What do you think this is?

just thoughts of a restless mind...

What to do with the center of security?

What to do with the center of security?

Some years ago, during a (quite extended) phishing avalanche in the company I was at the time, the (then) CIO said: Let’s fire every user that falls for a phishing mail! That will solve the problem for good.
I considered it a joke, and I replied pretty much with a rhyme: Let’s train them before we blame them and I didn’t give it a second throught. We went on to deploy some training modules, but never really implemented the technical controls on the mail server; an activity that if had been implemented, several of those phishing mails would never have entered the company. I think that this is not strictly a user failure and I’m inclined to blame the IT deparment more than the user.

Read more ...

Tagged in : security, awareness, management, leadership, social engineering

Steps in no-man’s land

Steps in no-man’s land

Some major breaches have seen the light of day lately, and everybody agrees that they will keep coming. I don’t believe you will find any security professional respecting himself to tell you that this will stop. The reasons are many, but the most important one is the (lack of) security design. Systems, processes and services have been moving to production without security design for years. And unfortunately in many cases they still do.

In our (security) profession it is becoming common to jump on each other’s throat; and the result is the public blaming of the CISO involved - like leaving them alone to take some hard steps in the middle of no man’s land.

Read more ...

Tagged in : business, security, leadership

Building up a SOC - the candidate challenge

Building up a SOC - the candidate challenge

Building a Security Operations Center from scratch is not an easy thing. But since it’s not the first time I’m doing it, I am familiar with the challenges. These challenges include the building of the processes in a company-adjusted manner, the selection of the toolset and integrations to match the company’s enterprise architecture, network architecture and of course my own security architecture, but nowadays, and due to the significant skill shortage in cybersecurity the major challenge is finding the right people.

Read more ...

Tagged in : interviews, management, leadership