Showing posts with label Continuous Improvement. Show all posts
Showing posts with label Continuous Improvement. Show all posts

Wednesday, December 18, 2019

Learning From Your Own Malware


The best threat intelligence comes from your own organization’s own endpoints.  One aspect to this is treating every instance of unwanted software such as malware or adware that lands and installs on a machine as an indicator of a gap in controls coverage. 



A control that is present but somehow misconfigured.
A control that is missing or has been disabled.
An error by a user. 

So, when you encounter evidence of malware, a key followup item is to determine just how the malware got there.

Sunday, December 15, 2019

Cyber Leaders And Story Telling


Good story telling is an under-valued skill for cyber security leaders. It’s a skill that helps executives gain a deeper understanding of an organization’s cyber program and gaps. This includes the current state of the program, and properly set expectations about the resources needed to keep, or change, the current state. 


All wrapped up in an easily digestible, non-technical story.

Wednesday, December 11, 2019

The Hard Part Of Automating Cyber Security


Your cyber security program isn’t going to scale without automation. 



There is automation within tools, but also automation that creates efficiencies across tools and processes.

Tuesday, December 10, 2019

Security Connective Tissue Behind Digital Transformation


Digital transformation is what the business see and their customers experience. 


It’s the face of the transformation.

Exposing business value via APIs.

But there is also magic happening behind the scenes.

Monday, December 9, 2019

Mentoring Around Measuring Cyber Progress


Peter Drucker is famous for saying that you can only manage what you can measure. Nice thought but, by itself, not much help in terms of practical advice to the cyber security leader.



So how do we mentor showing progress?

Sunday, December 8, 2019

Kicking The Can Down The Road


Sometimes you might not have enough resources to do all of the things that really are important. 



We can model three types of execution: 


Critical projects tied to a commitment which has resources and a champion.

Key projects with resources that are important but for which you, as the senior cyber leader, might be the only champion.

Other projects that are important but without sufficient resources. 

Saturday, December 7, 2019

The Engagement Problem of Cyber Security Ownership


This post is part 2. Part 1 is “The Conceptual Problem ofCyber Security Ownership.


So, you decided to distribute ownership of securing business processes outside of the cyber security team within the standads set by the security team. You have a conceptual model. Now, we need to examine the mechanics of implementing that model.




Communications isn’t enough to transfer ownership to business process owners. If communications alone was sufficient, almost every cyber security team would have distributed ownership of cyber security by now. 


Communications infers one way directives. 


Easy to ignore proclamations. 

Friday, December 6, 2019

Success: The Bigfoot of Cyber Security


Success can be elusive in cyber security. Elusive, in that there is often a chasm between the cyber leader’s definition of success and the expectations of the Board and/or executives. That chasm is too often explained away as “the executives don’t understand cyber security,” or, worse yet, “a cyber team can’t be successful.”



So, for some organizations, finding success is like finding Bigfoot from the light of a UFO. 

Tuesday, December 3, 2019

Cyber Leaders, Critical Thinking, and Team Colors


Purple teams confuse me.



To be more precise, small cyber teams thinking that they need some separate purple capability is what actually confuses me.

Monday, December 2, 2019

Mentoring Cyber Leaders To Say No (And Yes)


Being able to prioritize and being able to say no are two closely linked critical skills for cyber security leaders. The linkage is strong. Without being successful at one, it can be very difficult to be successful at the other.



Don’t get me wrong. The learned and practiced skill of being able to say no is really about the ability to say, “yes”.  

No to the wrong things, and yes to the right things. 

Sunday, December 1, 2019

Servant Leadership In Cyber Security


Servant leadership seems to be a growing buzzword in cyber security.




Robert K. Greenleaf coined the words "servant-leader" and "servant leadership" in 1970 with the publication of his classic essay, The Servant as Leader.

Saturday, November 30, 2019

The Luck Factor In Incident Response


When malware passes through the perimeter and internal network controls, it’s going to land on something. That something is most often some sort of endpoint whether a server or user machine. 




Malware that lands on an endpoint as a result of a broad blind attack, the attacker most likely won’t know what machine it’s on, what privileges it has, or where it can easily laterally move. For some destructive attacks, this isn’t important but for many attackers, establishing basic information is.

Friday, November 29, 2019

A Security Culture From Nothing


There are organizations that have no cyber security culture. Others that have a cyber security culture that consists entirely of an annual video for all employees.  If the successful practice of cyber security relies on the corresponding ownership of secure practices throughout the company, real security awareness involves cultural change. 



A cyber security team will never be large enough to accomplish the task themselves. 


So you, as a cyber security leader, are starting from nothing. You’ll need a plan to get your organization from where they are today to where you want them to be. 

Tuesday, November 26, 2019

The Rest Of Cyber Security


There is some truth to the movement that you don’t need to be technical to be in cyber security. Some truth in that there are a number of roles that are clearly less technical and more framework oriented than others. The roles in which questions like, “are the correct configuration boxes checked?”, "can this person pass as a employee through security checks?" or, “is this particular business process mature to the clearly understandable standard?” can be answered in non-technical ways.



And then, there is the rest of cyber security. You know, the non-prescriptive, often technical part. 

Monday, November 25, 2019

Mentoring Execution Improvements In Cyber Security


A key moment in the career of a cyber leader is when they realize the difference between simple activity and a planned set of work designed to mature the security program in a purposeful direction. 


Activity isn't a reliable metric for improvement within a security program. And, yet, activity seems to be a popular justification for more resources. We have to think like a business leader to understand why it might not be.

Thursday, November 21, 2019

Starting With Not-So-Shiny Cyber Threat Intelligence


Cyber security is interesting in that there is encouragement and peer pressure to start with the most shiny of shiny things. Cyber threat intelligence is no exception. 




When starting a cyber security threat intelligence program, most organizations have some fixed amount of resources and a lot of choices.

Tuesday, November 19, 2019

Transforming Cyber News Into A Value Add


Retweeting or forwarding news articles about a cyber breach seems somewhat mindless.  A company made the headlines for being breached...again. It might be mildly interesting if the breached party is a technology vendor or a management consulting company with a cyber practice.The frequency is overwhelming.


That said, is there really any value left in being the 10,000th person to retweet or forward the link about that latest breach?


Perhaps there is a different way to think about cyber news. 

Sunday, November 17, 2019

Some Cyber Security Value In Frustration


Frustration is a great trailing indicator for cyber leaders as it generally occurs when we keep trying to do something that isn’t working. Frustration isn’t the problem. It’s a symptom.



We clearly would not want to take actions that intentionally increase frustration for others. That’s not the intent of finding value in frustration.  The intent is that we want to be vigilant of early frustration so that the source of frustration, that underlying issue, can quickly be sussed out and remediated.  


Once recognized, frustration can become a tool for continuous improvement.