Good to see the @WSJ with a sensible and approachable article about Zero Trust.
https://t.co/HrbmE4cuwk via @WSJ
For more on Zero Trust, and a link to my book, see https://t.co/r8KVL9Ss1C
@RayGilray@FedInsider@pingidentity This is a terrible idea, and is counter to security and Zero Trust principles. There is no reason whatsoever to make a private application accessible to threat actors. It needs to remain private - e.g. *only* accessible to authenticated and authorized users.
Announcing Arlette Hart as Vice President, #Threat Advisory Services to lead the team in helping organizations discover defensive weaknesses through advanced #pentesting, adversary simulation and specialized consulting services. Read the news: https://t.co/mB9F1etndz
That is, start with a few focused security initiatives, and see them through to at least a moderate level of maturity. A Zero Trust approach definitely works, when done thoughtfully and when taken beyond the early stage. /19 (end)
Some conclusions: Data breaches continue to grow in impact, but well-deployed security solutions help. The data indicates that deployment maturity matters – it seems better to do fewer things well vs. many things poorly. /18
The annual @IBMSecurity Cost of a Data Breach report is out – thanks to the stellar team there for this great work (with credit to @PonemonResearch for conducting the actual survey). My comments and analysis on the report from a security (and Zero Trust) perspective – a thread /1
Breach costs are larger when organizations have compliance failures (opinion: this is an indicator of a less-than-effective security team), are performing a Cloud migration, or are facing security system complexity (opinion: aren’t we all?) /17