Michelle Drolet
A practical guide for higher-ed leaders reviewing vendor risk, identity and integrations, and institutional readiness after the Canvas compromise.
0 Minute 0 Second Read
Michelle Drolet
A practical guide for higher-ed leaders reviewing vendor risk, identity and integrations, and institutional readiness after the Canvas compromise.
0 Minute 0 Second Read
Michelle Drolet
The Canvas compromise is like a lesson in SaaS security for organizations that have operational dependency on SaaS platforms. The Canvas global community includes more than 8,000 institutions across more than 100 countries, and Canvas is used by 100% of Ivy League universities. No surprise, then, that this compromise took both an operational and a reputational toll
4 Minute 48 Second Read
Michelle Drolet
With the rapid adoption of AI and with quantum threats on the horizon, the security team’s reaction window is compressing fast. AI is not only accelerating attacks but also making these easier to scale. Quantum computing is forcing leaders to question whether today’s cryptographic protections will be enough in a quantum world. It is therefore important to understand
5 Minute 5 Second Read
Michelle Drolet
Cybersecurity has generally kept pace with the growing sophistication of threats. It has evolved from firewall and antivirus to next-gen firewalls, comprehensive endpoint security suites and intelligence-driven approaches such as EDR, XDR and MDR—solutions based on the assumption that systems behave predictably and that risks can be mapped, monitored and mitigated within specific guardrails. But even
4 Minute 19 Second Read
Janelle Drolet
10. Cyber risks go beyond just IT. A cyberattack can freeze operations and damage customer relationships. A breach exposing client data can trigger lawsuits, while downtime during an attack may lead to cash flow issues. Cybersecurity isn’t just about data; it’s about business continuity. 9. Complacency can be a threat. Many businesses assume they’re too
1 Minute 50 Second Read
Michelle Drolet
In December last year, a shooting incident at Brown University saw two students lose their lives, and left nine injured. And on March 12, an active shooter killed an ROTC instructor at Old Dominion. Tragically, it seems like such disturbing news from university campuses is becoming normalized. Federal authorities have opened an investigation into Brown, digging into the ‘how’ of
5 Minute 59 Second Read
Michelle Drolet
A security incident is all but inevitable for nearly every organization. By “incident” we mean a cyberattack that successfully accesses enterprise resources or somehow puts the finances, operations, and reputation of an organization at risk. A major breach can drive a company out of business. To fight back, every organization needs a cohesive incident response (IR) strategy, backed by a well-trained team
4 Minute 30 Second Read
Janelle Drolet
10) Aim to prevent costly downtime. Risk assessments help you spot weak points that can halt operations. Costs of business downtime are in the billions each year. 9) Clean up hidden weak spots from spaghetti IT. Systems bolted together over time create gaps; conducting a risk assessment will surface those loose webs. The goal is to streamline
1 Minute 34 Second Read
Michelle Drolet
An organization’s initial reaction to a cybersecurity incident is critical when a ransomware attack or a data breach occurs. These actions ultimately determine whether the incident escalates into a more damaging issue or is contained swiftly. A quick and timely response can help mitigate the impact and minimize financial losses, protect sensitive data and safeguard
4 Minute 2 Second Read
Michelle Drolet
Approximately 1 in 3 SMBs were hit by a cyberattack last year—some costing upward of $7 million. The need to prioritize cybersecurity has never been greater. Let’s explore nine cybersecurity elements that organizations must prioritize for 2025. 1. Put Someone In Charge Just like you have an expert in charge of looking after your company’s finances, it’s
3 Minute 54 Second Read