Dec 4, 20218 minHow is the Security Profession Doing? I spoke on a CIISEC panel a few months ago about the state of the information security profession. This post is based on remarks I made...
Nov 20, 20214 minSecurity Program Tactics - UpdatedWhen starting or reinvigorating a security program, focus on a small number of meta-objectives that can have sustained outsize effects in...
Nov 6, 20216 minSlipstreaming : Business Tactics for Security & Control ImplementationOne of the most frequent cybersecurity binary thinking curses is that just because senior leadership in organizations won’t do every...
Oct 22, 20214 minConferences and the Wider Security Eco System Culture - Toxic or Not?This could be part of another whole series on the curse of binary thinking so please read this in that tone. In other words, I’m trying...
Oct 9, 20213 minThe Leading Indicators of a Great Info/Cybersecurity Program - UpdatedAs we see more incidents occurring, whether ransomware, data breaches or fraud, many thoughts turn to how to know whether those we do...
Sep 25, 20214 minCyber Deterrence : A Simple Perspective Cyber deterrence is a topic that comes in and out of vogue. It is widely studied but often misunderstood. It also suffers tremendously...
Sep 12, 20218 minIf Accounting were like CybersecurityIt has always struck me how well the field of finance and more specifically accounting has done to standardize on its terms. This...
Aug 27, 20213 minRisk Management is not only about Reducing Risk - UpdatedThis is an update from a post of a couple of years ago prompted by some recent observations from a few different organizations. It seems...
Aug 14, 20219 minRisk = Hazard + OutrageThere are four major insights that, above all others, have influenced my approach to security and risk management over the past decades....
Jul 30, 20217 minCISO: Archeologist, Historian or Explorer?We talk about attackers being the enemy. Sometimes we talk about insider threats. But one of our biggest enemies is pernicious...
Jul 16, 20218 minCybersecurity - The Board's PerspectiveHow Boards, especially public company Boards, oversee cybersecurity is a crucial but difficult topic. This previous post discussed how...
Jul 3, 20216 minCybersecurity and the Curse of Binary ThinkingWorking in information/cybersecurity and technology risk is a fascinating and challenging career, as I’ve covered here. There is, mostly,...