Wednesday, June 24, 2015

To The Cloud! What do we have to lose?

The cloud is an oft-discussed topic these days.  But beyond the hype and buzz, what are the ramifications of a move to the cloud for security operations and incident response?  I share my thoughts on the topic in my latest SecurityWeek piece: http://www.securityweek.com/cloud-what-do-we-have-lose.

Sunday, June 21, 2015

Why encryption can't replace security operations

But isn't encryption enough?  No way.  Curious why?  Have a look at my latest piece in The Business Journals: http://www.bizjournals.com/orlando/how-to/technology/2015/06/why-encryption-cant-replace-security-operations.html.  Hope you enjoy the read.

Thursday, June 11, 2015

Isn't retention as important as recruiting?

In my experience, retention is equally important, and perhaps more important than recruiting.  Given that, why do so many organizations struggle to retain talented security analysts?  My thoughts in my latest SecurityWeek piece: http://www.securityweek.com/five-ways-chase-away-your-best-security-analysts.  Hope you enjoy, and more importantly, hope you can take something of value with you away from the article.

Tuesday, June 9, 2015

Security Metrics: It's All Relative

What can a haircut teach us about communicating security value to executives and non-security professionals?  I discuss this question in my latest piece in DarkReading: http://www.darkreading.com/analytics/security-metrics-its-all-relative/a/d-id/1320772?.  Wondering what one thing has to do with the other?  Have a look at the piece.  Hope you enjoy!

Wednesday, May 27, 2015

Stay Out of the Tunnel to Minimize Risk

The tempation to enter the tunnel can be almost insurmountable.  But in the long term, it is much more advantageous to remain strategically focused towards improving the organization's overall security posture.  Curious what I'm referring to?  Have a look at my latest piece in SecurityWeek: http://www.securityweek.com/stay-out-tunnel-minimize-risk

Wednesday, May 13, 2015

Taking A Security Program From Zero To Hero

How does one take a security program from zero to hero?  It is certainly not an overnight process, but it is an attainable goal.  My latest piece in DarkReading discusses this topic: http://www.darkreading.com/informationweek-home/taking-a-security-program-from-zero-to-hero/a/d-id/1320388?.  Hope you enjoy!

Friday, May 8, 2015

Alert fatigue: 6 steps for dealing with constant alerts

Alert fatigue is an almost universal challenge that affects nearly every aspect of a security program.  I am often asked about how organizations can overcome alert fatigue.  My thoughts on this important topic in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/technology/2015/05/dealing-with-constant-security-alerts.html.  Hope you enjoy this piece and find it useful.