I increasingly feel like the vast majority of CyberSecurity issues stem from poor governance and management of existing technologies. You can do a lot if you have the culture to tighten controls and enforce least privilege. #riskmanagement#CISSP#CyberSecurity
Remember the days when things were much easier for sysadmins? @techspence
dsquery user -inactive 7
Compare this to the madness of Graph PowerShell to do the same thing ๐คฆโโ๏ธ
@CisoDisabled I've seen one before. It worked like this, MSSP uses Azure Guest accounts for SSO so they control the password. Password is controlled by Delinea secrets server. The customer gets the Delinea logs. Customer can remove the guest account to revoke access at any time and has logs.
"For security reasons, we will be sending your username and password in separate emails"
This is absolute clown show security theater.
Know what? We (as an industry) get the security outcomes we deserve.
I just put in my two weeks' notice today. Goddamn it feels good. I don't think I'll ever return to the financial sector again. It's not all companies and people but there is a higher-than-average amount of people devoid of ethics or morals in the financial sector. #CyberSecurity
@arekfurt I just spent 18 months fighting an organization of 3000 people to put MFA on all SSO platforms. It was the hardest project I have ever worked on but it was worth it .
@bettersafetynet@UK_Daniel_Card The best change management process I've ever had was one where the ITSM tool had an API. I then had a bunch of .sh scripts that I could use to create said change for boilerplate conditions I'd pass into the script.