Wednesday, August 3, 2016

The Pen is Mightier Than Hot Air

Documentation isn't exactly a lot of fun, but it is extremely important to improving security operations and incident response.  I discuss the reasons why, as well as list a few areas where documentation can assist in my latest SecurityWeek piece: http://www.securityweek.com/pen-mightier-hot-air-why-documentation-key.  Hope you enjoy.

Wednesday, July 27, 2016

5 Failsafe Techniques For Interviewing Security Candidates

Hiring is, and will likely remain, a strategic challenge for quite some time.  At the same time, a bad hire can have disastrous consequences for an organization.  Given this, interviewing candidates well becomes extremely important.  How can organizations interview well?  My thoughts in my latest DarkReading piece: http://www.darkreading.com/vulnerabilities---threats/5-failsafe-techniques-for-interviewing-security-candidates/a/d-id/1326360?.

Wednesday, July 13, 2016

Hacking is Sexy, But Defending is the Grown-up Thing To Do

Hacking is most definitely sexy.  But shouldn't equal attention be paid to those who toil day in and day out defending their organizations from compromise?  My thoughts on the topic in my latest SecurityWeek piece:  http://www.securityweek.com/hacking-sexy-defending-grown-thing-do.  Defending is an important piece of the security puzzle too often missing from the broader dialogue.

Wednesday, June 29, 2016

The Increasing Importance Of Security Analytics

Although many people talk about analytics in the security field, there is still a tremendous amount of confusion around the topic.  I discuss this in depth in my latest SecurityWeek piece: http://www.securityweek.com/increasing-importance-security-analytics.  I think it's a dialogue the infosec community sorely needs to have.

Monday, June 27, 2016

Mind The Gap: CISOs Versus 'Operators'

In order for a security organization to evolve and mature, it needs to mind the gap.  What exactly am I referring to here?  Check out my latest piece in DarkReading to find out: http://www.darkreading.com/vulnerabilities---threats/mind-the-gap-cisos-versus-operators/a/d-id/1326050?.  I think it's an important topic, and I hope you will agree.

Sunday, June 26, 2016

How can SMBs deal with security work overload?

Almost all security organizations have more work than they can realistically do.  SMBs feel this pain more acutely than others.  What can security organizations do to ease the pain?  My thoughts in my latest piece in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/technology/2016/06/how-to-deal-with-tech-security-work-overload.html

Wednesday, June 8, 2016

Security Teams: Trust the One You're With

What can Stephen Sills' 1970 "Love The One You're With" teach us about information security?  I discuss that within the context of trust in my latest SecurityWeek piece: http://www.securityweek.com/security-teams-trust-one-youre.  I think you'll enjoy it.