NetWorks Group Blog

Amanda Berlin

Amanda Berlin is a Senior Security Analyst at NetWorks Group. She has spent over a decade in different areas of technology and sectors providing infrastructure support, triage, and design. Amanda has been involved in implementing a secure Payment Card Industries (PCI) process and Health Insurance Portability and Accountability Act (HIPAA) compliance as well as building a comprehensive phishing and awards-based user education program. She is the author for a Blue Team best practices book called “Defensive Security Handbook: Best Practices for Securing Infrastructure” through O’Reilly Media. She is a co-host on the Brakeing Down Security podcast and writes for several blogs.
Find me on:

Recent Posts

HIPAA vs Security: Building security into medical purchasing decisions

Posted by Amanda Berlin on Jan 23, 2018 10:37:00 AM

What the security community says about a specific industry vertical usually holds true for a good percentage of what is seen in the wild. You can ask any hacker, defender, CISO, etc what industries struggle the most and there are common themes in their answers. Top of the list includes healthcare, manufacturing, government, and financial. Some of the most heavily compliance controlled and regulated are also some of the least secure. Why is this? Is it due to administrators and senior management taking compliance standards as gospel? Maybe it’s a lack of knowledgeable staff like the blind leading the blind.

Read More

Topics: Information Security, Compliance, Healthcare, HIPAA

Spectre & Meltdown: Important Vulnerability Advisory

Posted by Amanda Berlin on Jan 4, 2018 4:09:27 PM

Spectre 

Release Date (01-03-18) CVE-2017-5753 & CVE-2017-5715

Read More

Topics: Ethical Hacking, Threat Management, Threat Advisory

Data Loss Prevention: Fundamentals

Posted by Amanda Berlin on Sep 29, 2017 12:05:42 PM

Where to start with Data Loss Protection

DLP or Data Loss Protection is a strategy for ensuring that end users or malicious actors do not send sensitive or critical information outside the corporate network either maliciously or accidentally. A DLP strategy should only be introduced within organizations that already have a mature security infrastructure.

Read More

Equifax breach: A learning opportunity to get ahead of the constant threats

Posted by Amanda Berlin on Sep 8, 2017 12:10:43 PM

If you haven’t heard already, Equifax one of the “big-three” U.S. credit bureaus has announced a data breach that may have affected 143 million Americans, including consumer Social Security numbers, birth dates, addresses and some driver’s license numbers. For a good rundown of what has transpired so far, Krebs on Security has a solid in-depth article on it here. Every time there is a breach in the news, most other outlets swarm to a few different types of articles. Some popular directions are attribution, defense advice, or sensationalist journalism.

Read More

Topics: Managed Detection & Response, Ethical Hacking, Information Security, Threat Advisory

Subscribe to our blog!