelligence: Make Intelligence Actionable Curate threat intelligence around what matters for your environment: top TTPs targeting your sector or key events, identity-oriented attacks, cloud misconfiguration exploits, and emerging malware families. Translate intel into detections, guardrails, and simulations: •

Build or tune detections against prevalent attacker behaviors

•

Share concise intelligence briefings with your SOC, engineering team, leadership, and the larger community

•

Convert intel into TTX scenarios to assess readiness

If this attack happens tomorrow, can your team detect, block, respond to, and report on it today?


Technology and Tooling: Validate, Patch, and Prove Resilience January is the month for hygiene. Patch aggressively by prioritizing Tier 1 and crown jewel assets, internet-facing systems, identity providers, endpoint agents, and high-value data services. Review EDR coverage and sensor health. Review SIEM parsing fidelity, retention policies, and data onboarding from Tier 1 and crown jewel assets. Run backup and disaster recovery tests in production-like conditions and assess recovery point and recovery time objectives, integrity of restores, and dependency mapping. Confirm that incident-response integrations work as designed. If you haven’t assessed your zero trust posture recently, perform a quick maturity snapshot: identity strength, least privilege, continuous verification, and segmentation.

People and Training: Strengthen the Human Firewall Security is everyone’s responsibility. Refresh your awareness program with crisp, real-world scenarios such as credential hygiene, MFA pitfalls, secure data use, and reporting norms. Update phishing simulations to reflect modern technology and attacks. Revisit insider threat protocols to ensure monitoring is proportionate, privacy-aware, and focused on risk indicators, not surveillance. For the security team, invest in relevant skills like AI, cloud-native security, identity engineering, detection engineering, threat hunting, and secure coding. Publish a quarterly learning plan with defined outcomes. Look for cross-training

opportunities throughout the organization by rotating analysts through purple team exercises and have architects sit in on SOC post-incident reviews. Document tribal knowledge into resilient runbooks to prevent loss of information.

Set Measurable Goals: Tie Security to Business Outcomes Translate strategy into measurable objectives and key results that align with your organization. For example: •

Reduce mean time to detect through improved log onboarding and detection tuning

•

Increase MFA phishing resilience by enabling phishing-resistant methods for privileged users

•

Improve backup recoverability to meet target RPO/RTO across Tier 1 and crown jewel applications

•

Raise secure build adoption by integrating SAST/DAST/SCA with release gates in pipelines

Establish rhythms: monthly metrics reviews, quarterly tabletop exercises, bi-weekly detection backlog triage, and a standing architecture forum. Security initiatives thrive with consistent cadence and clear ownership.

Conclusion The start of the year is your leverage point. Review what mattered, update the guardrails, ground yourself in actionable intelligence, prove resilience, invest in people, and set measurable goals. Most importantly, align everything with the business. A strong January builds a safer year.

Tie objectives to business outcomes and bonus structures. Communicate these goals widely; security outcomes should be visible across leadership and engineering.

Communicate and Collaborate: Make Security a Shared Commitment Security succeeds when it’s embedded. Kick off the year with stakeholder briefings tailored to executives, IT, product, and compliance. Share last year’s highlights and lessons, this year’s objectives, and the “what we need from you” asks. Winter 2025/26

17


UpcomingEvents January January 7 – 11 The National Association of Election Officials will host the 2026 Joint Election Official Liaison Conference (JEOLC) at The Ritz-Carlton Pentagon City in Arlington, VA. The event will bring election officials from across the country together to learn from industry experts and network with peers. Center for Internet Security® (CIS®) VP of Elections Operations Marci Andino will lead a session discussing cybersecurity resources for election agencies. Learn more at https://portal.electioncenter. org/EventList.

January 27 – 29 The Florida Local Government Information Systems Association (FLGISA) will host the 2026 FLGISA Winter Symposium at Embassy Suites Orlando Lake Buena Vista South in Kissimmee, FL. The event will bring together hundreds of Florida's top local government technology and IT leaders to gain insight into the latest industry trends, engage with industry partners, learn from experts and thought leaders, and network with peers. CIS Director of Member Success & Strategic Accounts Kateri Gill will lead a session at the event discussing whole-of-state cybersecurity. Learn more at https:// www.flgisa.org/events/.

18

Cybersecurity Quarterly

January 28 – 31 The National Association of Secretaries of State (NASS) will host the NASS 2026 Winter Conference at the Grand Hyatt Washington in Washington, D.C. The event will bring together the nation's Secretaries of State and their staff to network with peers, discuss the year's upcoming policy and legislative developments, and learn about the latest industry updates. Learn more at https://www.nass.org/events/nass2026-winter-conference.

February February 1 – 3 The National Association of State Election Directors (NASED) will host the 2026 NASED Winter Conference in Washington, D.C. The event will bring together the nation's election agency leaders and their staff to network with peers, discuss upcoming election policy updates for the 2026 elections, and share best practices. Learn more at https://www.nased.org/2026conf.

January 30

February 2 – 4

The 7th Annual Tampa Official Cybersecurity Summit will take place at the Tampa Hilton Downtown in Tampa, FL. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo. com/tampa-2026.

The Texas Association of Community Colleges (TACC) will host the TACC-CIO Annual Conference at Tarrant County College in Fort Worth, TX. The event will bring together Chief Information Officers and their staff from the state's community colleges together to learn from industry experts, share best practices, and network with peers. The CIS team will be onsite sharing our cybersecurity resources available to the state's community colleges through Texas's statewide MS-ISAC membership. Learn more at https://tacccio. wildapricot.org/conference2026.

January 31 – February 4 The National Sheriff's Association will host the 2026 National Sheriff's Association Winter Conference at the J.W. Marriott Washington D.C. The event will bring together law enforcement leaders and professionals from across the country along with high-level leadership from federal agencies and members of U.S. Congress to explore current legislation, learn about relevant topics, and explore trending technologies and products. Learn more at https://nsawinter.org/.

February 3 The 11th Annual Seattle/Bellevue Official Cybersecurity Summit will take place at the Hyatt Regency Bellevue in Bellevue, WA. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/seattle_bellevue-feb-2026.


February 5

February 19 – 21

The 7 Edition of the San Diego Official Cybersecurity Summit will take place at the San Diego Marriott Marquis in San Diego, CA. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/sandiego-2026.

The National Governors Association (NGA) will host the 2026 NGA Winter Meeting at the Grand Hyatt Washington in Washington, D.C. Governors and their staff from across the nation, along with national experts and other partners, will meet for in-depth conversations on pressing national issues like education, energy, economic growth, artificial intelligence and more. Learn more at https://www.nga.org/2026-nga-wintermeeting-partners/.

February 6

February 21 – 24

The 14th Edition of the Atlanta Official Cybersecurity Summit will take place at the Grand Hyatt Atlanta in Buckhead in Atlanta, GA. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo.com/ atlanta-2026.

The National Association of Counties (NACo) will host the 2026 NACo Legislative Conference at the Washington Hilton in Washington, D.C. The event will bring together nearly 2,000 elected and appointed county officials to focus on federal policy issues that matter most to county governments. Attendees will experience timely, high-impact policy sessions and will interact with executive branch officials, members of U.S. Congress, and their staff. Learn more at https:// www.naco.org/event/2026-nacolegislative-conference.

th

February 11 The 11th Annual Silicon Valley Official Cybersecurity Summit will take place at the Santa Clara Marriott in Santa Clara, CA. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https:// cyberriskalliance.swoogo.com/siliconvalley-feb-2026.

February 25 The 17th Edition of the New York Official Cybersecurity Summit will take place at the Sheraton New York Times Square Hotel in New York, NY. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https:// cyberriskalliance.swoogo.com/ NewYork-2026.

March March 3 The 12th Annual Chicago Cybersecurity Summit will take place at the Chicago Hyatt Regency in Chicago, IL. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo.com/ chicago-march_2026.

March 5 The 13th Annual Dallas Cybersecurity Summit will take place at the Dallas Marriott Downtown in Dallas, TX. It will bring together leaders and cybersecurity professionals to learn about the latest cyber threats. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https:// cyberriskalliance.swoogo.com/ dallas-march_2026.

March 9 The National Association of State Procurement Officials (NASPO) will host NASPO Exchange at Disney's Coronado Springs Resort in Lake Buena Vista, FL. Co-hosted by NASPO and the Procurement Professionals Alliance (PPA), the conference builds relationships among the supplier community and government entities. The conference is where learning, networking, and partnering come together to develop business relationships that support public procurement outcomes that are effective, efficient, transparent, and fair. Learn more at https://www.naspo.org/ events-and-webinars/naspo-exchange/..

Winter 2025/26

19


March 9 – 11

March 19

March 23 – 26

The 3 Annual Billington State and Local Cybersecurity Summit will take place at the Ronald Reagan Building and International Trade Center in Washington, D.C. The event will bring together top federal, state, local, and tribal government officials along with industry experts to share best practices, learn from one another, enhance current cyber operations, and bolster future defenses. The CIS team will be on site, sharing our cybersecurity resources and leading thought-provoking sessions to help U.S. government organizations of every level improve the cybersecurity. Learn more and register at https:// statelocal.billingtoncybersummit.com/.

Amazon Web Services will host AWS Imagine for Nonprofits at the MGM National Harbor Hotel and Casino in Oxon Hill, MD. The event unites visionary leaders, technologists, and changemakers from the nonprofit sector who are driving social and environmental impact through technology. This in-person event combines thoughtprovoking discussions, interactive sessions, hands-on workshops, and networking opportunities that explore how advanced technologies like artificial intelligence (AI) and intentional innovation are transforming the nonprofit sector. Learn more at https://aws.amazon.com/ government-education/nonprofits/ imagine-nonprofit/.

RSAC 2026 Conference will take place at the Moscone Center in San Francisco, CA. One of the largest and highly-regarded cybersecurity conferences, the event will bring thousands of cybersecurity leaders and professionals from around the world together for a week of inspiring keynotes, cutting-edge sessions, hands-on learning, and opportunities to network with peers. This year's focus will be on the Power of Community and how real changes happens when cybersecurity professionals unite. The CIS team will be at the event at Booth 4624 in the Moscone North Expo, sharing our cybersecurity resources with attendees. A number of our experts, including Senior Director of Information Security Stephanie Gass, Director of Information Security Mathew Everman, VP of Security Operations and Intelligence Randy Rose, and Senior VP and Chief Engineer Marcus Sachs, will also be leading sessions on the agenda. When registering, be sure to enter our promo code 16UCISAD to save an additional $150 off an All Access Pass on top of existing discounts. Learn more and register at https://www. rsaconference.com/usa.

rd

March 16 – 18 The National League of Cities (NLC) will host its 2026 Congressional City Conference at the Marriott Marquis Washington, DC. The event will bring together local government leaders from across the country to engage on policy, learn from experts, and make connections. Attendees will gain the tools they need to tackle the new federal resources coming to local communities and connect with their peers in local government. Learn more at https:// ccc.nlc.org/.

20 Cybersecurity Quarterly

March 23 Carahsoft will host the 13th Annual RSA Public Sector Day at RSAC Conference at the Hilton San Francisco Union Square in San Francisco, CA. The event will bring together government leaders from across the country to explore key areas crucial for government cybersecurity. Key topics will include AI's role in advancing federal missions, strategies for creating secure and scalable FedRAMP cloud architectures, approaches to navigating CMMC compliance, methods for modernizing state cyber defenses with emerging technologies, strategies for building and retaining a skilled government cyber workforce, and techniques for managing AI-driven threats across an evolving cyber landscape. Learn more at https:// carahevents.carahsoft.com/PSD2026.


CIS Managed Detection and Response™ Ad Placement Continuous Endpoint Monitoring Learn more


CIS CyberMarket

Interested in being a contributor? Please contact us: CyberMarket@cisecurity.org www.cisecurity.org 518.266.3460

cisecurity.org learn@cisecurity.org 518-266-3460 Center for Internet Security @CISecurity TheCISecurity cisecurity CenterforIntSec


Turn static files into dynamic content formats.

Create a flipbook
Cybersecurity Quarterly Winter 2025/26 by Cybersecurity Quarterly - Issuu