Wednesday, August 31, 2016

The Only Constant is Change

Sometimes it seems like change is everywhere.  So much so that one might feel that the only constant is change.  There is something to that, and I explore the topic in more depth in my latest SecurityWeek piece: http://www.securityweek.com/information-security-only-constant-change.  In particular, I examine how organizations can stay focused on what matters amidst a sea of distractions.  I hope you enjoy the piece.

Wednesday, August 17, 2016

It's All About The Base

Want to get the most out of your scarce security analyst resources?  It's all about the base.  Other than making a silly pun, what do I mean by that?  Have a look at my latest piece in SecurityWeek for a more in-depth discussion: http://www.securityweek.com/maximizing-security-analyst-resources-its-all-about-base.

Thursday, August 11, 2016

Theory Vs Practice: Getting The Most Out Of Infosec

Theory and practice are two very different things.  In fact, I would argue that they are two different philosophies, or mindsets, that often guide how people approach information security.  But which one is more effective?  I discuss this topic in my latest DarkReading piece: http://www.darkreading.com/analytics/theory-vs-practice-getting-the-most-out-of-infosec/a/d-id/1326564?

Wednesday, August 3, 2016

The Pen is Mightier Than Hot Air

Documentation isn't exactly a lot of fun, but it is extremely important to improving security operations and incident response.  I discuss the reasons why, as well as list a few areas where documentation can assist in my latest SecurityWeek piece: http://www.securityweek.com/pen-mightier-hot-air-why-documentation-key.  Hope you enjoy.

Wednesday, July 27, 2016

5 Failsafe Techniques For Interviewing Security Candidates

Hiring is, and will likely remain, a strategic challenge for quite some time.  At the same time, a bad hire can have disastrous consequences for an organization.  Given this, interviewing candidates well becomes extremely important.  How can organizations interview well?  My thoughts in my latest DarkReading piece: http://www.darkreading.com/vulnerabilities---threats/5-failsafe-techniques-for-interviewing-security-candidates/a/d-id/1326360?.

Wednesday, July 13, 2016

Hacking is Sexy, But Defending is the Grown-up Thing To Do

Hacking is most definitely sexy.  But shouldn't equal attention be paid to those who toil day in and day out defending their organizations from compromise?  My thoughts on the topic in my latest SecurityWeek piece:  http://www.securityweek.com/hacking-sexy-defending-grown-thing-do.  Defending is an important piece of the security puzzle too often missing from the broader dialogue.

Wednesday, June 29, 2016

The Increasing Importance Of Security Analytics

Although many people talk about analytics in the security field, there is still a tremendous amount of confusion around the topic.  I discuss this in depth in my latest SecurityWeek piece: http://www.securityweek.com/increasing-importance-security-analytics.  I think it's a dialogue the infosec community sorely needs to have.