• Skip to primary navigation
  • Skip to main content

American Cyber Security Management

Secure and certify all your data and processes

  • LinkedIn
  • Twitter
  • YouTube
  • Services
    • MSP/MSSP
    • Privacy
    • Security
    • ISO/IEC 27001:2022 Training & Certification
    • Secure DevOps
    • InfoSec Risk Management
    • Incident Response Planning
    • Artificial intelligence Readiness Offering
    • AppSec-as-a-Service
    • CISO As A Service
    • DPO As A Service
    • Security Monitoring
    • Security Operations
    • Awareness Training
  • Frameworks
    • CPA
    • CCPA/CPRA
    • GDPR
    • ISO 27001:2022
    • NIST 800-171
    • NIST 800-53
    • US Privacy Laws
  • News
  • Careers
    • DPO
    • CISO
  • Partners
  • About Us
    • Privacy Notice
    • Cookie Policy
  • Contact Us

Don’t Let Phishing Emails Reel You In! Here’s How to Spot Them

October 15, 2024 By Paul Herbka

Imagine you’re fishing, but instead of catching fish, someone’s trying to catch you. That’s phishing—emails that look legit but are actually trying to steal your info. 🐟

Phishing emails can be sneaky, but they almost always show some red flags:

  • Too Good to Be True: “You’ve won $1,000,000!” (No, you haven’t). 🚩
  • Urgent and Scary: “Your account will be closed if you don’t respond NOW!” Take a deep breath; it’s probably fake. 🚩
  • Odd Language: Typos, weird grammar, or a generic “Dear User” instead of your name? 🚩
  • Suspicious Links: Hover over links to see where they actually lead. If it doesn’t match what the email says, don’t click it! 🚩

What to do if you spot one of these bad boys:

  1. Recognize the threat: If it feels off, it probably is.
  2. Resist the temptation: Don’t click! Report the email as phishing to your IT team or email provider.
  3. Delete it NOW: Trash that message and don’t look back. 🗑️

Phishing scammers rely on fear and confusion, but you’re smarter than that. Just a little caution goes a long way in keeping your info safe.

 #SecureOurWorld #CybersecurityAwarenessMonth

Filed Under: Cyber Security News

MFA: Your Secret Weapon Against Hackers

October 8, 2024 By Paul Herbka

What’s better than a strong password? A strong password with backup! That’s where Multi-Factor Authentication (MFA) comes in. MFA is like a double lock on your door—hackers might crack your password, but with MFA, they’re not getting in without that second key.

Here’s the deal: MFA adds an extra step, like a code sent to your phone or a fingerprint scan, to make sure you are really you. Easy, right?

Setting it up takes about two minutes in most systems:

  1. Go to Settings: You’ll find it under something like “Account Settings” or “Privacy.”
  2. Turn on MFA: It might be called Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA). Either way, turn it on.
  3. Pick Your Method: You can choose a text code, an authenticator app, or even your fingerprint. Pick whatever’s easiest for you.

Done! You’ve just added an extra layer of security to your account, and that makes you a cybersecurity rock star. Start with your most important accounts, like email and banking, and work your way through the rest. 🎸

 #SecureOurWorld #CybersecurityAwarenessMonth

Filed Under: Cyber Security News

Passwords Don’t Have to Be Painful—Let’s Secure Yours Today

October 1, 2024 By Paul Herbka

Ugh, passwords. We all hate them, but we need them! The good news is there’s a way to make passwords both strong and manageable. Say goodbye to “password123” and hello to super secure (but not brain-draining) ways to protect your accounts.

Here’s how to make your passwords awesome:

  • Go Big or Go Home: Use at least 16 characters. Yep, 16! It sounds long, but the more characters you use, the harder it is for hackers to guess. Think of it like turning your front door into a vault.
  • Mix It Up: Toss in some uppercase, lowercase, numbers, and special characters. Some websites even let you use spaces, so you can make your password a secret sentence.
  • One and Done: Each account gets its own unique password. No repeats! Imagine wearing the same outfit every day—boring for you, and easy for hackers to spot. The same goes for passwords.

But, hey, you don’t have to remember them all. That’s what password managers are for! A password manager will handle the hard work, generating strong, unique passwords for you and storing them safely. You only have to remember one master password—think of it as the key to your password vault.

Several password managers:

            1Password

            Bitwarden

            Dashlane

            NordPass        

💡 Pro Tip: Use a very long but memorable passphrase for your password manager, like “CleverElephantsDanceInHats!2EatPeanuts” Fun and secure!  (Think one “ring [password] to rule them all” so it has to be much longer).

By the end of today, you could have the world’s best passwords with hardly any effort. High five!

 #SecureOurWorld #CybersecurityAwarenessMonth

Filed Under: Cyber Security News

Cybersecurity Awareness Month is Coming! Let’s Get Ready for October 2024

September 26, 2024 By Paul Herbka

🎃 Guess what? October isn’t just about spooky costumes and pumpkin spice lattes—it’s also Cybersecurity Awareness Month! No tricks here, just some super useful tips to help you protect your personal info and avoid falling into the scary world of cyber threats.

This year’s theme is “Secure Your World: One Step at a Time,” and that’s exactly how we’re going to do it. Each week, We will share bite-sized tips that are super easy to follow. You don’t need to be a tech expert to protect yourself—it’s all about making small changes that add up to big security.

We’ll cover:

– How to build strong passwords and use password managers (no more sticky notes!).

– The magic of Multi-Factor Authentication (MFA).

– Spotting sneaky phishing emails before they get you. (Don’t get fooled).

– Keeping your software up-to-date (it’s easier than it sounds, I promise).

Ready to take control of your cybersecurity without breaking a sweat? Let’s do this! Stay tuned for fun, easy tips coming your way.

 #SecureOurWorld #CybersecurityAwarenessMonth

*American Cyber Security Management (AmericanCSM.com) is focused on reducing your risk of data misuse. We do this through our Security, Privacy and DevOps offerings, delivered by seasoned experts.

Filed Under: Cyber Security News

Understanding NIST AI Risk Management Framework: Addressing Generative AI

September 11, 2024 By Paul Herbka

With the rise of generative AI—a class of AI systems capable of producing content such as text, images, music, and even deepfakes—NIST has introduced its AI Risk Management Framework (RMF) to specifically address the unique risks posed by these technologies. Generative AI has immense potential but also introduces complex challenges around misinformation, intellectual property, and ethical use. To navigate these challenges, NIST’s RMF serves as a comprehensive guide for identifying, assessing, managing, and mitigating risks associated with AI, particularly generative AI.

The NIST AI RMF focuses on four core functions: Map, Measure, Manage, and Govern. These functions provide a structured approach to managing AI risks throughout its lifecycle and are particularly relevant to generative AI, given its capacity to produce high-impact content.

1. Mapping Risks in Generative AI

Generative AI offers both tremendous benefits and risks. While it can enhance creativity, it also poses serious threats, such as generating deepfakes, fake “facts”, or content that misleads users. NIST’s RMF encourages developers to map out potential risks during the design and development stages. This means identifying both the technical and societal impacts of the technology, including potential misuse. For example, generative AI models could be weaponized to create realistic but fraudulent content, influencing public opinion or compromising trust.

By proactively mapping these risks, developers can implement early-stage controls to mitigate misuse, safeguarding both the technology and society from harmful applications.

2. Measuring and Mitigating Bias

Generative AI models often rely on vast datasets, which may contain inherent biases. If unchecked, these biases can be replicated and even amplified in AI-generated content, leading to unfair or discriminatory outcomes. NIST highlights the importance of measuring bias in these models and recommends robust evaluation techniques to identify and mitigate these biases.

In the context of generative AI, this could involve analyzing the outputs for any discriminatory language, stereotypes, or misrepresentations that reflect biased data. By developing methods to reduce bias, organizations can ensure that the content generated is fair, balanced, and responsible.

3. Managing Security and Ethical Concerns

Security is another critical concern for generative AI. These systems can be manipulated or exploited to create malicious content or even trigger misinformation campaigns. NIST’s framework stresses the need for strong security measures to protect generative AI models from adversarial attacks or tampering.

Additionally, ethical considerations must be at the forefront of AI development. This includes ensuring that generative AI is used for lawful and beneficial purposes, avoiding harmful applications. Continuous monitoring and adaptive controls can help maintain ethical standards, preventing the use of AI in ways that harm individuals or society.

4. Governance for Generative AI

Governance is key to ensuring that generative AI systems are used responsibly. NIST’s RMF emphasizes the importance of establishing clear policies, accountability structures, and transparency in the use of these systems. Governance frameworks should ensure that users, developers, and stakeholders understand the risks associated with generative AI and have processes in place to manage those risks effectively.

This governance also includes making sure that organizations are transparent about how their generative AI systems are trained, how outputs are validated, and how they will be held accountable if the technology is misused or produces unintended harm.

Conclusion

As generative AI continues to shape industries and influence how content is created, it is vital that organizations manage the associated risks responsibly. NIST’s AI Risk Management Framework provides a comprehensive and structured approach to addressing these risks, helping organizations map potential challenges, measure and mitigate bias, manage security concerns, and establish effective governance structures.

By adhering to NIST’s guidelines, developers and users of generative AI can ensure that these powerful tools are used ethically, securely, and fairly, creating a future where AI serves as a responsible force for innovation.

For more information about this feel free to reference the document on NIST Trustworthy and Responsible AI called “NIST AI 600-1”.

Filed Under: Cyber Security News

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Interim pages omitted …
  • Page 26
  • Go to Next Page »
  • ISSA
  • ISACA
  • ISC2
  • IAPP
  • CSA
  • CIS
  • Privacy Notice
  • Cookie Policy
  • Services
  • Frameworks
  • News
  • Careers
  • Partners
  • About Us
  • Contact Us

Copyright © 2026 American Cyber Security Management