Security Advisor at @WombatSecurity. Former Fortune 500 CISO. Founding member of Microsoft Security Council. Board Chair of CMU’s CISO Executive Program.
I’m looking forward to joining a few of my contemporaries tomorrow to discuss best practices for #SupplyChain#RiskManagement. If you’ll be attending the @CERT_Division #Cyber Law and Privacy Symposium in #Pittsburgh, please be sure to say hello. ow.ly/ob0150u1Oj0
I've posted about this before, but it's worth repeating: Prioritizing time-to-market over solid #cybersecurity is a mindset that we, the good guys, need to change if we ever hope to get ahead of the #security curve. ow.ly/SExx50rjwh7
As a #CISO, I (unfortunately) experienced the impact of a #NationState attack, so I can understand why #cyber insurance coverage would have seemed like a light at the end of the tunnel for these orgs. Curious to see how this plays out. ow.ly/AA8a50rjvQg
I am shocked ... and, frankly, disappointed ... by findings that most orgs don't have a #CSIRP in place. Many things about #cybersecurity aren't fully in our control, but we MUST be better about the things we can control. More from @ITProPortal. ow.ly/wJNi50qoZsP
I generally read the @WombatSecurity#StateOfThePhish Report multiple times ... it's a great resource for real-world #phishing impacts and actionable advice. In my opinion, it's only gotten better over the years. ow.ly/jSY350qoZgj