The Coalfire Blog

Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique cybersecurity issues that impact the industries we serve, including Cloud Service Providers, RetailFinancial Services, Healthcare, Higher Education, Payments, Government.

The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts.


  • Ransomware: the anatomy of paying a ransom to decrypt hostage files

    Bryce Bearchell, Security Consultant

    Ransomware is on the rise and clients seeking to understand the process can learn from this client’s story about being a victim of ransomware as to what can be expected and how to handle a ransomware attack. Recently a company facing a malware infection approached us to help them deal with the encryption of most of their servers across their domain. This also included systems that held online backups - and there was no offline backup solution (that’s a topic for a whole different blog post). The company had discovered a ransom note on their affected systems, along with data files that had been deleted and new files created in the format of <original_filename>.whereisyourfile that appeared to be encrypted.

    Read more
  • SOC 2 Type 1 and SOC 2 Type 2 Frequently Asked Questions

    Dixon Wright, VP SOC, ISO, and Healthcare Services, Coalfire

    Coalfire’s SOC Practice Directors Dixon Wright and Jeff Cook recently conducted a webinar on AWS and SOC Reporting, What you need to know. The presentation provided a lot of good points that organizations should know or be prepared for regardless of the technology that is being used. Below you will find a transcript of the Q&A session from the webinar.

    Read more
  • The Cost of a FedRAMP Assessment from a 3PAO Perspective

    Abel Sussman, Senior Project Manager, Commercial Services, Coalfire

    FedRAMP.gov recently published a blog titled ‘How Much Does It Cost to Go Through FedRAMP?’ As a FedRAMP Third Party Assessment Organization (3PAO), we wanted to provide additional factors for consideration for organizations that are evaluating or pursuing a FedRAMP authorization.

    Read more
  • FedRAMP High Baseline Requirements Published

    Abel Sussman, Senior Project Manager, Commercial Services, Coalfire

    The Federal Risk and Authorization Management Program (FedRAMP) Project Management Office officially released its High baseline for High impact-level systems. This baseline is at the High/High/High categorization level for confidentiality, integrity, and availability in accordance with FIPS 199; and is mapped to the security controls from the NIST SP 800-53, Rev. 4 catalog of security controls. Previously, the FedRAMP authorization process was only designed for low and moderate impact systems.

    Read more
  • Displaying results 146-149 (of 149)
     |<  <  21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 >  >|
Top