FoxPointe Security Hub

Subscribe to the blog

Receive articles and resources from the information risk management experts at FoxPointe.

Data Privacy can be best defined as the protection of personal data from those who should not have access to it and the ability to individuals to determine who can access their personal information. AI’s Impact on Informational Privacy The use of Artificial Intelligence (AI) has become widespread and almost...

The State University of New York (SUNY) has introduced an updated Information Security Policy (ISP) aimed at creating a cohesive cybersecurity framework across all its campuses. With the rise in cyber threats and increasing regulatory demands, this policy provides a structured approach to protect SUNY’s critical data and digital infrastructure...

As organizations operate and grow, so too does the amount of data that they’re responsible for. Properly managing and safeguarding organizational and customer data can help ensure compliance with GDPR, CCPA, GLBA, and regional laws. Failure to implement and maintain secure data practices can lead to significant fines, legal action,...

The purpose of a Compliance Program in any industry is to ensure that an organization is following all applicable laws, regulations, and ethical practices. The laws and regulations governing compliance are ever-changing and becoming more complex, so how does a Compliance Officer know if the Compliance Program that their organization...

The cyber-threat landscape has evolved dramatically over recent years, becoming more sophisticated and unpredictable. Organizations worldwide face an array of challenges—from advanced persistent threats and ransomware attacks to insider threats and vulnerabilities introduced by remote work. In this context, traditional security models that rely on perimeter defenses are no longer...

In today’s dynamic and increasingly complex cyber landscape, organizations need a holistic, strategic approach that brings together people, processes, and technology. At FoxPointe Solutions, we understand that effective cybersecurity is about more than technical solutions; it’s about integrating expertise, structured processes, and the right technology to build a truly resilient...

This article was written by Paul Mayer and Heather Brownson. The past two years have been very eventful for Compliance Professionals, starting with changes to the Office of Medicaid Inspector General’s (OMIG) Title 18 NYCRR Part 521 regulations. 18 NYCRR Part 521 was first made effective in 2009 and the...

Cyber liability insurance can be a critical weapon in your war against cyber criminals. We often get asked by our clients, “Do I really need cyber liability insurance?” It is often prefaced with the comment ‘I have general business insurance coverage and a really good IT team.’ The short answer...

Insider threats pose a significant risk to organizations, involving individuals with access to critical systems and data. These threats can come from malicious insiders intent to cause harm, careless employees who unknowingly compromise security, or those whose credentials have been stolen by external attackers. Unlike external threats, insider attacks can...

Multi-Factor Authentication (MFA) is a comprehensive approach to authenticating users, relying on two or more credentials to verify an individual’s identity. Typically, these credentials are chosen to be: Something you know (i.e., a memorized password) Something you have (i.e., a physical access badge or smartphone) Something you are (i.e., a...

Introduction Fraud risk mitigation is crucial in business operations to safeguard assets, maintain financial integrity, and uphold the trust of stakeholders. The impact of fraud can be devastating, leading to significant financial losses, reputational damage, and legal consequences. Implementing robust fraud risk mitigation strategies helps to prevent and detect fraudulent...

Since 2004, October has been marked as National Cybersecurity Awareness Month. This month raises awareness about the importance of cybersecurity and how to protect yourself from cybercrime. Perform third-party due diligence on all critical vendors. Ensure that they have either a SOC2 report or a similar certification that covers the...