While not exhaustive, I've written down some ideas to help small and medium-sized business (SMB) mitigate the risk posed by insider threat. My latest piece in The Business Journals discusses this interesting, but challenging topic: http://www.bizjournals.com/bizjournals/how-to/technology/2015/09/ways-to-deal-with-insider-cybersecurity-threats.html. Hope you enjoy this piece and find it helpful.
Friday, September 18, 2015
Tuesday, September 15, 2015
Information Security Lessons From Literature
What can literature teach us about information security? I would argue quite a bit. Curious what I mean? Have a look at my latest piece in DarkReading: http://www.darkreading.com/operations/information-security-lessons-from-literature/a/d-id/1322178?. Hope you enjoy!
Thursday, September 10, 2015
The Security Operations Hierarchy of Needs
I am often asked a number of different questions by organizations that are just beginning their security maturity journey. Some of the most common questions include: Where do I begin? How do I know what to prioritize? How can I build a strong foundation of security fundamentals? In what order should I add or improve capabilities?
These are all very good questions, and I tried to answer them, along with other questions, in my most recent SecurityWeek piece. The piece is entitled "The Security Operations Hierarchy of Needs": http://www.securityweek.com/security-operations-hierarchy-needs. While the length of the piece does not permit an in-depth discussion of all the points, I believe the piece does provide some helpful guidance for those searching for it. Hope you enjoy.
Tuesday, August 25, 2015
We're Looking at Information Sharing The Wrong Way
We're looking at information sharing the wrong way. Sound radical? Curious what I mean by this statement? Have a look at my latest piece in SecurityWeek: http://www.securityweek.com/were-looking-information-sharing-wrong-way. After you read it, you might just agree with me.
Thursday, August 20, 2015
Endpoints come in all shapes and sizes
The concept of a security perimeter begins to break down in the modern business environment. Nowhere is the pain felt more acutely than on the endpoint. What are some things to consider when looking to protect endpoints of any persuasion in the current environment? My thoughts in my latest piece in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/technology/2015/08/why-endpoint-security-is-the-new-frontier.html.
Tuesday, August 11, 2015
Detection May Not Be What You Think It Is
Sometimes, I hear the concept of detection criticized. More often than not, it's not clear to me that the person or organization doing the criticizing actually understands what detection is really all about. There are no silver bullets in security, but the concept and practice of detection are an important part of a holistic and well-rounded approach to risk management. I explain my perspective in my latest SecurityWeek piece: http://www.securityweek.com/detection-may-not-be-what-you-think-it. Hope you enjoy.
Monday, August 10, 2015
Data Visibility: A Matter of Perspective
What can the dentist teach us about visibility? Quite a bit, actually. Curious what on earth I could possibly be referring to? Have a look at my latest piece in DarkReading: http://www.darkreading.com/analytics/data-visibility--a-matter-of-perspective/a/d-id/1321687? I discuss the topic of visibility and how more angles and perspectives are better than just one or a few. Hope you enjoy!
Subscribe to:
Posts (Atom)
