Don’t let cyber losses go unreported

During a cybersecurity incident, it can seem daunting to remember every step you need to take, and in what order. Tasks like isolating affected systems, notifying the right people and documenting events can feel hard to prioritize when everything is “critical.” Sometimes you need to report cybersecurity issues to the State Auditor’s Office, but when? Here is some important information that can help you comply with Washington’s rules and regulations.

Operational Technology Security and the Iranian Cyber Threat

Cyber Hacker with Iran's flag background

The geopolitical landscape shifted dramatically on February 28, 2026, when U.S. and Israeli military operations against Iranian nuclear and military infrastructure triggered a sharp escalation in Iranian state-sponsored cyber activity. For members operating in the energy, utility, and water sectors, the threat is no longer theoretical. Iranian cyber actors have demonstrated both the capability and the intent to target Operational Technology (OT) systems—the same industrial control systems that regulate power grids, pump stations, and water treatment facilities across the country.

Business Email Compromise (BEC): What it is, why it works, and how to stop it

If you’ve ever received an email that looks like it’s from your executive, a vendor, or even a coworker asking for a quick bank change or an urgent payment, you’ve met Business Email Compromise (BEC). It’s not a noisy, virus-style attack. It’s quiet, targeted social engineering—criminals either spoof a trusted address or gain access to […]

Critical Infrastructure Cyber Alert

The following message was shared with us by the Multi-State Information Sharing and Analysis Center (MS-ISAC). Critical Infrastructure members should take special note of the following content.   TLP: CLEAR Date: May 8, 2025 Earlier this week, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation and other US government (USG) partners published […]

Cybersecurity Awareness Month 2024

Cybersecurity Awareness Month

Enduris is committed to cybersecurity education by participating in the 21st Annual Cybersecurity Awareness Month.  Founded in 2004, Cybersecurity Awareness Month, held each October, is the world’s foremost initiative to promote cybersecurity awareness and best practices.

Cybersecurity Training Opportunities for Members

network equipment

Local Government University (LocalGovU) is an on-line learning platform that Enduris provides as a free benefit for all members. LocalGovU now has a t… This content is exclusive to Enduris Members. Please sign in to your account or sign up to become a member to read more.     Username or E-mail Password Remember Me […]

RECEIVE A FREE CYBER CHECKUP FROM THE STATE AUDITOR’S OFFICE

Checkups are fast, free and confidential By Debbie Pennick, Assistant Director for SAO’s Center for Government Innovation Reducing your risk of a cyber incident is now a bit easier, thanks to a free cyber checkup program offered by the Center for Government Innovation (https://sao.wa.gov/improving-government/center-government-innovation), a service of the Office of the Washington State Auditor. It’s […]

Gone Phishin’

Gone Phishin’ is now sophisticated. In the early days of phishing email scams, cyber attackers used the tactic of blasting millions of email addresses with the hopes of catching a few unaware people with the phishing scam attempt. This practice is still going strong today in our technological universe. These attackers will engage victims by […]