Jan 17, 20213 minSituational Drivers of Cyber-RiskMany years ago I wrote down a list of the drivers that create information / cyber-risk or that otherwise compel the need to mitigate this...
Jan 2, 20211 min2020 Short ReviewAt the risk of being too understated, 2020 was an interesting year. In this blog I’ve covered many topics across the range of strategy...
Dec 19, 20205 minPrivilege Management Program - GovernanceI can’t recall having seen an overview of a systematized privilege management program. There are lots of great articles on specific...
Dec 13, 20208 minSecurity Ratings: Love, Loathe or Live With Them?Security ratings services tend to be loved or loathed. Loved if you consume them and it makes your job easier, especially if you have no...
Dec 6, 20206 minThe Seat at the Table: Integrating Security into your BusinessThe success of a security program is largely determined by how well it is integrated into the fabric of the organization, in terms of...
Nov 29, 20203 minSimple Rules of (InfoSec) Career Success - UpdatedOver the years I've noted the behaviors I’ve seen from consistently successful people. In this context I define success as a balance of...
Nov 22, 20205 minScenario Planning - The Best Technique You Might Not Be UsingScenario planning is one of the most underutilized techniques in security. Which is surprising given how effective it is in [good]...
Nov 15, 20206 min12 Step Guide on Escalating Risk and Security Issues Escalating issues is part of the foundation of any good risk and security program. Unfortunately, human nature is such that most people...
Nov 8, 20204 minPrinciples for Cybersecurity Metrics“For every metric, there should be another ‘paired’ metric that addresses adverse consequences of the first metric.” - Andy Grove We talk...
Nov 1, 20207 minThe Uncanny Valley of Security (or Why We Might Never Finish Anything)The uncanny value is a famous term in robotics. It is used to describe how we accept robots that don’t attempt to look too human, but,...
Oct 25, 20204 minCybersecurity Macro Themes for the 2020’s - UpdatedThere will be 6 major themes that differentiate great security programs, products, features and processes. These are different from...
Oct 18, 20203 minWhy Cybersecurity Budget Benchmarks are a Waste of TimeI have built up a disdain for cybersecurity budgeting benchmarks. To be fair, there are some good attempts amid a sea of haphazard...