Imagine having benchmarks, community-proven trends, and documented best practices to enhance your #ThreatModeling efforts. ๐
The first community-led State of Threat Modeling (#SOTM) Survey is hereโadd your insights ๐ https://t.co/6zK2kbJQNR
@halvarflake@dinodaizovi@tecnik but often we should be calculating "time series probabilities" (ie calculate it over dependent events eg 1 company reports cost of 1000 incidents). Sometimes the result is the same (ergodic system), often it is not.
@halvarflake@dinodaizovi@tecnik What I took away from his work (which is just a tiny part of it), is that most probabilities are "ensemble probabilities" (ie calculate it over independent events eg a 1000 companies report cost of 1 incident),
@halvarflake@dinodaizovi@tecnik Nassim Taleb's books cover low probability, high impact events (black swans), including some strategies for dealing with them.
See also Ole Peters work on ergodicity that explains how we calculate probabilities is often fundamentally flawed.
threatware is a threat modelling tool I have been working on. If you want to threat model in a document, and you need to scale and manage threat models, it's worth a look.
#threatmodelling#threatmodeling#threatmodel#threatmodels
https://t.co/JRdEKhxxed
@PureGym reducing your opening hours (8am open) so people can't go to the gym before work any more (hence at all often) only serves to make self-isolation harder and condense people in the gym. Please reconsider
Okay, so know how people are like โlol just patch it u dumbassโ
I work at a Big Place now.
I had no freaking idea.
Thereโs literally someone whose job is just scanning machines to patch.
Thereโs an entire department that just schedules changes.
And downtime is $10,000 a minute
Here's the truth about Brexit, the "punishment" some people claim the EU wants to inflict on us, the full horrific consequences of no deal, and the dangers lurking behind any deal we reach. Buckle in, it's pretty long. Better to be thorough than to leave anything out. 1/47
@cigitalgem @SeniorWata @4Dgifts Stop thinking like a security researcher (everything is important) and think like development/operations faced with 10s thousands of issues. What to address? Only those than can be reached, provide attacker value, and have significant impact. Nothing else.
@BrkSchoenfield@jeremiahg@randomuserid my blog article on Game Theory and security https://t.co/bvUPzQPkv0 speaks to considering the attacker more. But no easy answers sorry.
We (security defenders) would all be doing well to emulate this kind of clarity about what we are trying to defend and how we are trying to do it. Well done to your team @dk_effect