What is the point of analysis anyway? Perhaps this sounds like a bit of a shocking or radical question, but I’d argue that it...
Hi, what are you looking for?
What is the point of analysis anyway? Perhaps this sounds like a bit of a shocking or radical question, but I’d argue that it...
A few months back, I was a passive observer to an interesting email thread. People on the thread were discussing a breach that was...
Unlike the Common Cold, Security Professionals Have the Ability to Treat the Root Case of Problems
I haven’t met too many security professionals that don’t have enough work to do and are looking for more. This may seem obvious to...
Those who read my pieces regularly likely realize that I enjoy writing on topics around which I see a lack of clarity. Whenever possible,...
If you read my pieces regularly, you might have guessed that approaching security operations and incident response in a strategic, holistic, and analytical way...
Boards and Executives Don’t Want to Hear Solely About the Problem Anymore
The Time to Move to a Narrative-driven Model is Long Overdue
At the recent FIreEye Cyber Defense Summit in Washington, DC, I had the privilege of hearing General (ret.) Colin Powell deliver one of the...
In many aspects of the physical world, we’re quite accustomed to seeing things from the user perspective.
There is a great deal of wisdom contained in the well-known idea that we can each learn something from everyone we meet. As you...
Some time ago, I met with an organization that had asked to speak with me because of my experience in the security operations realm....
Recently, it seems like I’ve been hearing phrases like: “we need to get better at information sharing”, “we need to share more information”, or...
Detection is a Philosophy, Approach, and Methodology...
In almost any endeavor, success usually comes with additional responsibility. For example, a promotion into a management or executive position comes with the additional...
I’m sure most of us have seen one of the many cartoons recently circulated on LinkedIn. This particular cartoon caught my eye due to...
Visibility is Likely the Greatest Deficit That a Move to the Cloud Brings to a Security Organization
One topic of conversation that surfaces quite regularly is the skills gap and critical staffing shortage present in the security field. From the data...