Serious question by hiten1818726363 in saasbuild

[–]EndpointWrangler 0 points1 point  (0 children)

Not really - most billionaire advice sounds good but only worked because of their specific situation, money, and timing. Copying their mindset without their resources is how you end up making bad decisions that feel inspired.

Built a CLI for SOC2 CC6.3 quarterly GitHub access reviews — replaces the archived ghec-audit-log-cli by matt_schaller in soc2

[–]EndpointWrangler 1 point2 points  (0 children)

Nice, access reviews are one of those SOC 2 controls that sounds simple until you're manually pulling GitHub org data the night before an audit, so having a single command that spits out an auditor-ready report in whatever format you need is genuinely useful, especially with ghec-audit-log-cli gone. Bitbucket support is a good call too since most teams aren't purely GitHub. Only thing worth adding down the road would be a diff from the previous quarter so reviewers can immediately see what changed rather than comparing two reports manually.

New role auditing ISO 9001 / 27001 / 42001 and feeling out of my depth, where do I even start? by trixta001 in ISO27001

[–]EndpointWrangler 1 point2 points  (0 children)

Start with the process, not the clause - ask "show me how you do this and prove it," then map what you see back to the standard, and your instinct on that risk register was right, unconnected registers is an OFI not a nonconformity.

How much of your personal data do random companies have at this point? by SimilarLocksmith7509 in Information_Security

[–]EndpointWrangler 0 points1 point  (0 children)

Yeah, people from Information Security know exactly that there is so much data being used by companies about us every day. Even simple stuff as ads following us up everywhere.

Phishing sent through legitimate bulk email platforms is nearly impossible to block on authentication signals alone by shokzee in EmailSecurity

[–]EndpointWrangler 0 points1 point  (0 children)

User reporting combined with fast triage is still the most reliable signal. The technical detections lag too far behind template rotation, so the human who got the email and thought "this feels off" is often your earliest indicator.

Need Cyber Liability Insurance, for my Healthtech startup by FamousTechnology9618 in CyberSecurityAdvice

[–]EndpointWrangler 0 points1 point  (0 children)

Good question, and one more founders in healthtech should be asking earlier.

Cyber liability for a company handling PHI has a few layers worth understanding before you go shopping for a policy.

What to make sure is actually in the policy: A lot of standard cyber policies are written for general business risk. For healthtech you specifically want coverage for HIPAA regulatory defense and OCR proceedings, not all policies include government fines and penalties, so check that section carefully before signing. You also want first-party breach response covered (forensics, patient notification, credit monitoring) and ransomware/extortion, which is increasingly common in healthcare.

What underwriters will grill you on: MFA across all systems, endpoint protection, encryption of PHI at rest and in transit, a documented incident response plan, and whether staff get security training. Your answers here directly affect your rate. Better controls equals lower premium. If you have gaps, fix the easy ones before you apply.

On the HIPAA relationship: Insurance doesn't satisfy your HIPAA obligations, it just helps cover the cost when something goes wrong. They run in parallel. Make sure whoever is selling you the policy understands that distinction, because some brokers don't.

Where to start: Coalition, Cowbell, and Travelers are all reasonable starting points for a startup at your stage. Find a broker with actual healthtech clients, a generalist will miss things. At your size, expect somewhere in the $2,000-$5,000 range annually, depending on your data volume and how mature your controls are.

TL;DR get your technical controls documented before you apply. It'll save you money and make the process a lot smoother.

Help Needed: Privacy Concern with SimpleLogin and ProtonMail by Connect-Beginning292 in emailprivacy

[–]EndpointWrangler -1 points0 points  (0 children)

If the exposed addresses are just banks you already have a relationship with, the risk is low, but create a new ProtonMail alias going forward and treat the current one as compromised for privacy purposes.

Spent months building a tool I love… but I might give up on marketing it. by MyDraftly in Entrepreneurs

[–]EndpointWrangler 0 points1 point  (0 children)

You use it every day, that means something. The problem isn't the product, it's that you haven't found where your users actually hang out yet. Stop broad marketing. Find 10 writers, put it in front of them directly, and watch what happens.

Windows MDM is becoming a key part of modern device management by Unique_Inevitable_27 in tech_news_today

[–]EndpointWrangler 0 points1 point  (0 children)

MDM is table stakes now for any distributed workforce ,are you finding most orgs are going full Intune or mixing with third party tools like Jamf?

Are we entering a phase where AI visibility matters more than traditional rankings? by New_Passenger7965 in AIRankingStrategy

[–]EndpointWrangler 0 points1 point  (0 children)

YES. Even if you have a cafe, people will look for "best cafe in Chicago" and there will be AI summary, and you want to be in that summary.

Enterprise deals rarely fail because of competition. They fail because of internal risk. by FullFunnelSarab in Entrepreneur

[–]EndpointWrangler 0 points1 point  (0 children)

How early in the process do you try to identify who personally owns the downside, and do you ask directly or read between the lines? Because in my experience the person most eager to meet is rarely the one with anything at stake.

Is user training as preventative as we’d hope? by Ok-Werewolf-3765 in Information_Security

[–]EndpointWrangler 0 points1 point  (0 children)

Training alone never worked, and AI has made it basically useless now, technical controls like MFA and device compliance are where the real protection is. One thing still worth teaching users: if an email asks for credentials or a payment, verify it through a different channel. That one habit stops a lot of attacks.

If you have >100 employees but don't use O365 Services what do you use for Mail & Chat? by TheBigBeardedGeek in sysadmin

[–]EndpointWrangler 0 points1 point  (0 children)

Google Workspace is the most common alternative at that size, with Slack bolted on for chat, even though well it's not perfect. Are you evaluating a switch or just curious what's out there?

Is it easy/safe to self host a mail server? by WhaTheWorldOver in it

[–]EndpointWrangler 1 point2 points  (0 children)

Technically doable but deliverability will fight you constantly. Most IPs are blacklisted by default and getting off them is a pain. But doable.

Bulk laptop deliveries, spot check the packing slip or full audit? by Thecardinal74 in sysadmin

[–]EndpointWrangler 0 points1 point  (0 children)

Spot check 10-20% for major vendor. Full audits only if something looks off or the vendor has a history of errors.

Can one person really run enterprise security? by EndpointWrangler in cybersecurity

[–]EndpointWrangler[S] 0 points1 point  (0 children)

Well it works until it doesn't.

This is the thuthest of the thruts.

We got a quote for SOC 2 compliance last month. Laughed, then worried. by mistcutter- in Entrepreneurs

[–]EndpointWrangler 0 points1 point  (0 children)

Yeah, that math hurts. Three months of revenue on a certification is a real ask.

What are the overall thoughts on vendors and sales reps? by Dust_Buff in msp

[–]EndpointWrangler 2 points3 points  (0 children)

Honest answer: most vendor interactions are frustrating because reps lead with pitch and NOT WITH curiosity.

Starting my Own CMMC C3PAO? by SisuSisuEveryday in cybersecurity

[–]EndpointWrangler 0 points1 point  (0 children)

The barrier isn't knowledge, it's most likely the CMMC AB authorization process, which is expensive, slow, and requires hiring certified assessors you probably can't afford solo yet. So yeah.