A security use case for ChatGPT: Email Scam Robo Judge

I have been noodling around with ChatGPT recently and have found a nice little use case that I hope someone with more coding skills and ...
Secret Volcano Starburst TV Commercial

Hunting for secrets on GitHub

We need to work with system designers and developers to make them understand that using a secure credential vault with programmatic access is not an optional luxury - it is a basic ...

EmailRep – Squeezing actionable info from malicious email addresses

Yes, I know it has been quite a while since I have posted anything to the old blog, but I do have an excuse… in ...
Recognizing and dealing with insider risk

Recognizing and dealing with insider risk

I came across an interesting white paper from the deep mists of the past (2011) which is as relevant today as it was back when ...

Can experience be a hindrance in making security decisions?

| | CSO, deep thoughts, useful stuff
Some interesting insight from the Harvard Business Review’s January 2020 IdeaWatch section: A study looked at how people react to information which indicates that a ...
Juice Jacking – meh!

Juice Jacking – meh!

Lately, I have been seeing a number of posts and articles warning us all not to use publicly available USB charging points due to the ...

Security awareness materials you can use – “Why we fall for cons”

| | Awareness, useful stuff
One of my favorite parts of my job as a CSO is building security awareness amongst my colleagues. I really believe that the time put ...

Orvis data leak and the need to monitor ‘paste’ sites

Fishing retailer Orvis had a serious (and embarrassing) data breach recently. Independent security researchers found a posting on text snippet site Pastebin with what appeared ...

US DoJ guidance on responding to and reporting cyber incidents

When thinking about how to respond to cyber security incidents, you need to think about how your organization will engage with law enforcement – and ...
NIST & Microsoft partner for patching pointers

NIST & Microsoft partner for patching pointers

The US Government’s National Institute of Standards and Technology and 8,000,000 pound gorilla Microsoft are working together to provide industry with definitive guidance on keeping ...