May 89 minRegulatory RelationshipsFor some reason there have been a few people already in or moving into highly regulated industries, like finance or healthcare, that have...
Apr 213 minThe Stress and Joy of Security Jobs - UpdatedThere’s a lot going on in the world from conflict, crime, economic and many other pressures. Many of these matters have security...
Feb 1218 minOrganizational PoliticsAt every stage in your career and in every part of your role you are going to have to deal with organizational politics. By this, I don’t...
Jan 2916 minSecrets of Successful Security Programs - Part 2As introduced in the last post, a successful security program is made up of two distinct elements: A series of episodic big bets that...
Jan 1511 minSecrets of Successful Security Programs - Part 1A successful security program (although I imagine this advice could apply to any discipline) is made up of two distinct elements: A...
Jan 17 minThe Obvious CISO : Don’t Overlook the SimpleThere is a great little book I read recently, “Obvious Adams - The Story of a Successful Businessman", it’s available on Amazon, but it’s...
Dec 4, 20218 minHow is the Security Profession Doing? I spoke on a CIISEC panel a few months ago about the state of the information security profession. This post is based on remarks I made...
Nov 20, 20214 minSecurity Program Tactics - UpdatedWhen starting or reinvigorating a security program, focus on a small number of meta-objectives that can have sustained outsize effects in...
Nov 6, 20216 minSlipstreaming : Business Tactics for Security & Control ImplementationOne of the most frequent cybersecurity binary thinking curses is that just because senior leadership in organizations won’t do every...
Oct 22, 20214 minConferences and the Wider Security Eco System Culture - Toxic or Not?This could be part of another whole series on the curse of binary thinking so please read this in that tone. In other words, I’m trying...
Aug 14, 20219 minRisk = Hazard + OutrageThere are four major insights that, above all others, have influenced my approach to security and risk management over the past decades....
Jul 16, 20218 minCybersecurity - The Board's PerspectiveHow Boards, especially public company Boards, oversee cybersecurity is a crucial but difficult topic. This previous post discussed how...
Jul 3, 20216 minCybersecurity and the Curse of Binary ThinkingWorking in information/cybersecurity and technology risk is a fascinating and challenging career, as I’ve covered here. There is, mostly,...
Jun 19, 20217 minThe Actual Cybersecurity Workforce ChallengeWe continuously hear about the millions of unfilled cybersecurity roles, although I’ve yet to see a study that actually supports that...
Jun 5, 20216 minRelationship Management for the InfoSec ProgramA key part of any security leader's role is relationship management. In my experience this is another one of those leadership skills that...
Apr 24, 20211 minLeadership, Business, Security and Risk Reading ListThis is my list of favorite books across the various professional disciplines I’m interested in. I have a set of favorite books that are...
Feb 27, 20213 min"Hell Yes, or No" vs. "Soft Yes, and Fast Quit"I am a big fan of the concept of saying, “Hell Yes, or No” to decide whether to do something or not. Derek Sivers has written well about...
Dec 6, 20206 minThe Seat at the Table: Integrating Security into your BusinessThe success of a security program is largely determined by how well it is integrated into the fabric of the organization, in terms of...
Nov 29, 20203 minSimple Rules of (InfoSec) Career Success - UpdatedOver the years I've noted the behaviors I’ve seen from consistently successful people. In this context I define success as a balance of...
Nov 15, 20206 min12 Step Guide on Escalating Risk and Security Issues Escalating issues is part of the foundation of any good risk and security program. Unfortunately, human nature is such that most people...