On July 10th, 2025, Stern Security‘s Founder & CEO, Jon Sternstein spoke to financial organizations at the Carolinas Credit Union League event. Jon Sternstein discussed the essentials of quantifying cyber risk in the age of AI threats. The world is rapidly evolving and there are numerous way to conduct cyber risk quantification and business impact analysis activities to speak the language of the business.
Presentation Abstract
“Love, Lies, and Ledger Sheets: Quantifying Cyber Risk in the Age of AI Threats” by Jon Sternstein
“In a world where artificial intelligence can mimic your voice and craft malware that slips past traditional defenses, cybersecurity is no longer about counting vulnerabilities—it’s about understanding business risk. Join Stern Security’s Founder & CEO, Jon Sternstein, as he unveils the evolving threat landscape through real-world stories (starting with a romance you won’t forget), and makes the case for why credit unions must shift from legacy reporting to actionable cyber risk quantification. Plus, a light look at global tensions and what they could mean for your cyber defenses.”
Conclusion
The presentation went into details about modern threats (AI deception threats, romance scams, gift card scams, wire transfer attacks, hacking incidents) in addition to proven solutions. Jon discussed various methodologies to quantify risk from simple to advanced options. Stern Security’s Velocity platform automates the cyber quantification needed to translate the security risk into business terminology and quickly help make security teams successful. The presentation include engaging true stories, laughs, “wow” factors, and audience participation cyber challenges. The credit unions left the event inspired and armed with the tools they need to increase their security posture to the next level.
In today’s complex cybersecurity environment, Chief Information Security Officers (CISOs) face mounting pressure. Threats grow more advanced, regulations more demanding, and business operations increasingly intertwined with cyber risk. CISOs must balance these challenges while aligning cybersecurity initiatives with business strategy. Data and analytics are no longer optional—they are vital for budgeting, risk management, and executive communication.
That’s where Velocity by Stern Security comes in—a pioneering cyber risk analytics platform built specifically for today’s cybersecurity leaders. Velocity doesn’t just provide data; it delivers clarity, helping CISOs make smarter, faster decisions and clearly demonstrate value to stakeholders.
Why Cyber Risk Analytics Matters
Velocity is more than just another analytics tool—it sets the standard for cyber risk analytics by giving CISOs strategic advantages to stay ahead:
1. Unified Risk Visibility
Gain a comprehensive, single-pane view of your organization’s cyber risk posture.
2. Data-Driven Decision Making
Quantified risk metrics enable informed prioritization, helping CISOs assess impact, likelihood, and the effectiveness of mitigation strategies with precision.
3. Cost Efficiency
By tying cybersecurity plans to financial data, analytics platforms reveal solution overlaps, identify savings opportunities, and streamline budget planning.
4. Streamlined Compliance
Simplify tracking and reporting for regulations like HIPAA, NIST CSF, and CISv8.1. Automated tools reduce administrative burden and strengthen audit readiness.
Stern Security’s Velocity platform is purpose-built for CISOs. It redefines the cyber risk analytics space by bridging the gap between technical cybersecurity operations and business impact through precise financial quantification.
How Velocity Empowers CISOs:
Financial Clarity
Translate Risk: Convert technical risks into financial terms to facilitate clear communication with executives.
Justify Budgets: Use financial data to support investment decisions and secure resources.
Prioritization and ROI
Focus Remediation: Identify and prioritize the most significant risks based on cost impact.
Optimize Spending: Recommend solutions based on ROI to make the most of existing resources.
Compliance & Reporting
Automate Reporting: Generate ready-to-deliver reports for HIPAA, NIST, CIS, and more.
Audit Readiness: Track progress, store evidence, and simplify preparation.
Executive Communication
Dashboards That Speak Business: Visualize key risks and financial exposure in executive-friendly formats.
Board Alignment: Equip CISOs with the data they need to engage boards in meaningful conversations.
Real-World Use Cases
Mergers & Acquisitions
Evaluate cyber risk and compliance posture of acquisition targets.
Quantify potential financial impact to inform negotiations and due diligence.
Cyber Insurance
Assess breach cost estimates to validate insurance coverage levels.
Use quantified data to negotiate better policy terms.
Score and track vendor risk using verified evidence.
Automated SOC 2 reviews for greater efficiency.
Final Thoughts
Velocity is not just a tool—it’s the cyber risk analytics platform for today’s CISOs. By quantifying risk, simplifying compliance, and improving communication, it empowers CISOs to lead with clarity and confidence. Built with innovation at its core, Velocity positions cybersecurity as a strategic business enabler.
Want to learn how our cyber risk analytics platform, Velocity, can empower your cybersecurity strategy?
Thousands of wide-eyed spectators around the world were getting ready to watch the Olympics, one of the largest events in the world. Suddenly the main website for the Olympic games goes down. The website was not only informational, but it was also the online ticketing system so in-person spectators couldn’t retrieve tickets. Next, the wi-fi at the games went offline leaving many individuals without connectivity to the outside world. This happened at the 2018 PyeongChang Winter Olympics in South Korea after a successful phishing attack and malware dubbed “Olympic Destroyer” spread through the compromised network. Connectivity was restored within a few hours at the 2018 games. Unfortunately, cyber-attacks are common occurrence at large events. This is why one must SECURE the Games by implementing solid cybersecurity measures.
Olympic Interview
Jon Sternstein, the Founder and CEO of Stern Security was interviewed by Spectrum News before the 2024 Olympic games in Paris to discuss protecting large events. In the interview, Sternstein discussed previous attacks at Olympic games. He discussed how event organizers have their work cut out for them at the games. Finally, he concluded with a mnemonic, SECURE, he uses to educate event attendees for staying protected.
S – Sources: Use only known good sources of information.
E – Enable updates: Keep devices up to date with the latest patches.
C – Caution with links: Be careful about clicking on links.
U – Use official apps: Only use official apps for event information.
R – Restrict network access: Be careful when joining unknown networks.
E – Enable MFA: Enable multi-factor authentication.
To make the best business case for increasing cybersecurity at major events, one must quantify the risk. Disruptions to ticketing systems have a direct financial impact that can be calculated. This is the same with customers asking for refunds because of the inability to retrieve tickets or attend events. Customers losing confidence in the ability for organizers to have a smooth event, may impact future ticket sales as well. A cyber attack that limits the ability for spectators to enter a venue (disrupting ticketing systems, misdirecting individuals, etc…) affects concession sales, merchandise sales, and sponsors at the event. Sponsors may even be less willing to sponsor future events if they lose confidence in the ability for event organizers to pull off a secure event. Cybersecurity teams can use the financial loss data from quantifying cyber risks to receive the. necessary budget and optimize cyber costs at the event.
The CIA Triad and Large Event Security
The core pillars of cybersecurity are Confidentiality, Integrity, and Availability. Large games such as the Super Bowl and the Olympics need to cover all three pillars to have a smooth event.
Confidentiality: It is essential to protect attendee data, athlete/celebrity/VIP data, media/programming content, and secure communications.
Integrity: Ensuring that directions, results, ticketing, broadcasts and aren’t tampered with.
Availability: Keeping official communications, apps, ticketing, payment systems, and broadcasts online.
SECURE Mnemonic for Attendees
Stern Security created the mnemonic, SECURE, to help event attendees have an easy way to remember protective measures.
S – Sources: Event attendees should only use known good sources of information. Use the official webpage for an event to receive the schedule, ticketing information, seating, and transportation information.
E – Enable updates: Keep devices, including phones and laptops, up to date with the latest patches. Attendees and spectators may be targeting by malware and it is essential to keep electronic devices up to date.
C – Caution with links: Always be careful about clicking on links. Criminals will often send spam, phishing emails, or malicious advertisements that target event attendees. Only click on links that are trusted and necessary.
U – Use official apps: When attending an event, only download and use the official app, no matter how tempting other events look..
R – Restrict network access: In-person attendees should be careful when joining unknown networks. There may be many “free wi-fi” networks that may be malicious. Utilize your cellular connection instead of joining wi-fi networks if possible. If a wi-fi network is needed, only connect to the official guest network that is listed on the official event details.
E – Enable MFA: Enabling multi-factor authentication is an absolute necessary security measure to protect your account. Don’t let criminals get into your account and take your expensive tickets.
Quantifying Cyber Risk and ROI with Velocity
Cybersecurity is often viewed as an expense rather than an investment until an incident occurs. Stern Security’s Velocity platform helps organizations move beyond vague cyber plans and ineffective gap assessments by delivering quantifiable metrics, optimizing cyber costs, calculating cyber ROI, and prioritizing protective measures. Use Velocity’s data-driven intelligence to increase security.
Conclusion
As more criminals direct their attention towards large gatherings such as the Olympics and the Super Bowl, cybersecurity professionals must be proactive in their defense efforts. In order to get the needed resources to protect an event, cyber defense teams must quantify risk and show the likelihood and impact of a cyber threat. The SECURE mnemonic can be used by attendees to have an easy way to remember how to protect themselves while attending events. When performed effectively, cybersecurity defense measures will help large-scale events operate without incident.
There are hundreds of cybersecurity products on the market and it can be difficult to select one between the noise. Do you select a cybersecurity product based on an alert you see on the news? Choose based on an advertisement or magazine article? Do you simply select one because it appears on a “magic quadrant”? Here are the top 5 tips for choosing a cybersecurity product.
Tip #1: Fits a Gap
The top tip for choosing a cybersecurity product is to look for one that fits a gap or need within your environment. The most straightforward way to do this is to align your organization with a cybersecurity framework or maturity model.
For example, if you choose the CISA Zero Trust 2.0 Maturity Model, the “Authentication” function within the “Identity” pillar requires “phishing-resistant MFA (multi-factor authentication)” once you reach the advanced maturity level. To accomplish this maturity level and fill the gap within your posture, you may purchase hardware WebAuthn/FIDO2 keys such as Yubikey or Feitian. This purchase fits a direct need and helps your organization achieve a higher cybersecurity maturity level for your chosen framework.
Tip #2: It Works
After you determine that a product fits a gap, it has to work in your environment. See if you can do a free trial before you buy. The product may also have a freemium model so you can use the free version and upgrade to the paid version when you determine that the product works and fulfills a need. Even security hardware companies will usually let an organization test a product before purchasing.
Tip #3: Secure
This should go without saying, but a cybersecurity product should be secure. It’s always a good idea to do your due diligence on a product and company before utilizing it. The product should increase security posture, not the opposite. You can request security audit or perform your own. Research should also be performed on the company and product.
Tip #4: Pricing
The cybersecurity product should fit your budget. If you need the product and you don’t have the budget…then you may need a larger budget. Alternatively, you can look for less expensive or open-source options to fulfill your needs.
Tip #5: Recommendation
Lastly, you can choose a cybersecurity product based on a recommendation from a colleague. The benefit with utilizing a recommendation is that you have a solid review from a trusted source. On the downside, your colleague’s environment and use cases may be different than yours so the product may not work the same in your environment. Additionally, it may be more difficult to find the most innovative product if you’re only choosing products based on older recommendations. The most innovative product may be a new offering from a known vendor or new startup.
Velocity Can Help
Stern Security’s Velocity product helps organizations find the best cybersecurity products for their needs by aligning a company’s security posture to a security framework or maturity model (Tip #1), and then showing the solutions that are needed to fill the gaps.
Conclusion
While there are many choices on the market, these are the top 5 tips for choosing cybersecurity products. Use these tips to sift through the noise and choose the best products for your organization.
The 2022 Triangle InfoSeCon event hosted by Raleigh’s ISSA was on September 9th, 2022. To a full crowd, Stern Security‘s Founder & CEO, Jon Sternstein, gave a presentation titled: “Break Down Silos & Secure the Planet”.
The presentation abstract was the following:
People tend to cluster in their own silos and tribes in both society and within companies. We have seen the dangers of lack of communication between individuals with different viewpoints play out between nations, states, politics, and more. This siloed mindset also occurs within companies and industries and can lead to massive cybersecurity issues.
This presentation will discuss the importance of breaking down silos. Technical stories will be shared of large security vulnerabilities that we have discovered that would have been prevented if the company’s employees and contractors did not operate in silos. We’ll also discuss some hacks to break out of your own silos, hack impostor syndrome, infiltrate executive ranks, and secure the planet.
Jon Sternstein’s presentation was an important lesson on working together to secure companies and to have a stronger society. Secure the Planet!
Our company mission is to “Secure the Planet”. This means that we aim to provide education and solutions that any company in the world can use to reduce cyber risk. Our flagship product, Velocity, is a web application (SaaS product) which companies can use to evaluate their own cybersecurity posture as well as to evaluate cyber risks in all of their third-party vendors. While we strive to have fair pricing and various levels that companies of any size can subscribe to, it’s clear that some organizations simply do not have funds budgeted to spend on cybersecurity or to try new products. We’re moving Velocity to a freemium model so any company can measure their baseline security posture for free.
Details
If we’re serious about securing the planet and providing solutions for all organizations regardless of size and budget, we needed to expand our offerings. From my many years working in the cybersecurity industry, both on the customer side and the consulting side, I know that many organizations do not evaluate their security posture at all. Many of those that do, still measure their security posture using an inefficient, often inaccurate, spreadsheet approach. They list every cybersecurity measure that they should be doing in one column and then they state whether they are completing the task or not in another column. It’s easy, but inefficient, painful to manage, difficult to track progress, and tough to update. Velocity eliminates the need for spreadsheets to measure internal risk with these known frameworks. The free version of Velocity is an easy and economical tool for any company in the world to measure their cyber security posture.
What is included?
In the free version of Velocity, companies can evaluate their own security posture using any of several frameworks. Additionally, companies receive access to dashboards that give critical insight into their security posture. As an added benefit, companies eliminate the use of inefficient spreadsheets to evaluate risk. The frameworks that are included in the free version of Velocity are as follows:
CISA Shields Up – To address increased risk due to Russia’s invasion of Ukraine, the Cybersecurity & Infrastructure Security Agency (CISA) released security guidance for organizations. This free valuable guidance is built into Velocity. We will continue to update this significant resource on Velocity as the guidance updates and transforms.
CMMC 2.0 Level 1 – In late 2021, the Department of Defense (DoD) released CMMC 2.0 which is designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). There are three levels within this model and most defense contractors will need to adhere to Level 1. Organizations can evaluate their compliance with Level 1 CMMC 2.0 for free within Velocity. The smaller subset of organizations that access more classified information can pay for a Velocity subscription to evaluate their compliance with the higher levels within this framework. Our company pays to have certified CMMC staff. For more information on CMMC, please review our latest article on the subject: https://www.sternsecurity.com/blog/cmmc-2-0-program-update/
CIS v8 Group 1 – The Center for Internet Security (CIS) has a well-known list of cybersecurity controls that are recommended for all organizations. The latest version (v8 as of this writing) splits the security framework into three groups depending on the size and cybersecurity maturity of the organization. The free version of Velocity includes the first group, Implementation Group 1. Organizations looking to evaluate their maturity with Groups 2 and 3 can upgrade to a paid subscription within Velocity. Our company pays an annual license fee to utilize this security framework.
How do we pay for this?
We have to pay for this somehow as we definitely cannot help secure the planet if we don’t have the funds to run our product. While several frameworks (or parts of frameworks) are free, we have over 10 other major security and compliance frameworks that companies can pay a subscription for. We continue to add more frameworks. We pay subscription fees which we pass on to companies who subscribe to additional features within Velocity. Additionally, we charge companies to evaluate the security posture of their vendors. While utilizing the free version, there is an easy path to upgrade to a paid subscription to utilize other frameworks or evaluate vendors.
I’m incredibly excited to announce our freemium version of Velocity. This is the result of months of hard work from an amazing team. We are so proud of the result and what it can do for the world. Now that Velocity is offering this freemium model, we see a clear path to making our motto “Secure the Planet” a reality. Velocity is not going to solve every cybersecurity problem, but it does give organizations actionable items they can perform to reduce risk. Now any company in the world can measure their baseline security for free on a beautiful web interface.