Three DevSecOps Lessons Drawn from Conversations with 45 CISOs

Recently, I moderated round table discussions between dozens of CISOs at Evanta CISO Summits in Chicago and Atlanta. My colleague, Michelle Dufty, moderated a similar event in San Francisco ... Read More

Sonatype Nexus is Rising Above the Swamp

In case you missed it -- our rival JFrog published this blog post on Thursday. Amidst the hyperbole, JFrog made a few statements that are true, and numerous that are rooted in fear mongering, falsehoods and gimmicky marketing tactics. Please, allow me to explain ... Read More
severity, Tenable, application security, vulnerabilities, software, vulnerabilities, issues, servers, vulnerability, Linux, vulnerability management, risk-based, vulnerabilities third-party supply chain Okta endpoint security

In the Dark About Supply Chain Vulnerabilities

The software supply chain can create a seemingly endless attack surface. Here’s what you can do to better protect it. Is the “Barium” hacking collective Chinese? Russian? North Korean? It really doesn’t matter. What we know for sure is that their tactics are new, pervasive and exceptionally dangerous. Barium’s tactics ... Read More
Security Boulevard