Security Blog
-
CISO TALK: Navigating Boardroom Realities and Liability
I appeared with Mitch Ashley and JJ Minella on Techstrong TV to discuss the realities of a CISO’s journey into the boardroom, liability, and the SEC’s new disclosure rules.
-
6 Steps to Landing a Job in Cybersecurity
Looking to move into a cybersecurity career? Start with these six steps to evaluate and prepare yourself.
-
Why assessing third parties for security risk is still an unsolved problem
A recent ranking of the most cyber-secure companies reveals weaknesses in current third-party risk management practices. A Forbes article is making the rounds right now about America’s most cyber-secure companies, and I can already see the cybersecurity outrage machine up in arms. Full confession: I haven’t yet read the article, but I’m about to. I’m writing this…
-
Learning More from Accidents
When accidents happen, there’s a seductive call to look for a root cause – that is, a chain of events without which, the accident would not have happened. In hindsight, root causes are apparently easy to identify; one works backwards from the accident, identifying causal threads until reaching the “root cause.” It’s simple, and it’s generally wrong.…
-
Software liability reform is liable to push us off a cliff
Regulatory mandates for software security like those in the Biden Administration’s National Cybersecurity Strategy could cause more problems than they solve. Like “SBOMs will solve everything,” there is a regular cry to reform software liability, specifically in the case of products with insecurities and vulnerabilities. US Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly’s comments this…
-
What the Uber verdict means to CISOs: You’re (probably) not going to jail
CISOs and potential CISOs worried about criminal risk won’t go to jail if they follow four simple steps. There seem to be two reactions to the verdict in the Sullivan case. One reaction, often from CISOs already stressed by being outside the room where it happens, is to decide that being a CISO isn’t worth the risk…
-
TikTok resets the clock on security leadership
Roland Cloutier is stepping down as global CSO to become a strategic advisor to TikTok’s CEO. The clock is ticking on the CSO succession plan. The best time to do succession planning was last year. But the next best time is right now. The news this morning that Roland Cloutier is stepping away from the TikTok…
-
We don’t need another infosec hero
By setting yourself up as the defender, the solver of problems, you cast your business colleagues as hapless victims or, worse, threats. This is not a useful construct for engagement. There’s this belief among a lot of security professionals that we are special, in that we are the defenders of our companies. We like to…
-
The cloud security emperor has no pants
“Shared responsibility” usually means that no one is responsible for minding the gap. Don’t fall in. As anyone who has worked on a cross-functional team with no clear owner knows, “shared” or “joint” responsibility often means that everyone assumes that someone else is taking care of the problem. Without clear effort to make sure that…
-
The security user experience (SUX)
Security processes that treat the very users we protect as unwanted burdens and alienate them in the process are a path to failure. The next time you receive a phishing email, forward it to wherever your organization tells you to report phishing attempts. What response would you appreciate? Maybe a brief thank you or follow-up…
Leadership Newsletter
-
Making Bets
Leadership Moment: Snowmageddon? Or is that NOmageddon? While I’m now enjoying the lovely weather in Tel Aviv, last week I was home outside Boston, prepping to leave, when I was joined by my whole family, since school was closed for the impending snow storm. The storm was a dud, however. rain, wintry mix, and a… Read this …
-
Engaging Backups
Leadership Moment: Leaning In for the Needy This past Shabbat our synagogue graduated seven new adult Torah readers, which deepens our bench of people to leyn Torah (chant from the Torah) each week. Learning to leyn Torah isn’t as easy as “can you read Hebrew?” Reading the Hebrew isn’t all that difficult. The large symbols… Read this …
-
Let your grace shine through
Leadership Moment: Letting Go A few weeks ago, Cloudflare let go a number of folks in its sales organization, and one of them (let’s call them AE) recorded the experience, and shared it online. It’s a long video, but to summarize: An HR representative, and a member of sales management (not AE’s manager or director,… Read this …
Fiction
-
Skeleton
A necromancer and an Olympic event [Read the story]
-
Albus Dumbledore and the Rituals of Immortality
The words that didn’t make the Harry Potter septology that fill in the blanks for what’s really going on. [Read the story]