The Security Pigeon
The Security Pigeon I spent the early part of my career getting paid to break into things. Energy infrastructure, manufacturing plants, financial systems. If it had a network and someone was worried about it, I was probably poking at it. It was, without question, the best education I could have gotten. You see the best…
Rubber Ducky, You’re the One!
Many years ago, when I was a wee baby programmer, someone taught me about “rubber duck programming”. When you can’t find the source of an error, explain your code line by line to a rubber duck. Somewhere along the way, you read out a line and realize immediately that’s where your error is. The duck…
Artificial Intelligence, Natural Consequences
At this point, arguing about whether AI belongs in software development is a little like arguing about whether the internet belongs in software development. The discussion is over. The tooling is already here. Developers are using it. Product teams are integrating it. Security teams are experimenting with it. And adversaries are absolutely operationalizing it. The…
Out of Sight, Out of Mind – Mastering the Art of Remote Leadership
I will preface this by saying that I have been primarily remote since about 2013. While I did a fair bit of work visiting customers in their offices for a number of those years, I have not lived in the same state (or even the same time zone) as my direct manager since then. I…
Inspiration Series: Eric Reiners
This one is very special to me, because in all this series, Eric is the first person I’m featuring who has been my direct leader. Eric is the person who taught me through his actions the difference between a manager and a leader. He is also the person who taught me the importance of work-life…
No Dislocated Knees!
I was recently re-reading my old posts, just to see how they’ve held up with evolution within the industry as well as within my own thinking. When I came across When You Point a Finger, Three Point Back, I immediately sent this to my team, realising that it reaffirms a lot of the guidance I’ve…
Inspiration Series – Coach Gregg Popovich
This has been sitting in my drafts for longer than I care to admit, and today’s passing of the torch seemed like the right time to get these thoughts out there. With so much of my family based in San Antonio, it’s no surprise the part that Coach Pop has played in forming who I…
Inspiration Series – Dan Kaminsky
I said I’d write a few of these posts and, having referenced Dan in my last post, I realised he should be next. This is a hard one to write, as I still haven’t quite processed his death, and I wish like hell he were still around to hear this. I don’t think I could…
Guppy in the Sea
Reflecting on Chef Kristi’s incredible success yesterday really made me think about my own trajectory and my tendency to mentally downplay the significance of my own accomplishments. While I can’t say I’ve had my face on the giant screens at the sportsball stadium (seriously, how cool was that?!), I realise I have made some huge…
Inspiration Series – Chef Kristi Brown
[Foreword: I shared this on my personal social media in light of an event I was attending yesterday, but it sparked a serious fire of reflection on my current growth and those who got me here. I’ve decided to share it here so that I can also share the continuing thoughts that I shared today,…
You have no thumbs!
Many years ago, I received a seemingly random text from a friend. He said he was sitting in a meeting and it suddenly dawned on him, “You have no thumbs!” The response from the table was, “So? We’ve never had thumbs before!” Obviously, everyone at the table had actual thumbs, but he was referring to…
Hold the door! Hodor!
We seem to have a lot of great work going on to increase diversity in our talent pool, through mentorship and outreach, for STEM generally and specifically in infosec. We’ve even started to recognise the need for sponsorship in tandem with mentorship, helping open doors for the talent we’ve identified and getting them through their…
Leading Without Authority
This is a simple infographic that boils down a very complex thought pattern. When I spent several months working closely with a colleague from our Customer Support team last year, he mentioned using “we” instead of “I” when working with a customer – a tactic he leveraged to make the customer feel as if we’re working proactively WITH…
YOU HAVE BEARS!
Vulnerability management is still a tough thing to rally support for and everyone loves a good story, so today I figured I’ll just combine both! Once upon a time, a company took all of their employees camping. These employees saw all of the signs posted about the campground warning that there might be bears. They understood…
When You Point a Finger, Three Point Back At You
Sometimes, you reach a point where when you look back, you shake your head and wonder how it ever was that you got there. That’s a bit how I feel about the security industry. It took off like a bat out of hell, full of a bunch of misfit kids trying to do good and…
Putting the “Management” Back Into “Vulnerability Management”
One of the most frustrating parts of external penetration testing was coming back the next year and finding the same vulnerabilities. When you look at the remediation plan you gave them, it looks like it took nine months just to figure out who was responsible for each of the problems. The other three months seem…
Project Management for Geeks
One of the interesting things about the infosec community is how lopsided the skill sets tend to be. Most of the seriously brilliant creative people I know are from this community. Try to get any of these folks to add some soft business skills to their repertoire, though, and they shriek and run like vampires…
Who’s Job Is It, Anyway?
In security, we’re not only expected to be Jacks of all Trades, we need to maintain a high level of mastery in each area, as well. We must be able to design secure networks, provide system and database level hardening for all platforms, expertly guide developers in writing secure code, oversee incident response and disaster…
Understanding your Organization
One of the interview skills that is most often preached yet least often followed is this – Research the company before you walk in the door. Without understanding the organization, its products, and its values, it’s very difficult to explain why you would be the best person for a job within it. It is important…
The Compliance Sword
Regulatory Compliance – Two simple words that make security practitioners around the world shudder in fear and disdain. Compliance is traditionally the realm of box-checking auditors who seek to undermine the foundation of security, by turning complex architecture decisions into nothing more than a checklist.All too often, we see it as a hurdle that must…
Sexism in Hacker Culture (Or: The Day I Discovered I was a Man)
DISCLAIMER: This was written a very long time ago. My feelings have changed, but I think it’s important we don’t just scrub away the things where we might have been coming from a different place in our journey, to acknowledge where we came from. I will say that I have come to understand the importance…
Telling your career story
Interviews are scary. You’ve managed to get past the screening software and onto the hiring manager’s short list. You have a legitimate shot at the job you’re hoping for. Your fate lays in how well you can express yourself in a few short minutes. The secret to good interviews is having your story when you…