Skip to content
CTS Field Notes

CTS Field Notes

Ideas, observations, and useful links from CTS Companies.

An eclectic collection of interesting things from around the web—technology, security, science, business, and the occasional useful oddity. The connection may be loose; the standard is that each link is worth your time.

Eight Ways Technology Becomes an Organizational Problem

1. NIST small-business cybersecurity resources

NIST’s small-business material is a useful antidote to the idea that security begins with buying the largest tool. It begins with understanding the systems the organization actually depends on.

2. The FTC on vendor security

Third parties create a peculiar kind of risk: they can be outside the organization while still being inside its systems. The remedy is explicit access and explicit responsibility.

3. CISA Cybersecurity Performance Goals

These goals are useful because they turn broad security ambitions into observable practices. A goal is easier to manage when someone can tell whether it happened.

4. NIST cybersecurity basics

The basics are not beneath sophisticated organizations. They are the floor beneath everything sophisticated organizations build.

5. CISA incident-response basics

An incident plan is not a document that proves preparedness. It is a way to reduce the number of decisions people must invent under pressure.

6. FTC data-breach response guide

The guide is a reminder that response includes communication, legal questions, and business continuity—not only technical cleanup.

7. Microsoft’s small-business Zero Trust guidance

“Verify explicitly” is less a slogan than a challenge to assumptions about trusted devices, users, and locations.

8. CISA threat and advisory resources

The useful habit is not reading every alert. It is knowing which alerts could change an actual business decision.

Permalink

Eight Small Clues About Better Security

1. CISA on stronger MFA

CISA makes the useful distinction that MFA is not one uniform technology. The interesting implication is that “MFA enabled” is an incomplete operational description; the method and the recovery process matter.

2. CISA guidance for small and midsize organizations

This guidance connects backups, MFA, least privilege, and vendor access. It is a good reminder that security failures often cross organizational boundaries.

3. The FTC’s small-business cybersecurity guide

The FTC’s advice is intentionally unglamorous: update software, back up data, train people, and plan for incidents. That is precisely why it is useful.

4. NIST Cybersecurity Framework

The framework is best read as a way to organize conversations, not as a badge. Its categories help a leadership team ask what is known, protected, detected, responded to, and recoverable.

5. FIDO’s passkey overview

Passkeys are a useful example of security changing the user experience instead of merely adding another warning. The business question is where they fit in the identity lifecycle.

6. CISA StopRansomware

The value here is not the scary headline. It is the emphasis on preparation, response, and recovery before an incident forces a rushed decision.

7. NIST’s cyber history

The history shows that incident response became a discipline because organizations needed a way to coordinate, not because someone found a perfect security product.

8. FTC vendor-security guidance

Vendor access deserves the same clarity as employee access: who has it, why, for how long, and what happens when the relationship changes.

Permalink