iCOUNTER’s cover photo
iCOUNTER

iCOUNTER

Computer and Network Security

Dallas, Texas 2,334 followers

Counter Threats Before They Strike

About us

iCOUNTER's Third Party Compromise Intelligence addresses cyber's fastest growing attack vector - third parties. Delivered through our Counter Threat Operating System, iCOUNTER conducts continuous observation on your third parties. Leveraging human and technical intelligence and by monitoring adversary infrastructure, we detect compromise often before the third party's own SOC is aware.

Website
https://www.icounter.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Dallas, Texas
Type
Privately Held
Specialties
Threat intelligence, Cyber risk intelligence, Cybersecurity, Third Party Threat Detection & Response, Third Party Risk Management, and Cybercrime

Locations

Employees at iCOUNTER

Updates

  • AI has changed the economics of cyber risk. Attackers can move faster, scale wider, and exploit the weakest point across an increasingly interconnected retail ecosystem. Join Optimal Advisory’s David Schick and Jonathan Feeney with John Watters, Chairman & CEO of iCOUNTER, for a timely discussion on AI-Driven Cyber Threats to Retail & Brand Global Supply Chains & Digital Assets. Retailers and global brands now depend on payment providers, logistics partners, SaaS platforms, suppliers, and e-commerce technologies. Attackers see that ecosystem as one interconnected attack surface. And with 48% of breaches involving third parties, periodic questionnaires and point-in-time risk assessments are no longer enough. The conversation will explore: • How AI is changing the speed, scale, and asymmetry of cyberattacks • What the next five years of cyber risk could look like for retail and global brands • What management teams should be doing differently now • How investors should evaluate companies that are best, and worst, positioned for this new threat environment At iCOUNTER, we believe the next era of cybersecurity is about more than identifying risk. It is about using intelligence to determine what is actively threatening your organization and ecosystem, then driving action before that risk becomes an incident. Optimal Advisory is an independent advisory boutique focused on the intersection of capital, technology, and the consumer economy. The firm works with investors, boards, and companies, combining sector research, proprietary analysis, and the experience of its team and advisor network to inform investment and strategic decisions. Join the conversation: https://luma.com/ns030i6g #Cybersecurity #ThreatIntelligence #RetailSecurity #ThirdPartyRisk #SupplyChainSecurity #AI #CyberRisk #iCOUNTER The iCOUNTER Team is ready to discuss this hot topic! Muslim Koser, CISSP Ali W. Maggie McDaniel Joey Vinck Joel Molinoff Alexander Harstrick Jay Leek Jeff (J.D.) Jack Jeff Karras Lisa Hayashi Ashley Stone Scott Schneider Jennifer V. Jen Crumley, MBA Jessica Simon Rick LaCoume David P. Smith Danielle M Gagnon Daniel Kropp Mindy L. Natalie Moore

  • Every voice on the Black Hat floor agrees on one thing: the industry is moving into the third wave whether it is ready or not. "I don't think people appreciate how fast and aggressive the new offensive AI tools are getting." So excited to share the latest episode of Watters Edge Podcast! This one is a little different. Instead of a single interview, we took the mic to the floor at Black Hat 2026 for a supercut of quick, honest takes from across the industry, including voices from Cisco, SAP, Armadin, ICM Cyber, and former NSA leadership. We asked everyone the same three questions, and the answers dive deep into: 🔹 The AI Everywhere Effect: Why nearly every conversation, product, and hallway pitch at Black Hat this year ran through AI in some form. 🔹 Riding the Third Wave: How different leaders are thinking about the speed, scale, and formation of this next wave of cybersecurity. 🔹 Industry Myths: The honest, sometimes blunt takes on what the industry accepts as truth that might not hold up. 🔗 Catch the full episode now with the links in the comments! #Cybersecurity #WattersEdge #BlackHat2026 #AI #ThirdWave

  • Vendor criticality should be expressed in business consequences and time. A useful TPRM model scores five dimensions: 1.) Data sensitivity. 2.) Privileged access. 3.) Operational dependency. 4.) Concentration. 5.) Time-to-impact. That last dimension deserves far greater attention. A vendor compromise that can affect production, payments, customer data or privileged infrastructure within hours should receive a different monitoring and response posture. This also gives CISOs and risk leaders a clearer way to prioritize. The strongest vendor risk programs know where exposure exists, how quickly it can become consequential and which action reduces that exposure fastest.

  • Geopolitical volatility shortens the planning horizon for critical infrastructure security. Today, public search interest around the Strait of Hormuz is surging. CISA also issued an active threat advisory involving Siemens S7 programmable logic controllers used across critical infrastructure. For energy, water, agriculture and manufacturing operators, ecosystem visibility becomes essential under these conditions. -System integrators. -Remote maintenance providers. -OT vendors. -Engineering partners. -Internet-exposed devices. -Software and firmware dependencies. Each creates a possible path into operations. Security teams need to know which external organizations can touch critical technology, what access they hold and how quickly that access can be contained. An advisory should trigger action. The dependency map determines where that action starts.

  • The shelf life of a threat intelligence report used to be measured in years. Today it is six months, and shrinking. "The life expectancy of a really well written intelligence report, man, today, six months tops." We're so excited to share the latest episode of Watters Edge Podcast! This week, John Watters sat down with Errol Weiss, Chief Security Officer at the Health-ISAC. They had an insightful conversation that dives deep into: 🔹 Building the ISAC Model: How Errol helped shape FS ISAC in its earliest days and carried those same lessons into growing Health ISAC from a few hundred members to nearly twelve hundred. 🔹 The Shrinking Shelf Life of Intel: Why threat intelligence that used to stay relevant for years now holds its value for about six months. 🔹 The Third Party Risk Blind Spot: Why breaches tied to third parties have jumped from nine percent to forty eight percent in just three years. Catch the full episode now with the links in the comments! #Cybersecurity #WattersEdge #ThreatIntelligence #AI #CyberDefense

  • Life sciences companies operate under continuous scrutiny from investors, regulators, patients and partners. Cyber events enter that visibility cycle fast. This month, Amgen disclosed that attackers stole patient information and proprietary company data from cloud environments operated by third-party providers. For #lifesciences security leaders, the third-party risk map should follow the assets that create enterprise value. -Clinical information. -Patient data. -Research and development. -Intellectual property. -Manufacturing dependencies. #Cloud environments supporting regulated workloads. Each external provider connected to those assets creates a distinct consequence profile. #TPRM becomes far more useful when leaders can see exactly which third-party relationships connect to the information and operations the business cannot afford to lose.

  • AI agents are entering the third-party risk program with credentials, tools and initiative. That combination deserves serious attention. The UK AI Security Institute recently disclosed testing in which AI agents took unsanctioned actions on the live internet. One attempted to insert malicious code into an open-source project and used fabricated identities to pressure a maintainer. For enterprise security teams, agent risk comes down to permissions and reach. What systems can the agent access? What actions can it execute? Which credentials does it inherit? How quickly can those privileges be revoked? Every agent connected to code, cloud infrastructure, identity systems or financial workflows has a potential blast radius. Map it before deployment.

  • A supplier cyber incident can show up as a missed production target before it appears on an executive risk dashboard. A new Make UK survey found that 30% of manufacturers experienced a cyber incident affecting their business or supply chain during the past year. Affected companies reported production delays, output cuts and supplier disruption. #Manufacturing #TPRM needs to connect cyber exposure directly to production dependencies. Which suppliers can stop a line? Which providers have remote OT access? Where are substitute suppliers limited? How quickly can operations isolate a compromised partner? Cyber risk becomes tangible when it reaches throughput, inventory and customer delivery. Vendor visibility should be built around those consequences.

  • #SocialEngineering is becoming an infrastructure problem. Levi Strauss disclosed that an unauthorized third party gained access to company systems following a social engineering attack targeting three employees. Reuters reported that the actors behind a broader phone-based campaign had created digital traps targeting over 200 companies in five weeks. That pattern should get the attention of TPRM leaders. Contractors, service providers, MSPs, support teams and delegated administrators often hold identities with meaningful access into enterprise environments. Those identities create an ecosystem attack surface. Security teams need current visibility into where external access exists, how privileged it is, and what happens when one of those identities is compromised.

  • #Healthcare concentration risk has a very specific shape: One platform. Thousands of providers. Millions of sensitive records. CareCloud disclosed this week that 3.7 million people were affected by a breach involving one of its electronic health record environments. For healthcare security leaders, vendor criticality needs to reflect the full dependency. Patient data. Clinical workflows. Authentication. Revenue operations. Connected providers. Downstream partners. A single technology relationship can create exposure across an entire healthcare ecosystem. That makes dependency mapping a security function, an operational resilience function and an executive risk function. Know which providers can create the largest blast radius. Then make sure their risk posture receives the attention that blast radius deserves.

Similar pages