top of page
Search
Crucial Questions from CISOs and Security Teams
In this, third in a series of Crucial Questions posts I’m going to focus on the questions from CISOs and security teams. This builds on...
Aug 27, 202223 min read
Â
Â
Crucial Questions from CEOs and Boards
Over the past few years I have done a lot of speaking at conferences, events and small group settings for Board directors and corporate...
Jul 31, 202211 min read
Â
Â
3 Year Review
I’ve been doing this blog for around 3 years, largely succeeding in posting every 2 weeks. I have learnt a lot in this process and I...
Jul 16, 20223 min read
Â
Â
The Reporting Line of Security Teams / CISOs - Updated
This can be an emotive topic for many people. It is one, I’ve found, colored more by dogma than nuance (as it seems with many things...
Jul 2, 20225 min read
Â
Â
Are Security Analogies Counterproductive?
Do analogies actually help us or do they set back our ability to drive change? On the face of it they are a useful explanatory tool, as...
Jun 18, 20226 min read
Â
Â
Defense in Depth
Defense in depth is a well accepted security principle. Intuitively, it stipulates there should be multiple lines of controls so as to...
May 21, 20227 min read
Â
Â
Regulatory Relationships
For some reason there have been a few people already in or moving into highly regulated industries, like finance or healthcare, that have...
May 8, 20229 min read
Â
Â
10 Fundamental (but really hard) Security Metrics
As an industry we have been trying to deal with the issue of security metrics for a long time. I’ve written about this here, and in the...
Apr 9, 20229 min read
Â
Â
Resilience is about Capabilities not Plans - Updated
Over the past 2 years, since I wrote the first version of this post, we’ve had a lot of opportunity to test our collective resilience....
Mar 26, 20227 min read
Â
Â
Human Error
Human error is not an explanation, rather it is something to be explained. In analyzing and learning from incidents, not just security...
Mar 12, 20229 min read
Â
Â
Controls - Updated
I wrote the first version of this post nearly 3 years ago. It is interesting that since then much of it remains true. Oddly, it also...
Feb 26, 20224 min read
Â
Â
The Obvious CISO : Don’t Overlook the Simple
There is a great little book I read recently, “Obvious Adams - The Story of a Successful Businessman", it’s available on Amazon, but it’s...
Jan 1, 20227 min read
Â
Â
Risk Megatrends - Updated
Megatrends are long-term, large-scale forces that shape the world around us. They are the driving forces that have tactical consequences...
Dec 18, 20213 min read
Â
Â
How is the Security Profession Doing?
I spoke on a CIISEC panel a few months ago about the state of the information security profession. This post is based on remarks I made...
Dec 4, 20218 min read
Â
Â
Security Program Tactics - Updated
When starting or reinvigorating a security program, focus on a small number of meta-objectives that can have sustained outsize effects in...
Nov 20, 20214 min read
Â
Â
Slipstreaming : Business Tactics for Security & Control Implementation
One of the most frequent cybersecurity binary thinking curses is that just because senior leadership in organizations won’t do every...
Nov 6, 20216 min read
Â
Â
The Leading Indicators of a Great Info/Cybersecurity Program - Updated
As we see more incidents occurring, whether ransomware, data breaches or fraud, many thoughts turn to how to know whether those we do...
Oct 9, 20213 min read
Â
Â
If Accounting were like Cybersecurity
It has always struck me how well the field of finance and more specifically accounting has done to standardize on its terms. This...
Sep 12, 20218 min read
Â
Â
Risk Management is not only about Reducing Risk - Updated
This is an update from a post of a couple of years ago prompted by some recent observations from a few different organizations. It seems...
Aug 27, 20213 min read
Â
Â
Risk = Hazard + Outrage
There are four major insights that, above all others, have influenced my approach to security and risk management over the past decades....
Aug 14, 20219 min read
Â
Â
bottom of page

