[{"data":1,"prerenderedAt":793},["ShallowReactive",2],{"\u002Fblog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface":3,"blog-all-posts":708},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"cardTitle":10,"titleLines":11,"descriptionLines":15,"bodyLeadTitle":18,"publishedAt":19,"updatedAt":19,"tags":20,"coverImage":24,"coverAlt":25,"heroLayout":26,"heroTitleSize":27,"heroCopyPosition":28,"featured":6,"draft":6,"body":29,"_type":702,"_id":703,"_source":704,"_file":705,"_stem":706,"_extension":707},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface","blog",false,"","Executive Operational Security (OPSEC) Part Two: OSINT Attack Surface","Publicly available information expands an executive's attack surface and gives cybercriminals the intelligence needed for targeted attacks.","Executive Operational Security Part Two",[12,13,14],"Executive Operational","Security Part Two:","OSINT Attack Surface",[16,17],"Public information expands an executive's","attack surface and enables targeted attacks.","High Value & Elevated Risk","2026-08-06",[21,22,23],"executive security","OPSEC","OSINT","\u002Fblog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface\u002Fcover.jpg","Executive standing beside a digital OSINT profile mapping public and professional information","overlay","compact","right",{"type":30,"children":31,"toc":692},"root",[32,48,53,108,116,123,133,145,150,243,248,253,258,264,269,322,327,332,338,343,426,431,437,442,505,510,518,524,529,534,572,577,583,595,600,633,639,644,677,682],{"type":33,"tag":34,"props":35,"children":36},"element","p",{},[37,40,46],{"type":38,"value":39},"text","Cybercriminals don't view executives as employees; they view them as high-value targets. CEOs, CFOs, CIOs, CISOs, and other senior leaders possess ",{"type":33,"tag":41,"props":42,"children":43},"strong",{},[44],{"type":38,"value":45},"highly privileged information, decision-making power, and influence.",{"type":38,"value":47}," Before attackers attempt to compromise your organization, they often begin by profiling you.",{"type":33,"tag":34,"props":49,"children":50},{},[51],{"type":38,"value":52},"If you are an executive in a large company, you may be at elevated risk from attackers. Here’s an example of the critical information that executives often have direct access to that malicious actors want:",{"type":33,"tag":54,"props":55,"children":56},"ul",{},[57,68,78,88,98],{"type":33,"tag":58,"props":59,"children":60},"li",{},[61,66],{"type":33,"tag":41,"props":62,"children":63},{},[64],{"type":38,"value":65},"Chief Executive Officer (CEO):",{"type":38,"value":67}," Strategic decisions, mergers and acquisitions, and confidential business information.",{"type":33,"tag":58,"props":69,"children":70},{},[71,76],{"type":33,"tag":41,"props":72,"children":73},{},[74],{"type":38,"value":75},"Chief Financial Officer (CFO):",{"type":38,"value":77}," Financial reporting schedules, banking relationships, wire transfers, or invoice payments.",{"type":33,"tag":58,"props":79,"children":80},{},[81,86],{"type":33,"tag":41,"props":82,"children":83},{},[84],{"type":38,"value":85},"Chief Information Security Officer (CISO):",{"type":38,"value":87}," Privileged network access, technologies in use, and security team structure.",{"type":33,"tag":58,"props":89,"children":90},{},[91,96],{"type":33,"tag":41,"props":92,"children":93},{},[94],{"type":38,"value":95},"Chief Information Officer (CIO):",{"type":38,"value":97}," Privileged network access, tech stack, cloud providers, new digital initiatives, and vendor partnerships.",{"type":33,"tag":58,"props":99,"children":100},{},[101,106],{"type":33,"tag":41,"props":102,"children":103},{},[104],{"type":38,"value":105},"Chief Technology Officer (CTO):",{"type":38,"value":107}," Privileged network access, GitHub repos, patent filings, and engineering topologies.",{"type":33,"tag":34,"props":109,"children":110},{},[111],{"type":33,"tag":41,"props":112,"children":113},{},[114],{"type":38,"value":115},"Whether you like it or not, you are on the front lines of the cyber threat environment.",{"type":33,"tag":117,"props":118,"children":120},"h2",{"id":119},"osint-defined",[121],{"type":38,"value":122},"OSINT Defined",{"type":33,"tag":34,"props":124,"children":125},{},[126,128],{"type":38,"value":127},"It's important to understand the concept of OSINT. Modern cyberattacks increasingly ",{"type":33,"tag":41,"props":129,"children":130},{},[131],{"type":38,"value":132},"begin with intelligence gathering rather than exploitation.",{"type":33,"tag":34,"props":134,"children":135},{},[136,138,143],{"type":38,"value":137},"OSINT stands for Open Source Intelligence. The concept comes from the military, much like many concepts in cybersecurity, including penetration testing. OSINT is the ",{"type":33,"tag":41,"props":139,"children":140},{},[141],{"type":38,"value":142},"collection and analysis of publicly available information",{"type":38,"value":144}," to understand individuals, organizations, technologies, and potential security risks, and then use the information for exploitation.",{"type":33,"tag":34,"props":146,"children":147},{},[148],{"type":38,"value":149},"Attackers can take the information gathered from OSINT and perform a series of dangerous attacks:",{"type":33,"tag":54,"props":151,"children":152},{},[153,163,173,183,193,203,213,223,233],{"type":33,"tag":58,"props":154,"children":155},{},[156,161],{"type":33,"tag":41,"props":157,"children":158},{},[159],{"type":38,"value":160},"Spear phishing:",{"type":38,"value":162}," Highly targeted phishing emails.",{"type":33,"tag":58,"props":164,"children":165},{},[166,171],{"type":33,"tag":41,"props":167,"children":168},{},[169],{"type":38,"value":170},"Whaling attacks:",{"type":38,"value":172}," Spear phishing that targets high-ranking executives, such as CEOs and CFOs.",{"type":33,"tag":58,"props":174,"children":175},{},[176,181],{"type":33,"tag":41,"props":177,"children":178},{},[179],{"type":38,"value":180},"Business Email Compromise (BEC):",{"type":38,"value":182}," Impersonating executives to authorize fraudulent wire transfers, invoice payments, or sensitive information requests.",{"type":33,"tag":58,"props":184,"children":185},{},[186,191],{"type":33,"tag":41,"props":187,"children":188},{},[189],{"type":38,"value":190},"Supply chain attacks:",{"type":38,"value":192}," Exploiting relationships with vendors and contractors to gain access to an organization.",{"type":33,"tag":58,"props":194,"children":195},{},[196,201],{"type":33,"tag":41,"props":197,"children":198},{},[199],{"type":38,"value":200},"Identity theft:",{"type":38,"value":202}," Collecting personal information to impersonate individuals, commit fraud, or open fraudulent accounts.",{"type":33,"tag":58,"props":204,"children":205},{},[206,211],{"type":33,"tag":41,"props":207,"children":208},{},[209],{"type":38,"value":210},"Corporate espionage:",{"type":38,"value":212}," Gathering intelligence on business strategies, mergers, and intellectual property.",{"type":33,"tag":58,"props":214,"children":215},{},[216,221],{"type":33,"tag":41,"props":217,"children":218},{},[219],{"type":38,"value":220},"Insider recruitment:",{"type":38,"value":222}," Identifying susceptible employees for coercion, bribery, or recruitment based on publicly available information.",{"type":33,"tag":58,"props":224,"children":225},{},[226,231],{"type":33,"tag":41,"props":227,"children":228},{},[229],{"type":38,"value":230},"Extortion and blackmail:",{"type":38,"value":232}," Leveraging sensitive personal or corporate information to pressure victims into making payments or disclosing additional information.",{"type":33,"tag":58,"props":234,"children":235},{},[236,241],{"type":33,"tag":41,"props":237,"children":238},{},[239],{"type":38,"value":240},"Deepfake impersonation:",{"type":38,"value":242}," Using AI-generated voice or video to convincingly impersonate executives during calls, meetings, or financial approvals.",{"type":33,"tag":34,"props":244,"children":245},{},[246],{"type":38,"value":247},"Executives can’t offload their personal security entirely to their technology team. They need to understand the risk posed by OSINT and perform their job securely.",{"type":33,"tag":34,"props":249,"children":250},{},[251],{"type":38,"value":252},"With cybersecurity, it's important to take control of your own destiny.",{"type":33,"tag":34,"props":254,"children":255},{},[256],{"type":38,"value":257},"Effective executive security begins with developing a healthy level of professional skepticism.",{"type":33,"tag":117,"props":259,"children":261},{"id":260},"developing-an-osint-mindset",[262],{"type":38,"value":263},"Developing an OSINT Mindset",{"type":33,"tag":34,"props":265,"children":266},{},[267],{"type":38,"value":268},"Executives should develop an OSINT mindset and get into the mind of an attacker who asks questions such as:",{"type":33,"tag":54,"props":270,"children":271},{},[272,277,282,287,292,297,302,307,312,317],{"type":33,"tag":58,"props":273,"children":274},{},[275],{"type":38,"value":276},"Who runs the company?",{"type":33,"tag":58,"props":278,"children":279},{},[280],{"type":38,"value":281},"Who approves payments?",{"type":33,"tag":58,"props":283,"children":284},{},[285],{"type":38,"value":286},"Who has privileged access?",{"type":33,"tag":58,"props":288,"children":289},{},[290],{"type":38,"value":291},"What vendors are trusted?",{"type":33,"tag":58,"props":293,"children":294},{},[295],{"type":38,"value":296},"What technologies are used?",{"type":33,"tag":58,"props":298,"children":299},{},[300],{"type":38,"value":301},"Who reports to whom?",{"type":33,"tag":58,"props":303,"children":304},{},[305],{"type":38,"value":306},"What projects are underway?",{"type":33,"tag":58,"props":308,"children":309},{},[310],{"type":38,"value":311},"Where are executives traveling?",{"type":33,"tag":58,"props":313,"children":314},{},[315],{"type":38,"value":316},"Which acquisitions are occurring?",{"type":33,"tag":58,"props":318,"children":319},{},[320],{"type":38,"value":321},"Which conferences are being attended?",{"type":33,"tag":34,"props":323,"children":324},{},[325],{"type":38,"value":326},"More often than not, these questions are answered publicly through websites, blog posts, and social media. The more these questions are answered publicly, the less work an attacker must perform.",{"type":33,"tag":34,"props":328,"children":329},{},[330],{"type":38,"value":331},"The next step is to understand your executive digital footprint.",{"type":33,"tag":117,"props":333,"children":335},{"id":334},"executive-osint-footprint",[336],{"type":38,"value":337},"Executive OSINT Footprint",{"type":33,"tag":34,"props":339,"children":340},{},[341],{"type":38,"value":342},"The technologies executives use each day leave digital traces across hundreds of locations:",{"type":33,"tag":54,"props":344,"children":345},{},[346,351,356,361,366,371,376,381,386,391,396,401,406,411,416,421],{"type":33,"tag":58,"props":347,"children":348},{},[349],{"type":38,"value":350},"Company websites",{"type":33,"tag":58,"props":352,"children":353},{},[354],{"type":38,"value":355},"Press releases",{"type":33,"tag":58,"props":357,"children":358},{},[359],{"type":38,"value":360},"LinkedIn",{"type":33,"tag":58,"props":362,"children":363},{},[364],{"type":38,"value":365},"Facebook",{"type":33,"tag":58,"props":367,"children":368},{},[369],{"type":38,"value":370},"Instagram",{"type":33,"tag":58,"props":372,"children":373},{},[374],{"type":38,"value":375},"X",{"type":33,"tag":58,"props":377,"children":378},{},[379],{"type":38,"value":380},"Threads",{"type":33,"tag":58,"props":382,"children":383},{},[384],{"type":38,"value":385},"GitHub",{"type":33,"tag":58,"props":387,"children":388},{},[389],{"type":38,"value":390},"Conference biographies",{"type":33,"tag":58,"props":392,"children":393},{},[394],{"type":38,"value":395},"Podcasts",{"type":33,"tag":58,"props":397,"children":398},{},[399],{"type":38,"value":400},"Interviews",{"type":33,"tag":58,"props":402,"children":403},{},[404],{"type":38,"value":405},"YouTube presentations",{"type":33,"tag":58,"props":407,"children":408},{},[409],{"type":38,"value":410},"SEC filings",{"type":33,"tag":58,"props":412,"children":413},{},[414],{"type":38,"value":415},"Board memberships",{"type":33,"tag":58,"props":417,"children":418},{},[419],{"type":38,"value":420},"Charity organizations",{"type":33,"tag":58,"props":422,"children":423},{},[424],{"type":38,"value":425},"University alumni pages",{"type":33,"tag":34,"props":427,"children":428},{},[429],{"type":38,"value":430},"Most executives underestimate how many sources mention them. These sources provide a rich dataset of information that can form the strong foundation of an OSINT collection.",{"type":33,"tag":117,"props":432,"children":434},{"id":433},"executive-ecosystem-osint-footprint",[435],{"type":38,"value":436},"Executive Ecosystem OSINT Footprint",{"type":33,"tag":34,"props":438,"children":439},{},[440],{"type":38,"value":441},"Malicious actors don't only profile the executive. Motivated attackers expand the profile to include everyone who associates with an executive. They also profile:",{"type":33,"tag":54,"props":443,"children":444},{},[445,450,455,460,465,470,475,480,485,490,495,500],{"type":33,"tag":58,"props":446,"children":447},{},[448],{"type":38,"value":449},"Executive assistants",{"type":33,"tag":58,"props":451,"children":452},{},[453],{"type":38,"value":454},"IT staff",{"type":33,"tag":58,"props":456,"children":457},{},[458],{"type":38,"value":459},"Finance",{"type":33,"tag":58,"props":461,"children":462},{},[463],{"type":38,"value":464},"HR",{"type":33,"tag":58,"props":466,"children":467},{},[468],{"type":38,"value":469},"Legal",{"type":33,"tag":58,"props":471,"children":472},{},[473],{"type":38,"value":474},"Immediate family members",{"type":33,"tag":58,"props":476,"children":477},{},[478],{"type":38,"value":479},"Personal assistants",{"type":33,"tag":58,"props":481,"children":482},{},[483],{"type":38,"value":484},"Board members",{"type":33,"tag":58,"props":486,"children":487},{},[488],{"type":38,"value":489},"Vendors",{"type":33,"tag":58,"props":491,"children":492},{},[493],{"type":38,"value":494},"Managed service providers",{"type":33,"tag":58,"props":496,"children":497},{},[498],{"type":38,"value":499},"Law firms",{"type":33,"tag":58,"props":501,"children":502},{},[503],{"type":38,"value":504},"Accounting firms",{"type":33,"tag":34,"props":506,"children":507},{},[508],{"type":38,"value":509},"The goal is to identify the easiest path toward the executive and the valuable information an attacker wants to exploit. If an attacker learns that an executive assistant is an avid soccer fan or frequently searches for recipes, they can craft highly personalized phishing messages around those interests. Personalized attacks are often significantly more convincing than generic phishing campaigns.",{"type":33,"tag":34,"props":511,"children":512},{},[513],{"type":33,"tag":41,"props":514,"children":515},{},[516],{"type":38,"value":517},"A compromised assistant, vendor, or family member is one step closer to you.",{"type":33,"tag":117,"props":519,"children":521},{"id":520},"travel-osint-footprint",[522],{"type":38,"value":523},"Travel OSINT Footprint",{"type":33,"tag":34,"props":525,"children":526},{},[527],{"type":38,"value":528},"Executives often unintentionally reveal travel plans that contain valuable pieces of information.",{"type":33,"tag":34,"props":530,"children":531},{},[532],{"type":38,"value":533},"Examples include:",{"type":33,"tag":54,"props":535,"children":536},{},[537,542,547,552,557,562,567],{"type":33,"tag":58,"props":538,"children":539},{},[540],{"type":38,"value":541},"Airport check-ins",{"type":33,"tag":58,"props":543,"children":544},{},[545],{"type":38,"value":546},"Conference registrations",{"type":33,"tag":58,"props":548,"children":549},{},[550],{"type":38,"value":551},"Hotel photos",{"type":33,"tag":58,"props":553,"children":554},{},[555],{"type":38,"value":556},"Boarding passes",{"type":33,"tag":58,"props":558,"children":559},{},[560],{"type":38,"value":561},"Meeting announcements",{"type":33,"tag":58,"props":563,"children":564},{},[565],{"type":38,"value":566},"Speaking engagements",{"type":33,"tag":58,"props":568,"children":569},{},[570],{"type":38,"value":571},"Real-time social media posts",{"type":33,"tag":34,"props":573,"children":574},{},[575],{"type":38,"value":576},"A photo of a boarding pass contains valuable data. A post about a vacation or trip to a subsidiary offers a time window to send a phishing email to your staff when you're away. Attackers can use this information to time phishing campaigns, impersonation attempts, or physical targeting.",{"type":33,"tag":117,"props":578,"children":580},{"id":579},"ai-osint-collection",[581],{"type":38,"value":582},"AI OSINT Collection",{"type":33,"tag":34,"props":584,"children":585},{},[586,588,593],{"type":38,"value":587},"Artificial intelligence has fundamentally changed how OSINT is performed. Tasks that once required days or weeks of manual research ",{"type":33,"tag":41,"props":589,"children":590},{},[591],{"type":38,"value":592},"can now be completed in minutes,",{"type":38,"value":594}," allowing attackers to profile executives at unprecedented scale.",{"type":33,"tag":34,"props":596,"children":597},{},[598],{"type":38,"value":599},"AI enables attackers to:",{"type":33,"tag":54,"props":601,"children":602},{},[603,608,613,618,623,628],{"type":33,"tag":58,"props":604,"children":605},{},[606],{"type":38,"value":607},"Correlate thousands of data sources in minutes",{"type":33,"tag":58,"props":609,"children":610},{},[611],{"type":38,"value":612},"Build executive profiles automatically",{"type":33,"tag":58,"props":614,"children":615},{},[616],{"type":38,"value":617},"Summarize years of public information",{"type":33,"tag":58,"props":619,"children":620},{},[621],{"type":38,"value":622},"Identify relationships",{"type":33,"tag":58,"props":624,"children":625},{},[626],{"type":38,"value":627},"Translate foreign-language content",{"type":33,"tag":58,"props":629,"children":630},{},[631],{"type":38,"value":632},"Detect patterns humans would overlook",{"type":33,"tag":117,"props":634,"children":636},{"id":635},"managing-risks-from-open-source-intelligence-osint",[637],{"type":38,"value":638},"Managing Risks from Open Source Intelligence (OSINT)",{"type":33,"tag":34,"props":640,"children":641},{},[642],{"type":38,"value":643},"Addressing the risks from OSINT requires a proactive strategy that includes:",{"type":33,"tag":54,"props":645,"children":646},{},[647,652,657,662,667,672],{"type":33,"tag":58,"props":648,"children":649},{},[650],{"type":38,"value":651},"Minimizing unnecessary public exposure",{"type":33,"tag":58,"props":653,"children":654},{},[655],{"type":38,"value":656},"Regularly auditing and removing sensitive information from public sources",{"type":33,"tag":58,"props":658,"children":659},{},[660],{"type":38,"value":661},"Strengthening privacy settings across online platforms",{"type":33,"tag":58,"props":663,"children":664},{},[665],{"type":38,"value":666},"Implementing multi-factor authentication across critical systems",{"type":33,"tag":58,"props":668,"children":669},{},[670],{"type":38,"value":671},"Providing executive-focused cybersecurity awareness training",{"type":33,"tag":58,"props":673,"children":674},{},[675],{"type":38,"value":676},"Continuously monitoring for exposed credentials, leaked data, and impersonation attempts",{"type":33,"tag":34,"props":678,"children":679},{},[680],{"type":38,"value":681},"Organizations should also integrate OSINT risk management into their broader executive security and cyber risk programs to reduce the likelihood that publicly available information can be exploited against senior leadership.",{"type":33,"tag":34,"props":683,"children":684},{},[685,687],{"type":38,"value":686},"The risks from an OSINT collection will always be there. ",{"type":33,"tag":41,"props":688,"children":689},{},[690],{"type":38,"value":691},"Smart companies take control of their cybersecurity destiny by meeting the threat before it happens.",{"title":7,"searchDepth":693,"depth":693,"links":694},2,[695,696,697,698,699,700,701],{"id":119,"depth":693,"text":122},{"id":260,"depth":693,"text":263},{"id":334,"depth":693,"text":337},{"id":433,"depth":693,"text":436},{"id":520,"depth":693,"text":523},{"id":579,"depth":693,"text":582},{"id":635,"depth":693,"text":638},"markdown","content:blog:executive-operational-security-opsec-part-two-osint-attack-surface.md","content","blog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface.md","blog\u002Fexecutive-operational-security-opsec-part-two-osint-attack-surface","md",[709,711,723,733,744,754,762,772,783],{"_path":4,"title":8,"description":9,"cardTitle":10,"publishedAt":19,"tags":710,"coverImage":24,"coverAlt":25,"featured":6},[21,22,23],{"_path":712,"title":713,"description":714,"cardTitle":715,"publishedAt":716,"tags":717,"coverImage":721,"coverAlt":722,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two","Understanding Your True Attack Surface: Part Two","Few companies understand how they look to an attacker. Your Internet attack surface is exactly what attackers see first.","Understanding Your True Attack Surface Part Two","2026-07-28",[718,719,720],"attack surface","internet security","cybersecurity strategy","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two\u002Fcover.jpg","Cyber operations control tower monitoring a connected city and its Internet-facing attack surface",{"_path":724,"title":725,"description":726,"publishedAt":727,"tags":728,"coverImage":731,"coverAlt":732,"featured":6},"\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026","Top Cyber Threats Facing Businesses in 2026","Businesses face AI-assisted hacking, interception-proxy phishing, dark web breach data, and API attacks in 2026.","2026-06-26",[729,730,720],"cyber threats","business security","\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026\u002Fcover.jpg","A city skyline beneath a massive storm cloud embedded with cybersecurity symbols and lightning",{"_path":734,"title":735,"description":736,"publishedAt":737,"tags":738,"coverImage":742,"coverAlt":743,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two","Challenges Facing AI Frontier Models Part Two","Frontier AI models must overcome constraints in context, agent design, data quality, energy, and open-source competition.","2026-06-25",[739,740,741],"artificial intelligence","frontier models","AI safety","\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two\u002Fcover.jpg","A humanoid robot ascending a snowy mountain ridge toward the sunset",{"_path":745,"title":746,"description":747,"cardTitle":748,"publishedAt":749,"tags":750,"coverImage":752,"coverAlt":753,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one","Understanding Your True Attack Surface: Part One","The modern attack surface extends far beyond the corporate firewall.","Understanding Your True Attack Surface Part One","2026-06-21",[718,751,720],"network security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one\u002Fcover.jpg","Security leader reviewing an enterprise attack surface dashboard spanning cloud, applications, remote offices, devices, patching, identities, and internet exposure",{"_path":755,"title":756,"description":757,"publishedAt":758,"tags":759,"coverImage":760,"coverAlt":761,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models","Challenges Facing AI Frontier Models Part One","Frontier AI models face a series of challenges that threaten their viability","2026-06-12",[739,740,741],"\u002Fblog\u002Fchallenges-facing-ai-frontier-models\u002Fcover.jpg","A humanoid robot standing among clouds beneath a blue sky",{"_path":763,"title":764,"description":765,"cardTitle":766,"publishedAt":767,"tags":768,"coverImage":770,"coverAlt":771,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation","Executive Operational Security Part One: Setting the Foundation","Executive OPSEC protects senior leaders, privileged access, sensitive information, communications, travel, and personal activity from targeted threats.","Executive Operational Security Part One","2026-06-10",[21,22,769],"risk management","\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation\u002Fcover.jpg","Executive reviewing his phone beside a laptop in a private office",{"_path":773,"title":774,"description":775,"publishedAt":776,"tags":777,"coverImage":781,"coverAlt":782,"featured":6},"\u002Fblog\u002Fevaluating-identity-before-attackers-do","Evaluating Identity Before Attackers Do","An IAM assessment evaluates authentication, access controls, user behavior, and identity resilience before attackers can exploit them.","2026-06-07",[778,779,780],"identity security","IAM assessment","access management","\u002Fblog\u002Fevaluating-identity-before-attackers-do\u002Fcover.jpg","Open cyber vault displaying identity security controls and authentication monitoring",{"_path":784,"title":785,"description":786,"publishedAt":787,"tags":788,"coverImage":791,"coverAlt":792,"featured":6},"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment","The Necessity of an Enterprise Risk Assessment","Effective Cybersecurity is both a Technical and Procedural Endeavor","2026-05-26",[789,769,790],"enterprise risk assessment","cybersecurity governance","\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment\u002Fcover.jpg","CISO in an aircraft cockpit overlooking clouds with technical and procedural cybersecurity displays",1786043143719]