It’s Time to Democratize Security
A Seat at the Security Table Should Not be for Only the Elite and Largest of Businesses or Security Vendors
read more
Collaborate Disseminate
A Seat at the Security Table Should Not be for Only the Elite and Largest of Businesses or Security Vendors
read more
Do You Have Data Around What Security Products and Services Other Organizations Use and How They Use Them?
read more
Continue reading The Importance of Benchmarking in Your Security Program
In my previous piece, I discussed the difficulty vendors sometimes have in understanding what security buyers are really looking for. As I mentioned in that piece, this confusion is further compounded by the large volume of vendors and distinct m… Continue reading Marketing Security Solutions: Is There a Better Way?
The information security market has been a topic of acute interest for quite some time now. Estimates around the current size of the market range between $75 and $150 Billion. That is far larger than the market was even just a few years ago. That… Continue reading What Are Security Buyers Looking For?
Recently, I was thinking about the time during high school when I took a trip to visit my elementary school. I’m not sure why this memory suddenly popped into my head, but it did remind me of an important topic in security that I’ve been meaning to write about.
Recently, the WannaCry ransomware worm was big news. For security professionals working inside organizations with unpatched systems vulnerable to infection, it was a particularly busy period. Plenty has been written about the malware itself, how it spread, the need to patch, and many other technical topics around the recent outbreak. Much great analysis has been done, and I certainly don’t need to rehash that here. I’d like to focus on a different angle ent
Recently, I was reminded of the well known quote from William Shakespeare’s play “Romeo and Juliet”: “A rose by any other name would smell as sweet”. What exactly was I doing that reminded me of this quote? I was reviewing the different markets in the security space. How exactly does this bring this famous quote from “Romeo and Juliet” to mind? Allow me to elaborate.
Continue reading What Romeo and Juliet Can Teach Us About Security Market Confusion
The European Union’s General Data Protection Regulation (GDPR) goes into effect on May 25, 2018. The regulation is primarily designed to protect the private data of EU citizens.
Continue reading The Practical Effects of GDPR on Security Operations and Incident Response
In the incident response world, we used to draw a clear line between the capabilities of attackers affiliated with nation-states and those not affiliated with any nation-state. Nation-state attackers always seemed to be the most well equipped and the m… Continue reading Beyond Nation-states: The Disappearing Line Between Attacker Capabilities
The time has come to start paying attention to the other sixty percent. No, this isn’t a political piece. Rather, I am trying to call attention to something that, in my opinion, is not high enough on the priority list of many people in the information security profession.
Continue reading Intrusions Without Malware: Don’t Forget the Other Sixty Percent