Why WannaCry Really Makes Me Want to Cry

Recently, the WannaCry ransomware worm was big news.  For security professionals working inside organizations with unpatched systems vulnerable to infection, it was a particularly busy period.  Plenty has been written about the malware itself, how it spread, the need to patch, and many other technical topics around the recent outbreak.  Much great analysis has been done, and I certainly don’t need to rehash that here.  I’d like to focus on a different angle ent

read more

Continue reading Why WannaCry Really Makes Me Want to Cry→

What Romeo and Juliet Can Teach Us About Security Market Confusion

Recently, I was reminded of the well known quote from William Shakespeare’s play “Romeo and Juliet”: “A rose by any other name would smell as sweet”.  What exactly was I doing that reminded me of this quote?  I was reviewing the different markets in the security space. How exactly does this bring this famous quote from “Romeo and Juliet” to mind?  Allow me to elaborate.

read more

Continue reading What Romeo and Juliet Can Teach Us About Security Market Confusion→

Beyond Nation-states: The Disappearing Line Between Attacker Capabilities

In the incident response world, we used to draw a clear line between the capabilities of attackers affiliated with nation-states and those not affiliated with any nation-state. Nation-state attackers always seemed to be the most well equipped and the m… Continue reading Beyond Nation-states: The Disappearing Line Between Attacker Capabilities→

Intrusions Without Malware: Don’t Forget the Other Sixty Percent

The time has come to start paying attention to the other sixty percent.  No, this isn’t a political piece.  Rather, I am trying to call attention to something that, in my opinion, is not high enough on the priority list of many people in the information security profession.

read more

Continue reading Intrusions Without Malware: Don’t Forget the Other Sixty Percent→