Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Principle Logic, LLC: You can't secure what you don't acknowledge. ## Sitemaps [XML Sitemap](https://www.principlelogic.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [What Decades of Penetration Testing Taught Me (and what Ben Rothke confirmed)](https://www.principlelogic.com/blog/uncategorized/what-decades-of-penetration-testing-taught-me-and-what-ben-rothke-confirmed/): After decades of testing systems for security flaws, many (arguably most) things haven't changed. One in particular: most security failures still come down to basics that were assumed, ignored, or never verified. - [The real problem with threat intelligence isn’t volume](https://www.principlelogic.com/blog/ai/the-real-problem-with-threat-intelligence-isnt-volume/): Most enterprise threat intelligence programs didn’t end up where they are by accident. They evolved that way over time. One feed, one tool, one integration at a time. The thought was: more data, more visibility, better security. But then complexity grows until the moving parts are no longer serving the mission. I’ve seen this happen across organizations of all sizes, and on the surface, it looks like progress is happening. But when you see how these threat intelligence programs operate under pressure, it becomes clear that something is missing. - [The biggest AI risk in your company has a corner office](https://www.principlelogic.com/blog/people-problems/the-biggest-ai-risk-in-your-company-has-a-corner-office/): We spend a lot of time worrying about employees clicking email links and reusing passwords. Both are valid concerns in our new world of AI. But this approach misses a larger (and more shocking) reality. The single biggest AI-related risk in most organizations is at the help desk or buried somewhere in accounting or IT. It’s sitting in the C-suite, operating with authority and speed, with little to no friction. - [The Epstein Files and the email footer that changed nothing](https://www.principlelogic.com/blog/email-security/the-epstein-files-and-the-email-footer-that-changed-nothing/): "Here is a rich man who is the victim of a painful and persistent disease as the result of gluttony. He is willing to give large sums of money to get rid of it, but he will not sacrifice his gluttonous desires. He wants to gratify his taste for rich and unnatural viands and have his health as well. Such a man is totally unfit to have health, because he has not yet learned the first principles of a healthy life." — James Allen, As a Man Thinketh - [Security’s defensibility problem. Can you truly defend what you’ve built?](https://www.principlelogic.com/blog/data-protection/securitys-defensibility-problem-can-you-truly-defend-what-youve-built/): You've secured the budget. You've implemented the program. You've checked every box on the information security checklist. Frameworks? Followed. Best practices? Established. Policies? Written and approved. The technology stack is humming along, auditors are nodding approvingly, and consultants are signing off on your approach. Everything suggests your network and information assets are locked down tight. Then the breach happens. The investigation reveals gaps you never saw coming. How did this occur when you did everything right? - [Doing the Hard Things (in security, and in life)](https://www.principlelogic.com/blog/low-hanging-fruit/doing-the-hard-things-in-security-and-in-life/): Everything is easy, until it's not... - [Embracing Incident Response at Petit Le Mans: A Positive Outlook for Cybersecurity?](https://www.principlelogic.com/blog/incident-response/incident-response-and-the-petit-le-mans-reality-check/): At the Petit Le Mans race this past weekend, the TV announcers couldn’t stop talking about incident responsibility. Apparently, the International Motor Sports Association (IMSA) made it clear they’re done tolerating sloppy driving. . The rules of racing have always been there; now IMSA says they’re finally going to enforce them. Zero tolerance. No excuses. Yay...I think... This change in attitude reflects a growing trend in sports and other high-stakes environments where accountability is paramount. Just as in racing, where a split-second decision can lead to disastrous consequences, in the world of cybersecurity, the results of negligence can be equally catastrophic. - [Hacking For Dummies, 8th edition…It’s official!](https://www.principlelogic.com/blog/hacking/hacking-for-dummies-8th-edition-its-official/): After months of writing, revising, and updating real-world examples, Hacking For Dummies, 8th Edition is finally out in the wild.👉 Get it here on Amazon (affiliate link) - [Leverage MSSPs where it makes sense, but do your due diligence](https://www.principlelogic.com/blog/marketing-hype/leverage-mssps-where-it-makes-sense-but-do-your-due-diligence/): It seems that more and more businesses are leveraging managed security service providers (MSSPs) to help with ongoing security improvements. I think this is a positive sign that both IT professionals and business leaders are realizing that they can't do it all in terms of security. There’s no shame in that game if outsourcing managed security services is done for the right reasons. No doubt, some businesses wish to engage with an MSSPs for risk deference, i.e. so they can bring these vendors into the downstream liability discussion when incidents and breaches occur. Or, worse, just to check a box that those aspects of security are being handled. Whatever the case, if you choose to bring a MSSP into the discussion and integrate their services with your security program, there's a lot to be gained. You just must make sure that you're asking the right questions and fully understand what you're getting into. - [Don’t let your security program fail like a bad relationship](https://www.principlelogic.com/blog/people-problems/dont-let-your-security-program-fail-like-a-bad-relationship/): TL;DR - Just like a relationship, a security program needs honesty, maintenance, and timely conflict resolution...or it will collapse under neglect.  - [Harvard Business Review article nails the challenges with underimplemented security tools](https://www.principlelogic.com/blog/back-to-basics/harvard-business-review-article-nails-the-challenges-with-underimplemented-security-tools/): Harvard Business Review (HBR) just published a great piece that covers the challenges associated with information security tools and highlights many of the reasons that security programs often fail. Here’s the essence of the piece: Despite spending billions on tools, most organizations are seeing modest results. Nearly half the tools companies invest in go unused. - [What do truckers in the inside lanes, the Georgia State Patrol, and infosec policies have in common?](https://www.principlelogic.com/blog/compliance/what-do-truckers-in-the-inside-lanes-the-georgia-state-patrol-and-infosec-policies-have-in-common/): Security policies are garbage unless someone actually enforces them. They exist to tick boxes, impress auditors, and give leadership a warm-and-fuzzy about “doing security.” But when nobody lives by them, they’re nothing but paperwork liabilities. Certainly not the safeguards many assume them to be. They're certainly not worth the paper on which they're printed, or the storage space they're occupying on the network. - [CIOs: You can’t afford to sit out on security (especially with AI in the mix!)](https://www.principlelogic.com/blog/security-leadership/cios-you-cant-afford-to-sit-out-on-security-especially-with-ai-in-the-mix/): As an information security consultant, I’ve worked with many CIOs over the years. Some get it when it comes to security… and some not so much. Those who don’t are often the ones calling me in after the fact, cleaning up breaches that could have been prevented with stronger executive engagement. I've actually seen people in this role run interference with security. I'm assuming so they weren't made to look bad...Go figure! - [Revisiting an article on the security basics I wrote over two decades ago](https://www.principlelogic.com/blog/back-to-basics/revisiting-an-article-on-the-security-basics-i-wrote-over-two-decades-ago/): This article is from 2004. Tell me what has changed or is outdated...Perhaps my reference to "SSL" VPNs or "anti-virus" software? ;) - [My guide for building out your incident response plan and program](https://www.principlelogic.com/blog/security-leadership/my-guide-for-building-out-your-incident-response-plan-and-program/): Security incidents are a case of when not if. Whether it’s ransomware, information theft, denial of service - you name it, you need a structured and practical approach to incident response without the fluff and vendor noise. Is - [A look at Charles Cresson Wood’s Internal Policies for Artificial Intelligence Risk Management](https://www.principlelogic.com/blog/cool-products/book-review-of-charles-cresson-woods-internal-policies-for-artificial-intelligence-risk-management/): I’ve known Charles Cresson Wood for a long time, both as a trusted business colleague and a friend. You may know him as the creator of the original masterpiece on information security policies over two decades ago: Information Security Policies Made Easy. Charles and I have worked together on a few projects over the years, and what’s always stood out to me is his ability to tie together security, legal, and business strategy. His latest book, Internal Policies for Artificial Intelligence Risk Management, is a great example of that mix coming together. And it couldn’t be more timely with all that's going on in/around AI. - [Adoption, perception, strategy…how businesses are struggling with AI](https://www.principlelogic.com/blog/artificial-intelligence/3950/): Inc.com had a piece on AI adoption/perception/strategy recently. I feel that it provides some interesting insight into what's to come as it relates to dealing with employees working for - and against - the business...especially as it relates to sabotaging AI efforts. Lots of things for IT and security leaders and admins to pay attention to that I've summarized here: - [The new realities of career networking](https://www.principlelogic.com/blog/careers/the-new-realities-of-career-networking/): They say your network is everything. I’d argue that what truly matters is your time and your knowledge - those are the real currencies in today’s business world. Still, there’s no denying that staying connected, especially online, plays a critical role in your long-term success. The old saying “It’s who you know” has evolved into “It’s who knows you.” In our hyperconnected reality - where virtual presence carries as much weight as real-world rapport - visibility matters more than ever. - [Using zero-based thinking to improve your security program](https://www.principlelogic.com/blog/security-leadership/using-zero-based-thinking-to-improve-your-security-program/): It's almost 2025. We've known for quite some time what needs to be done in terms of information security. Most best practices and standards have been around for decades... - [Extremely blessed to go from near death to keynote speaking again](https://www.principlelogic.com/blog/motivation/extremely-blessed-to-go-from-near-death-to-keynote-speaking-again/): My rising from the ashes moment... - [It’s 2024, yet college football’s Power Four teams were using unencrypted GSC helmet communications](https://www.principlelogic.com/blog/back-to-basics/its-2024-yet-college-footballs-power-four-teams-were-using-unencrypted-gsc-helmet-communications/): Just when you think most people understand the basics of security, along comes a story like the following: - [Career networking success – what you should do…and not do](https://www.principlelogic.com/blog/careers/career-networking-success-what-you-should-do-and-not-do/): If you work in IT or information security, there's one thing that you'll want to be good at: networking. No, not the TCP/IP and Ethernet stuff but networking for your career. You can do this both internally within your own company as well as externally, networking with outsiders. Even if you have a job, rubbing elbows with the right people today can end up landing you work down the road when you need it. Career networking has returned many many dividends for me and you can reap the same benefits. - [Find at-risk internal user accounts with myNetWatchman’s AD Credential Audit tool](https://www.principlelogic.com/blog/security-policies/find-at-risk-internal-user-accounts-with-mynetwatchmans-active-directory-audit-tool/): I'm always on the lookout for new tools that can do new and interesting things for those of us working in information security. They are few and far between, it seems, at least in the context of vulnerability and penetration testing. However, I've found one that can pay huge dividends. It's called AD Credential Audit (formerly known as Active Directory Audit) by threat intelligence company, myNetWatchman. - [3 resources to help with the SEC’s cybersecurity ruling on incident reporting](https://www.principlelogic.com/blog/uncategorized/3-resources-to-help-with-the-secs-cybersecurity-ruling-on-incident-reporting/): There's been a lot of buzz in recent months regarding the new US Securities and Exchange Commission (SEC) cybersecurity ruling involving incident resporting. Check out the following resources I created for the folks at web application and API vulnerability scanning vendor Probely. We help you cut through the noise and understand what really matters in the context of incident reporting/response and, especially, its impact on overall application security. - [Too many people, too many policies, too much busy work! Security has to wait…](https://www.principlelogic.com/blog/security-leadership/too-many-people-too-many-policies-too-much-busy-work-security-has-to-wait/): Busy, busy, busy...That's what everyone working in and around IT/security seems to be these days. Ditto for the average user. So many things to do and not enough time to do them. It appears that everyone is completely overwhelmed with work, putting out fires, rather than focusing on  productive work that moves the business forward. But is this really the case? Based on studies I've seen and things I witnessed with my own eyes, I suspect the average user and even IT/security staff member is working at about 60-70% utilization, on actual fruitful work, at best. - [Cybersecurity All-In-One For Dummies – a new book my vulnerability and penetration testing content is featured in](https://www.principlelogic.com/blog/cool-products/cybersecurity-all-in-one-for-dummies-a-new-book-my-vulnerability-and-penetration-testing-content-is-featured-in/): I was recently surprised to find out about this new book - Cybersecurity All-In-One For Dummies - that much of my Hacking For Dummies content is featured in. The following chapters from my book are included: - [The tautology of “Russian hacking” + why you can’t believe everything you hear/read](https://www.principlelogic.com/blog/hacking/the-tautology-of-russian-hacking-why-you-cant-believe-everything-you-hear-read/): Remember back in 2017/18 during the rise of the Trump regime, when the media kept repeating over and over and over again how the Russians were meddling in the election? It was convenient for them to talk about this so-called "Russian hacking" because those who control the messaging understand the average person knows very little about hacking. - [My health story is a reminder that we need to rely on the right experts](https://www.principlelogic.com/blog/message-from-kevin/my-health-story-is-a-reminder-that-we-need-to-rely-on-the-right-experts/): I'm back! After quite the hiatus dealing with a rare health condition, I'm coming back to life and getting better every day! - [It’s here! Hacking For Dummies, 7th edition](https://www.principlelogic.com/blog/web-application-security/its-here-hacking-for-dummies-7th-edition/): Hot off the press, the latest (7th) edition of my best-selling book on security vulnerability and penetration testing, Hacking For Dummies, is here! - [Is it safe to give out your CISSP number?](https://www.principlelogic.com/blog/cissp/is-it-safe-to-give-out-your-cissp-number/): I recently had someone contact me claiming he needed to validate my CISSP certification for a client of mine via the (ISC)² verification page. Apparently, this validation was needed for an audit he was doing. He said the Credly badge (ISC)² offers that I have on my website was not good enough without him having to perform a "risk assessment" on that company. 🙄 - [Security assessment interviews/questionnaires versus reality](https://www.principlelogic.com/blog/compliance/security-assessment-interviews-questionnaires-versus-reality/): Not long ago, I performed what I call a security operations review where I asked various questions about how IT and security are managed within an organization I was working with. One of the topics was on patching and vulnerability management. I got a lot of good information, including specific details on how Windows, macOS, and even third-party patches are taken care of. Everything sounded great and I expected to see very few findings with my internal vulnerability scans and penetration testing... - [Macs are secure…no need to test them?? You might want to rethink that approach.](https://www.principlelogic.com/blog/penetration-testing/macs-are-secure-no-need-to-test-them-you-might-want-to-rethink-that-approach/): Macs are secure! Right...? They don't really need to be tested...including them in an overall vulnerability management program is likely overkill. - [Veracode’s secure code training – a possible boost to your developer & security staff](https://www.principlelogic.com/blog/application-security/veracodes-secure-code-training-a-possible-boost-to-your-developer-security-staff/): Hope this helps! - [My new Principle Logic race car livery](https://www.principlelogic.com/blog/message-from-kevin/my-new-principle-logic-race-car-livery/): I recently upgraded my Spec Miata race car to a newer (1999) model. I decided that life was too short to have to drive my older (1990) Spec Miata 100+ percent all the time just to keep up with my competitors who were not having to work as hard. Although my car was really nice with its blue and orange Gulf Oil livery (pic below), it just wasn't me. So, I went for a completely new design. Here's my new Principle Logic-sponsored livery in some shots I took while attending a recent race at Road Atlanta: - [People talking used to be a phishing defense…what can you do now?](https://www.principlelogic.com/blog/uncategorized/people-talking-used-to-be-a-phishing-defense-what-can-you-do-now/): I was speaking with a client recently about when their users receive phishing emails, they will typically yell to others across the room and down the hallway to be on the lookout. But, the days of everyone being in the office at the same time and users having that luxury are gone. At least for now... - [The 21 Best Ways to Lose Your Information, revisited](https://www.principlelogic.com/blog/back-to-basics/the-21-best-ways-to-lose-your-information-revisited/): With all the crazy incidents and breaches brought about by so many unfortunate "glitches" combined with how I continually harp on the importance of mastering the information security basics, I thought it'd be appropriate to re-post the content of an article I wrote for Computerworld back in 2002... - [How to network to boost your IT career](https://www.principlelogic.com/blog/security-leadership/how-to-network-to-boost-your-it-career/): If you asked me what the one critical element is for maintaining a successful career in IT, I’d say networking. No, I’m not talking about the Ethernet, layer 3 switch, and VLAN type of networking. Rather, I’m referring to staying in touch with existing colleagues and attending networking events (presentations, seminars, conferences, etc.) with the intent of meeting new people who can, ultimately, help you accomplish your career goals. The top people in IT – and any field – are those who are continually networking to move ahead. - [A great read on the Great Reset](https://www.principlelogic.com/blog/situational-awareness/a-great-read-on-the-great-reset/): Here on my blog, I normally post about information security...often with a sprinkling of psychology and the political nonsense of the world and how they impact security in business. Now, though, I want to share what I believe is a great read on this "Great Reset" that's going on in society right now. I can't share it on social media - Big Tech likes to block stuff like this for some reason... - [Networked IP cameras as vulnerable as ever…no excuses these days.](https://www.principlelogic.com/blog/back-to-basics/networked-ip-cameras-as-vulnerable-as-ever-no-excuses-these-days/): You've likely heard the news about security cameras being vulnerable to exploits like what was covered in this piece: - [If you mastered nothing else but this one thing, you’d be ahead of the security curve](https://www.principlelogic.com/blog/back-to-basics/if-you-mastered-nothing-else-but-this-one-thing-youd-be-ahead-of-the-security-curve/): In my virtual CISO consulting engagements and vulnerability and penetration testing, the process of patch management ALWAYS comes up for discussion. Given the threats, the vulnerabilities, and the risks – everything that's at stake – I cannot think of any single aspect of a well-functioning information security program that's more important than patch management. It's one of a few things in security that you CAN control! - [Review of Corporate Directors’ & Officers’ Legal Duties for Information Security and Privacy: A Turn-Key Compliance Audit Process](https://www.principlelogic.com/blog/cool-products/review-of-corporate-directors-officers-legal-duties-for-information-security-and-privacy-a-turn-key-compliance-audit-process/): One of the great tragedies impacting businesses today is the disconnection between executive leadership and the information security function. The general assumption has long been that technical staff have everything under control and, therefore, management doesn't need to get all that involved in IT security and compliance related initiatives. I first noticed this situation in the late 1990s working on information security security projects with clients. Shortly thereafter, I wrote about the disconnect. Oddly enough, even in the year 2021, I'm still witnessing executive disconnection with the information security function. - [Stanley Roberts – catching people misbehaving digitally too](https://www.principlelogic.com/blog/social-engineering/stanley-roberts-catching-people-misbehaving-digitally-too/): A few weeks ago, I promised my friend, Stanley Roberts (a well-known journalist who uses video to capture people doing dumb things) that I would post about a Facebook scam that he recently encountered. And then life got in the way...but here it is. - [TikTok app privacy. Is it really a big deal?](https://www.principlelogic.com/blog/mobile-apps/tiktok-app-privacy-is-it-really-a-big-deal/): I was recently interviewed for a news segment about privacy concerns over TikTok...is it a problem? What makes it different from typical social media data collection? - [The miracle of COVID-19 testing: more tests= more cases. (It works for security too!)](https://www.principlelogic.com/blog/data-breaches/the-miracle-of-covid-19-testing-more-tests-more-cases-it-works-for-security-too/): I'm no jet fuel genius. Nor am I a statistician. I'm certainly no epidemiologist. I don't even consider myself to be one of the smartest people in my own field. But I do know enough to realize that when a problem exists (even if it's yet to be acknowledged), once it's sought after, it will be uncovered. And once it uncovered, does this newfound knowledge actually change anything? Not necessarily. It provides new insight and information but it doesn't immediately translate into a "problem", decisions being made, and so on. The long-term outcome may change...but, then again, maybe not. The situation is the same the moment before and the moment after, regardless. - [Security awareness/training and security policy tips for tough times](https://www.principlelogic.com/blog/security-leadership/security-awareness-training-and-security-policy-tips-for-tough-times/): It's a tired subject at this point. Still, I still wanted to share some pieces that I've written on security awareness/training and security policies over the years that your business might benefit from to help get (keep) your arms around your remote workforce and overall information security program...no need to buy anything or hire anyone to help. The following are all you need to get rolling and/or fine-tune: - [Want to get better at (whatever)? Explain the concepts to others.](https://www.principlelogic.com/blog/careers/want-to-get-better-at-whatever-explain-the-concepts-to-others/): I recently had the opportunity to write an article for Ross Bentley's Speed Secrets Weekly newsletter. It's one of the most popular newsletters in motorsports with a ton of visibility. Ross was kind enough to let me reshare my article here...I wanted to share it with you because it relates to IT and security just as much as it does to racing a car. - [Look for the lessons and be a leader among the COVID-19 panic](https://www.principlelogic.com/blog/security-leadership/look-for-the-lessons-and-be-a-leader-among-the-covid-19-panic/): “The hardest thing to explain is the glaringly evident which everybody had decided not to see.” – Ayn Rand - [Speaking engagement for ALAS in Phoenix was a big success!](https://www.principlelogic.com/blog/incident-response/speaking-engagement-for-alas-in-phoenix-was-a-big-success/): I had the opportunity to be invited to speak at the Attorney's Liability Assurance Society (ALAS) 2020 Cybersecurity Conference in Phoenix, AZ last week, and it was awesome. With a great group of 220 law firm IT leaders and general counsel professionals, I presented Beyond the Policies: Top 5 Security Findings (that I see in literally every security assessment I perform). I also served as a panelist for a lively session on incident response tabletop exercises. - [Learning to be a better security speaker with Brian Tracy](https://www.principlelogic.com/blog/speaking-engagements/learning-to-be-a-better-security-speaker-with-brian-tracy/): I recently had the most amazing opportunity to learn more about becoming a better speaker. I got to spend two full days sitting around a conference table and in the studio with the one and only Brian Tracy. - [SQL injection is lurking…Are you looking for it?](https://www.principlelogic.com/blog/security-testing-tools/sql-injection-is-lurking-are-you-looking-for-it/): I don't always find SQL injection vulnerabilities in the web applications I test but I have been seeing it more and more recently. I can't figure out why... When I do uncover this grandest of all vulnerabilities, it's usually pretty ugly as it was with this recent finding: - [Cities + hacking & ransomware: what’s really going on?](https://www.principlelogic.com/blog/uncategorized/cities-hacking-ransomware-whats-really-going-on/): I do a lot of work for municipalities - cities, towns, and county governments - and I've concluded one thing: I don't envy those in charge of their IT and security. Apparently, municipal hacking is all the rage. At least that's what the media is currently portraying. For example, it's on the front page of today's New York Times: - [How does your incident response program measure up?](https://www.principlelogic.com/blog/data-breaches/how-does-your-incident-response-program-measure-up/): I've heard it said that experience is something you don't get until just after you need it. Incident response is one of those things. How do you fully prepare for something that you've never had to deal with? Well, there are ways, but you have to prepare before the going gets rough. - [IT and computer security career tips & resources](https://www.principlelogic.com/blog/careers/it-and-computer-security-career-tips-resources/): In preparation for my upcoming webinar on information security careers (check that out, by the way!), I was updating my website with IT and security career-related articles. Since I last updated my careers page, I've written 35 new pieces...35! Wow, apparently I need to go back and read some of my own tips on time management. :-) - [Here’s a BIG mobile security exposure you may be overlooking](https://www.principlelogic.com/blog/data-breaches/heres-a-big-mobile-security-exposure-you-may-be-overlooking/): With security, if your goal is to minimize your maximum regret, there's a lot to be thinking about. User behaviors involving mobile devices are at the heart of some of the larger business risks, especially if you're like the majority of businesses I see and support bring your own device (BYOD) For phones and tablets. Well, here's something that you may have thought about in passing but haven't done anything about... - [Networking + learning at the 2019 SecureWorld Atlanta show](https://www.principlelogic.com/blog/uncategorized/networking-learning-at-the-2019-secureworld-atlanta-show/): I found that practicing and growing these aspects of my career is as important as ever. Even if you can't get out or don't like getting out, you need to network. Attending security events is not only a great way to clear your mind and learn new things... it's also a great way to develop new and existing relationships. - [Healthcare’s latest (ridiculous) proposal to improve security in that industry](https://www.principlelogic.com/blog/security-leadership/healthcares-latest-ridiculous-proposal-to-improve-security-in-that-industry/): For years, I've ranted about the rebranding of information security to "cybersecurity". This strategy is nothing more than a means to redirect attention - even create confusion - over what we do so that something shiny, new, and sexy can be sold to those who are buying. It's bad for what we're trying to accomplish in this field. We need less confusion rather than more. - [I’m IT…Respect my authoriTAH!](https://www.principlelogic.com/blog/security-leadership/im-it-respect-my-authoritah/): If you've watched the animated TV show, South Park, you'll appreciate this. I just came across an article titled The Importance of Respecting Expertise in IT Professionals by Michelle Rakoczy. It's a thoughtful and well-researched piece on why people outside of IT need to respect the guidance/opinions of IT professionals (yet often don't). - [WP Security Audit Log – a must for WordPress security oversight and resilience](https://www.principlelogic.com/blog/web-application-security/wp-security-audit-log-a-must-for-wordpress-security-oversight-and-resilience/): Not long ago I moved my information security consulting business website to WordPress - something I thought I'd never do. The burden of hosting it myself combined with the hassles of working with Dreamweaver forced the change. I wasn't initially a big fan of WordPress...it's almost too much to take on. This coming from a technical guy who hosted Apache on Windows and did most of my administration at the command prompt. - [Hacking For Dummies in India](https://www.principlelogic.com/blog/hacking/hacking-for-dummies-in-india/): Signed copies of my books have made it to some far-reaching places but I believe this one takes the cake. I was excited to see that my good friend, Jeff Jenkins, recently delivered copies of Hacking For Dummies to his team in Bengaluru! Thanks Jeff and thanks team - I hope you enjoy it! - [Good, old-fashioned, boring passwords – the key to good security](https://www.principlelogic.com/blog/uncategorized/good-old-fashioned-boring-passwords-the-key-to-good-security/): Many people are quick to proclaim that passwords are dead...that SSO, MFA, and related technologies are THE solution. Not so fast. Passwords, as we've known them for decades, are not going away anytime soon. Sure, I'll embrace the technologies that help take the pain out of passwords and password management. Hopefully we will be password-free in the next few decades. Still, pragmatism will win out over presumed quick fixes every time. Until then, there are some things that you can – and must – do in order to minimize this maximum security risk. The following are password and penetration testing related pieces that I recently wrote for the nice folks over at Specops Software that can help put you on the right path: - [Hacking For Dummies now in its 9th language](https://www.principlelogic.com/blog/penetration-testing/hacking-for-dummies-now-in-its-9th-language-translation/): I just found out from my publisher, Wiley, that my book Hacking For Dummies is being published in Dutch. That makes the ninth language for my book since its inception way back in 2003. Here's the full list of languages: - [Fortinet study on CISOs and the security skills gap](https://www.principlelogic.com/blog/security-leadership/fortinet-study-on-cisos-and-the-security-skills-gap/): We hear a lot about the information security skills gap but what does that really mean? Actually it means a lot of different things to different  people. Check out this Ziff Davis webinar on which I recently served as a panelist. We had a great discussion and the study commissioned by Fortinet is very telling about what employers are looking for and what jobseekers believe that they bring to the table. I've been talking about many of these things for years and I'm glad to see it getting the traction it deserves. - [Crashing race cars and preparing for incidents that have never happened](https://www.principlelogic.com/blog/incident-response/crashing-race-cars-and-preparing-for-incidents-that-have-never-happened/): Just over 17 years ago, on 9/11, we witnessed what it was like dealing with something that had never occurred. I remember thinking at the time and it still rings true – it's hard to protect against something that's never happened. Little to no clues, as far as we know...massive destruction on a scale we never expected. That's the tricky thing about terrorist threats and, on a much smaller scale, this challenge can impact IT and information security. I personally experienced an unexpected event recently when racing my car. It's somewhat baffling but, essentially, my car connected with that of a fellow competitors and we both drove our cars into the wall as you can see here: - [Using Securolytics for enhanced IoT security](https://www.principlelogic.com/blog/cool-products/using-securolytics-for-enhanced-iot-security/): I often say that you can't secure the things that you don't acknowledge...I can't imagine that reality applying to anything in IT or security as much as it applies to securing Internet of Things (IoT) devices that are on your network, creating risks...this very moment. The trouble with IoT devices that they can be not only hard to discover and manage but they're also extremely difficult to identify. Oftentimes, in my vulnerability and penetration testing work, I come across IoT devices but much of it is a guessing game – especially when it comes to determining the specific manufacturer and what CVE or related vulnerabilities it might have.  Traditional web and network vulnerability scanners are good at discovery and uncovering OS and application-related flaws but they lack the ability to dig in further and find out more information on the devices. That's a problem... - [A great reminder about relationships in information security](https://www.principlelogic.com/blog/security-leadership/a-great-reminder-about-relationships-in-information-security/): I've always believed that poor communication can make or break an information security program. So many times, I witness IT and security professionals failing to get their messages across to their audience and, worst of all, talking down to the very people whom they should be lifting up. I've written about it many times over the years: - [CNN news story on Omarosa getting fired from the White House that quotes me on the reality of security culture](https://www.principlelogic.com/blog/policy-enforcement/cnn-news-story-on-omarosa-getting-fired-from-the-white-house-that-quotes-me-on-the-reality-of-security-culture/): Security culture is everything. If you work in security, you probably already know that...For business executives, though...well, that mindset is largely absent. In fact, as this new CNN piece I'm quoted in about Omarosa secretly recording her firing in the most "secure" room of the White House highlights, talk is cheap. IT and corporate security professionals can evangelize the importance of security - especially security culture - all day long, every day of the year...but as soon as an executive decides that he or she is going to do things his or her way, that basically negates all security efforts to that point. - [Check out my webinar on the big risks involving unstructured information – 2pm ET today (reading assignment links)](https://www.principlelogic.com/blog/data-breaches/check-out-my-webinar-on-the-big-risks-involving-unstructured-information-2pm-et-today-reading-assignment-links/): Join me today at 2pm ET for my Ziff Davis webinar Addressing the Security Risks Around Unstructured Information sponsored by Citrix ShareFile. Unprotected files scattered about the network environment is one of the biggest vulnerabilities I see...and it continues to create tangible business risks for every organization. I'll talk about the risk, share some examples of what I'm seeing in my work perform security assessments, and provide some ideas on what you can do to address thee situation. I hope you'll join me! You can register here. - [Join me at 2pm ET today for a discussion on data breaches + reading assignment links](https://www.principlelogic.com/blog/security-leadership/join-me-at-2pm-et-today-for-a-discussion-on-data-breaches-reading-assignment-links/): The data breach numbers we see in the studies and headlines every year (day!?) are pretty amazing...It's clear that we have not just an IT challenge on our hands but a true business problem... - [Introducing my brand new vulnerability and penetration testing book: Hacking For Dummies, 6th edition](https://www.principlelogic.com/blog/uncategorized/introducing-my-brand-new-vulnerability-and-penetration-testing-book-hacking-for-dummies-6th-edition/): Want to learn the essentials of vulnerability and penetration testing? Looking for insight into which testing tools you need to use to get the job done right? Maybe you need help in determining the difference between the vital few security vulnerabilities and the trivial many that sidetrack so many people? Perhaps you need help selling information security to management and keeping them on board with what you're doing? Well, if any of the above apply to your situation, you should check out the fully-updated, 6th edition of my best-selling security book, Hacking For Dummies. - [Web application and mobile app security testing – Are you on board?](https://www.principlelogic.com/blog/mobile-apps/web-application-and-mobile-app-security-testing-are-you-on-board/): Here are some recent pieces I've written regarding web application and mobile app security based on the work I do that you might be interested in: - [When PR spam is actually amusing](https://www.principlelogic.com/blog/people-problems/when-pr-spam-is-actually-amusing/): I get spammed by PR firms all the time - quite likely a dozen or more emails from them in my business inbox every day. I think I get on their radar because certain articles I write happen to be related to what these spammers are trying to promote. Well, I recently got this spam message via email from a PR firm regarding an upcoming security conference. Looks interesting. But to heck with the show...and don't worry about what it says (I know, it's hard to see)...What's funny is that someone apparently did some edits to the original press release and the guy who sent it forgot to accept those changes (and proofread)...can't make this stuff up. ;-) - [Hacker Halted – a security show worth attending](https://www.principlelogic.com/blog/message-from-kevin/hacker-halted-a-security-show-worth-attending/): I've been a big advocate of attending security shows in order to learn, network, and see/hear about the latest technologies. There are a ton of these shows each year - some are a good fit, others not so much. Well, there's one show that I just attended in Atlanta this week that's worth my mentioning and recommendation. It's called Hacker Halted. Put on by the EC-Council (Certified Ethical Hacker) folks, it's well-attended but not too big. I spoke with and exchanged business cards with several people from around the country. Word had it that around 2,000 people were in attendance. I saw several good speakers including one of the best in the business, Winn Schwartau, as well as the EC-Council's founder and president, Jay Bavisi. Jay shared some great points on the state of security, including how we're facing a skills shortage, not a labor shortage. I totally agree. There are many people working in positions of security authority and decision-making that don't really know a whole lot about security. It's learn as they go and that's bad for business, good for the criminals.  - [SEC, Equifax, what’s next? Focus on – and fix – the stuff that matters in security.](https://www.principlelogic.com/blog/computer-glitch/sec-equifax-whats-next-focus-on-and-fix-the-stuff-that-matters-in-security/): I recently consulted with a client on the SEC and Equifax breaches and had some thoughts that I left with that I wanted to share here: - [HIPAA and data encryption – what you need to know](https://www.principlelogic.com/blog/compliance/hipaa-and-data-encryption-what-you-need-to-know/): When I co-wrote the first edition of the book The Practical Guide to HIPAA Privacy and Security Compliance, both HIPAA and data encryption were a big deal. Fast forward nearly 15 years and they're still a big deal, yet many people are still struggling with both.  - [Hacking For Dummies featured in new Lifetime movie Running Away](https://www.principlelogic.com/blog/message-from-kevin/hacking-for-dummies-featured-in-new-lifetime-movie-running-away/): I had the neat opportunity to recently see my book, Hacking For Dummies,  featured in this summer's Lifetime movie called Running Away. I've known that it was a possibility for some time but it was cool to see it on the screen! Here's the scene it's featured in: - [Rapid7’s Insight platform provides focused analytics for your security program](https://www.principlelogic.com/blog/cool-products/rapid7s-insight-platform-provides-focused-analytics-for-your-security-program/): Fairly recently, Rapid7 took their vulnerability management platform up to the next level with their analytics platform called Rapid7 Insight. It's a beneficial for an independent consultant like myself and even more useful for enterprises with IT environments of growing complexity. Rapid7 Insight is marketed as a way to bring together the Nexpose vulnerability research, Metasploit exploits, global security intelligence and exposure analytics into a single system that can help businesses solve more - and better - security problems. A cloud tool that integrates with your Nexpose instance, Rapid7 Insight lets you see what's being uncovered in your environment, monitor specific vulnerabilities, and bring it full circle with ticketing system integration to support remediation workflows. you even have a choice on where to store your data in the cloud in order to meet specific compliance/legal requirements. Here are some examples of Insight's "Liveboards" that provide info on specific areas of vulnerability management. These are external-facing security vulnerability data including details on exploitable vulnerabilities. - [How to gain control & become an IoT security expert](https://www.principlelogic.com/blog/security-testing-tools/how-to-gain-control-become-an-iot-security-expert/): You've no doubt heard the vendor spiels and seen their solutions for gaining control of your Internet of Things environment. But do you truly have IoT under control? Like other things in IT, it can be pretty overwhelming, especially when you're struggling to keep your arms around your traditional network environment with cloud and mobile and all the complexities they bring.  - [Using Centrifuge for IoT security testing](https://www.principlelogic.com/blog/security-testing-tools/using-centrifuge-for-iot-security-testing/): I love hacking things, especially new things like what's showing up on networks around the globe in the form of IoT. If IoT security is anywhere on your radar, you're likely incorporating these devices into your security testing program. Well, there's a new IoT security assessment tool in town that you need to know about called Centrifuge brought to you by Tactical Network Solutions - makers of the former (and awesome) Reaver Pro tool.  - [From web to mobile to connected cars – here are some application security resources you need to check out](https://www.principlelogic.com/blog/mobile-apps/from-web-to-mobile-to-connected-cars-here-are-some-application-security-resources-you-need-to-check-out/): Given all of the variables and complexities associated with information security, I still believe that application security is the biggest weakness in most organizations and the one area where we can truly effect the greatest change. Here are some pieces that I have written recently regarding web and mobile app security that you might enjoy: - [My new content on preventing ransomware + infosec leadership and careers](https://www.principlelogic.com/blog/security-leadership/my-new-content-on-preventing-ransomware-infosec-leadership-and-careers/): An unfunded mandate is not a mandate - [The real reasons behind the WannaCry ransomware](https://www.principlelogic.com/blog/hacking/the-real-reasons-behind-the-wannacry-ransomware/): As we continue down the path of yet another major security breach - this time with the ransomware WannaCry - let us remember that it's not just about the criminal hackers, out-of-control government agencies such as the NSA, or vendors such as Microsoft putting out vulnerable software. Every single one of us working in IT, security, and business today are complicit in these challenges. - [My CSO interview/story: What it takes to be an independent information security consultant](https://www.principlelogic.com/blog/message-from-kevin/my-cso-interview-story-what-it-takes-to-be-an-independent-information-security-consultant/): I'm very honored to have been interviewed recently for CSO Magazine about my background and what it takes to stand out - and survive - as an independent security consultant. Check it out here: - [Thoughts on the 2017 Verizon DBIR, hacking security policies, breaking into the infosec field, ransomware and more](https://www.principlelogic.com/blog/kevins-security-content/thoughts-on-the-2017-verizon-dbir-hacking-security-policies-breaking-into-the-infosec-field-ransomware-and-more/): Here are some recent pieces I've written for the good people at IANS: - [Why SOC audit reports can be misleading, mobile app security gotchas, and more…](https://www.principlelogic.com/blog/mobile-apps/why-soc-audit-reports-can-be-misleading-mobile-app-security-gotchas-and-more/): Common oversights in mobile app security - [People will violate your policies all day long…if you let them.](https://www.principlelogic.com/blog/people-problems/people-will-violate-your-policies-all-day-long-if-you-let-them/): I recently saw this out in front of a local restaurant where management was trying to resolve parking, sidewalk access, and traffic issues. Their "control" obviously doesn't work: - [Outsourcing security monitoring, guest wireless network risks, and more infosec content to help your business](https://www.principlelogic.com/blog/security-testing-tools/outsourcing-security-monitoring-guest-wireless-network-risks-and-more-infosec-content-to-help-your-business/): I can't believe that I recently submitted my 1,000th article...it's been a long time coming! I first started writing in 2001 and it has been one of the best things I ever did. Thanks so much for your support over the years! - [Web and mobile application security vulnerability and penetration testing resources](https://www.principlelogic.com/blog/mobile-apps/web-and-mobile-application-security-vulnerability-and-penetration-testing-resources/): Application security is no doubt one of the most important aspects of a security program. Here are some new pieces I've written that can help keep your web and mobile app vulnerabilities in check and your application security program on the right track...pay special attention to the last one regarding security assessments and reality: - [Email phishing services: Just what you need to know to start mastering the task](https://www.principlelogic.com/blog/penetration-testing/email-phishing-services-just-what-you-need-to-know-to-start-mastering-the-task/): Got phished? Of course you have...whether you know it or not!  - [Getting to know your network with Managed Switch Port Mapping Tool](https://www.principlelogic.com/blog/cool-products/getting-to-know-your-network-with-managed-switch-port-mapping-tool/): In my years performing independent network security assessments, one thing that has really stood out to me is the lack of network insight. Regardless of the size of the organization, the industry in which they operate, and the level of security maturity, in most cases, I see IT and security shops with very little: - [Prepping for – or dealing with – a computer security incident? Here are some resources for you.](https://www.principlelogic.com/blog/security-leadership/prepping-for-or-dealing-with-a-computer-security-incident-here-are-some-resources-for-you/): Questions that must be answered once a security breach occurs - [Children’s Hospital Los Angeles breach reminds us that HIPAA means nothing if you ignore its requirements](https://www.principlelogic.com/blog/security-leadership/childrens-hospital-los-angeles-breach-reminds-us-that-hipaa-means-nothing-if-you-ignore-its-requirements/): Back in 2007 I wrote a blog post on what's it going to take to encrypt laptop hard drives. After seeing this recent story about Children's Hospital Los Angeles, I can't help but shake my head. - [Hacking is not just an action, it’s an excuse](https://www.principlelogic.com/blog/hacking/hacking-is-not-just-an-action-its-an-excuse/): Given all the ridiculous analyses and "findings" on Russian hacking as of late such as federal government bureaucrats who said there's no evidence to prosecute Clinton or who claim that the NSA does not collect data on America citizens yet they're certain that the Russians meddled in the U.S. election - many assertions of which are coming from talking heads with zero experience working in this field - I thought this blog post I wrote back in June of 2011 was worthy of a re-post: - [Keys to a great 2017](https://www.principlelogic.com/blog/message-from-kevin/keys-to-a-great-2017/): Welcome to 2017!  - [Trump’s an expert on hacking too, huh?](https://www.principlelogic.com/blog/hacking/trumps-an-expert-on-hacking-too-huh/): Yesterday, soon-to-be President Donald Trump showed just how ignorant politicians can be when it comes to computer security, breaches, and hacking. Referring to the Russians interfering with our recent election, the Donald said: - [Using NowSecure for automated mobile app testing](https://www.principlelogic.com/blog/mobile-apps/using-nowsecure-for-automated-mobile-app-testing/): As an independent information security consultant, I'm always looking for good testing tools to rely on for my work. These tools, such as vulnerability scanners, network analyzers/proxies, and related manual analysis tools, are not the be-all-end-all answer for uncovering security weaknesses, but they are a very important aspect of what I do. Be it more generic vulnerability scans, a targeted penetration test, or a broader, more in-depth, security assessment, I simply don't have the time or brainpower to forgo using good tools. - [Careers in information security, dealing with ransomware, and more](https://www.principlelogic.com/blog/security-leadership/careers-in-information-security-dealing-with-ransomware-and-more/): With the field information security as popular as ever, I thought this would be a good time to share some pieces I've written on breaking into the field along with a few more on information security leadership. Oh, and I've thrown in a couple of pieces and a webcast on ransomware since that's a big deal these days. Enjoy!10 Tips for Breaking into the Infosec Field  - [Join me along with ISACA and TechTarget today to learn about how to advance your infosec career!](https://www.principlelogic.com/blog/message-from-kevin/join-me-along-with-isaca-and-techtarget-today-to-learn-about-how-to-advance-your-infosec-career/): I'm happy to announce that I'll be joining ISACA and TechTarget for their annual online security seminar - a day-long learning event for IT and information security professionals.  My session this afternoon, which starts at 3:30pm ET, will be I Can Do versus I Have Done...Certification, Experience, and the Information Security Career Path. - [People Behaving Badly and information security’s tie-in](https://www.principlelogic.com/blog/cool-sites/people-behaving-badly-and-information-securitys-tie-in/): Last week, I had the opportunity to travel to the Bay Area in California to record an information security video (thanks Intel and TechTarget!). Of course, I couldn't travel across the country and not see the sights of San Francisco. A most excellent highlight of the trip was for my son and I to meet television and social media celebrity, Stanley Roberts. My son is a huge fan of Stanley's, has learned a ton from him (me too!), and was over the moon-excited to be able to meet him in person. - [What, exactly, is reasonable security? The state of California knows!](https://www.principlelogic.com/blog/security-leadership/what-exactly-is-reasonable-security-the-state-of-california-knows/): With all that's happening in the world of information security, it seems that there's never enough regulation. From to HIPAA to the state breach notification laws to PCI DSS and beyond, there are rules - and guidance - around every corner. Oddly enough the breaches keep occurring. As if what we've been told up to this point is not reasonable enough. Some people, mostly federal government bureaucrats and lawyers who stand to benefit from such power, believe we need more regulations. Some are even attempting to rebrand information security as "cybersecurity" which only serves to create another layer of complexity and hurt our cause long-term. - [How to (finally) get your information security program on track](https://www.principlelogic.com/blog/kevins-security-content/how-to-finally-get-your-information-security-program-on-track/): Here's some of my latest content...this time on running a well-oiled information security program. Enjoy! ## Pages - [Cloud Security](https://www.principlelogic.com/cloudsecurity/): Cloud security You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Windows](https://www.principlelogic.com/windows/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Webapps](https://www.principlelogic.com/webapps/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [VOIP](https://www.principlelogic.com/voip/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Toolstesting](https://www.principlelogic.com/toolstesting/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Testimonials](https://www.principlelogic.com/testimonials/): The following are testimonials from my Fortune 500, mid-market enterprise, Internet startup, software development, state and local government, and non-profit clients. Click here for testimonials on my speaking engagements. - [Storage](https://www.principlelogic.com/storage/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Social Engineering and Phishing](https://www.principlelogic.com/socialengineering/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Security Speaker](https://www.principlelogic.com/securityspeaker/): The following are testimonials on keynote presentations, seminars, webcasts and other talks I've given: - [Policies](https://www.principlelogic.com/policies/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Physical Security](https://www.principlelogic.com/physical/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Passwords](https://www.principlelogic.com/passwords/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Mobile](https://www.principlelogic.com/mobile/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Messaging](https://www.principlelogic.com/messaging/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Management](https://www.principlelogic.com/management/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Malware](https://www.principlelogic.com/malware/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [IoTsecurity](https://www.principlelogic.com/iotsecurity/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Incident Response](https://www.principlelogic.com/incidentresponse/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Databases](https://www.principlelogic.com/databases/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Compliance](https://www.principlelogic.com/compliance/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Careers](https://www.principlelogic.com/careers/): You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. - [Advanced Malware Paper](https://www.principlelogic.com/advancedmalware/): I appreciate your interest in my paper The Malware Threat Businesses are Ignoring and How Damballa Failsafe Fits In - [Contact](https://www.principlelogic.com/contact/): Contact Principle Logic, LLC 1720 Mars Hill Rd. Suite 8-343 Acworth, GA 30101 kbeaver@principlelogic.com   - [Blog](https://www.principlelogic.com/blog/) - [Resources](https://www.principlelogic.com/resources/): Principle Logic blog - [Services](https://www.principlelogic.com/services/): Network security assessments are great for discovering technical weaknesses that exist in your broader group of network hosts. Using well-known and widely-accepted commercial tools as well as in-depth manual analysis I will look at your external and/or internal systems (including Internet of Things/IoT devices, medical devices, and Operational Technology/OT systems) from the perspective of an untrusted outsider, trusted insider, or both. I can test your wireless (Wi-Fi and others) networks as well for common flaws as it relates to weak encryption keys and misconfigured guest wireless networks. I can also perform open source intelligence (OSINT) of your Internet domains and/or employees to uncover potentially sensitive information that is being exposed. - [Home](https://www.principlelogic.com/): Kevin Beaver is the founder and principal consultant of Principle Logic, LLC. He is an independent information security (a.k.a. cybersecurity) expert who helps businesses uncover real risks, protect systems and information, and make smarter security decisions without wasting time or money. - [About](https://www.principlelogic.com/about/): Kevin is an independent computer and information security (a.k.a. cybersecurity) consultant, professional speaker, and writer with over 38 years of experience in IT - the last 32 of which he has dedicated to security. Before starting Principle Logic in 2001, Kevin served in various information technology and security roles for several healthcare, e-commerce, financial firms, educational institutions, and consulting organizations.