---
title: | white paper
description: white paper |
---

<https://blog.nisos.com/technical-blogs/tag/white-paper#tmpmodule_158169730197071>

- [Home](https://www.nisos.com/)
- Solutions 
    - [Manage Human Risk](https://nisos.com/solutions/human-risk/)
    - [Protect Online Platforms](https://www.nisos.com/solutions/trust-safety/)
    - [Manage Cybersecurity Risks](https://www.nisos.com/solutions/cybersecurity/)
    - [Protect Executives, Assets, and Reputation](https://www.nisos.com/solutions/corporate-security/)
    - [Secure the Employee Lifecycle](https://nisos.com/solutions/workforce-risk/)
- Services 
    - [Human Risk](https://nisos.com/services/human-risk/) 
          - [Employment Shield](https://nisos.com/services/employment-shield/)
          - [Executive Shield](https://nisos.com/services/executive-shield/)
          - [Third-Party Intelligence Solutions](https://nisos.com/services/third-party-intelligence-solutions/)
          - [Insider Threat Intelligence Solutions](https://nisos.com/services/executive-shield/)
    - [Risk Assessment](https://www.nisos.com/services/risk-assessments/) 
          - [Threat Landscape](https://www.nisos.com/services/threat-landscape-assessment/)
    - [Threat Monitoring](https://www.nisos.com/services/threat-monitoring/) 
          - [OSINT Monitoring & Analysis](https://www.nisos.com/services/osint-monitoring-and-analysis/)
    - [Investigations](https://www.nisos.com/services/investigations/) 
          - [Adversary Investigation](https://www.nisos.com/services/adversary-insights/)
- Company 
    - [About Us](https://nisos.com/company/about-us/)
    - [The Nisos Difference](https://nisos.com/company/the-nisos-difference/)
    - [Client Success](https://nisos.com/company/client-success/)
    - [Careers](https://www.nisos.com/company/about-the-company/careers/)
- Resources 
    - [News](https://www.nisos.com/newsroom/)
    - [Blog](https://www.nisos.com/nisos-blog/)
    - [Events](https://www.nisos.com/events/)
    - [Resource Library](https://www.nisos.com/resources/library/)
    - [Podcasts](https://www.nisos.com/podcasts/)
- [Contact](https://www.nisos.com/contact/)

[![Nisos-Logo-Blue](https://blog.nisos.com/hubfs/Nisos-Logo-Blue.png) ![Nisos-Logo-White](https://blog.nisos.com/hubfs/Nisos-Logo-White.png) ![Nisos-Logo-Blue](https://blog.nisos.com/hubfs/Nisos-Logo-Blue.png)](https://www.nisos.com/)

- [Default HubSpot Blog](https://blog.nisos.com/blog)

- [Home](https://www.nisos.com/)
- Solutions 
    - [Manage Human Risk](https://nisos.com/solutions/human-risk/)
    - [Protect Online Platforms](https://www.nisos.com/solutions/trust-safety/)
    - [Manage Cybersecurity Risks](https://www.nisos.com/solutions/cybersecurity/)
    - [Protect Executives, Assets, and Reputation](https://www.nisos.com/solutions/corporate-security/)
    - [Secure the Employee Lifecycle](https://nisos.com/solutions/workforce-risk/)
- Services 
    - [Human Risk](https://nisos.com/services/human-risk/) 
          - [Employment Shield](https://nisos.com/services/employment-shield/)
          - [Executive Shield](https://nisos.com/services/executive-shield/)
          - [Third-Party Intelligence Solutions](https://nisos.com/services/third-party-intelligence-solutions/)
          - [Insider Threat Intelligence Solutions](https://nisos.com/services/executive-shield/)
    - [Risk Assessment](https://www.nisos.com/services/risk-assessments/) 
          - [Threat Landscape](https://www.nisos.com/services/threat-landscape-assessment/)
    - [Threat Monitoring](https://www.nisos.com/services/threat-monitoring/) 
          - [OSINT Monitoring & Analysis](https://www.nisos.com/services/osint-monitoring-and-analysis/)
    - [Investigations](https://www.nisos.com/services/investigations/) 
          - [Adversary Investigation](https://www.nisos.com/services/adversary-insights/)
- Company 
    - [About Us](https://nisos.com/company/about-us/)
    - [The Nisos Difference](https://nisos.com/company/the-nisos-difference/)
    - [Client Success](https://nisos.com/company/client-success/)
    - [Careers](https://www.nisos.com/company/about-the-company/careers/)
- Resources 
    - [News](https://www.nisos.com/newsroom/)
    - [Blog](https://www.nisos.com/nisos-blog/)
    - [Events](https://www.nisos.com/events/)
    - [Resource Library](https://www.nisos.com/resources/library/)
    - [Podcasts](https://www.nisos.com/podcasts/)
- [Contact](https://www.nisos.com/contact/)

### Solutions

 Managed Intelligence solutions are designed to address your needs in an evolving risk landscape. Empower your organization with methodologies and actionable results tailored to the innovative ways adversaries are targeting you.

### Mitigate Advanced Threat Actors

 Inform your security operations with greater context answering the “how” and “why” of the threat actors you face.

### Counter Disinformation

 Enable informed business responses with the “who” and “why” behind coordinated campaigns.

### Mitigate Insider Threats

 Improve your program’s ability to get to “who” and “what” with technical program building and investigations.

### Stop Platform Abuse

 Take action against nefarious use of your platforms with the “who” and “how” of threat actors targeting them.

### Cyber Diligence for Mergers and Acquisitions

 Facilitate a smooth transition with the “what” and “why” of the security risks to your acquisition.

### Third Party Risk Dilligence

 Increase the effectiveness of your security evaluations with specifics on the “where” and “what” of your third party risk profile.

### Services

 Access a world-class intelligence capability tailored to your specific needs. Control a multi-million dollar program without the time or expense and solve problems both lasting and acute.

### Managed Intelligence

 Ongoing risks, whether from one threat actor or many, require persistent focus. Leverage skills, data, and technology to harden your defenses.

### Security Investigations

 Gain the context needed to make informed decisions during periods of heightened risk.

### What is Managed Intelligence?

## Technical Blogs

###### 6 min read

## [The Rise of Synthetic Audio Deepfakes](https://blog.nisos.com/technical-blogs/rise_synthetic_audio_deepfakes)

 By [Robert Volkert, VP Threat Investigations and Dev Badlu, VP Technology at Nisos](https://blog.nisos.com/technical-blogs/author/robert-volkert-vp-threat-investigations-and-dev-badlu-vp-technology-at-nisos) on Jul 19, 2020 4:35:26 PM

[![](https://blog.nisos.com/hubfs/deepfakes-01.png)](https://blog.nisos.com/technical-blogs/rise_synthetic_audio_deepfakes)

**Can Audio Deepfakes Really Fake a Human?**

Audio deepfakes are the new frontier for business compromise schemes and are becoming more common pathways for criminals to deceptively gain access to corporate funds. Nisos recently investigated and obtained an original attempted deepfake synthetic audio used in a fraud attempt against a technology company. The deepfake took the form of a voicemail message from the company’s purported CEO, asking an employee to call back to “finalize an urgent business deal.” The recipient immediately thought it suspicious and did not contact the number, instead referring it to their legal department, and as a result the attack was not successful.

Topics: [deepfakes](https://blog.nisos.com/technical-blogs/topic/deepfakes) [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [fraud](https://blog.nisos.com/technical-blogs/topic/fraud) [synthetic audio](https://blog.nisos.com/technical-blogs/topic/synthetic-audio) 

[Continue Reading](https://blog.nisos.com/technical-blogs/rise_synthetic_audio_deepfakes)

###### 3 min read

## [Establishing a System to Collect, Enrich, and Analyze Data to Generate Actionable Intelligence](https://blog.nisos.com/technical-blogs/establishing_system_collect_enrich_analyze_data_actionable_intel)

 By [Adam Gayde](https://blog.nisos.com/technical-blogs/author/adam-gayde) on Jul 15, 2020 11:53:58 AM

[![](https://blog.nisos.com/hubfs/managedintel2-01.png)](https://blog.nisos.com/technical-blogs/establishing_system_collect_enrich_analyze_data_actionable_intel)

In the era of data-driven decision making, the value of threat intelligence and interest in establishing or expanding threat intelligence programs is growing rapidly. However, the growing availability and access to data is outpacing the ability of these threat intelligence programs to leverage and operationalize it.

According to a recent Gartner report, “the value of (threat intelligence) services is sometimes constrained by the customer’s ability to afford, absorb, contextualize, and, especially, use the information provided by the services.” 1

Topics: [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [threat intelligence](https://blog.nisos.com/technical-blogs/topic/threat-intelligence) [data](https://blog.nisos.com/technical-blogs/topic/data) [actionable intelligence](https://blog.nisos.com/technical-blogs/topic/actionable-intelligence) [managed intelligence](https://blog.nisos.com/technical-blogs/topic/managed-intelligence) [managed intel](https://blog.nisos.com/technical-blogs/topic/managed-intel) 

[Continue Reading](https://blog.nisos.com/technical-blogs/establishing_system_collect_enrich_analyze_data_actionable_intel)

###### 5 min read

## [An Inside Look at Advanced Attacker TTPs and the Danger of Relying on Industry-based Threat Intelligence](https://blog.nisos.com/technical-blogs/inside_look_advanced_attacker_ttps)

 By [Vincas Čižiūnas](https://blog.nisos.com/technical-blogs/author/vincas-čižiūnas) on Jul 7, 2020 11:15:37 AM

[![](https://blog.nisos.com/hubfs/techstack3-01.png)](https://blog.nisos.com/technical-blogs/inside_look_advanced_attacker_ttps)

Many organizations use threat intelligence from industry peers to prioritize vulnerability management and assign criticality when there is not enough existing information directly about their organization or their organization’s critical assets. While this is a natural political response to frame the narrative to allow budgetary approval to build certain aspects of the security program, organizations need to defend specific to their own technology stack and assets, incorporate the proper tooling around this stack, and be able to log events at scale. 

If a security program indicates that their industry peers are being targeted by a variety of different threats broken down by industry, the narrative around this argument will likely be a more persuasive argument for non-technical business executives approving budgets.

Topics: [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [threat intelligence](https://blog.nisos.com/technical-blogs/topic/threat-intelligence) [signatures](https://blog.nisos.com/technical-blogs/topic/signatures) [TTPs](https://blog.nisos.com/technical-blogs/topic/ttps) 

[Continue Reading](https://blog.nisos.com/technical-blogs/inside_look_advanced_attacker_ttps)

###### 5 min read

## [Cyber Threat Intelligence: The Firehose of Noise and How We Got Here](https://blog.nisos.com/technical-blogs/firehose_noise_how_we_got_here)

 By [Zachary Henson](https://blog.nisos.com/technical-blogs/author/zachary-henson) on Jun 23, 2020 12:18:09 PM

[![](https://blog.nisos.com/hubfs/graphics-7.jpg)](https://blog.nisos.com/technical-blogs/firehose_noise_how_we_got_here)

Threat intelligence feeds have become popular, and a company's ability to track threats outside of its own environment is better than ever. With these improvements though, has come an increasing demand on security professionals to select and manage the right combination of tools to achieve their desired outcomes.

Here is a brief look at the history of the cyber threat intelligence industry, and where we might go from here.

Topics: [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [threat intelligence](https://blog.nisos.com/technical-blogs/topic/threat-intelligence) [noise](https://blog.nisos.com/technical-blogs/topic/noise) 

[Continue Reading](https://blog.nisos.com/technical-blogs/firehose_noise_how_we_got_here)

###### 1 min read

## [Leveraging Technical Expertise & Data Partnerships to Combat Disinformation](https://blog.nisos.com/technical-blogs/leveraging_technical_expertise_combat_disinformation)

 By [Matthew Brock](https://blog.nisos.com/technical-blogs/author/matthew-brock) on Jun 15, 2020 2:32:35 PM

[![](https://blog.nisos.com/hubfs/shutterstock_1441871069.jpg)](https://blog.nisos.com/technical-blogs/leveraging_technical_expertise_combat_disinformation)

Argument -  fierce, bold, and impassioned - has been at the heart of our American democracy since the founding. British censorship (colonists could speak without prior restraint but then be charged with sedition or libel) compelled the drafters of the Bill of Rights to include freedom of speech as part of the First Amendment to the US Constitution. 

Heated disagreement and even misinformation are as rampant on today’s internet as they were in the taverns and meeting halls of the colonies. This speech is rightly protected. But because of the sacredness of this right, it is **disinformation** – deliberate attempts by foreign and domestic actors to spread falsehoods in order to achieve a political end – that concerns us here at Nisos and that we leverage our capabilities to fight.

Topics: [disinformation](https://blog.nisos.com/technical-blogs/topic/disinformation) [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [threat intelligence](https://blog.nisos.com/technical-blogs/topic/threat-intelligence) 

[Continue Reading](https://blog.nisos.com/technical-blogs/leveraging_technical_expertise_combat_disinformation)

## [Real Cyber Intelligence Tells a SOC What Its Security Stack Cannot Detect](https://blog.nisos.com/technical-blogs/real_cyber_intel_tells_soc_what_security_stack_cannot_detect)

 By [Steve Michael](https://blog.nisos.com/technical-blogs/author/steve-michael) on Jun 9, 2020 1:30:12 PM

[![](https://blog.nisos.com/hubfs/home-page-globe-3-OPT.jpg)](https://blog.nisos.com/technical-blogs/real_cyber_intel_tells_soc_what_security_stack_cannot_detect)

Actionable cyber threat intelligence should inform a security operations center’s prioritization of the most critical applications and infrastructure to the business and threat hunt program in ways a security stack cannot. With hypotheses-led, defined use cases that focus on signatures and more importantly behavior, threat hunting programs can operationalize threat intelligence by mapping threats to data sources and decision matrices that provide alerts and subsequent action. As a deliverable, a SOC can then count the actionable alerts versus the total alerts and, if captured appropriately, a security program can scale by reducing time to respond with fewer resources.

Topics: [threat hunt](https://blog.nisos.com/technical-blogs/topic/threat-hunt) [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) [SOC](https://blog.nisos.com/technical-blogs/topic/soc) [threat intelligence](https://blog.nisos.com/technical-blogs/topic/threat-intelligence) 

[Continue Reading](https://blog.nisos.com/technical-blogs/real_cyber_intel_tells_soc_what_security_stack_cannot_detect)

## [Common Network Segmentation Strategies for Production Environments](https://blog.nisos.com/technical-blogs/network_segmentation_strategies)

 By [Nisos](https://blog.nisos.com/technical-blogs/author/nisos) on Jun 3, 2020 7:28:04 PM

[![](https://blog.nisos.com/hubfs/graphic-12-1.jpg)](https://blog.nisos.com/technical-blogs/network_segmentation_strategies)

Business needs for all company sizes increasingly require managed production environments to perform critical computational and data storage roles that are often administered by company IT professionals, as well as potentially providing services to both internal and external entities. As a preamble, most common production environments tend to be heavily Linux-based, while most corporate environments are either predominantly Windows or a mixed environment with Windows and MacOS machines. While it should be obvious that the production environment should be heavily protected from arbitrary access from the internet, it can be easily overlooked that protecting company and customer data necessitates security measures against the corporate and other internal networks.

Topics: [network](https://blog.nisos.com/technical-blogs/topic/network) [segmentation](https://blog.nisos.com/technical-blogs/topic/segmentation) [white paper](https://blog.nisos.com/technical-blogs/topic/white-paper) 

[Continue Reading](https://blog.nisos.com/technical-blogs/network_segmentation_strategies)

[All posts](https://blog.nisos.com/technical-blogs/all)

### Sign up for updates

### Featured

![](https://blog.nisos.com/hubfs/Nisos-Logo-White.png)

Responsive strategies and intelligent defenses for protecting your enterprise.

<https://twitter.com/nisos> <https://www.linkedin.com/company/nisos/>

- Services 
    - Managed Intelligence
    - Security Investigations
- Why Nisos
- Company
- Resources 
    - [Blog](https://blog.nisos.com/blog)
    - [Case Studies](https://blog.nisos.com/case-studies)
    - [White Papers](https://blog.nisos.com/technical-blogs)
    - [Podcast](https://blog.nisos.com/podcast)
    - [News](https://blog.nisos.com/news)
- Contact

###### Contact Us

[1-703-382-8400](tel:1-703-382-8400)

[info@nisos.com](mailto:info@nisos.com)

603 King Street, Suite 300  
Alexandria, VA 22314

[![Learn More](https://no-cache.hubspot.com/cta/default/6068438/043dbe58-e265-499f-8574-2e0d1b4d410e.png)](https://cta-redirect.hubspot.com/cta/redirect/6068438/043dbe58-e265-499f-8574-2e0d1b4d410e)

©2020 Nisos. All rights reserved.

- Terms
- Cookie Policy
- Privacy Policy

![](https://px.ads.linkedin.com/collect/?pid=1593266&fmt=gif)