Skip to content

The Glass Perimeter

The perimeter isn’t where it used to be.

You are here:HomeTag: ciso
Tagged As:

ciso

Categories: SecurityAuthor Dan GPosted on 2026-04-052026-04-052 Comments on The Unmonitored Layer

The Unmonitored Layer

Something’s Missing I’ve been at RSAC 2026 this week [edit: well, last week but work and travel got in the way of posting], and in the numerous sessions, talks, and … Continue reading “The Unmonitored Layer”

Categories: SecurityAuthor Dan GPosted on 2025-04-152025-04-15

The Cyber Ecosystem Shift

As federal cyber leadership pulls back, the balance is shifting across states, agencies, and industries. Here’s what that means—and why timing matters. Ecosystems are interconnected, interdependent systems. Think of a … Continue reading “The Cyber Ecosystem Shift”

Categories: Security TechnologyAuthor Dan GPosted on 2025-04-112025-04-11

FFFFFFFound in the archive

I was cleaning up my hard drive when I found an unpublished blog post I had written in 2008 during my stint at American Airlines as an information security architect. … Continue reading “FFFFFFFound in the archive”

Categories: SecurityAuthor Dan GPosted on 2022-12-152022-12-153 Comments on tl;dr – A Wonk’s Guide to Effective Vulnerability Management

tl;dr – A Wonk’s Guide to Effective Vulnerability Management

I published a rather lengthy blog post about the importance of patch management to the success of a security program. Due to the length of the post I thought I’d … Continue reading “tl;dr – A Wonk’s Guide to Effective Vulnerability Management”

Categories: SecurityAuthor Dan GPosted on 2022-12-142022-12-153 Comments on A Wonk’s Guide to Effective Vulnerability Management

A Wonk’s Guide to Effective Vulnerability Management

I’m going to cover something that arguably has the greatest impact on the security posture of an organization and is not something that information security is typically responsible for. It’s … Continue reading “A Wonk’s Guide to Effective Vulnerability Management”

Categories: SecurityAuthor Dan GPosted on 2022-12-082022-12-08

What CISO’s really mean when they say “threat”

When I hear a CISO speaking about threats on an information security podcasts I know most everyone probably thinks they are talking about nation-state or criminal actors. The truth is … Continue reading “What CISO’s really mean when they say “threat””

Categories: Security UncategorizedAuthor Dan GPosted on 2022-12-052022-12-051 Comment on RSAC CISO Boot Camp 2023

RSAC CISO Boot Camp 2023

I’m humbled to be brought back as a panel speaker at the CISO Boot Camp. I was involved in designing and ended up MC’ing the first two CISO Boot Camps (2019 and 2020).

Categories: ManagementAuthor Dan GPosted on 2022-12-032022-12-053 Comments on Eating the elephant

Eating the elephant

I’ve seen it time and time again. An executive wants a to fund a transformational project of specious value but requires multiple years of expensive funding. The executive will work … Continue reading “Eating the elephant”

Categories: Security Social TechnologyAuthor Dan GPosted on 2022-11-292022-11-30

Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea

This post is part experiment, part memorializing a short conversation I had with Sasha Romanosky (one of the creators of CVSS). I have more thoughts on the subject of the … Continue reading “Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea”

The Glass Perimeter Powered by Designed by FancyThemes.

Loading Comments...