I finally made it over to Ireland! It’s quite embarrassing having lived all my life in London that I never did get the chance to hop sooner. But we are where we are, and what better reason to go over than to attend IRISSCON. At the airport, I was about to board my flight I […]
One of my favourite bloggers Troy Hunt posed a question on Twitter yesterday asking whether a user should share responsibility for a weak password that they reuse across multiple services. There was a lot of great discussion and debate, and I found myself opposing Troy’s views. It was getting late in the night and despite […]
Red Hat was recently acquired by IBM for and eye-watering $34 Billion, and while it’s the largest deal of its nature, it did get me curious as to how frequent it is for open-source companies to get involved in a bit of M&A. To keep it simple outside of my usual IT Security wheelhouse, let’s […]
October is National Cyber Security Awareness Month (NCSAM), but why restrict it to a month, when we need it all year round. So, I created a few very short videos on a few security awareness topics. The idea was to keep them short enough so people would watch them to the end, have a bit […]
via IFTTT Another busy and enjoyable day at the AT&T business summit in Dallas. Today was spent mainly in sessions, and I ended up spending an hour in an ‘ask the expert’ session as well as getting interviewed by Shira Rubinoff. Yay, go me! Tomorrow is the last day, and I have a very important […]
via IFTTT I’m in Dallas, and there’s not Ewing in sight. Luckily, what is here, is a great business summit. Here are some of the highlights from day 1 where I spent most of the time drooling over the booths.
I got the dates wrong in the video, should have said 21st Aug to 5th Sept. But, this is me looking at the whole incident as a customer, not as a security professional. I received the email notification from British Airways informing me of the breach and the fact that customers payment and personal information […]
Around 2006 / 2007 I began blogging and tried to get into video blogging. Although I’d been working in information security for 7 years up to that point, I wasn’t well-connected in terms of what conferences ran, who the influencers were, or who the editors of any of the numerous security magazines or websites were. […]
Social channels are an oft-overlooked area when it comes to information security. Social channels are left in the hands of marketing departments for customer engagement purposes. However, the adoption of social digital tools for the purposes of conducting business is widespread and largely unregulated, creating a major area of risk for organisations. If we look […]
Overall, technologies can be pretty straightforward to secure. Teach software not to execute a certain command, block a port, or alert on a set of conditions, and it will abide. Humans, on the other hand are not as easy to harden against attacks. These attacks are frequently delivered through emails, text messages, social media, or […]
This video was prompted by discussions with someone that was adamant that they would never, never, everrrrr put their logs in the cloud. I enquired as to why they weren’t open to the option, and their response was that they don’t believe that sensitive information like logs should be in the cloud. Now that’s all […]
It’s coming up on my 3 year anniversary at AlienVault – and after a conversation with a friend, it dawned on me that I don’t think I’ve ever really explained what AlienVault does. So, when I was in Austin this last week I recruited some of my colleagues to help make this short video to […]
A lot of individuals and companies of all sizes often use the phrase where they ‘think’ they’ve been hacked or breached, or had some form of unwanted event. There is usually a lack of conviction in this statement, and in hindsight it’s not easy to validate. Sure, one could use a service like haveibeenpwned.com to […]
Anytime we discuss security, it’s mainly to talk about the failures. So I’m taking time out today to spread some positivity to all those security folks that have made it through the week without an incident occurring.
via IFTTT After its 2015 breach, the Information Commissions Office (ICO) has released a very thorough report which highlights a number of deficiencies in Carphone Warehouse’s security. I’ve summed up some of the key points in dramatic fashion The report well worth a read: http://ift.tt/2AM6B7B