• 15 Dec 2011

    Going green’s tie-in with infosec

    If you've been following my blog and my principles for even a short period of time you've probably figured out that I pull no punches when it comes to personal responsibility and limited government. There's hardly anywhere I'm more passionate in this regard than the marketing smoke and mirrors of "Going Green" and the religion of "global warming". I should say "climate change"; that covers warming and cooling for the ...

    Continue Reading...
  • 07 Dec 2011

    Information security quote

    Don't expect short-term perfection in your security program. Instead, aim for incremental improvements over time. -KB...

    Continue Reading...
  • 27 Nov 2011

    Don’t get mired striving for perfection

    As we wind down 2011, here's a quote that relates to information security, incident response and overall risk management:“The person who insists upon seeing with perfect clearness before he or she decides, never decides.” -Henri Frederic AmielSo, do something to better your information security program. Any positive step forward - anything - is much better than getting mired in the desire for perfection and doing nothing at all....

    Continue Reading...
  • 20 Nov 2011

    A new way to bleed

    I was in New York City this past week for my final keynote and related presentations for our TechTarget & CDW information security roadshow. Wow, 10 cities in eight months - what a great way to end our year. Of course, being in New York I couldn't help but notice the *constant* coverage of the Occupy Wall Street protests that ended up turning a bit ugly on Thursday - the ...

    Continue Reading...
  • 01 Nov 2011

    What needs to change?

    The late Richard Carlson once said:Circumstances don't make a person, they reveal him or her. There are times when other people and/or circumstances contribute to our problems, but it is we who must rise to the occasion and take responsibility for our own happiness. Deep.Whether you're caught up in an IT project mess, a data breach or even the #Occupy "movement", keep this in mind. We're the sum of our ...

    Continue Reading...
  • 25 Oct 2011

    Your title really means nothing

    I can't tell you how many times I've met people over the years who have a fancy title like CEO or Director of This and That and it ended up being more of a façade than anything. As John Maxwell talks about in this video, your title really means nothing.I've often told people, I don't care what you call me as long as you pay me what I'm worth. That ...

    Continue Reading...
  • 27 Sep 2011

    Web security essentials: something old and something new

    Here are some new bits I've written on Web security that you may be interested in. First a bit on SQL injection - the greatest Web flaw of all in my humble opinion:SQL Injection – The Web Flaw That Keeps on GivingAnd a bit on how to use your users to your advantage to minimize Web security risks:Getting users on your side to improve Web security...and finally a piece on ...

    Continue Reading...
  • 26 Sep 2011

    Compliance or risk: what the real IT leaders focus on

    Whatever your approach to managing IT and information security, here's a new bit I wrote for Security Technology Executive magazine on fixing what needs to be fixed before you do ANYTHING else:Fix Your Low-Hanging Fruit or Forever Hold Your PeaceOnce you have the urgent flaws on your most important systems out of the out of the way, here are some pieces I wrote for SearchCompliance.com on dealing with compliance while, ...

    Continue Reading...
  • 13 Sep 2011

    Stephen Covey’s insight applies to information security

    I love the following quote...very applicable to what we do:"You can't talk yourself out of a problem you behave yourself into." - Stephen CoveyOkay, you may be able to talk your way out of bad security decisions with the right attorneys or a cybersecurity insurance policy. Having worked cases involving data breaches, compliance and intellectual property, I can say that it won't be a short-lived, inexpensive or painless ordeal....

    Continue Reading...
  • 07 Sep 2011

    What it takes to get ahead in IT and beyond

    Good economy or not, people often ask: What can I do to get ahead in business? How can I stand out above the noise to enhance my career? How can I be a better network engineer, information security administrator, IT manager, speaker, writer and so on...?Whether you work for yourself or for someone else the answer is the same. You simply seek out the people who are at the top ...

    Continue Reading...