Podcast

Watermarks: the good, bad, and ugly

There has been a lot of discussion and debate over Anthropic’s watermark announcement, but it’s not much of an issue. It is required not only by the EU but China so AI companies must provide this technology. So for those who don’t like it, this is a chance to make lemonade out of lemons.

At Cyber Protection Magazine, we see some very positive aspects of this developing technology. We use AI in various ways: to automate the processing of junk… er, press releases, research purposes and identifying original content. While the AI industry like to promote the scare tactic of replacing humans, we see it as an efficiency tool, freeing us to do the work of covering cybersecurity news.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Collaboration fueling configuration drift

Collaboration tools have fueled configuration drift facilitating phishing attacks since they became widespread during the COVID pandemic. The core of the problem is, as usual, human failure, or more accurately, human procrastination.

Configuration drift happens when vendors and customers join corporate networks with supposedly temporary credentials. When those credentials are not revoked quickly after the collaboration, system settings gradually, almost imperceptibly, diverge from a secure baseline state.

Collaboration tools, beginning with email in the 1970s, were largely clunky, on premises and limited to technically sophisticated organizations. Through the 20 years following the turn of the century they became more sophisticated and allowed inclusion of users outside the networks, like vendors, consultants, and customers. Approximately 400 to 600 million people in professional contexts today use Microsoft Teams, Slack, Google Workspace, Zoom, and dozens of others collaboration tools. Gartner said 90% of Fortune 500 companies standardize on Teams. Moreover, every team that uses collaboration tools configures every collaboration tool differently with no central enforcement.

“Configuration drift is one of the most under-recognized risks in modern cybersecurity,” said Garrett Hamilton, CEO and founder of Reach Security. “Security tools are constantly changing due to updates, new features, and operational adjustments. Over time, those changes create drift that quietly weakens defenses. Organizations need a continuous way to validate that the controls they depend on are still working as intended.”

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Data removal services face uphill battle in healthcare

The data broker market is worth half a trillion dollars and growing at a rate of 7.3 percent annually through 2033. That means they don’t care that you want your privacy. They are making too much money selling your personal information to care. That lack of concern doesn’t just affect an individual’s privacy. It threatens their security and that of nation states. The personal data removal and online privacy niche is fixing the problem. That industry, however is worth a 10th of the data broker market so it doesn’t have the political clout of data brokers. And nowhere is it bigger than the healthcare industry, according to Rob Shavell, CEO of Deleteme.

Read more...

Agency admits most marketing is misinformation

A public relations firm in the United Kingdom said the quiet part out loud about cybersecurity marketing: that much of it is fiction if not outright fraudulent.

Whiteoaks International surveyed 152 senior marketing, PR and communications professionals in the country, working in cybersecurity. The results found 30% said they helped produce content that was excessive, misleading, or unsubstantiated. More than half (51%) said they had seen this type of messaging in the sector.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Scam Bucket: Legal but “scammy”

Many shady practices on the internet are scams, but some seem "scammy." Cyber Protection Magazine came across one such operation.

While ordering food on Grubhub recently, a pop-up appeared telling us we “earned a reward!” Clicking on the link it offered a $20 rebate on my next purchase. Sounds good, doesn’t it? Not really.

Note: All the companies involved in this transaction will be named in this article. All were contacted for comment. Only Grubhub responded with a request for additional information and then went silent.

Even though the transaction was occurring within the Grubhub mobile app, the pop-up was from an organization called Cashback-Now. The company name is relatively common for several companies, all apparently running the same type of business. In this case the URL is cashback-now.com.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Security for less than $500 a month

Cybersecurity companies tend to target large enterprises because, that’s where all the money is. supposedly. They may be missing a lucrative bet and a solution to AI-generated attacks.

In 2025, Comcast issued a report that said 95% of all cyber breaches began with someone in an organization clicking on a malicious link. It wasn’t a brilliant hacker breaking through military grade encryption, or a rogue LLM from a major AI platform discovering backdoors. It was someone not paying attention to the warning signs.

Security training is supposed to reduce that by making users more aware of those signs. That is being tested by AI-generated phishing programs massively increasing the number of attempts. A Hoxhunt survey estimated Ai has caused a 14X increase in phishing attempts in the past year.

Stopping the inevitable

The question is, with cybersecurity hitting a $328 billion market size, why is it getting worse?

Benny Czarny, CEO of OPSWAT, answers that question in a new book, “Upside Down Cybersecurity” that just came out. “The reality is that the market is not adopting this technology or it’s underlying concept fast enough.”

To be accurate, Czarny is talking about OPSWAT’s content disarm and reconstruction (CDR) technology, but based on talks with dozens of CEOs and CISOs at the RSAC Conference in April, the same complaint is made by every company in cybersecurity.

Essentially, the customers that haven’t bought into a cybersecurity service or tool is stupid. They don’t say that for publication, but they do say it. They may be missing another reason. Cybersecurity companies don’t know how to sell their products and services to the people that most need them. Conversations with customers at RSAC back that up.

Untapped SMB market

A 2022 McKinsey survey showed small to medium businesses (SMBs) represent a total market of $1.5 trillion to $2.0 trillion. That market is generally ignored in favor of Fortune 1000 companies. Moreover, the survey noted that current commercial solutions do not meet needs of SMBs and mid-market companies.

(It should be noted that McKinsey’s numbers are based on an erroneous 1998 report on the cost of the cybercrime that was overstated by a factor of between 5 and 10 times the actual number. Official total of cybercrime total less than $1 trillion, making the total available market need at less than that.)

That’s a meaningful response to Czarney’s complaint. OPSWAT’s focus is on big infrastructure. Their pricing is not transparent because, as the saying goes, “if you have to ask, you can’t afford it.” That limits OPSWAT’s market to less than 150 customers and, as he said, they are making a good living off of it. OPSWAT and the majority of the industry are still, however, leaving billions of dollars on the table.

There is evidence that better training makes a difference. Security behavior-change programs, as opposed to traditional awareness model, employees recognized and reported social engineering attacks with a 6x improvement in 6 months, and reduced the number of malicious clicks by 87%, according to a recent report by Hoxhunt. The key, however, may be providing services that block malicious links or alert users to potential danger and with little to no cost to an organization. Encouragingly enough, there are services that do exactly that.

Security at $500/month

DNSFilter processes about 170 billion DNS queries daily, blocking 200 million categorized threats. That’s millions of phishing campaigns failing to reach targets That's significant volume. They also claim to block threats an average of 10 days faster than traditional threat feeds. Significantly, their pricing model starts at $240 a year, for up to 20 users up to a minimum of $1080 per year for a large enterprise. This easily fits into the Cyber Protection Magazine Security Under $500 a Month classification.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Reporter’s notebook: Taking a CNAPP

Cloud-native application protection platforms (CNAPP) emerged as an industry niche around 2021, when Gartner coined the term to describe to consolidate cloud‑security capabilities under a single term. The niche evolved as organizations adopted cloud-native technologies and needed integrated security solutions.

In short, CNAPP providers consolidate security and compliance into a unified platform to prevent misconfigurations as compliance requirements evolve. It provides real-time detection and response to threats across cloud workloads. It scans code under development for vulnerabilities preventing runtime issues. CNAPP follows and protects cloud-native applications from development to production.

Now it sounds like subscribing to a CNAPP tool set is an easy decision for application developers. That’s the easiest decision. It gets harder going forward.

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
Read more...