Concerning News I’m very concerned about the current implementation of the UK’s Online Safety Act and the emerging digital identity framework, particularly in relation to fairness, civil liberties, and recent proposals relating to VPN restrictions. While I fully support the goal of making the internet safer, I’m worried that the direction being taken, which may unintentionally harm the very gr...
Best Practice Throughout my career in InfoSec, I must have heard the term “Information Security best practice” thousands of times. I didn’t think too much about it until recently, waving it off as a heuristic way to describe how something is “appropriately secured”, or “secured in line with an industry’s expectations”. The term bothered me and I knew some colleagues who had a distaste for it,...
Scene setting Over the last few years, I’ve witnessed many organisations express pretty negative views and misplaced ideas about DevOps and Agile, while sometimes using them as excuses to sidestep process gates and governance. In response, I’ve often tried to explain the benefits and specific uses of DevOps and Agile practices, and attempted to correct those who abuse DevOps and Agile terms t...
What is Vulnerability Management? Well, running a periodic Nessus scan on some of your organisation’s stuff ain’t it. That’s because it’s a full lifecycle of tools, team collaboration and processes, including: Periodic/continuous scanning of all your organisation’s assets, using various tools Informed measurement and prioritisation of findings from these tools The remediation of t...
How Information Security (InfoSec) Risk Management can practically improve the security posture of your organisation if implemented correctly. Introduction The purpose of this article is to clearly describe how InfoSec Risk Management can tangibly improve the security posture of your organisation while outlining some common pitfalls and mistakes. TL;DR Risk Management provides methodolog...