GRC, Pen Testing, SecOPS, Threat Intel Stuff, Audit/Assessment, Incident Response & Digital Forensics - Tweets are mine (or are they? Did you read the EULA?)
So, what did we learn today?
1) who tests before applying patches,
2) who has separate test and prod networks,
3) who has current biz continuity plans,
4) who has tested DR capabilities.
As it turns out, not as many as you would expect and hope.
From airlines to hospitals
Client: Our operations and applications are HIPAA compliant.
Me: Cool, can we chat with your privacy and compliance officers?
Client: we don't have those, we are all responsible!
Unfortunately, a tabloid newspaper has got hold of a music video I recorded in Islington North with an iconic grime artist I've admired for years.
They are planning to publish a heavily edited clip, so I'm releasing the full version myself. Watch here: tinyurl.com/yeymfb96
If you're having nvidia-docker-container issues after an update, nuke /etc/nvidia-container-runtime/config.toml and restart everything. I can't tell you how many hours I chased my ass on that.
Been having some real frustrating conversations lately.
Tons of jr or mid career security people landing at places and getting no mentorship, no training. No support. Treated pretty aggressively by Sr resources.
They were promised Sr people would be there to help, guide, and train.
Instead they are threatened and obsfucate their working knowledge in fear of … replacement? I dunno.
It’s sad.
Have a working mentorship program and some training.
As a cyber security company that is table stakes.
Or lose out on the future, lose the next generation of protectors.
Be aware of your legal obligations when it comes to ethical AI. These are evolving fast and may impact the systems you are building.
Great talk with many case studies from Rachael Greaves of Castlepoint Systems @qconlondon
#infosec#ProTip if you haven't lived through technical debt, it's not fun. It will slow down development, modernization and transformation projects to a standstill; burning out folks as they work to address issues from a decade ago rather than the current goal.
Never underestimate the number of people who say they want need "a transformation" but in reality want most things, tools, processes, people to stay the same. #random
#infosec#ProTip there is a difference on focus between confidentiality (protecting the enterprise) and privacy (protecting the individual).
They serve two distinct and separate functions.
#infosec#ProTip you have a choice, you can choose to test your plan yourself or you can choose for an adversary to test your plan.
Which one sounds better?