Security Advisor at @WombatSecurity. Former Fortune 500 CISO. Founding member of Microsoft Security Council. Board Chair of CMU’s CISO Executive Program.
#WednesdayWisdom: Don't make assumptions about vulnerabilities and targets, put #ThreatIntel to work for you. Learn how your org is being attacked and who is being targeted ... and use that to inform your #SecurityAwarenessTraining activities. https://t.co/hVJCgQeyAu
I’m looking forward to joining a few of my contemporaries tomorrow to discuss best practices for #SupplyChain#RiskManagement. If you’ll be attending the @CERT_Division #Cyber Law and Privacy Symposium in #Pittsburgh, please be sure to say hello. https://t.co/AGljQ7r3CV
#TuesdayThoughts: I have written and spoken about #GDPR quite a bit. This @WSJ story is one I will follow with interest ... and if your organization handles the #data of #EU residents, I suggest you do the same. #cybersecurity#DataPrivacy https://t.co/DVSgizukpk
Some interesting findings presented in this @TechRepublic article. I was personally surprised to see that #SMB execs view #SocialMedia and apps to be the biggest source of #cyber risk, as opposed to #phishing emails. https://t.co/4uRU4id6e2
I've posted about this before, but it's worth repeating: Prioritizing time-to-market over solid #cybersecurity is a mindset that we, the good guys, need to change if we ever hope to get ahead of the #security curve. https://t.co/kQfzLIoWwH
As a #CISO, I (unfortunately) experienced the impact of a #NationState attack, so I can understand why #cyber insurance coverage would have seemed like a light at the end of the tunnel for these orgs. Curious to see how this plays out. https://t.co/m4KbnA5IRq
I am shocked ... and, frankly, disappointed ... by findings that most orgs don't have a #CSIRP in place. Many things about #cybersecurity aren't fully in our control, but we MUST be better about the things we can control. More from @ITProPortal. https://t.co/XuveL1Kqkm
I generally read the @WombatSecurity#StateOfThePhish Report multiple times ... it's a great resource for real-world #phishing impacts and actionable advice. In my opinion, it's only gotten better over the years. https://t.co/KlyoWBkBlS
Good to see that coordinated efforts between the #IRS, #TaxProfessionals, state #tax agencies and others have led to fewer incidents of #IdentityTheft for US taxpayers. More from @AccountingToday. https://t.co/R2MXZS2z9R
Thank you to those who planned and hosted the #CyberRiskSummit in #Toronto last week. I enjoyed connecting with other #infosec pros and sharing my own #CISOWisdom. If you have an opportunity to attend a @NetDiligence#cyber conference, take advantage! https://t.co/TyF68gs6G4
I'm at the @NetDiligence#CyberRiskSummit in #Toronto today, and I'm looking forward to sharing some #CISOWisdom with my fellow panelists during the #CISO Round Up session at 4:15pm. Hope to see you there! https://t.co/gaRZgjpCPg
If you will be at the @NetDiligence#CyberRiskSummit in #Toronto tomorrow, I hope you will stop by the #CISO Round Up session at 4:15pm. I'd love to meet you in person. https://t.co/jszZGg01os
I have been involved with the @HeinzCollege#CISO program at @CarnegieMellon since its inception, and it is an excellent option for any #infosec-minded person interested in this career path. https://t.co/Ot14dldhL5