Publications and Speaking
Articles and Publications
Rethinking Cyber Talent: Take a New Approach to Recruiting
Date: Feb 23, 2023
Article Summary:
The demand for cybersecurity professionals is on the rise, with nearly 500,000 unfilled cybersecurity job openings in the US alone. As organizations face complex cyber threats and evolving risks, finding, and retaining skilled talent has become a critical challenge. Conventional recruitment channels often fall short, prompting a need for innovative approaches. A strategic consulting company, AHEAD, shares its success in building a talent pipeline through non-traditional methods, such as leveraging platforms like Reddit to identify passionate self-learners. This highlights the importance of cybersecurity training and education, the value of attitude and aptitude over formal degrees, and the benefits of automating routine tasks through code-savvy professionals. As the cybersecurity landscape evolves, businesses should consider such unconventional strategies to address talent shortages effectively.
D&O insurance not yet a priority despite criminal trial of Uber’s former CISO
Date: Sept 22, 2022
Article Summary:
The criminal trial of former Uber CISO Joe Sullivan, charged with obstructing justice and failure to report a crime related to a data breach, has drawn attention to the legal uncertainties faced by cybersecurity chiefs. Despite the trial, experts note that there is currently no significant demand for directors-and-officers (D&O) insurance among CISOs. The rising threat of ransomware attacks and potential gray areas in dealing with cybersecurity incidents have raised concerns about personal liability. However, CISOs are primarily focused on general cyber liability insurance. Additionally, the organizational structure of CISO roles and the high cost of D&O insurance contribute to the limited demand. Protective governance policies that clearly assign responsibility for risk decisions may provide a better safeguard for CISOs. As cybersecurity regulations evolve, executives who fail to follow emerging guidance could face increased liability. Overall, CISOs should remain vigilant and ensure they are adequately protected within their organization's governance framework.
Note: I have since changed my views on this topic...
Biden Administration Tries New Tack in Battle Against Ransomware Attacks: Bounties Offered on Identification of Major Players
Date: July 21, 2021
Article Summary:
The Biden administration is introducing a range of measures to address the increasing threat of ransomware attacks. The package includes offering rewards of up to $10 million for information leading to the identification of foreign actors involved in malicious cyber activity against critical U.S. infrastructure. However, the information must be linked to "state-sanctioned" actors, potentially limiting the scope of eligibility. The administration has also established a task force to coordinate federal agency efforts, launched a new website (stopransomware.gov) to provide public resources and consolidate information on securing networks, and directed the Treasury Department to collaborate with banks and tech industry companies to prevent money laundering through cryptocurrency. Public-private collaboration is emphasized, with businesses urged to review their ransomware security practices. While the measures are seen as a step in the right direction, experts highlight the need for broader private sector engagement, addressing cybersecurity talent shortages, and overcoming legal hurdles in pursuing identified criminals residing in foreign countries. The effectiveness of the rewards program in countering the ransomware threat remains uncertain.
Post-SolarWinds, IT departments increase vendor scrutiny
Date: March 12, 2021
Article Summary:
The fallout from the SolarWinds hack continues to shape the way organizations approach third-party services and vendor relationships. The incident revealed vulnerabilities in the procurement process and the level of access granted to third-party vendors. As a result, there will likely be new legislation or guidance from the federal government on third-party risk management. Rebuilding trust and implementing security measures go beyond meeting new guidelines. While big and well-known companies are often trusted due to their reputation, the SolarWinds and Microsoft Exchange vulnerabilities have highlighted the fallibility of all organizations to threats. IT departments now have the responsibility to integrate security into procurement processes, asking vendors about access to source code repositories, monitoring practices, anomaly detection, and two-factor authentication for developers. Additionally, the hack emphasized the importance of network visibility and understanding the ecosystem to prevent future supply chain attacks. Compliance alone does not guarantee security, necessitating a deeper understanding of vendor access within the network.
https://www.ciodive.com/news/solarwinds-third-party-trust-IT/596661/
5 Ways Enterprises Inadvertently Compromise Their Network Security
Date: March 26, 2020
Article Summary:
Enterprises often compromise their network security unintentionally, neglecting fundamental actions that could safeguard their infrastructure. Here are key areas where organizations tend to compromise network security and corresponding solutions:
Relying solely on a single solution: Merely identifying vulnerabilities and acquiring hardware or software is insufficient. Continuous testing and assurance are crucial to ensure the solution remains uncompromised.
Overreliance on VPNs: Virtual private networks (VPNs) are considered secure, but they have vulnerabilities and can complicate network administration. Organizations should consider adopting Software-Defined Perimeter (SDP) technology as a more secure and efficient alternative.
Inadequate IoT and OT protection: Insufficient network security monitoring for Internet of Things (IoT) and Operational Technology (OT) devices leads to potential vulnerabilities. Implementing agentless monitoring, auto-discovery, and behavioral anomaly detection are vital for protecting these devices.
Poorly-architected or outdated network design: Organizations often fail to properly segment their networks based on security needs, leading to risks across all data. Implementing security zones and proper segmentation based on sensitivity levels can mitigate these risks.
Failing to stay ahead of emerging threats: Knowledge and planning are crucial for enterprises to stay a step ahead of network attackers. Identifying likely threats, staying current with threat protection measures, and keeping software up to date with patches and updates are essential practices.
By addressing these oversights and implementing appropriate measures, organizations can enhance their network security and mitigate potential risks.
Automated security services essential for cloud security
Date: July 23, 2019
Article Summary:
Securing cloud environments requires a different mindset and approach compared to securing on-premises infrastructure. As organizations increasingly migrate to the cloud, automated cloud security services are essential to mitigate risks. However, automated security does not mean easy or unchallenging. Even after applications are moved to the cloud, security operations must continue.
Cloud environments offer financial and operational benefits, but security within the infrastructure and additional layers of security for hosted assets are crucial. Scalability in cloud platforms can make security measures difficult to implement and manage. That's why automated security tools and functions are necessary. While the cloud offloads certain security responsibilities, organizations must still maintain a strong security program and validate controls. They should not become complacent about their own security management, even when servers are no longer under their control.
Automated cloud security brings its own challenges. It requires testing for weak credentials, lack of two-factor authentication, insecure APIs, vulnerabilities in operating system images, malicious insiders, unintended information disclosures, and denial of service attacks. Consistency is crucial in the security posture of cloud environments. It is important to establish a standard process for utilizing cloud resources securely. Automation can help standardize secure configurations and remove inconsistencies caused by human error.
Proper planning is essential when implementing automated cloud security services. Starting without a clear plan and strategy can create security vulnerabilities. Risk assessments are necessary to understand specific use cases and threats. Automated security should not be seen as a panacea but as a means to enhance existing cybersecurity and data privacy programs. Enterprises must actively manage, monitor, and update automated security systems to adapt to evolving threats.
Leveraging APIs and sticking to security basics, such as patching and access control, are important for effective cloud security. It is also crucial to have proper documentation from service providers and ensure compatibility with open standards.
In summary, securing the cloud requires a comprehensive approach that includes automated security services, adherence to security basics, proper planning, and ongoing monitoring and updates. It is a shared responsibility between organizations and cloud service providers.
https://www.scmagazine.com/news/content/cloudy-with-a-chance-of-automation
Speaking Events
Secure World 2025
[Opening Keynote] Securing the Motor City and Beyond: Lessons in Leadership from Top CISOs

Secure World 2023:
Navigating the Security Challenges of AI

Secure World 2022:
Talent Development in a 'Drought' of Cybersecurity Talent



