Monday, April 16, 2018

Not a conference conference

This week many people are at RSAC for the week gaining knowledge and a ton of vendor swag.
Believe me when I say I am not bitter about not being there. But watching from the sidelines got me thinking...    What if we took all the time and resources we spend on conferences and put them into security improvements? 

What would that look like? Well, surely you've been to working meetings where everyone brings their gear and talents and you collaborate on tasks. Sometimes this doesn't happen until a "crash team" is needed. Other times it more proactive. 

Food for thought.

Wednesday, November 15, 2017

Hacking the generation Gap - leading millennials in infosec

Millennials are the generation born from 1980 to 2000. Do you work with or lead millennials? The answer is likely yes. This group encompasses all workers between 18 and 37 years old!

Would you approach a problem in your job the same no matter the requirements, challenges or other considerations? Would you try to secure a cloud infrastructure the same way you would an on-premise infrastructure? Would those same controls work? Likewise, would you conduct a pentest the same without considering the environment? Fashion the payload without regard for the antivirus vendor? Deliver the same web app exploit without consideration for the use of a WAF? Attempt to bypass an nextgen firewall just as you would a traditional firewall? Obviously not, so why then are so many people trying approach leading the millennial generation using the same old tactics, techniques and procedures? Despite the stigmas and stereotypes this generation has differences that require a different approach.

I'd like to introduce you to four (4) ways you can (and perhaps must) change in order to effectively lead millennials - ABCs & Ds if you will.
  1. Accept their differences
  2. Bring the bigger picture into focus
  3. Change our mindset
  4. Develop their strengths; ignore their weaknesses

To further explain these areas I've recorded a short video. It's a first take but I hope it will help you greatly in your pursuit to lead millennials within your organization!



Wednesday, February 1, 2017

Why military members past present and future are more well equipped for Cyber Security than almost every other candidate

How many of your candidates have consistently received user awareness training in phishing, information security and operational security annually for the past 3 or more years?

I am guessing not many, which is precisely why military members are among the most well-trained candidates you will see. Military members receive world-class user awareness training that's application focused. Like all military training it is about meeting mission and nothing is more about application than mission!

Hire a vet.