“Before Tyler joined Exabeam, we faced a series of security incidents in rapid succession—serious enough to require direct involvement from our CMO and me (Product) for damage control and corrective action. From the moment Tyler stepped in, he took ownership by stabilizing and transforming our security posture. Within weeks, the difference was clear. He conducted a thorough audit of all known risks, uncovered additional vulnerabilities, enhanced our crisis communications playbook, and developed a strategic plan to systematically reduce our exposure quarter over quarter. Thanks to his leadership, for the remainder of my four years at Exabeam, I was never pulled into another security incident and was able to focus entirely on growing the business. Tyler is a rare breed—a pragmatic CISO who delivers robust security without burdening the organization with unnecessary bureaucracy or secrecy. He’s an invaluable asset to any team, and I would work with him again in a heartbeat.”
Sign in to view Tyler J.’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tyler J.’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
San Francisco Bay Area
Sign in to view Tyler J.’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
11K followers
500+ connections
Sign in to view Tyler J.’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tyler J.
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tyler J.
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tyler J.’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Recommendations received
2 people have recommended Tyler J.
Join now to viewView Tyler J.’s full profile
-
See who you know in common
-
Get introduced
-
Contact Tyler J. directly
Other similar profiles
-
Michael D. Farren, CISM, CAP, CMMC (AB)-RP, CDPSE
Michael D. Farren, CISM, CAP, CMMC (AB)-RP, CDPSE
Golden Gate University
3K followersLas Vegas Metropolitan Area
Explore more posts
-
Kingz Protection and Security Services INC
12 followers
📈 The Growing Need for Security Guards in California Crime patterns and risk landscapes are shifting—businesses, communities, and properties across California now require stronger security measures. KPSS dives into how increasing incidents, organized theft, and evolving threats make professional guard services Not Optional—but Essential. Read more to understand the risks and smart strategies. 🔗 https://lnkd.in/gbcgjs3j #SecurityTrends #CaliforniaSafety #SecurityGuards #RiskManagement #KPSSInsights #ProtectWhatMatters
-
Anergi - Cybersecurity Incident Management
518 followers
The Trustee Partner Model for Enterprise Incident Management in 2026 In the current threat landscape, enterprise resilience is defined by the transition from reactive recovery to proactive, managed readiness. For Anergi’s clients, Incident Management is a core pillar of our trustee partnership—an integrated lifecycle that combines technical precision with strategic governance to safeguard business continuity. 1. Enterprise Readiness and Continuous Simulation Readiness in 2026 is no longer a static state achieved through annual reviews. Anergi aligns client infrastructure with the updated NIST SP 800-61r3 framework, treating incident response as a continuous process. Agentic AI Tabletops: We conduct advanced simulations specifically designed for automated threats, such as model poisoning and fast exfiltration. These exercises identify communication gaps between technical teams, legal, and executive leadership. Mapping Identity and Assets: You cannot protect what you cannot see. We maintain real-time inventories of "Non-Human Identities" (NHIs) and critical assets, ensuring that containment strategies are ready for immediate execution. 2. High-Fidelity Triage and Decision Authority Enterprise-scale environments generate immense signal noise. Our process prioritizes high-fidelity detection, ensuring remediation resources are deployed based on actual business risk. The Incident Commander Model: During an event, Anergi establishes a single point of decision-making authority. This role manages stakeholder communication and prioritizes remediation tasks, preventing the coordination delays that typically double containment times. Strategic Prioritization: Incidents are categorized by tangible impact—customer data exposure, financial risk, and regulatory implications—ensuring that response efforts remain aligned with organizational goals. 3. Surgical Containment and Identity-First Response With nearly 90% of modern investigations involving compromised credentials, our containment strategies are identity-centric. Autonomous Containment: We utilize AI-driven response to isolate compromised workloads and revoke session tokens in real-time. This "Identity-First" approach halts lateral movement without requiring a total network shutdown. ISO 42001 and AI Governance Integration: Our response protocols are mapped to ISO 42001 (Artificial Intelligence Management System). When an AI agent deviates from its baseline, our systems trigger automated guardrails to ensure its actions remain within legal and ethical envelopes. References: https://lnkd.in/e-qzbkJc https://lnkd.in/eEKeRVAy https://lnkd.in/eBi9fy5R
-
Glossifi Inc
128 followers
Scanners, audits, monitoring, SBOMs, reputation systems, governance frameworks. A dense network of epistemic feedback loops that often feed back into a void. The question is what happens when those signals stop terminating in reports and start coordinating capital instead. https://lnkd.in/grQ6-6dc
1
-
Giulio Saggin
SecAlerts • 528 followers
CRITICAL VULNERABILITY ALERT CISA has highlighted a critical security vulnerability - CVE-2025-5086, CVSS 9.0 - impacting Dassault Systèmes DELMIA Apriso Manufacturing Operations Management (MOM) software. According to Dassault, the issue impacts versions from Release 2020 through Release 2025. Information for this vulnerability can be found on SecAlerts: CVE-2025-5086, CVSS 9.0: https://lnkd.in/gBRUAAbw #ciso #cio #cto #vulnerabilities #cybersecurity #secalerts #msp #mssp #dassault #CVE20255086 https://lnkd.in/ga29CFy4
2
-
Exoexcellence
3K followers
Characterizing Cybersecurity Outcomes NIST IR 8349 introduces a methodology for defining and measuring cybersecurity outcomes. 📊 This supports ISO/IEC 27001’s requirement for evaluating the effectiveness of security measures and driving continual improvement. Exoexcellence shares this to promote outcome-driven security. #ISO27001 #CyberRisk #SecurityMetrics #ISMSImprovement #NISTMethodology #Exoexcellence
1
-
SecureTECC Solutions
8 followers
Cybersecurity is no longer optional for Ventura County businesses. From phishing emails and ransomware attacks to weak passwords and outdated systems, cyber threats are becoming more common across Ventura, Oxnard, Thousand Oaks, and Camarillo. Many small and mid-sized businesses assume they’re too small to be targeted — but in reality, they’re often the most vulnerable. A single cyber incident can disrupt operations, expose sensitive customer data, and create serious compliance risks under California privacy laws like CCPA and CPRA. That’s why we created a practical Cybersecurity Guide specifically for Ventura County businesses. Inside the guide, you’ll learn: • Common cyber threats affecting local businesses • Email and cloud security best practices • Data backup and ransomware protection strategies • California cybersecurity and data privacy considerations • Long-term cybersecurity planning for business resilience Strong cybersecurity is not just about protection — it’s about business continuity, trust, and long-term growth. Read the full guide here: https://lnkd.in/gHRusXY3 Have questions or need reliable IT support? Get in touch today through the link in our bio. 877-707-TECC info@securetecc.com securetecc.com Proudly based in Ventura County, serving Santa Paula, Ventura, Oxnard, Camarillo, Thousand Oaks, Santa Barbara, Fillmore, Hollywood, Beverly Hills, Pasadena, and Burbank. #Cybersecurity #VenturaCounty #ManagedITServices #BusinessCybersecurity #ITSupport #OxnardBusiness #ThousandOaksBusiness #SecureTECCSolutions #CaliforniaBusiness
2
-
Dan Nguyen-Huu
Decibel Partners • 9K followers
CISA Issued an Emergency Directive on the F5 Breach What We Know So Far 👉On October 15, 2025, CISA released Emergency Directive ED 26-01, compelling federal civilian agencies to inventory, patch, isolate, or decommission vulnerable F5 devices. 👉 The breach stems from a nation-state actor gaining persistent access to F5’s internal development and engineering systems starting in August 2025. 👉Exfiltrated data reportedly includes segments of the BIG-IP source code and F5 asserts there’s no evidence of tampering with its build pipelines or supply chain, nor confirmed exploitation of undisclosed vulnerabilities. 👉That said, some stolen files may include configuration or implementation data tied to a limited subset of customers, which could offer threat actors insight into deployment patterns. What Organizations & Customers Should Know: 1. Inventory your F5 footprint: Catalog all physical and virtual F5 devices (BIG-IP, F5OS, BIG-IQ, etc.). 2. Evaluate exposure: Check for public internet access to management interfaces; reduce or eliminate such exposure. 3. Apply patches immediately: Apply F5’s October 2025 updates. Prioritize modules with known vulnerabilities. 4. Retire or isolate unsupported hardware: If a device is end-of-support or cannot be securely patched, plan decommissioning or isolation. 5. Enhance logging, monitoring, and threat hunting: Monitor for suspicious changes, credential use, lateral movement, and configuration drift. 6. Engage in forensic review if signs of compromise emerge: If you detect anomalies, coordinate with incident response and your F5 contacts. Big shoutout to Matt Johansen for his clear and concise breakdown on Vuln U. Great resource to follow along on what the latest is (see link below).
32
6 Comments -
Hussar Systems LLC
42 followers
Audit Retrospective: Lagging Event Logging Maturity Hindered Federal Cybersecurity Response A 2023 GAO report found that 20 of 23 major federal agencies had not met advanced event logging requirements by the deadline. This highlighted the persistent challenge of implementing foundational security controls at scale across complex government IT environments. The performance audit reviewed the incident response capabilities of 24 Chief Financial Officers Act agencies from January 2022 to December 2023, focusing on implementation of Executive Order 14028 requirements. Logging Shortfalls: As of August 2023, auditors found that only 3 agencies had reached the required "Advanced" (Tier 3) maturity level for investigative logging, while 17 remained at the "Not Effective" (Tier 0) level. Detection & Remediation Risk: The report documented that until event logging is fully implemented, the government's ability to detect, investigate, and remediate cyber threats remains constrained. Progress in Other Areas: The review noted positive progress in standardizing incident response plans, with all 23 agencies incorporating the CISA playbook, and 16 agencies reporting at least 80% endpoint detection coverage. Key Challenges: Agency officials identified three major hurdles: lack of skilled staff, technical complexities in logging (especially with legacy systems), and limitations in sharing timely, actionable cyber threat intelligence. Audits like this provide the essential benchmarks that catalyze structured improvement and resource prioritization. The underlying issue of operationalizing comprehensive security telemetry is universal: what foundational data controls has your organization prioritized to ensure effective incident investigation and response? For the detailed findings, review the 2023 GAO report GAO-24-105658, "CYBERSECURITY: Federal Agencies Made Progress, but Need to Fully Implement Incident Response Requirements." #GAO #Audit #Cybersecurity #IncidentResponse #Governance #RiskManagement #Compliance #PublicSector #ContinuousImprovement #ITSecurity
1
-
Hitchhiker's Guide to the GRC Technology Galaxy Podcast
2K followers
In this episode of The Hitchhiker's Guide to the GRC Technology Galaxy Podcast, GRC field researcher and intergalactic GRC hitchhiker Michael Rasmussen sits down with Adil Khan, CEO of SafePaaS, to explore what governance looks like when the enterprise is no longer neatly contained. They begin with the story of SafePaaS, including where it came from, what it set out to solve, and why it has taken a different path from many other GRC platforms. At its core, SafePaaS focuses on one of the most immediate and material risks organizations face today: cybersecurity risk, and how controls around identity, transactions, and access can be continuously governed rather than periodically checked. The conversation moves into real-world use cases, from IT general controls and segregation of duties to continuous monitoring across complex ERP and cloud environments. Along the way, Adil explains how SafePaaS delivers not just compliance, but efficiency, effectiveness, resilience, and agility and why those outcomes matter more than features alone. They also explore how SafePaaS is approaching AI and where it’s being applied today, what’s practical versus speculative, and how automation is reshaping control environments. Finally, they look ahead to 2030 and what governance may need to become as enterprises grow more distributed, systems more autonomous, and risk more dynamic. In a universe where complexity tends to expand faster than control, staying “under control” may require rethinking how control itself is designed.
4
-
Kalpa Consulting Services
548 followers
Running a GRC program isn’t advisory work. It’s operational. It’s tracking open items and aging. It’s following up until closure. It’s reviewing evidence consistently. It’s escalating when timelines slip. It’s keeping systems current so leadership has visibility. Strategy sets direction. Execution determines outcomes. #GRC #RiskManagement
-
Mark43
17K followers
A lot of public safety technology vendors talk about security. Few can prove it. When evaluating your CAD/RMS vendor or issuing your next RFP, ask: Do they maintain ALL of the following? ✅ CISA Secure by Design Pledge ✅ SOC 2 Type II ✅ CJIS Security Policy compliance ✅ FedRAMP High Authorized (RMS/CAD) ✅ GovRAMP High Authorized ✅ ISO 27001 certified ✅ Cyber Essentials Plus At Mark43, the answer is yes — across the board. Not "some". Not “in progress”. Not “roadmap”. All of them. Why? Because protecting sensitive public safety data isn’t a feature, it’s a responsibility we take seriously. If your current vendor can’t check every box, it’s worth asking why. Mark43 maintains one of the strongest security postures in the public safety market. Learn more: https://trust.mark43.com/ and request a demo: https://bit.ly/4rQPRGp
32
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content