top of page
Search
Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls
Security breaches are often not the result of awesome attacker capabilities or the sudden emergence of sophisticated zero-day exploits. Instead, what we usually find are the controls designed to stop the attack were believed to be operational but were actually broken or misconfigured at the moment when they were needed. Sometimes they were never fully in place to meet the security team's original intent. So, continuous control monitoring is needed to counter the natural dec
Jul 255 min read
Technology Waves and Security - Is This Time Really Different?
Most people have been through at least one wave of technology transformation. Some of us have been through a few and all carry the wisdom and scars from these. When you’ve experienced these changes you learn to appreciate, as the adage goes, that history might not repeat but it certainly does rhyme. In my working lifetime I caught the tail end of the mainframe to PC transition, the proliferation of client/server and distributed system architectures, wide-spread Internet adop
Jul 119 min read
CISO Version 2.0
Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some “point releases” on the way. This is simply because version 1 of the role is
Jun 124 min read
Maintenance of Everything : A Review
I haven’t done a book review for a while and there’s no better way to get back to this than a look at Stewart Brand’s Maintenance of Everything . Stewart developed a lot of this book in an open editing process and so the final delivery of what is Part 1 of a forthcoming series was all the more anticipated. I’ve long been obsessed with the need for maintenance in the context of technology risk management, security and reliability. A big part of technical debt build up and the
Apr 186 min read
bottom of page