What a Security Leader Actually Does
TL;DR I was never a CISO by title. My networking partner and I were both directors, and since our boss was not security savvy, the two of us functioned as
Cybersecurity articles from someone who ran security for a national retailer for two decades and passed every audit. Real talk on what protects a business and what just looks like protection, from the infrastructure side where the actual work happens.
TL;DR I was never a CISO by title. My networking partner and I were both directors, and since our boss was not security savvy, the two of us functioned as
TL;DR Most security tools are theater. I sat through endless vendor pitches for products with huge dashboards full of blinking widgets that looked impressive and did almost nothing. Security is
TL;DR The human layer is the biggest security weakness, and the one people are least ready for, because they do not expect other people to be malicious. They do not
Passing an audit and being secure are not the same thing. Here’s how to document security policies that reflect how your organization actually operates.
Passwords, backups, network security, phishing defense, and threat protection. A guide from a former Director of Computer Operations who managed cybersecurity.
An outdated version of a regulatory standard is one of the most common compliance mistakes. Here’s how to find, organize, and interpret what applies to you.
TL;DR Security is mostly boring work nobody wants to do. Patching, access reviews, and backups. I ran enterprise security for two decades, and the one time everything went wrong, it
TL;DR Attackers do not usually come through your firewall. If they do, you were sloppy, because firewalls and pen testing are the easy part. The real ways in are social
TL;DR I wrote the security policies and procedures for a company against NIST CSF and NIST 800-53, and these days I ghostwrite books for the security leaders who live this
TL;DR I led cybersecurity at a major national retailer for twenty years. Once PCI DSS applied, we passed every audit we faced. Now I ghostwrite books for the security leaders
If this sparked something, let's talk about turning your expertise into a finished book.