Rethinking what it means to win in security

Are you winning in cybersecurity?  Michael Santarcangelo at CSO Online challenges us to rethink what "winning" actually means.  

In the article, Michael argues:

  • Security is not a sprint
  • It's not a marathon either...
  • He urges us all to consider "reasonable security"
  • He warns us to be careful of "risk catnip"

Overall, Michael makes some great points, and we like the risk-based approach and agree with applying a sense of economics to cybersecurity (i.e. don't spend $100 to protect $1).  

It's a thought-provoking read and can be found here:
http://www.csoonline.com/article/3206128/leadership-management/rethinking-what-it-means-to-win-in-security.html

What Benefit is there in a Business Impact Analysis?

What Benefit is there in a Business Impact Analysis?

So what Benefit is there in a Business Impact Analysis?

Read More

SIEM challenges: Why your security team isn’t receiving valuable insights

I thought this was an interesting article as I've seen some banks struggle with the reporting mechanisms in their SIEM. Something to look at if you...

Read More
Are We Relying Too Much On User Awareness In Cybersecurity?

Are We Relying Too Much On User Awareness In Cybersecurity?

Steven Chabinsky, former Deputy Assistant Directory of Cyber for the FBI, says that we do rely too much on user awareness and we need to do a "180"...

Read More