ChatGPT is incredibly limited, but good enough at some things to create a misleading impression of greatness.
it's a mistake to be relying on it for anything important right now. it’s a preview of progress; we have lots of work to do on robustness and truthfulness.
This will hurt a lot of feelings so buckle up.
Cyber security is exactly as difficult as your org makes it.
If you have burdensome process, if your machines are overloaded with agents, if you have alert fatigue, etc.
You have a culture problem, not a tech problem.
1
Some great security programs come from the results of grand challenges but all have a relentless commitment to execution.
#1 - Plan for that relentless grind
https://t.co/3mMY9RrxAy
Ian Levy’s departure blog (from UK NCSC) is pure gold.
For me his point about details matter is spot on. Too many reports / calls to action gloss over details and nothing gets done or things stall because no-one worked through the needed detail.
https://t.co/PAMbmEuQ7q
@anton_chuvakin@jcfarris Perhaps: for smoother migration rides: provide sovereignty model like an onion. Outest is the enduser, accountable, responsible. Inner rings are managed/outsourced service/cloud providers. They could provide auditable options for any desired sovereignty ops model mix/fate.
@anton_chuvakin@JayHeiser1 Maybe: understanding the A to Z of that decision first. Potentially still unclear to many orgs. It is a form of outsourcing, the context in which it happens is specific for each organization. => having the retained budget, orga, skills to manage cloud (and on-prem in parallel)?
#OSCP Online, Part-Time #Pentest Training in German language. Wer Interesse hat schreibt mich gerne an für einen Voucher mit Preisnachlass #solangedervorratreicht ;) Wer hätte gedacht, dass wir das mal hingestellt bekommen ;) https://t.co/7C6s4Y90Rp
We are deeply saddened to hear of Jim “Pee Wee” Martin’s passing. He is a true legend in the 101st and will live on forever. This division was founded on the sacrifice, valor, audacity and sheer grit of Soldiers like Pee Wee Martin. Pee Wee will be greatly missed.
@philvenables Indeed. Also reminds me of active and passive safety engineering eg. in auto or aviation. A lot of these elements are now standard and unthinkable not to be in each model's spec sheet and outfit. Sometimes these approaches work independently, on different layers, in combination.
This 2009 (!) blog came up in a conversation today: https://t.co/kyUobS8XIa - to me, this is still one of the best illustrations of compliance != technical security; it is juicy, painful, hits hard and didn't age at all since 1912...