Personal Access Tokens Have No Place In Modern Development Pipelines
Personal access tokens are long-lived, broadly scoped and invisible to identity controls, and recent breaches trace back to them.
Long-form writing on cyber security leadership, technology risk, identity, cloud and AI, mostly for executives and people moving into security.
Personal access tokens are long-lived, broadly scoped and invisible to identity controls, and recent breaches trace back to them.
Cyber risk as a series of trade-off decisions rather than technical fixes, from incident response to patching.
A quick take on what Claude Mythos means for organisations, and what cyber security teams will have to do to respond.
Sanctions, espionage, trade disputes and digital sovereignty have made geopolitics a technology risk for the CISO's agenda.
Why software bills of materials (SBOMs) are becoming essential for supply-chain risk, incident response and compliance.
AI agents are entering business workflows fast, but most enterprises have not extended identity and access controls to them.
Why organisations should prepare now for quantum computers able to break today's encryption, and how to plan the transition.
Why cyber risk monitoring underpins resilience, and how frameworks, real-time insight, AI and skilled people make it work.
The technology risk management process from identification to monitoring, the role of controls, and quantitative risk models.
The building blocks of data security: classification, logging, encryption, hardening, configuration, policies and awareness.
Common network threats, from malware and ransomware to insiders, and the practices that network professionals use against them.
Network types, devices, IP addressing, ports, and the OSI and TCP/IP models, with an introduction to cloud service models.
Access management principles and controls: least privilege, segregation of duties, MFA, privileged access and provisioning.
Incident response, business continuity and disaster recovery: plans, impact analysis, recovery strategies and crisis management.
The essentials of protecting information, from the CIA triad to risk management and privacy, explained in plain terms.
A six-part guide to the ISC2 Certified in Cybersecurity (CC), the entry-level certification for people starting out in security.
Practical guidance for vendor managers on reducing supply-chain cyber risk, from selecting secure vendors to robust contracts.
If you have been using ChatGPT, you probably feel now that nothing will never be the same. It is the same feeling you had when you used the internet for the first time, when you touched your first iPhone. There will be a before…
As Cyber Awareness Month is coming to an end and Halloween is almost upon us, I thought it would be a great time to share a few real cyber-horror stories, and how to protect yourself from them.
Confidentiality, integrity and availability, the three ideas at the heart of information security, explained for non-specialists.
What vulnerability management is, and why fixing vulnerabilities takes security teams so much effort, explained for non-specialists.
"Defence in depth", sometime also called “layering” is a central concept in information security. It relates to the idea that security components should be designed so they provide redundancy in the event one of them was to fail…
How digital identity and authentication work, and how they are used to give access to websites, services and applications.
With Christmas coming fast, it is a great time to remember identity crime is a critical threat to the everyone. A short beginner guide on how to protect yourself against identity theft and what to do if your identity get stollen.
Following my presentation on Building an Information Security Policy Framework at the "Implementing CPS 234" conference held in Sydney in May 2019, I received many requests to publish a transcript. Thank you all for your interest…
Corporate reality is that there is a growing interest from employees to use their personal devices for work. This can have a very positive impact on business – choosing which device is best for them and when, empowers workers and…
More than ever, financial institutions in Australia and New Zealand are moving toward public cloud computing as a way to benefit from easy to use, flexible, cost effective and reliable infrastructures and services. Despite its…
The Australian Prudential Regulation Authority (APRA) just published the final version of the Prudential Standard CPS 234 (Information Security), that will be enforceable by 1 July 2019. Have you assessed your readiness? This…
You are regularly being reminded by your security team that sharing sensitive information by email is not safe. But why? Well, good question. Here are some answers
As an executive or senior manager, what should I know and what should my company be doing about Meltdown and Spectre? If you are not an IT Security specialist and you have been trying to understand what all the fuss is about…
Java runs on computers, phones and TVs, and it is the reason Action(s) runs on Windows, Linux and Mac OS X alike.
New articles are also available by RSS.