I was told posting consecutively for 200 days is not going to be easy and I almost backed out.
In a couple of weeks, we'd have spent 200 days this year already.
I didn't start back then but I am starting now!
This is Day 1/200 days of show up challenge with @gabbytech01.
1/2
and for the right reasons
It's where governance becomes action.
As organizations adopt cloud technologies and AI, identity becomes even more important.
Before asking, What can this AI do?
We should first ask:
What should this AI be allowed to access?
#IAM#CyberSecurity#GRC
Day 31 of #200daysofcybersecurity
The last few posts has majorly been about exploring Governance, Risk, and Compliance (GRC).
But policies alone don't secure an organization.
Someone or something has to enforce them.
That's where Identity & Access Management (IAM) comes in.
1/3
Day 30 of #200daysofcybersecurity!
Every security control is a compromise.
Strong passwords
Vendor assessments
They all ask us to give up a little convenience.
That's why security often feels like friction.
But remove those controls, and you're making a different compromise
1/3
Let's talk about why identity has become the new security perimeter. Every security policy eventually leads to a simple question which is:
Who should have access to what?
IAM helps to answer that question by ensuring the right people have the right access, at the right time
2/3
The two worst things you can say to yourself when you get an idea are:
โThatโs never been tried before, so I canโt do itโ
and
โThatโs been tried before, so I canโt do it either!
Most people network up. They chase the person two levels above them.
The real edge is networking sideways. The peer who is just as hungry, just as early, just as unproven as you.
In ten years, one of them will be in a position to change your life. And they will remember who showed up before anyone had to.
3/3
Good security isn't about eliminating inconvenience.
It's about making small, deliberate trade-offs today to avoid much bigger consequences tomorrow.
#cybersecurity#cybersecuritytips
Day 30 of #200daysofcybersecurity!
Every security control is a compromise.
Strong passwords
Vendor assessments
They all ask us to give up a little convenience.
That's why security often feels like friction.
But remove those controls, and you're making a different compromise
1/3
Day 29 of #200daysofcybersecurity.
A policy no one follows isn't control.
It's documentation.
The goal isn't to write policies that look impressive.
The goal is to create policies people can actually understand, follow, and apply.
1/2
The question isn't whether you'll pay a price.
The question is when you'll pay it.
A few extra seconds to log in today...
Or hours of incident response, financial loss, and damaged trust tomorrow.
2/3
Unpopular opinion: Glasses don't automatically increase your IQ. ๐ซ ๐ซ
For many people, they're just the difference between Who's that? and Oh, it's you.
The internet has a large memory, not just large but also long! One post you made 5 years ago is capable of changing people's perception of you.
Once you hit send, you may not have control of it anymore.
Cheers to posting responsibly ๐ฅ
#tuesday
2/2
Good governance isn't measured by the number of documents.
It's measured by the behaviors those documents produce.
#CyberSecurity#GRC#Compliance#InfoSec
Day 29 of #200daysofcybersecurity.
A policy no one follows isn't control.
It's documentation.
The goal isn't to write policies that look impressive.
The goal is to create policies people can actually understand, follow, and apply.
1/2
Day 28 of #200daysofcybersecurity
In cybersecurity, "nothing happened" and "nothing was detected" are not always the same thing.
I started having a different perspective after I learned about false negatives.
A false negative is when a malicious activity slips through,
1/3