I’ve seen it time and time again. An executive wants a to fund a transformational project of specious value but requires multiple years of expensive funding. The executive will work … Continue reading “Eating the elephant”
security
SGA (Some Good Advice)
I submitted a short blurb to an effort to gather advice from CISO’s. I believe many CISO’s (especially new ones) will focus primarily on advanced security controls and miss the … Continue reading “SGA (Some Good Advice)”
Security tool costs
I really miss the days when I paid maintenance for software. The new ARC paradigm really sucks for the consumer. The only positive piece is that the financial implications of … Continue reading “Security tool costs”
Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea
This post is part experiment, part memorializing a short conversation I had with Sasha Romanosky (one of the creators of CVSS). I have more thoughts on the subject of the … Continue reading “Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea”
Getting into the time machine
I’ve been trying to clean up my document repositories and found a talk I gave at RSAC back in 2016 that brought back some thoughts I’ve been having recently about … Continue reading “Getting into the time machine”