WRAL Interview: Cyber Attack on Local Utilities

WRAL Interview: Cyber Attack on Local Utilities

WRAL Interviewed Jon Sternstein, Founder & CEO of Stern Security on January 29th, 2025 about recent cyber attacks on local utilities. The initial incident that the story focused on was the cyber attack on the town of Apex, NC which affected the local utilities billing system. Although this attack occurred last summer, the town is still working through the incident.

Jon Sternstein stated that while smaller utilities may have limited internal resources, there are a number a free cybersecurity resources available that they should all be utilizing.

  1. CISA.gov Cyber Hygiene Services – The Cybersecurity and Infrastructure Security Agency (CISA) offers free external vulnerability scans for members of the critical infrastructure. Organizations can enroll and start getting vulnerability scans in days.
  2. Stern Security’s Velocity (Freemium Edition) – Our enterprise cyber risk quantification platform that uses data from accurate internal and third-party risk information has a free version. Smaller organizations can use the free version to evaluate their baseline security and receive recommendations to increase their security.
  3. American Public Power Association (APPA) Cyber Guides – The APPA has free cyber guides such as Incident Response Plans for organizations.

The full interview can be found here: https://www.wral.com/news/local/apex-works-through-billing-issues-months-after-cyber-attack-jan-2025/

WRAL Interview: CrowdStrike Outage

WRAL Interview: CrowdStrike Outage

On Friday, July 19th, 2024, the WRAL News team interviewed Stern Security’s CEO, Jon Sternstein, about the massive CrowdStrike outage that blue-screened Windows devices around the world. Sternstein discussed the importance of business continuity plans and tabletop exercises to prepare for a downtime scenario. It must also be noted that after the downtime incident, CISA warned of threat actors that were quick to create malicious CrowdStrike campaigns to trick victims. The interview can be seen here: https://www.wral.com/story/computer-system-outage-paralyzes-local-companies-cause-travel-delays-and-more/21533355/

Automate SOC 2 Report Reviews

Automate SOC 2 Report Reviews

System and Organization Control (SOC) report reviews are a common part of the third-party due diligence function.  These reports can be lengthy, contain elements that you really need to understand and agree to, different reviewers may produce different results, and one must understand how to properly review them.  It is not sufficient enough to only search to see if there are any exceptions noted in the report.  Your team members have better things to do than read through SOC 2 reports all day.  So, how can you automate SOC 2 Report Reviews?  Velocity automates this for you!

Details

Velocity automates all the items necessary to properly review a SOC 2 report including, but not limited to, exceptions, management responses, trust criteria, ensuring the vendor and product match the expected solution, and more.  The platform also extracts the “Complementary User Entity Controls” or CUECs and creates an “Acceptance” column so customers can formally agree to each control that they are responsible for.  Velocity creates an executive report that customers can read instead of having to read a lengthy SOC 2 report.  Customers can include details in the report such as listing the type of data that the vendor has access to.

Benefits

  1. Speed – Velocity will give you time back in your day by automating the SOC 2 report review process.
  2. Consistency – A company may have multiple employees that analyze a SOC 2 report differently.  Velocity’s automation gives consistent results every time.
  3. Accuracy – An employee may miss something when reviewing a SOC 2 report.  Missed details can be costly for a company as this is the process used to identify risks within a third-party.  Velocity is not only fast and consistent, but also accurate with the reviews.  Velocity knows how to properly review a SOC report as it was built by practitioners.
  4. Documenting Third-Party Due Diligence – Collecting a SOC 2 report is not enough.  Companies need to document that they reviewed the SOC 2 report and Velocity provides a simple way to do that.

Full Assessment

Even after leveraging the automation within Velocity to review the vendor SOC 2 report, customers can still launch a full assessment on the vendor.  For example, let’s say a customer receives a vendor SOC 2 report and uploads it into Velocity.  The executive report that Velocity generates may contain concerning information about the vendor’s security posture.  The customer can then choose to launch a full velocity assessment on the vendor to fully address the concerns and determine when the vendor will resolve the issues.

Conclusion

There is limited time in the day and Velocity is your go-to platform for automating SOC 2 reviews.  Velocity has the benefits of speed, consistency, accuracy, and provides a way for customers to document their third-party review process.

WRAL Interview: AI and Election Meddling

WRAL Interview: AI and Election Meddling

On February 16th, 2024, WRAL News Interviewed Stern Security’s CEO, Jon Sternstein, about AI, deepfakes, and election meddling. The interview discussed the current threat landscape, protective measures, and covered what big tech companies are doing to combat this issue. The interview also discussed positive aspects of AI. The full interview can be seen here: https://www.wral.com/video/cybersecurity-expert-explains-how-ai-could-meddle-in-elections/21288228/

WRAL TechWire Covers Velocity at Venture Connect

WRAL TechWire Covers Velocity at Venture Connect

WRAL TechWire, the leading technology news publication in the Carolinas, highlighted Velocity at the top of their Venture Connect conference coverage. Jon Sternstein, the Founder and CEO of Stern Security, took the stage at CED’s Venture Connect conference. He discussed how the Velocity SaaS product accurately evaluates cyber risk and uses this information to show companies where to spend their cybersecurity budget. The full article can be found here: https://wraltechwire.com/2023/03/30/fighting-hackers-cybersecurity-takes-the-stage-at-venture-connect/