GRC, Pen Testing, SecOPS, Threat Intel Stuff, Audit/Assessment, Incident Response & Digital Forensics - Tweets are mine (or are they? Did you read the EULA?)
@zenrandom So please approve the rule for ANY ANY,
Let the traffic flow with glee!
For if we had a rule for ANY ANY,
Our firewalls would sing in harmony!
@zenrandom Oh, I’d love you to grant a rule for ANY ANY,
That is what I’d truly like to see!
Cause if we had a rule for ANY ANY,
Our network could roam wild and free!
So, what did we learn today?
1) who tests before applying patches,
2) who has separate test and prod networks,
3) who has current biz continuity plans,
4) who has tested DR capabilities.
As it turns out, not as many as you would expect and hope.
From airlines to hospitals
Client: Our operations and applications are HIPAA compliant.
Me: Cool, can we chat with your privacy and compliance officers?
Client: we don't have those, we are all responsible!
If you're having nvidia-docker-container issues after an update, nuke /etc/nvidia-container-runtime/config.toml and restart everything. I can't tell you how many hours I chased my ass on that.
Be aware of your legal obligations when it comes to ethical AI. These are evolving fast and may impact the systems you are building.
Great talk with many case studies from Rachael Greaves of Castlepoint Systems @qconlondon
#infosec#ProTip if you haven't lived through technical debt, it's not fun. It will slow down development, modernization and transformation projects to a standstill; burning out folks as they work to address issues from a decade ago rather than the current goal.