• 26 Sep 2011

    Compliance or risk: what the real IT leaders focus on

    Whatever your approach to managing IT and information security, here's a new bit I wrote for Security Technology Executive magazine on fixing what needs to be fixed before you do ANYTHING else:Fix Your Low-Hanging Fruit or Forever Hold Your PeaceOnce you have the urgent flaws on your most important systems out of the out of the way, here are some pieces I wrote for SearchCompliance.com on dealing with compliance while, ...

    Continue Reading...
  • 15 Sep 2011

    Your organization vs. BP: what will faulty decisions lead to in your business?

    Imagine a scenario where poor management, failure to take appropriate action, personnel changes and miscommunication about who's responsible for what leads to a catastrophic event at your business? That's exactly what the findings were of the BP oil spill.Sadly, 11 people died because of this incident. Luckily, our line of work isn't quite so risky but your business can still get in a bind when information security is mismanaged.Here's a ...

    Continue Reading...
  • 07 Sep 2011

    What it takes to get ahead in IT and beyond

    Good economy or not, people often ask: What can I do to get ahead in business? How can I stand out above the noise to enhance my career? How can I be a better network engineer, information security administrator, IT manager, speaker, writer and so on...?Whether you work for yourself or for someone else the answer is the same. You simply seek out the people who are at the top ...

    Continue Reading...
  • 31 Aug 2011

    Talk is cheap: Time to rethink your data retention strategy (or lack thereof)?

    Here's a fascinating story about a court case involving data retention you need to read. And pass it along to your management as well. It talks about how businesses aren't doing what they need to be doing with regard to data retention and how decisions are being made for us by the courts. Interestingly most businesses I come across (large and small) don't have any semblance of a data retention ...

    Continue Reading...
  • 26 Aug 2011

    My new book: Implementation Strategies for Fulfilling and Maintaining IT Compliance

    Check out my latest book published by Realtimepublishers.com:In Implementation Strategies for Fulfilling and Maintaining IT Compliance I share strategic and tactical methods for getting your arms around the compliance beast. You can download all the chapters (below) for free by signing up on Realtime's site. They've got a ton over other good content too.Here's the low down:Businesses are struggling more and more with the compliance requirements being pushed on them ...

    Continue Reading...
  • 21 Aug 2011

    Getting ahead in your career + keeping IT staff on board

    Here are some new bits I've written about IT and information security careers. First, what you can do to stand out above the noise and move your career ahead: How IT pros can boost their worth -- and their salaries ...and second, what management can do to keep IT and security professionals interested in their jobs and on board with the business: How to retain your IT talent 8 best ...

    Continue Reading...
  • 05 Aug 2011

    You’re the sum of your choices

    Here's a 67 second video that defines the essence of where we are in life, our careers and even in information security today:I really like what John Wooden said:"There's a choice you have to make in everything you do. So keep in mind that in the end the choice you make makes you."I also love what John Maxwell says:"It's your personal choices. If they're good, it's going to help make ...

    Continue Reading...
  • 04 Aug 2011

    The difference between “No” and “How”

    Here's a humorous and thought-provoking post by my friend Pete Lindstrom that you should check out:Dr. Laura as Information Security OfficerIt's so easy for people to say "No" to information security rather than "How"...similar to how many people - children and adults alike - say "I can't!" rather than "How can I?".People are always going to take the path of least resistance...if you let them....

    Continue Reading...
  • 02 Aug 2011

    Indeed, many executives are insulated from reality

    Here's a piece where I, Richard Stiennon, Andrew Baker and others weigh on executive management's involvement in information security:Focus Experts’ Briefing: How CEOs Can Prepare for and Respond to CyberattacksUnless and until executives get on board with security - across the board - I'll continue reciting one of my favorite quotes:“Many executives are insulated from reality and consequently don’t know what the hell is going on.” -James Champy...

    Continue Reading...
  • 21 Jul 2011

    Thomas Paine knew his infosec

    Here's a great infosec quote from statesman Thomas Paine:"Our greatest enemies, the ones we must fight most often, are within."This applies to both malicious insiders and ourselves as each of us certainly tend to get in our own way when it comes to making things happen with security....

    Continue Reading...