<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>IOmergent Resources</title><description>Practical security guidance for growing companies: building security programs, passing customer security reviews, and making smart security decisions.</description><link>https://iomergent.com/blog/</link><language>en-us</language><atom:link href="https://iomergent.com/blog/rss.xml" rel="self" type="application/rss+xml"/><item><title>Security Requirements by Industry: Healthcare, Fintech, and General B2B Compared</title><link>https://iomergent.com/blog/security-requirements-by-industry/</link><guid isPermaLink="false">https://blog.iomergent.com/security-requirements-by-industry</guid><description>The question of when you need SOC 2 , ISO 27001, or other certifications isn’t universal. Your market tells you. And different markets have dramatically different expectations.</description><pubDate>Tue, 29 Sep 2026 13:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>What to Do When Your Security Team Can&apos;t Adapt to Business Changes</title><link>https://iomergent.com/blog/what-to-do-when-security-team-cant-adapt/</link><guid isPermaLink="false">https://blog.iomergent.com/what-to-do-when-security-team-cant-adapt</guid><description>Your security team built a compliance program for a customer that no longer exists. Your business acquired two companies, pivoted its strategy, and dropped that major healthcare client who demanded High Trust certification. Now your security people are still running the same playbook, unable to explain why any of it matters to new leadership.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Compliance Is Not Security (And Security Is Not Compliance)</title><link>https://iomergent.com/blog/compliance-is-not-security/</link><guid isPermaLink="false">https://blog.iomergent.com/compliance-is-not-security</guid><description>A global service provider with approximately 1900 employees had everything they needed from the CISO to sell to enterprise customers: a SOC 2 report, ISO 27001, and all the accompanying compliance paperwork, the ability to pass audits consistently. Their security team could whip the tech teams into enough compliance to satisfy auditors every year.</description><pubDate>Tue, 22 Sep 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>What Security Decisions Should a CEO Make? The Ones You Can&apos;t Outsource</title><link>https://iomergent.com/blog/what-security-decisions-should-ceo-make/</link><guid isPermaLink="false">https://blog.iomergent.com/what-security-decisions-should-ceo-make</guid><description>A fractional or virtual CISO can build your security program, implement controls, and advise on technical decisions. But certain decisions require executive judgment that can’t be outsourced.</description><pubDate>Tue, 15 Sep 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Business Email Compromise: The Most Common Breach We See (And What to Do About It)</title><link>https://iomergent.com/blog/business-email-compromise-what-to-do/</link><guid isPermaLink="false">https://blog.iomergent.com/business-email-compromise-what-to-do</guid><description>The call usually comes after something has already happened: bad actors got access to email tokens and started sending messages on behalf of employees, usually something related to finance like fake invoices to customers, wire transfer requests, or vendor payment redirections. CFOs and CEOs are often specifically targeted.</description><pubDate>Tue, 08 Sep 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>How to Answer Security Questionnaires Without Killing Your Enterprise Deals</title><link>https://iomergent.com/blog/how-to-answer-security-questionnaires/</link><guid isPermaLink="false">https://blog.iomergent.com/how-to-answer-security-questionnaires</guid><description>Your engineer answered every question on the security questionnaire truthfully and thoroughly but the deal is stuck in the buyer’s third-party risk management process and your champion hasn’t returned emails since she received an earful from their security team.</description><pubDate>Tue, 01 Sep 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>How to Hire a CISO When You&apos;re Not a Security Expert</title><link>https://iomergent.com/blog/how-to-hire-ciso-when-not-security-expert/</link><guid isPermaLink="false">https://blog.iomergent.com/how-to-hire-ciso-when-not-security-expert</guid><description>The people hiring CISOs are usually not security experts.</description><pubDate>Tue, 18 Aug 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Security Requirements for AI Startups: What Investors and Enterprise Customers Actually Expect</title><link>https://iomergent.com/blog/security-requirements-for-ai-startups/</link><guid isPermaLink="false">https://blog.iomergent.com/security-requirements-for-ai-startups</guid><description>Three years ago, you could argue that seed and series A companies had the luxury of finding product market fit and achieving early revenue traction first and securing later. Operate as lean as possible, build something people want and prove you can sell it without a founder in the room. Then come back to security once you have early growth to protect.</description><pubDate>Tue, 04 Aug 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Backup Question Nobody Wants to Answer</title><link>https://iomergent.com/blog/the-backup-question-nobody-wants-to-answer/</link><guid isPermaLink="false">https://blog.iomergent.com/the-backup-question-nobody-wants-to-answer</guid><description>Most companies we work with don’t have a data inventory.</description><pubDate>Tue, 28 Jul 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Every Startup Says &apos;Security Is a Priority.&apos; Here&apos;s What That Actually Means at the Infrastructure Level</title><link>https://iomergent.com/blog/startup-security-infrastructure/</link><guid isPermaLink="false">https://blog.iomergent.com/startup-security-infrastructure</guid><description>“We take security seriously.” If you’ve been selling into the enterprise, you’ve probably said this in a pitch deck. You might even believe it. But startup security infrastructure has matured to the point where those words carry zero weight with sophisticated buyers. They’ve heard them from every vendor, including the ones that got breached six months later.</description><pubDate>Tue, 21 Jul 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>SOC 2 vs ISO 27001: Which First?</title><link>https://iomergent.com/blog/soc2-vs-iso-27001-which-first/</link><guid isPermaLink="false">https://blog.iomergent.com/soc2-vs-iso-27001-which-first</guid><description>A mid-market company gets told by an enterprise customer: you need ISO 27001 by the end of the year. They have no certifications, shaky documentation, and inconsistent security answers. The deal however depends on meeting this requirement.</description><pubDate>Tue, 14 Jul 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Using AI to Add Business Context to Cloud Security</title><link>https://iomergent.com/blog/using-ai-to-add-business-context-to-cloud-security/</link><guid isPermaLink="false">https://blog.iomergent.com/using-ai-to-add-business-context-to-cloud-security</guid><description>When a new alert comes in, the first thing you want to know isn’t what the vulnerability is. You want to know whether you should care.</description><pubDate>Tue, 07 Jul 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Your Next Enterprise Deal Will Die in the Security Questionnaire</title><link>https://iomergent.com/blog/security-questionnaire-enterprise-sales/</link><guid isPermaLink="false">https://blog.iomergent.com/security-questionnaire-enterprise-sales</guid><description>The security questionnaire is where enterprise deals go quiet. You built the product, nailed the demo, got the champion excited. Then procurement sends over 300 questions about your security posture, and the deal enters a black hole.</description><pubDate>Tue, 30 Jun 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Beyond the Scanner: When You Need Custom Tooling for Cloud Security</title><link>https://iomergent.com/blog/beyond-the-scanner-when-you-need-custom-tooling-for-cloud-security/</link><guid isPermaLink="false">https://blog.iomergent.com/beyond-the-scanner-when-you-need-custom-tooling-for-cloud-security</guid><description>We’re fans of cloud security tools over here: Prowler, Wiz, Orca, ScoutSuite. There are dozens of options, with new ones appearing regularly. They automate the heavy lifting of querying cloud environments and correlate findings across services.</description><pubDate>Tue, 16 Jun 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The AWS Bill Has a Security Problem Nobody&apos;s Looking At</title><link>https://iomergent.com/blog/aws-security-bill-cloud-cost/</link><guid isPermaLink="false">https://blog.iomergent.com/aws-security-bill-cloud-cost</guid><description>Cloud cost optimization isn’t usually a security conversation. It should be. The line items piling up on your AWS bill often point directly to forgotten infrastructure, and forgotten infrastructure is where breaches start.</description><pubDate>Tue, 09 Jun 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>How Much Should a Startup Spend on Security? A Budget Breakdown</title><link>https://iomergent.com/blog/how-much-should-startup-spend-on-security/</link><guid isPermaLink="false">https://blog.iomergent.com/how-much-should-startup-spend-on-security</guid><description>Nobody talks about what a security budget actually looks like. You hear general advice about investing in security, but the specific line items and realistic costs often stay vague.</description><pubDate>Tue, 02 Jun 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Hidden ROI of Cloud Security Hygiene</title><link>https://iomergent.com/blog/the-hidden-roi-of-cloud-security-hygiene/</link><guid isPermaLink="false">https://blog.iomergent.com/the-hidden-roi-of-cloud-security-hygiene</guid><description>We regularly find $5,000 to $10,000 per month in abandoned infrastructure during our first few weeks with a new client running our managed cloud security services .</description><pubDate>Tue, 26 May 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>What Your Engineers Won&apos;t Tell You About Shadow IT</title><link>https://iomergent.com/blog/engineering-shadow-it-risks/</link><guid isPermaLink="false">https://blog.iomergent.com/engineering-shadow-it-risks</guid><description>Engineering shadow IT risks are one of the most predictable blind spots in mid-market software companies. Not because anyone is acting in bad faith, but because the incentives point in the wrong direction. Your engineers solve problems by finding tools. Your security team finds out about those tools months later, if at all.</description><pubDate>Sat, 16 May 2026 19:53:59 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Should Your First Security Hire Be a CISO or Engineer?</title><link>https://iomergent.com/blog/should-first-security-hire-be-ciso-or-engineer/</link><guid isPermaLink="false">https://blog.iomergent.com/should-first-security-hire-be-ciso-or-engineer</guid><description>You’ve decided to invest in security. Now you need to figure out who to hire first. A security leader to build the strategy? An engineer to do the actual work? Some hybrid role that tries to do both?</description><pubDate>Sat, 16 May 2026 19:53:59 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>How to Build a Security Program from Scratch: The First 90 Days</title><link>https://iomergent.com/blog/how-to-build-security-program-from-scratch/</link><guid isPermaLink="false">https://blog.iomergent.com/how-to-build-security-program-from-scratch</guid><description>Something triggered this conversation. Maybe customers are demanding you beef up your security program. Maybe you had a near miss or actual incident. Maybe your management team knows from experience that you’ve deferred this too long and it’s time to invest.</description><pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>What the First 90 Days of Managed CSPM Look Like</title><link>https://iomergent.com/blog/what-the-first-90-days-of-managed-cspm-look-like/</link><guid isPermaLink="false">https://blog.iomergent.com/what-the-first-90-days-of-managed-cspm-look-like</guid><description>What happens when you engage a managed CSPM service ? Here’s what the first 90 days typically look like: from initial setup all the way through steady-state operations.</description><pubDate>Tue, 05 May 2026 13:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>SOC 2 Is Engineering&apos;s Problem Now</title><link>https://iomergent.com/blog/soc2-engineering-implementation/</link><guid isPermaLink="false">https://blog.iomergent.com/soc2-engineering-implementation</guid><description>Your auditor helped scope the audit. Sales promised a Type II by Q3. And now engineering has to figure out SOC 2 engineering implementation for 47 controls without blowing the product roadmap. This is the pattern at every mid-market software company going through SOC 2 for the first time.</description><pubDate>Tue, 28 Apr 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Security Quick Wins: What Gets Fixed in the First Two Weeks</title><link>https://iomergent.com/blog/security-quick-wins-first-two-weeks/</link><guid isPermaLink="false">https://blog.iomergent.com/security-quick-wins-first-two-weeks</guid><description>When we engage with a new client as a Fractional CISO, we don&apos;t simply build a roadmap or deploy new tools. We start by evaluating and understanding the business and the computing environment that supports it, with or without a formal security assessment (almost always recommended but not always required). During that informal evaluation or formal security and risk assessment, we inevitably identify some number of high impact issues that require little time and little to zero cost to fix.</description><pubDate>Tue, 21 Apr 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>DIY vs. Managed CSPM: An Honest Comparison</title><link>https://iomergent.com/blog/diy-vs-managed-cspm-an-honest-comparison/</link><guid isPermaLink="false">https://blog.iomergent.com/diy-vs.-managed-cspm-an-honest-comparison</guid><description>Should you run CSPM tools yourself or bring in a managed service instead?</description><pubDate>Tue, 14 Apr 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Security Debt Hiding in Your CI/CD Pipeline</title><link>https://iomergent.com/blog/cicd-security-risks/</link><guid isPermaLink="false">https://blog.iomergent.com/cicd-security-risks</guid><description>An autonomous bot spent a week in February attacking CI/CD pipelines across seven major open-source repositories. It compromised projects with 140,000+ stars, stole credentials with write access to production, and used those tokens to delete releases and push malicious artifacts to a marketplace. Nobody noticed for days.</description><pubDate>Tue, 07 Apr 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Real Cost of Not Having Security Leadership</title><link>https://iomergent.com/blog/cost-of-not-having-a-ciso/</link><guid isPermaLink="false">https://blog.iomergent.com/cost-of-not-having-a-ciso</guid><description>The cost of not having security leadership isn&apos;t simply the risk of getting hacked. It&apos;s the daily tax on your organization.</description><pubDate>Tue, 31 Mar 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Business Context Problem: Why Vulnerability Severity Scores Lie</title><link>https://iomergent.com/blog/the-business-context-problem-why-vulnerability-severity-scores-lie/</link><guid isPermaLink="false">https://blog.iomergent.com/the-business-context-problem-why-vulnerability-severity-scores-lie</guid><description>A critical vulnerability on an Alpine-based reverse proxy sitting behind three layers of network controls isn’t actually critical.</description><pubDate>Tue, 24 Mar 2026 16:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>CTO Security Responsibilities: You&apos;re the CISO Until You Hire One</title><link>https://iomergent.com/blog/cto-security-responsibilities/</link><guid isPermaLink="false">https://blog.iomergent.com/cto-security-responsibilities</guid><description>Nobody adds &quot;CISO&quot; to the CTO job description. It just shows up one day.</description><pubDate>Sun, 08 Mar 2026 13:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Does My Startup Need a CISO? Signs You&apos;ve Outgrown DIY Security</title><link>https://iomergent.com/blog/does-my-startup-need-a-ciso/</link><guid isPermaLink="false">https://blog.iomergent.com/does-my-startup-need-a-ciso</guid><description>The triggering moment usually isn’t dramatic. It’s a sales deal grinding to a halt because your engineering team gave technically accurate but security-irrelevant answers on a questionnaire. Or it’s your CTO realizing they’re spending 15 hours a week on compliance tasks instead of building a product.</description><pubDate>Wed, 04 Mar 2026 13:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Alert Fatigue Is a Design Choice: Building Views That Actually Help</title><link>https://iomergent.com/blog/alert-fatigue-is-a-design-choice-building-views-that-actually-help/</link><guid isPermaLink="false">https://blog.iomergent.com/alert-fatigue-is-a-design-choice-building-views-that-actually-help</guid><description>The default dashboard in your Cloud Security Posture Management (CSPM) tool is almost certainly wrong for you.</description><pubDate>Fri, 27 Feb 2026 17:35:57 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Introducing IOmergent Managed CSPM</title><link>https://iomergent.com/blog/introducing-iomergent-managed-cspm/</link><guid isPermaLink="false">https://blog.iomergent.com/introducing-iomergent-managed-cspm</guid><description>While running security programs for dozens of companies, we kept seeing the same pattern.</description><pubDate>Wed, 04 Feb 2026 16:41:23 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The vCISO Dividend: Why Fractional Security Leadership is Gaining Momentum</title><link>https://iomergent.com/blog/the-vciso-dividend-why-fractional-security-leadership-is-gaining-momentum/</link><guid isPermaLink="false">https://blog.iomergent.com/the-vciso-dividend-why-fractional-security-leadership-is-gaining-momentum</guid><description>The appeal of Fractional Security, and vCISO in particular, continues to broaden among small and medium enterprise customers. AI-native companies are retaining vCISOs before they start coding so they can train on proprietary data and achieve compliance benchmarks earlier than ever. Typical startups are getting serious about security and hiring vCISOs at earlier stages thanks to pervasive and increasingly rigorous third-party risk programs.</description><pubDate>Tue, 03 Feb 2026 15:58:11 GMT</pubDate><dc:creator>Brett Wilson</dc:creator></item><item><title>Why Do Fractional CISOs Get Sideways With Your MSP?</title><link>https://iomergent.com/blog/why-do-fractional-cisos-get-sideways/</link><guid isPermaLink="false">https://blog.iomergent.com/why-do-fractional-cisos-get-sideways</guid><description>It’s almost a maxim around here: the more one of our clients needs an MSP (Managed Service Provider) for IT services, the worse the service fit and the security posture between the client and the MSP.</description><pubDate>Thu, 20 Nov 2025 16:43:38 GMT</pubDate><dc:creator>Brett Wilson</dc:creator></item><item><title>A Tale of Two Security Programs and Two Different Trajectories</title><link>https://iomergent.com/blog/a-tale-of-two-security-programs/</link><guid isPermaLink="false">https://blog.iomergent.com/a-tale-of-two-security-programs</guid><description>It was the best of times, it was the worst of times, it was the age of resilience, it was the age of weakness, it was the epoch rigorous protection, it was the epoch of unmitigated vulnerability, it was the season of vigilance, it was the season of disregard.</description><pubDate>Thu, 16 Oct 2025 13:39:35 GMT</pubDate><dc:creator>Brett Wilson</dc:creator></item><item><title>Slay Internal Uncertainty With Effective AI Governance</title><link>https://iomergent.com/blog/effective-ai-governance/</link><guid isPermaLink="false">https://blog.iomergent.com/effective-ai-governance</guid><description>We are willing to wager that, sometime in the last six months or in the six months to come, AI has or will become the top source of angst and opportunity for your business and your employees. Just look at the macro discussion: Record venture funding in AI startups Record valuations of AI startups Record time to revenue traction by AI startups Record investment in datacenters Reported AI trial failure rates between 60 and 95% Persistent underemployment in tech sectors Announcements of future layoffs due to AI efficiency gains</description><pubDate>Thu, 02 Oct 2025 13:43:54 GMT</pubDate><dc:creator>Brett Wilson</dc:creator></item><item><title>SOC 2 Won’t Close the Deal. Customer Trust Will</title><link>https://iomergent.com/blog/soc2-wont-close-the-deal/</link><guid isPermaLink="false">https://blog.iomergent.com/soc2-wont-close-the-deal</guid><description>You’ve secured your SOC 2 report. You’ve passed the audit. Yet, your prospects keep asking questions about your security posture.</description><pubDate>Thu, 11 Sep 2025 14:29:02 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Security Isn’t a Department, It’s How You Operate</title><link>https://iomergent.com/blog/security-isnt-a-department/</link><guid isPermaLink="false">https://blog.iomergent.com/security-isnt-a-department</guid><description>When growing companies decide to “get serious” about security, the instinct is to put someone in charge, give them a title, and make it official.</description><pubDate>Thu, 04 Sep 2025 18:57:26 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The Real Hidden Costs of a Data Breach</title><link>https://iomergent.com/blog/the-real-hidden-costs-of-a-data-breach/</link><guid isPermaLink="false">https://blog.iomergent.com/the-real-hidden-costs-of-a-data-breach</guid><description>When most leaders think of data breaches, they think about the business disruption, client impact, and negative PR. Not to mention the actual unplanned financial cost of investigating, containing, and resolving the incident. From legal fees to fines and penalties, those numbers can add up quickly. We’ve never worked a declared incident where outside counsel was pulled in for less than $35K, and that’s without declaring a data breach. But short of a declared breach, those third party costs typically aren’t the ones that sting the most.</description><pubDate>Mon, 25 Aug 2025 15:37:49 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Policies Without Culture Are Just PDFs</title><link>https://iomergent.com/blog/policies-without-culture-are-just-pdfs/</link><guid isPermaLink="false">https://blog.iomergent.com/policies-without-culture-are-just-pdfs</guid><description>You can’t “compliance” your way out of culture problems.</description><pubDate>Tue, 12 Aug 2025 15:15:48 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>When Hiring a Full-Time CISO Is Too Much</title><link>https://iomergent.com/blog/when-hiring-a-full-time-ciso-is-too-much/</link><guid isPermaLink="false">https://blog.iomergent.com/when-hiring-a-full-time-ciso-is-too-much</guid><description>For many mid-to-late-stage growth companies, the first signs that “it’s time to get serious about security” feel urgent.</description><pubDate>Wed, 30 Jul 2025 15:53:34 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Hiring a CISO Won’t Magically Fix Security. Create Executive Alignment First.</title><link>https://iomergent.com/blog/hiring-a-ciso-wont-magically-fix-security-build-the-program-first/</link><guid isPermaLink="false">https://blog.iomergent.com/hiring-a-ciso-wont-magically-fix-security.-build-the-program-first</guid><description>A CISO without a security program is like a pilot without a plane. Many organizations under pressure to improve cybersecurity hire their first CISO and expect instant results. The reality is that simply appointing an experienced security leader, without first developing a solid understanding of the company’s security related objectives, cyber risks and tolerances, and at least a foundational consensus on how to proceed, rarely solves the problem. And in fact, it can make the problem worse.</description><pubDate>Mon, 21 Jul 2025 14:10:33 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Here are the 4 most thought-provoking cyber security questions the National Association of Corporate Directors (NACD) wants your board to ask you.</title><link>https://iomergent.com/blog/here-are-the-4-most-thought-provoking-cyber-security-questions-the-national-association-of-corporate-directors-nacd-wants-your-board-to-ask-you/</link><guid isPermaLink="false">https://blog.iomergent.com/here-are-the-4-most-thought-provoking-cyber-security-questions-the-national-association-of-corporate-directors-nacd-wants-your-board-to-ask-you</guid><description>We frequently ask these questions to executive teams to gauge the maturity of the cybersecurity program.</description><pubDate>Mon, 14 Jul 2025 12:30:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>We Use That?!</title><link>https://iomergent.com/blog/we-use-that/</link><guid isPermaLink="false">https://blog.iomergent.com/we-use-that</guid><description>Getting Your Arms Around Digital Supply Chain Security Risk In the case of third-party software libraries that your team builds into your SaaS offering, IoT or consumer electronics product, you need to have visibility and internal processes to analyze and manage related risks. The bottom line is that every company uses third-party software and while you don’t have to conduct a code review on everything, you do have to know the risks, in order to prioritize and manage them.</description><pubDate>Mon, 30 Jun 2025 12:45:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>The vCISO Dividend</title><link>https://iomergent.com/blog/the-vciso-dividend/</link><guid isPermaLink="false">https://blog.iomergent.com/the-vciso-dividend</guid><description>How Fractional Security Executive Retainers Make Dollars and “Sense” Most executive leadership teams today are uncomfortably aware of the need for a strong information security posture, but not all are able to ensure it. That might be because: they are focused on their company goals, such as growing the business their risks are not formally defined, or they simply do not have the time, budget, or expertise for information security.</description><pubDate>Sun, 22 Jun 2025 08:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>It takes 12 to 24 months to build a robust security program</title><link>https://iomergent.com/blog/it-takes-12-24-months-to-build-a-robust-security-program/</link><guid isPermaLink="false">https://blog.iomergent.com/it-takes-12-24-months-to-build-a-robust-security-program</guid><description>It takes 12–24 months to build a robust security program</description><pubDate>Thu, 12 Jun 2025 04:15:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Why Do Software Engineers Ignore Security Issues?</title><link>https://iomergent.com/blog/why-do-software-engineers-ignore-security-issues/</link><guid isPermaLink="false">https://blog.iomergent.com/why-do-software-engineers-ignore-security-issues</guid><description>Why is it, even in innovative companies, that development teams tend to ignore information security issues? Engineers and technical leaders don’t want to build insecure applications, platforms, and environments. Yet, in helping companies with their application security and DevSecOps, we usually find significant security backlogs. Let’s take it as a given that building secure applications requires expertise and investment and pose the question: Why is it, even in innovative companies, that development teams tend to ignore information security issues ?</description><pubDate>Thu, 01 May 2025 04:15:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Building a Strong Security Program Using the NIST Cybersecurity Framework</title><link>https://iomergent.com/blog/building-a-strong-security-program-using-the-nist-cybersecurity-framework/</link><guid isPermaLink="false">https://blog.iomergent.com/building-a-strong-security-program-using-the-nist-cybersecurity-framework</guid><description>How to Create Customer Trust and Win New Business</description><pubDate>Wed, 30 Apr 2025 10:00:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item><item><title>Accelerate Growth with a Strong Security Posture</title><link>https://iomergent.com/blog/accelerate-growth-with-a-strong-security-posture/</link><guid isPermaLink="false">https://blog.iomergent.com/accelerate-growth-with-a-strong-security-posture</guid><description>How to Create Customer Trust and Win New Business Chances are, if you are bidding on new business today, you’re being asked to fill out vendor security questionnaires and to demonstrate alignment, or even compliance, with your potential (and current) customers’ security programs, industry regulations, and risk appetites.</description><pubDate>Tue, 29 Apr 2025 11:45:00 GMT</pubDate><dc:creator>Jon Rose</dc:creator></item></channel></rss>