@vikingcloudcom

Delivering battle-tested cybersecurity and compliance solutions that simply work.

Chicago, IL
Joined March 2016
The call comes in to a store manager two states from headquarters. It's the regional VP, same voice, same urgency, asking for a quick approval before end of day. Except it isn't the VP. It's a cloned voice, and the manager has no reason to think twice. This is where the modern attack on a distributed enterprise begins. Not at corporate, where the security team lives, but at a single location that looks nothing like a target. 63% of distributed enterprises had at least one location receive a deepfake or cloned-voice attack impersonating an executive last year. And it's accelerating on all fronts. 87% say AI-generated phishing and deepfake attacks have grown more frequent, more severe, or both in the past 12 months, the second fastest-rising threat behind only ransomware at individual locations (88%). 60% are concerned frontier-model attacks are next. Attackers are targeting individual locations. Most security programs are still built around headquarters. VikingCloud's 2026 Cyber Threat Landscape Report: The Distributed Enterprise Illusion is out today. Read it here: bit.ly/4rlUEQQ. #Cybersecurity #DistributedEnterprise #CyberRisk #Deepfakes
1
27
Twenty years of securing payment data. Twenty years of the Council setting the standard. And in Edinburgh, the celebration is on us. VikingCloud is a Platinum Sponsor of the Welcome Celebration at the PCI Security Standards Council's 2026 Europe Community Meeting, 20 - 22 October in Edinburgh. On the opening evening, the community gathers at Mansfield Traquair, the hall known as Edinburgh's Sistine Chapel, to mark two decades of payment security. Come raise a glass with us beneath the murals. Welcome Celebration Tuesday, 20 October | 18:00 – 19:30 BST Mansfield Traquair, Edinburgh We're at Booth #8 all three days. Look for the helmets and bring your toughest compliance and security questions. Book time with us now and skip the on-site line. Here's to the next 20 years: bit.ly/4domxSv. #PCISSC #PCICompliance #Cybersecurity #PaymentSecurity
1
23
Thank you, PCI Security Standards Council, for 20 years of advancing payment security. Three days at Booth #13 in Vancouver: report copies handed out, consultations booked, one Plaud Note Pro claimed, and plenty of Viking helmets now in circulation. Didn't make it to Vancouver? The complimentary 30-minute PCI consultation still stands: bit.ly/4yU1srH. Next stop, Edinburgh. We'll see you at the Europe Community Meeting, October 20 – 22. #PCINACM26 #PCISecurityCouncil #PCICompliance #Cybersecurity
1
46
86% of distributed enterprises were breached last year. Most still feel secure. That's the illusion. When these brands get hit, the attack rarely stays put. 77% watched it spread to other locations, corporate systems, or shared vendors. How far it travels comes down to one thing: enforcement. Only 51% mandate one security standard across every location. The rest let individual sites interpret or replace corporate guidelines on their own, and that fragmentation is the path an attack follows. For brands with franchised locations, when corporate mandates one standard, an attack is 3x more likely to stay where it started. Governance is what keeps one location's incident from becoming a brand-wide breach. VikingCloud's new research on distributed enterprise cyber risk: bit.ly/4y6vZlP. #Cybersecurity #DistributedEnterprise #CyberRisk #Ransomware
2
32
See how far one attack travels. The findings drop tomorrow. For decades, distributed enterprises have measured cybersecurity by what corporate builds at the center: the policy, the technology stack, the team at headquarters. But what's built at the center rarely reaches every location. Footprints have grown. Franchising has splintered who enforces what. And an attack on a single location can reach every system the brand connects to. New VikingCloud research reveals how far one attack really travels, and what actually stops it. Stay tuned. The findings drop tomorrow. #Cybersecurity #DistributedEnterprise #CyberRisk #Ransomware
1
25
Incredible event, thanks for putting on an unforgettable community meeting, @PCISSC.🤝
If you haven’t stopped by the Vendor Showcase yet, today is your last chance! 👋 Connect with exhibitors and explore the latest solutions before the Community Meeting wraps up. Thank you to @vikingcloudcom for sponsoring the Vendor Showcase! #PCISSCTurns20
29
Today is National IT Professionals Day. If it looks like a normal Tuesday for you—systems up, inbox safe, nothing broken—that's not an accident. That's an IT professional doing their job well enough that you never had to think about it. To the ones patching at 6 a.m., catching the phishing email before it reaches the register, and running a security program across dozens of locations with barely enough hands to do it: thank you. The work rarely gets noticed. It still matters. Happy National IT Professionals Day. #ITProfessionalsDay
21
Most organizations know their biggest vendors. Far fewer know who has access to their locations, systems, and networks. HVAC techs, POS support, Wi-Fi providers—access builds up faster than teams can track it. Third-party breaches doubled in a single year, and most of them traced back to partners the victim didn't fully control. For multi-location businesses, this isn't just a cybersecurity issue. It's a direct threat to daily uptime. The vendor systems you rely on are the exact ones that keep your doors open—from payments to refrigeration. The operational risk belongs to corporate. The visibility doesn't. Fayyaz Makhani breaks down how to fix your vendor access governance before an incident forces your hand: bit.ly/46Bc1nd. #ThirdPartyRisk #VendorRiskManagement #Cybersecurity #OperationalResilience #MultiLocation
27
The operators your brand counts on for growth are spending their nights and weekends keeping the lights on. Not growing. Not serving customers. Managing security they were never trained for, on top of everything else that comes with running a small business. Two-thirds of franchisees give up personal time to keep up with cybersecurity. More than half have walked away from growth opportunities because staying secure kept getting in the way. That's not just a problem for the operator. It's a constraint on every location your brand is counting on to perform. The question worth asking at the corporate level: if security is this costly for your franchisees to carry alone, what is it costing the network? Read the blog: bit.ly/3RJ90gW. #Franchising #FranchiseOperations #ManagedSecurity #BusinessContinuity #Cybersecurity #FranchiseGrowth
1
39
For an online business, the storefront and the risk are the same system. CNBC Select just cited VikingCloud data in its look at business insurance for e-commerce operators, and the numbers explain why the conversation is shifting. Among small businesses, 27% experienced a customer data breach, and 26% were hit by ransomware or denial-of-service attacks. A breach costs more than data. It interrupts the one channel the business runs on. That's why cyber liability coverage is moving from optional to expected for e-commerce operators. The financial exposure from a single incident now rivals the physical risks insurance was built to cover. The numbers make the case on their own. When more than a quarter of small businesses have already faced a breach or ransomware attack, the question stops being whether to prepare and becomes how quickly. Read the full story in CNBC Select: cnb.cx/4xq9Tdq. #Cybersecurity #SmallBusiness #CyberInsurance #Ecommerce
1
39
Welcome to VikingCloud's Cyber Myths series! In Episode 13, we're busting one of the most common misconceptions in cybersecurity: "we would definitely know if we were hacked." The truth? Many breaches go undetected for months. In this episode we explore: - How hackers can avoid suspicion for sustained periods of time - The tools required to spot these attacks #CyberMyths #CyberSecurity #ComplianceMyth #CyberAwareness #BusinessSecurity
29
A Viking snorkeling on the reef. 🤿 Doesn't look right, does it? He's built to hunt threats, not chase tropical fish. So go ahead, trade the screen time for sea time this summer. Cybercriminals don't take time off, which is why our Managed Security Services team is on duty 24x7, axe at the ready. You clock out. We don't: bit.ly/3PY2GkV. #ManagedSecurityServices #CyberSecurity #SummerReady #VikingCloud
30
Travel agencies aren't under-protected because they don't care about security. They're under-protected because the person responsible for it is already handling bookings, managing suppliers, onboarding staff, and keeping customers happy. That's not a criticism. It's the reality of running a small agency. Security doesn't get skipped because it doesn't matter. It gets skipped because something more urgent always does. The problem is that a normal day in a travel agency; phones ringing, bookings moving fast, payments passing through third-party platforms, creates more exposure points than most owners realize. Passport details. Card data. Booking records. Customer credentials. All of it moving through systems that nobody has quite enough time to properly lock down. Cybercriminals have noticed. Here's what a single working day actually looks like from a security standpoint and where the exposure quietly builds. 92% of travel agencies experienced a cyber threat in the past year. Here's what the risk actually looks like across a single working day; and where the gaps are easiest to close: bit.ly/4oUcR72. #TravelAgency #Cybersecurity #PaymentSecurity #PCICompliance #SmallBusiness #TravelIndustry #SecureTrust
27
Transit operator Ruter tested two electric buses and found one had a live path into its battery and power-supply controls, reachable over the mobile network through a foreign SIM card. In theory, the manufacturer could stop or disable the bus from the outside. The finding pushed the U.K. and Denmark to open their own investigations. Over-the-air technology has been standard since Tesla began pushing updates in 2012, and it now runs quietly across buses, cars, rail, maritime, and industrial machinery. Every one of those channels is a live line into the system. VikingCloud's 2025 Cyber Threat Landscape Report found that nearly 80% of cybersecurity leaders were concerned about a nation-state attack in the next 12 months. A public bus fleet running on foreign hardware is that concern made physical, with critical transportation infrastructure sitting on the other end of an open channel. If someone can reach the vehicle to update it, they can reach it to control it. The companies securing that access now will be the ones still trusted to run these fleets long term. Read more on CNBC: cnb.cx/4pSbAxU. VikingCloud's Thomas Patterson shared his thoughts: OTA technology is here to stay. The question teams need to ask: *where* is the trust boundary? If your vendor can update the device remotely, they can compromise it remotely. That's not a feature gap, that's a security architecture question you need answered before deployment, not after a breach. While this story focuses on transport, we are seeing growing OTA updating in critical infrastructure like energy, water, and waste. #Cybersecurity #NationStateThreats #CriticalInfrastructure #OTA
68
ICYMI! 🚨 In this episode of VikingCloud's Cyber Myths, we're busting one of the most common misconceptions in cybersecurity: "cyberattacks are always sophisticated." Watch the full episode: bit.ly/4xxBBpD. #Cybersecurity #CyberMyths
20
What happens when a user transitions from a managed device to an unmanaged one? 🤔 In this snippet from VikingCloud's Business Uninterrupted, Jon Marler, CISSP, CEH, discusses how AI systems are designed to exploit gaps when a user transitions from a managed device to an unmanaged one. Check out the full episode: bit.ly/4tSYwIJ. #Cybersecurity #CISO #ManagedDevices #AIinCybersecurity #CyberRisk #BusinessUninterrupted
60
When someone books a trip through your agency, they're handing over more than a payment. Passport scans. Card details. Travel dates, destinations, itineraries. A complete picture of who they are and where they'll be. They hand it over without a second thought, because they trust you with the trip. What most customers don't think about, and most agencies don't have time to, is the responsibility sitting on the other side of that trust. The data doesn't disappear once the booking is confirmed. It stays in inboxes, in platforms, in systems that don't always get the attention they need. SecureTrust's 2026 Travel Agency Resilience Report gets into what that exposure actually looks like and what the agencies managing it well are doing differently. Travel agencies hold some of the most sensitive customer data in any industry. Here's what the 2026 Travel Agency Resilience Report found about how agencies are — and aren't — protecting it: bit.ly/4v739j4. #TravelAgency #Cybersecurity #PaymentSecurity #DataProtection #TravelIndustry #SmallBusiness #SecureTrust
22
A Viking catching some rays. ☀️ Doesn't look right, does it? He's built to hunt threats, not work on his tan lines. So go ahead, trade the spreadsheets for the sun lounger this summer. Cybercriminals don't take time off, which is why our Managed Security Services team is on duty 24x7, axe at the ready. You clock out. We don't: bit.ly/3PY2GkV. #ManagedSecurityServices #CyberSecurity #SummerReady #VikingCloud
1
251
Welcome to VikingCloud's Cyber Myths series! In Episode 12, we're busting one of the most common misconceptions in cybersecurity: "cyberattacks are always sophisticated." The truth? Many successful attacks are shockingly simple. In this episode, we explore: - Which simple attacks & exploits can harm your organization. - Why human error and misconfigurations can be your worst enemy. - What you can do to defend yourself against "simple" attacks. #CyberMyths #CyberSecurity #ComplianceMyth #CyberAwareness #BusinessSecurity #RiskManagement #VikingCloud #CyberRisk #MSSP #ManagedSecurity
44
Hackers accessed a third-party vendor serving a Texas state agency and walked away with driver's license numbers, passport numbers, and contact information for more than 3 million people. The agency has not named the vendor, disclosed how attackers got in, or confirmed whether a ransom demand was made. Unlike passwords, government-issued ID numbers can't be reset with a click, leaving those affected exposed for years. Whether or not ransomware was involved here, security leaders already know this is where they're thin. VikingCloud's 2025 Cyber Threat Landscape Report found that 36% of cybersecurity leaders say ransomware attacks on critical third parties are among the threats they feel least prepared for. The entry point in breaches like this is rarely the organization itself. It's the vendor chain behind it that nobody audits until after the breach. Link to the TechCrunch coverage in the comments. #Cybersecurity #ThirdPartyRisk #DataBreach #CyberThreats
40