Culture is an important but often overlooked aspect of a security organization. In particular, a culture of consistency leads to a better overall security posture. Does your security organization foster a culture of consistency, or the opposite? Curious what I mean by that? Have a look at my latest piece in DarkReading: http://www.darkreading.com/operations/8-signs-your-security-culture-lacks-consistency-/a/d-id/1325286?.
Wednesday, April 27, 2016
Wednesday, April 20, 2016
Cyber Insurance: Security Tool or Hype?
Is cyber insurance a useful security tool, or is it merely hype? I discuss this topic in my latest SecurityWeek piece: http://www.securityweek.com/cyber-insurance-security-tool-or-hype. I think you'll find my perspective a bit different than others you may have seen, and I hope you enjoy the piece.
Wednesday, March 23, 2016
What can the common cold teach us about infosec?
Does your security team most often treat the symptoms of problems, rather than the problems themselves? Interested in reading more about what I'm referring to? My latest piece in SecurityWeek discusses: http://www.securityweek.com/your-security-team-treating-symptoms-rather-problems.
Monday, March 21, 2016
Cloud Security: Understanding New Risks, Rising To New Challenges
Whether we like it or not, the move to the cloud is upon us. Further, the pace at which this move is occurring appears to be accelerating with each passing day. As information security professionals, we need to understand how we can get ahead of what is turning out to be one of the biggest business transformations of our time. I discuss this in my latest DarkReading piece: http://www.darkreading.com/cloud/cloud-security-understanding-new-risks-rising-to-new-challenges/a/d-id/1324769?. I think you'll find the piece very relevant to many of the security issues and challenges we're currently working through as a community.
Thursday, March 3, 2016
Incident Response: Work Smarter Not Harder
It will probably come as no surprise that most organizations have more work than they have people available to do that work. Since a large increase in staff is unlikely in most organizations, organizations need to think a little bit outside of the box in terms of how they approach the hectic workload an operational security environment brings with it. My thoughts on this topic in my latest SecurityWeek piece: http://www.securityweek.com/incident-response-work-smarter-not-harder. Hope you enjoy.
Wednesday, February 24, 2016
What Can Eminem Teach Us About Educating the Next Generation of Security Leaders?
What can Eminem teach us about educating the next generation of security leaders? It's an interesting question, isn't it? Or perhaps you are wondering what one thing has to do with the other? A fair question of course. I discuss this topic in my latest DarkReading Piece: http://www.darkreading.com/public-vs-private-is-a-prestigious-infosec-college-degree-worth-it/a/d-id/1324417?. Hope I've piqued your curiousity and that you enjoy the piece.
Thursday, February 18, 2016
When is intelligence not intelligent?
When is intelligence not intelligent? That is a question worth discussing in my opinion. Have a look at my latest piece in The Business Journals if I've got you wondering what exactly I mean: http://www.bizjournals.com/bizjournals/how-to/growth-strategies/2016/02/when-intelligence-isn-t-intelligent.html. Hope you enjoy!
Subscribe to:
Posts (Atom)
