• 09 Feb 2011

    Is it possible to do more with less?

    In this era of limited budgets and "wait and see" leadership you still have to do something to manage IT and information security. I've always had trouble understanding why people can't focus on the basics and solve these problems using solutions already at their disposal. I guess the marketing machine is just doing its job.Here's a good article about this very thing written by my colleague and publisher Steve Lasky ...

    Continue Reading...
  • 08 Feb 2011

    Principles are not values

    When I started my information security consulting business 10 years ago I believed the words "principle" and "logic" would be a good fit for the way I think and work. The concept and mode of operation has worked out great. I was just reading a quote by Stephen Covey that reminded me of this - and information security leadership in general...he said:"Principles are not values. A gang of thieves can ...

    Continue Reading...
  • 08 Feb 2011

    Findings from the Fort Hood shooting underscores today’s incident response reality

    You may have heard about this in the news over the weekend: apparently the Army psychiatrist turned Islamic extremist who killed 13 people at Fort Hood in November 2009 could've been prevented had the FBI and Army been communicating with one another.Sadly the same poor communication exists in the corporate world. Along the same lines of this incident, based on what I see in my security assessments I can confidently ...

    Continue Reading...
  • 31 Jan 2011

    It’s hard being human

    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and leadership. He said:"Character is the ability to carry out a good resolution long after the excitement of the moment has passed." When I saw this I was reminded of how pumped you can get when attending a show like RSA or CSI or how neat certain vendor marketing spiels sound. Another is ...

    Continue Reading...
  • 23 Jan 2011

    Cybersecurity schmybersecurity

    Here are a couple of #cybersecurity pieces I authored for TechTarget's SearchCompliance.com regarding the proposed Rockefeller-Snowe Cybersecurity Act of 2009 (Senate Bill 773) and Lieberman-Collins-Carper Protecting Cyberspace as a National Asset Act of 2010 (Senate Bill 3480):Why the Cybersecurity Act is better for government than businessIs the latest cybersecurity bill an Internet takeover by the fed?You know how I am about government growth and its intrusion into the free market. ...

    Continue Reading...
  • 11 Jan 2011

    What’s holding you back?

    Orison Swett Marden once said:"What keeps so many employees back is simply unwillingness to pay the price, to make the exertion, the effort to sacrifice their ease and comfort." So true...as the saying goes good enough hardly ever is....

    Continue Reading...
  • 10 Jan 2011

    Great quote on information security choices

    Here's a great quote by Fred Smith that says it like it is:"You are the way you are because that's the way you want to be. If you really wanted to be any different, you would be in the process of changing right now."Obviously this also applies to our careers and personal lives...Like calories we ingest, our choices add up dramatically over time....

    Continue Reading...
  • 05 Jan 2011

    Speaking of supererogation, here’s a great quote

    Regarding yesterday's post about the word supererogation and how it can help you in your infosec career, here's a great quote by the poet Ovid that supports such an approach:"Make the workmanship surpass the materials." Spot on...otherwise you just fall in line with the majority. Not good for your career, not good for business....

    Continue Reading...
  • 02 Jan 2011

    Security complacency & leadership – focus on both in 2011

    Happy New Year! Here are a couple of recent pieces I wrote for Security Technology Executive magazine I thought would be good to get things rolling for 2011:Don't lose sight of what's importantFour traits of successful information security leadersMy wishes to you and yours for a healthy and prosperous year ahead!...

    Continue Reading...
  • 20 Dec 2010

    Possible bomb at Newark, ratchet up security!!??

    I heard a news story this morning about the possible bomb that was found at Newark Airport. The reporter went on to say that TSA is "ratcheting up security" and searching bags with more scrutiny in the event the threat is real.What I want to know is (and can't seem to find the answer to): why is it we "ratchet up security" when a such threat is detected rather than ...

    Continue Reading...