Jun 19, 20217 minThe Actual Cybersecurity Workforce ChallengeWe continuously hear about the millions of unfilled cybersecurity roles, although I’ve yet to see a study that actually supports that...
Jun 5, 20216 minRelationship Management for the InfoSec ProgramA key part of any security leader's role is relationship management. In my experience this is another one of those leadership skills that...
May 22, 20212 minSegmentation Technologies / Zero TrustI first came across the notion of doctrine vs. structure in this depiction about the relative positioning of tanks from some blog or...
May 13, 20211 minCloud SecurityIn a few of my posts I've talked about the economy of scale of the cloud is fundamentally changing the game of security. The pace of...
May 8, 20217 minIs Complexity the Enemy of Security?One of the many pieces of accepted wisdom in information/cybersecurity is that complexity is the enemy of security. But is it? You...
Apr 24, 20211 minLeadership, Business, Security and Risk Reading ListThis is my list of favorite books across the various professional disciplines I’m interested in. I have a set of favorite books that are...
Apr 10, 20216 minSecurity Leaders Guide to Managing StressSecurity is a tough job. But it is not uniquely so. Our colleagues in risk, safety, compliance, privacy, and many other disciplines have...
Mar 27, 20215 minCybersecurity : The Winner’s Game and The Loser’s GameThere is a seminal paper in finance by Charles Ellis called the The Loser’s Game which, in simple terms, foretells the move from active...
Mar 13, 20214 minReturn on Investment for SecurityThe concept of return on investment (ROI) for security has bugged me for a long time. Not because it isn’t a laudable goal. Of course,...
Feb 27, 20213 min"Hell Yes, or No" vs. "Soft Yes, and Fast Quit"I am a big fan of the concept of saying, “Hell Yes, or No” to decide whether to do something or not. Derek Sivers has written well about...
Feb 13, 20214 minResearch Challenges in Info/Cybersecurity - Part 2: “Carbon”This is the second part of the post from 2 weeks ago, which explored research challenges in Info/Cybersecurity related to systems:...
Jan 30, 20215 minResearch Challenges in Info/Cybersecurity - Part 1: “Silicon"This is the first of a two part post on research challenges centered on systems, computer science and engineering research challenges....