• 29 Jul 2025

    Don’t let your security program fail like a bad relationship

    TL;DR - Just like a relationship, a security program needs honesty, maintenance, and timely conflict resolution...or it will collapse under neglect.  Success expert Brendon Burchard said that avoidance is the best short-term strategy to escape conflict, and the best long-term strategy to ensure suffering. I've seen it countless times over the years...companies that keep kicking security problems down the road. That is, until one day, those problems explode into things ...

    Continue Reading...
  • 14 Oct 2017

    When PR spam is actually amusing

    I get spammed by PR firms all the time - quite likely a dozen or more emails from them in my business inbox every day. I think I get on their radar because certain articles I write happen to be related to what these spammers are trying to promote. Well, I recently got this spam message via email from a PR firm regarding an upcoming security conference. Looks interesting. But ...

    Continue Reading...
  • 03 Apr 2017

    People will violate your policies all day long…if you let them.

    I recently saw this out in front of a local restaurant where management was trying to resolve parking, sidewalk access, and traffic issues. Their "control" obviously doesn't work:Be it parking cars or using computers, instant gratification is the name of the game. People want what they want. They want it right now. And, they will take the path of least resistance - and violate your policies in the process to ...

    Continue Reading...
  • 07 Apr 2015

    A core reason why security challenges go unresolved

    Constantly dealing with information security issues in your organization? It's really about dealing with management, peers, and subordinates. Here's some motivation:"The ability to deal with people is as purchasable a commodity as sugar of coffee, and I will pay more for that ability than for any other under the sun." -John D. Rockefeller If you're in search of other ideas on how to get (and keep) people on board with ...

    Continue Reading...
  • 13 Jan 2014

    How do you exercise your “power” in IT?

    My new favorite quote I came across recently is the following from Ayn Rand: "Economic power is exercised by means of a positive, by offering men a reward, an incentive, a payment, a value; political power is exercised by means of a negative, by the threat of punishment, injury, imprisonment, destruction. The businessman's tool is values; the bureaucrat's tool is fear."...interestingly, her quote applies directly to IT and security by ...

    Continue Reading...
  • 12 May 2011

    Amazon’s cloud outage, big deal…?

    Here's a great piece from my colleague Jonathan Feldman on why Amazon's recent outage is irrelevant. It reminds me of my what I've always preached: if it's got an IP address, a URL or human beings involved, it's fair game. Something's going to happen eventually.It's our job to help our businesses/clients to be able to respond appropriately and minimize the impact when something does occur. You've gotta have a fall ...

    Continue Reading...
  • 01 Jul 2009

    The definitive secret to success in your job and career

    It all comes down to this. I couldn't agree more."Eighty-five percent of the reason you get a job, keep that job, and move ahead in that job has to do with your people skills and people knowledge." - Cavett Robert...

    Continue Reading...
  • 01 Oct 2008

    Wonder how much Cisco spent on this study…

    Alert, Alert! Cisco has finally found the cause of information security problems! Apparently *employees* are the culprit. So...humans are the root cause of all this stuff we live and breath every day after all. Oh and apparently we need to focus more on awareness...You think??I believe this was a case of some Cisco employees needing to do some busy work to justify their existence in the company. Amazing use of ...

    Continue Reading...