Dave Shackleford
Owner & Principal Consultant, Voodoo Security
Dave Shackleford is the owner and principal consultant of Voodoo Security and faculty at IANS Research. He has consulted with hundreds of organizations in the areas of security, regulatory compliance, and network architecture and engineering, and is a VMware vExpert with extensive experience designing and configuring secure virtualized infrastructures. Dave is a SANS Analyst, serves on the Board of Directors at the SANS Technology Institute, and helps lead the Atlanta chapter of the Cloud Security Alliance.
Published Work
-
NIST CSF 2.0: Implications for Your Third-Party Risk Management Program
Enhanced cybersecurity supply chain risk management guidance has arrived with the final NIST CSF 2.0. Check...
09/25/2024 by Dave Shackleford
-
Third-Party Breach Response: 6 Immediate Actions to Take
Use these 6 tips to improve your third-party breach response procedures.
09/17/2024 by Dave Shackleford
-
How to Prepare for the Next Software Supply Chain Attack
Learn strategies for mitigating risks stemming from cyberattacks and vulnerabilities against your IT vendors.
05/01/2024 by Dave Shackleford
-
The Top Third-Party Cybersecurity Risk Priorities of 2024 – and...
It’s time to make third-party risk management a priority for your organization. Learn 7 ways to...
01/15/2024 by Dave Shackleford
-
Lessons from the 5 Worst Third-Party Cybersecurity Incidents of 2023
Third-party cybersecurity incidents were especially wide-ranging and damaging in 2023. Here are strategies to mitigate the...
12/19/2023 by Dave Shackleford
-
The Top Third-Party Breaches of 2022 (So Far): Steps to...
The pace of third-party data breaches and intrusions is accelerating at an alarming rate. Use these...
07/27/2022 by Dave Shackleford
-
Using NIST SP 800-61 to Prepare for the Next Third-Party...
More third parties mean more attack paths for cybercriminals targeting your organization. Here’s how the NIST...
11/18/2021 by Dave Shackleford
-
Some Vendor Cyber Risks Are Worse than Others
Be sure to prioritize these top cybersecurity issues in your vendor and supplier risk assessments.
10/19/2021 by Dave Shackleford
-
What Getting Serious About Third-Party Risk Really Means
Every third party represents a unique attack surface into your organization. Follow these steps to mitigate...
08/25/2021 by Dave Shackleford