You get a single team handling cybersecurity, IT, AI consulting, and data integration services like EDI, filling the gaps in your team.
“Corsica is a one-stop shop for us. If I have a problem, I can go to my vCIO or a number of people, and you take care of it. That’s an investment in mutual success.”
– Greg Sopcak | Southern Michigan Bank & Trust
From 24/7 SOC services to MDR/SIEM, penetration testing and training, we’ve got you covered.
Get the expert support you need for your network, on-premises devices, VoiP, M365, Google Workplace, and everything in between.
Full support of compliance frameworks, including CJIS, HIPAA, CMMC, NIST, SOC 2, and more
Cut through the hype with smart strategies and right-fit AI solutions for your organization.
Take strategic steps with confidence as you collaborate with our expert business and vCIO consultants.
Get cloud security, integration, server virtualization, and optimization strategies to reduce your cloud costs.
Connect any data source to any other with robust solutions and managed services.
Stay ahead of the curve, eliminate waste, and grow revenue with next-generation technologies.
Expert consulting, implementation, integration, managed services, and cybersecurity for Microsoft products.
One program. One partner. Complete AI transformation.
It takes dedicated experience to use technology strategically in your industry. That’s why we specialize in certain verticals while offering comprehensive technology services.
From webinars and video tutorials to guides and blogs, we’ve got resources to help you and your team address any technology challenge.
Corsica Technologies proudly services the Raleigh area by providing:
Corsica Technologies helps businesses in Raleigh, NC and neighboring areas with personalized cybersecurity, managed IT services, project support, and consulting. Our cybersecurity and IT specialists support and supplement local IT teams by filling skills and resource gaps or providing help where you need it.
24/7 monitoring and response for your essential systems, with remediation service guaranteed
Career experts in EDI and data integration, backed by the service delivery infrastructure of an MSP
M365 cloud services, MFA, endpoint management, and more—plus ongoing cost optimization
C-level perspective and collaboration on strategy, 3-year technology roadmap, and more
Our most popular service package covers ALL your technology needs for one monthly price.
Corsica Technologies participates and supports technology associations that help shape the future of our community
The world of cybersecurity is changing faster than ever. New threats, constrained resources, and increasing technical sophistication are driving emerging challenges in cybersecurity. Watch as Corsica’s Ross Filipek and Dave Heflin and Carl Young from ATC Development discuss the latest cybersecurity trends at at NC Tech’s Outlook for Tech.
Good afternoon, everybody. My name is Dave Heflon. I'm the Executive Vice President of Sales for Corsica Technologies. Have a long career in helping companies, identify, best in class, technology solutions to help solve and transform their businesses. And, I'm happy to introduce Corsica Technologies, to the audience today. We are a company that's approaching our thirtieth birthday. We help educate advise, and assist companies in implementing technology, both securely, efficiently and profitably to help transform their businesses. We have about one thousand customers in North America. Most of them coincidentally enough are in the southeast, in the Carolinas and the mid Atlantic region. And we focus on cybersecurity, and digital transformation. I'm happy to say today that I'm enjoined by two thought leaders in the industry. One thing that's a little bit unique about us as compared to some of the previous, presenters that and their companies that a little bit earlier is we help companies actually execute some of these visions and strategies, that were communicated today. So, I'm first introduced, I'll introduce Ross r CECO, and then Carl, who is one of our customers and talk about some real world exam apples of things that we face and look forward to facing and how we're going to mitigate them in twenty twenty four. Ross? Yeah. Thanks Hey, everybody. I'm Ross Philip. I'm the Chief Information Security Officer at Courts of Good Technologies. Separately from my CECO responsibilities. I provide virtual CSO Consulting Services for a lot of our clients, have been in the information security industry for about twenty five years, very happy to be here with you. Good afternoon, everybody. I'm Carl Young. I'm the chief information officer for ATC development. We are a, a small, I would say, a small half a billion dollar enterprise in Augusta, Georgia. Where we develop properties, build apartment complexes, manage them, and, of course, sell them over time. And part of my job as the first CIO of this organization is to wear many hats. I play part c t o c d o c I s o and CIO. I think I got them all. Oh, yeah. And I'm also one of the company strategists. And why did I get all that? Because, prior to joining AT see, last year. I was a defense contractor, a cyber architect. And prior to that, twenty seven years as a United States Army signal, information systems, and cyber officer. I keep getting fired from all of my jobs. Great. Thanks, Carl. So we wanted to talk about cyber, security, and it's really because of cybercrime. As many people in this room know cybercrime is big, and it's only getting bigger, bigger. So the industry predicted that it would be eight trillion dollars in twenty twenty three. I don't know if the verdict is in yet, but I'm pretty sure it hit that number and maybe exceeded it. And they expect it to be as much as ten point five trillion dollar in twenty twenty five. This is all up from a three trillion dollar global cybercrime, result back in twenty fifteen. So this double digit growth is really the largest wealth transfer in the history of the world. It's larger than any drug trade that's out there. It's, larger than just about any natural disaster, loss that ever occurred. So it's definitely worth talking about. Furthermore, we found out that it's not just limited to large enterprise companies. So, Gartner, did a study a couple years back, which many of you may be, familiar with, but sixty six percent small and medium enterprise companies defined as companies with less than one thousand employees have experienced cyber attacks with loss. And then, the FBI recently came out, and they communicated that, SMEs, will be even further susceptible cybercrime because as large enterprises start to, spend more on these ever increasing budgets, based upon, some of the other panelist, numbers that were communicated earlier today. Those professional hackers that are out there are going to start to point more and more towards SME. So If you haven't been hit, yet, you probably will be hit soon. So now it's a matter of what, threats will you face and then how will you mitigate them appropriately. So that's kind of where we wanted to gear, or steer the conversation to today. So, you know, One of the things, in a simple topic that everyone's gonna face is you're gonna face continued phishing attacks. And I wanted to turn it over to Ross to give a bit of insight on that and kind of introduce, how we deal with, what we see in twenty twenty four and, how we will mitigate that. Yeah. Thanks, Dave. Before I jump into the actual threats, that we're seeing out there, I think, you know, probably most of the people in this room understand that different organizations have to deal with different types of threats. Right? A lot of that's determined by what industry you're in and other factors. So, you know, and there's really no singular magic bullet for cybersecurity, right? You know, I wish there was. I wish there was, like, one thing we could go out and buy and install in our environments and, you know, have it take care of all our cyber risk, but unfortunately that just doesn't exist. And you compound that with if you guys think about the cybersecurity marketplace, right? You know, there's a million, you know, products and services out there. No organization has enough time or people or money to just go out and buy everything. Right? You know, we need some way to be judicious about the types of safeguards that we're selecting, for our environment. So how do we get there? This is where I hit on, the concept of cyber security risk assessment. So some of you may be familiar with that. You know, hopefully, some of you have done that for your own organizations, but that's really the right place to start when you set out on establishing a cybersecurity strategy for your organization. You know, it's really important to be able to identify the threat that are, germane to your organization, and that just really helps you be more effective with the overall strategy. So That said, they've mentioned phishing. So I'll tell you, as a managed cybersecurity services provider, social engineering is gonna continue to be a massive problem for a lot of organizations across the world And we've heard some really great content on generative AI so far at this conference. So, you know, and you guys all understand this now five years ago, ten years ago, it was pretty easy to spot a lot of phishing email. You know, you're looking for misspellings or bad grammar, you know, things like that. But you know, nowadays with generative AI, everything that comes through to your employees is going to be written in perfect English. So, you know, we can no longer rely on content so much as a red flag to be able to spot that type of thing. So, you know, roughly eighty percent now of all successful cyber attacks actually target humans, not computers. And, you know, we've heard similar statistics and other presentations this morning. But, you know, if you gotta stick about it, it it makes sense. Right? If I'm an attacker, why do I want to spend a week or a month or a year trying to find some technical vulnerability that I can exploit to get into your environment when I can just fish your users and have them give me their credentials. You know, it's so much easier that way. So what do we do about that? It's really going to be continued aggressive security awareness training for plays. That's really the only way to contend with this. And it's just in addition to the training piece. I think it's really important that we complement that with some kind of recurring testing that happens. So maybe that's like recurring phishing that you send to your employees, but we need some way as an organization to understand which of our employees are doing a good job with their security awareness and which ones do we need to focus on to give a little extra encouragement to. Yeah. Carl, you brought up a good point, when we were working with you on how you wanted your program to roll out when it came to this human centric focus because you have all different types of employees in your organization, and I thought it would be good to share the group. Yeah. So since the boss said I couldn't immediately fire anybody that did something wrong on their phones or computers, I had to come over the new way of doing business. And part of the problem is the squishy thing at the end of the keyboard is our number one vulnerability. And there's no real way to solve that problem. And so what we work as lot, what Ross described is we're building a training platform, and we're building a testing platform. And that's gonna be part of the solution the harder part is that managerial leadership piece. How do you ensure and again, as as Dave mentioned, I got a the full range of of skilled hardworking great people on our team, how do I make sure they understand their environment? It's one thing to know, not to click on the link. And that's great. I use bounties. I I reward people who turn in links as we do a little Amazon car. Hey, I'd rather pay twenty five dollar Amazon card all day long than repay the event we had last year prior to my arrival at this company Let's put it that way. That's the other piece. We gotta be honest about when we've been hit. We've gotta work together as share knowledge, share understanding about when we've been hit. Will the FBI solve the problem? No. Well, I mean, they'll they'll do their part. They're not gonna solve the problem of force because this is such a complicated crime arena. You know, eight trillion dollars out of the US GDP same year is about twenty eight trillion That's a ridiculous sum of money as they've pointed out. So how do we get the people to understand their environment? And that goes beyond teaching them how to work Microsoft. Now, again, I'm not I'm not the CIO of a tech company. I'm a CIO of a company company. I got just normal humans. I don't have all these truly brilliant tech types. And so I'm learning the the steep challenge of how to do that, how to convey information to them, and how to reward, and really work the psychology of of being a leader in a company to influence their attention span. By the way, I'm trying the same tricks on my mother to get her to click clicking all stuff too. Yeah. I I I find that interesting, about the the the cyber talent on both sides of spec room. When it comes to that, we have a, a sock that is in Augusta, Georgia, and it's built just outside of Fort Gordon, Georgia, which is, the army's, signal and cyber control, or, or school. And, it's interesting in the town that we've recruited from them in order to staff this facility, and it provides that twenty four seven coverage for our customer base as part of their extended strategy. But it's always good to have the top talent on our side as opposed to it being on the other side coming in. But, we've been grateful to Carl because he's been helping create a link where we've been able to apply our talent to an organization, that's been working very well there. Well, Dave, let me jump a second too, because that's another you highlighted the skills that that a managed security service provider brings. Okay. And this isn't an ad just a description of how to multiply your capabilities. They're watching twenty four hours a day. The trick is you cannot. You must not, you you can no longer think of cybersecurity in terms of building a wall, building a moat, adding alligators, and protecting your fiefdom. You must assume, and this is where I'll disagree with the Forrester executive. You must assume zero trust. You must assume you are compromised at all time. And the question is with better eyes, can you see adapt and react to it in a way that keeps your business viable. That's a different way of thinking, certainly than when I started in this business in the nineties. It's it's a you have to know you're gonna get hit or you're being hit right now. How quickly can you detect it? Anything else on, fishing Ross that you wanted to cover as far as I guess we kinda blew past that, dude. We're getting back. Yeah. No. Really, I mean, I think Carl stated it well, at the end of the day, this is really a human education problem and technology is great, but it's only gonna get us so far. So we have to address that human piece. Yeah. The the one other thing we wanted to kinda upon today in a thought leading discussion centers around IoT and what that brings to, your cybersecurity strategy, both from a threat perspective. Twenty twenty four, and then maybe ways to mitigate that. So Ross, if you wanna kind of explain, what IoT and how it relates to cyber, and then, we'll begin the discussion appropriately. Yeah. Yeah. IoT. So internet of things, certainly before COVID, but obviously during but I think a lot of us were probably working from home, you know, maybe on devices and, you know, through infrastructure, that was outside the scope the visibility and control of our company's IT departments. Right? So, yeah, that, that paradigm ended up causing a lot of cybersecurity problem for a lot of organizations. So over the past, you know, I'd say three or four years, we've really seen a lot of traction in the zero trust movement. And like Carl said, in a zero trust, conceptually, just assuming that all of your endpoints have been compromised and then being able to protect your assets accordingly. You know, maybe we start authenticating and authorizing everything at a session level, you know, but don't wanna get t four and the weeds on that. But yeah, certainly zero trust and as part of that initiative, one thing as a service provider that we've seen a lot of organizations have really great success with, in the last few years, especially for organizations that have a lot of employees using personal devices to access company data, something called mobile application management. Some of you guys may be familiar with that. I think a lot of us are familiar with MD, or mobile device management that's, you know, what gives us the ability to control individual devices, but mobile application management, I think, is a really unique and powerful cybersecurity tool that we can have in our arsenal going forward, and essentially what we are accomplishing with mobile application management is the organization can select which apps, you know, which applications are approved for use, if you have employees, you know, with their own personal devices, maybe the organization will say, well, you know, you can use Microsoft Outlook to get you to your company email. You know, great. So what the mobile application management tool allows that organization to do is think of it kind of like compartmentalizing the company's data on his personal devices, and that's really powerful because as an organization, that will help us prevent any of our data from being shared out to non managed ops on these personal devices. So a good degree of data loss prevention from that standpoint. It also gives the organization very powerful capabilities to, secure and purge their data from these personal devices. If they ever terminate somebody, you know, somebody quit, or it gets hit by a bus, whatever the case may be. So, yeah, mobile application management, I would say, you know, just as a technology, we've really in a strong uptick and, very successful deployments with that. Yeah. So in our business, we're building high end department complexes. So you've got, upwards to three or four hundred, residences that you're taken care of. And we wanna make high-tech part of a copilot. It's called property tech. Prop tech. And so one of the things that we're looking at is, you know, everything from predictive maintenance on air conditioned units to and especially in Georgia, that's thing. To how well I know if my fire suppression's ready to go, to electronic locks, to cameras on my door lock, to you name it. Okay? So all of these things are tremendous conveniences and they're marketable items. With all of these conveniences, however, we have to be deliberate in evaluating security risk. And I think that goes back to an understanding. First, if you assume you're compromised or comprehensible, You have to treat that conversation a little different. It's it's not just providing a convenience for convenience sakes. You have to understand that you're picking up risk to your potential customers. And making that risk assessment informed with a deeper understanding than just a topical is not only challenging, especially for non tech companies. But it's critical. You gotta have that advisor. So if you, you know, obviously, we're tech professionals here. So that's one thing. We can help this discussion But we have to understand the business value, the convenience value, security risk, and the mitigation value. Right? So those comp those business has specs, certainly are are something I'm having to learn, and these guys are helping me a lot with that. But it gives me a vernacular to talk to my boss about, hey, How do we make these good investments? How do we make investments that do not compromise security of the families that we provide housing for? You know, because we take very, very seriously. So you gotta be informed about that. Yeah. I had said that we were gonna bring it down to a tactical level. So with mobile mobile application ment. If someone gets hit by a bus, we can, mitigate any risk associated with the data that they may have had their hands on prior to that. So I think that's pretty tacked It is. Anyways. So, some of the other, things that that we wanted to stress today are just about you general best practices in twenty twenty four. It's really a continuation of what everyone has been doing in the past. But, you know, with the incorporation of Gen AI and other things like that. Everything seems to be that much, more important to pay attention to, and it's about executing better and really establishing a cyber strategy that's, embedded with a solid policy. The one thing we found out, and I'll let Ross explain to this is a lot of time when we go in and we see best practices being executed but it isn't based against anything. So it can't be incorporated into sort of a holistic strategy because it's not embedded in policy see. And that's something that we find really important. And Ross, I wanted you to just touch upon that as sort of when you develop this, you know, you have to start with the basic Yeah. You know, it's without thinking about what you're actually trying to accomplish, right? It's very difficult to know whether your IT department is configuring things the right way. Right? So it's really the importance of having that policy piece I work with a lot of clients who will have me come in and and say, they say, well, you know, take a look at my firewall configuration, tell me if it's okay. And, well, you know, I don't know if it's okay. Show me what your policy says, right? Because that, that's what determines how your safeguards need to be implemented in deployed. So, separately from the policy side, one thing I wanted to stress here that I think going forward is gonna be exceedingly important for organizations. You know, to have a well developed and well practiced incident response plan because it's really not a matter of if you get compromised, you know, it's going to happen sooner or later just in today's threat landscape. There's just too much out there. The cyber threats are too sophisticated. It is well worth the effort to sit down and develop a comprehensive incident response plan that talks about who do I notify if there's ever a cyber incident? How are we going to investigate that? How are we going to contain and eradicate that cyber threat. And most importantly, what are we going to do to recover our operations after that happens? It's just, you know, such a huge time saver and makes that response process goes so much more smoothly. If you take the time ahead of time, sit down and really think about what you're gonna do, get that all documented in an incident response plan, and then, you know, maybe a couple times a year or on an annual basis do a, you know, like a tabletop exercise, for instance, you know, sit down with all the people in your organization who play a role in incident response, and walk through, you know, like a mock scenario, you know, and say, Hey, we've got a ransomware outbreak. What are we going to do? Or, you know, there's a business email compromise and somebody initiated, you know, ten million dollars wire transfer. What are we going to do? Be able to work through that mock scenario just so everybody under stands what it is they're supposed to be doing and in what order when these types of things happen. So, yeah, you know, people say practice makes makes perfect and it's really no exception for, cyber preparedness. I want to take Ross's comment and kind of up it a little bit. Who thinks cyber insurance squared away, easy, good to go. Okay. I don't either. Because it's a hot zoo. You've got to be able to cover your own. Right? And so to Ross is absolutely right, you gotta build a plan. But really, I mean, I I actually grew up as as a South Carolina National Guard Army Officer. And, you know, we hear in the hurricane belt, we we practice our plans, and we depend on our guard. And so this is this is a thing. You gotta test it. You've actually gotta test it. One of the things I'm prepping my organization for is a complete nuke operation. I'm gonna we're gonna go in on a Friday. I'm gonna nuke every thing. And we're gonna see how fast we can recover. And now the executives are exceptionally nervous about this. And I may be looking for a job on Monday after. But, you know, if you don't test it, you don't know. And if you do test at Colonial pipeline, it's gotta be valid enough to survive. Right? So just some thoughts on that. Yeah. So I know we're coming up on time. So in summary, the things that we wanna distress, for companies and organizations to focus on in twenty twenty four when it comes to their cybersecurity, strategy and landscape is the number one, continue to assess your cyber strategy, whether you get that done with an internal look or, with your own internal experts, but go through a cybersecurity assessment, maintain a human centric approach because anywhere from seventy four the ninety percent of your cyber attacks will occur by the humans in your organization to make sure you understand how to mitigate that with a good training and testing platform, identify the specific threats in your organization part of that assessment, whether it be, continued, fishing attacks, leveraging a much more savvy approach with Genatith AI. Than maybe you've had in previous years, adopt the philosophy of zero trust. And then execute a cybersecurity strategy that's embedded in a solid policy so that your people and your experts can determine, number one, whether it's effective and that if it's being executed, in accordance with a strategy rather than just with sort of, unorganized and non integrated best practices. So I wanna thank you for today. We did not bring a QR code, but we do have a tabletop outside, where we'll be glad to definitely talk with you all. If you wanted to know more about how cyber security, can be assisted with course technology. Yes. Sure. Sure. If you're dealing with the government, to you must have a CMMC certification. Now, right now, it's Lucy Gucci, and you can self certify. Go ahead, go to the extra mile. Get some help, get it done right. Yeah. Specifically dealing with the Department of Defense, but I'll tell you guys, CMMC is a fantastic cyber security framework even if you're not a defense contractor. So even in industries other than working with the government, I can't stress enough. It's it's a very comprehensive, very well thought out, cybersecurity maturity model. I think we are out of gas. We're getting there. Thanks everyone for your time. Enjoy the rest of the conference and safe travels home. Thank you. Thank you.
“I have very few IT related headaches and scares when it comes to our system monitoring. The techs seem to be quick to respond.”
“Corsica has been such a help and we would be fully in the dark without them.”
“Corsica is the best partner available in cybersecurity. They know what they’re doing, and they guarantee it!”
“We have full IT management— they do a great job. We can count on Corsica 24/7. We have a great vCIO.”
“A pleasure to work with and very knowledgeable staff! Working with Corsica, I don’t have to worry about outages overnight.”
“Unparalleled customer support! They know exactly how to solve any issue, and their response time is always within 5-10 minutes of my request.”
Fill out this form to talk to a Corsica Technologies professional and learn how we can help with your cybersecurity and digital transformation initiatives.
We’ll respond within 1 business day, or you can grab time on our calendar.