top of page
Search
Security Budgets - Supply and Demand Thinking
How you obtain and manage a budget to drive an adequate level of security is immensely important. Yet, it is one of the least discussed...
Aug 29, 20205 min read
2,126
Cybersecurity Workforce Development - Updated
It is still somewhat frustrating that most of the dialog about the skills shortage in cybersecurity focuses, perhaps inevitably, on the...
Aug 22, 20203 min read
1,227
Tips for Running a Risk Committee
In any sizable organization it is important to have some form of management steering group or committee to oversee your risk program. The...
Aug 16, 20206 min read
2,718
Insider Threat - Blast Radius Perspective - Updated
Of the vast canon of insightful commentary that has come from Dan Geer over many years, one that especially stuck with me was his...
Aug 8, 20203 min read
1,278
Cybersecurity and the Board : A Fresh Perspective?
How to represent cybersecurity (or technology / information risks more generally) to the Board is an ongoing subject of discussion in...
Aug 1, 202010 min read
6,048
Compliance vs. Security
It is sad that many security discussions are so binary: that is, if you’re not wildly for something then you must be wildly against it....
Jul 25, 20204 min read
3,006
Threat Intelligence - Updated
This is an update from a thread that became a post last year. Threat intelligence seems, at least to me, to get maligned too much. For...
Jul 18, 20203 min read
1,339
Security Leadership: A-grades vs. Pass/Fail
The underlying secret of most great security leaders and teams is one thing: the ability to know what needs to be done really well vs....
Jul 12, 20203 min read
1,992
A Simple Manifesto for Leading Security and Risk Teams
I’ve been using variants of these principles for many years in many contexts, both for security and broader risk management teams. I have...
Jun 28, 20202 min read
2,212
A Security Professionals Guide to Dealing with Disagreement
Disagreement arises in many situations. It is an inevitable part of any work in any organization, or life in general. It is especially...
Jun 21, 20206 min read
3,142
Are Security Incidents Really Increasing?
I see regular waves of articles and commentary that assert : “We are spending more and more on security but security incidents / breaches...
Jun 7, 20204 min read
1,142
Resilience is about Capabilities not Plans
Resilience can be thought of as the ability to absorb shocks, adjust as needed and continue operation in the face of adversity. In other...
May 24, 20206 min read
2,104
bottom of page