Open in app

Sign in

Write

Sign in

freshman
freshman

264 Followers

Home

About

Sep 23

Government Shutdowns Create Insider Threats

We are on the precipice of another government shutdown if the United States Congress fails to act by September 30. This would be the 22nd U.S. government shutdown since 1976, with the most recent shutdown lasting 35 days from December 22, 2018, to January 25, 2019 — by far the…

National Security

6 min read

Government Shutdowns Create Insider Threats
Government Shutdowns Create Insider Threats
National Security

6 min read


Nov 15, 2022

Reflections on Digital Security Awareness: Why Availability is Not the Same Thing as Accessibility

For me, October was the acknowledgment of digital security and awareness, but honestly, it was more than that. November is a moment of reflection. For me, it’s reflecting on the question of how can we understand the barriers between awareness and implementation? To answer this, it’s imperative to understand the…

Cybersecurity

1 min read

Cybersecurity

1 min read


Feb 10, 2022

Stop the Insan-IT

Shadow-IT — Deployed information technology systems or services by employees or non-IT departments, to work around the shortcomings of the central information systems; actual or perceived. Example: The marketing team decides to use Third-party Software-as-a-Service (SaaS) applications outside the control of their IT department Scamicry — A “legitimate” interface or…

Security Culture

3 min read

Stop the Insan-IT
Stop the Insan-IT
Security Culture

3 min read


Oct 4, 2021

National Cyber Security Month is a Shared Responsibility

Looking back 5 years, the FDA marked National Cyber Security Awareness Month with a statement [1] (available on third party site) I feel is important to reflect on: “At FDA, we strongly believe that medical device cyber safety is a large and shared responsibility that requires diligence from all stakeholders…

Cyber Security Awareness

2 min read

National Cyber Security Month is a Shared Responsibility
National Cyber Security Month is a Shared Responsibility
Cyber Security Awareness

2 min read


Sep 17, 2021

Triple-A Security Ratings — Another Crisis Report in the Making

There was much fanfare that Moody’s put another “triple-A stamp of approval” on Security Ratings firm BitSight to the tune of $250 million. While this is a substantial, newsworthy investment, it isn’t “new” though. …

Cybersecurity

2 min read

Triple-A Security Ratings — Another Crisis Report in the Making
Triple-A Security Ratings — Another Crisis Report in the Making
Cybersecurity

2 min read


Aug 24, 2021

The Target: Healthcare, The Tool: Ransomware, The Impact: Your Lives. The Unsecured Truth

“Dozens of hospitals and clinics in West Virginia and Ohio are canceling surgeries and diverting ambulances following a ransomware attack that has knocked out staff access to IT systems across virtually all of their operations. Three hospitals started diverting emergency patients to Camden Clark Medical Center. The facility is an…

Ransomware

4 min read

The Target: Healthcare, The Tool: Ransomware, The Impact: Your Lives. The Unsecured Truth
The Target: Healthcare, The Tool: Ransomware, The Impact: Your Lives. The Unsecured Truth
Ransomware

4 min read


Jan 27, 2021

Response — Security Ratings: Love, Loathe or Live With Them

Prologue Shortly after seeing this story on Security Ratings published, attempts to reach Mr. Phil Venables were made to comment and offer assistance. Unfortunately, after a reasonable amount of time passed, it was determined that Mr. Venables did not wish to be reached for comment. I’m now releasing a response to…

Cybersecurity

5 min read

Response — Security Ratings: Love, Loathe or Live With Them
Response — Security Ratings: Love, Loathe or Live With Them
Cybersecurity

5 min read


Jul 10, 2019

The [Lacking] Contextual Evidence in Security Ratings Reporting

Let’s talk about contextual evidence, or rather the lack thereof, in the Security Ratings industry: For more than a year, I’ve witnessed the various Security Ratings vendors tell their customers and assessed organizations what they deem as “severe” findings in their reports, without any contextual evidence to support either investigation…

Cybersecurity

2 min read

The [Lacking] Contextual Evidence in Security Ratings Reporting
The [Lacking] Contextual Evidence in Security Ratings Reporting
Cybersecurity

2 min read


May 15, 2019

Reading is Fundamental [for Security Ratings]

Dear RiskRecon (and other Security Ratings vendors passively assessing organization’s patching posture), Failing to recognize, investigate, and implement the many well-documented ways that have been shared with you for how you identify backported security fixes in applications does not equate to a “false-positive” like you claim. …

Security

2 min read

Reading is Fundamental [for Security Ratings]
Reading is Fundamental [for Security Ratings]
Security

2 min read


Apr 23, 2019

Fair and Accurate Security Ratings: The Peculiar Case of Passive Patch Pronouncements

In a previous article, I spoke about receiving Security Rating reports with hundreds of pages findings. Many, if not all, Security Ratings reports contain findings and ratings of an assessed organization’s software patching cadence. We’ve all been reminded to ‘patch early and often’ and these Security Ratings reports are no…

Security

11 min read

Fair and Accurate Security Ratings: The Peculiar Case of Passive Patch Pronouncements
Fair and Accurate Security Ratings: The Peculiar Case of Passive Patch Pronouncements
Security

11 min read

freshman

freshman

264 Followers
Following
  • Anton Chuvakin

    Anton Chuvakin

  • Ryan McGeehan

    Ryan McGeehan

  • The Aerospace Corporation

    The Aerospace Corporation

  • Chad Warner

    Chad Warner

  • Tom Jarvis

    Tom Jarvis

See all (39)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams