RSSAmplifier

Blog

Thom Langford

Award winning* Blogging, so you don't have to.

thomlangford.comRSS feed ↗10 posts

Latest posts

Here is What the Rugby 6 Nations Taught me About B2B Marketing*

I reflect on the rugby Six Nations tournament's final match and draw parallels to cybersecurity, emphasising collaboration and camaraderie in both fields for improved performance and mutual support. It's also evidence of Brian Honan being an England supporter, even if for just one night.

Taking Care of Business

I remember back in early 1996 arriving home from work and telling the future ex Mrs Langford that was going to be very busy "for the next two to three months". There was a project going on that I decided I was going to get involved in (outside of my normal IT Manager day job) and that it was going to be good for my career. In modern parlance, I had decided to "lean in".

You, Me, and Dystopia

We all remember the Ocean's 11 styles of antics that criminals can emulate to gain access to IoT devices and, subsequently, the enterprise network on which they are hosted. It may have been an isolated incident, but it underscores that ANY vulnerability can be exploited.

Beer, PowerPoint and Politics

Gone are the days when being a CISO (or even just ‘the security guy/gal’) was about actual information security or IT security. Even the term IT Security is outdated now and emphasises a one-dimensional view of what security is really about. However, I digress…

When It All Goes Pete Tong…

Murphy's Law states, "If something can go wrong, it will go wrong". Many CISOs will also state that "it is not a case of if you have been breached, but rather that you have, you just don't know it yet".

We Have Both Types of Teaching Here; Education AND Awareness

It is an accepted truth (trust me, I am a professional), that security is often seen as just a technical profession; firewalls, DLP, DMARC, SFTP and TLAs (Three Letter Acronyms)are thrown around with gay abandon.

CISO Basics, Part 2

In this post, we will take this a step further and closer to actual business as usual and maintaining your security team as a functional part of the organisation.

CISO Basics, Part 1

So you want to be a CISO? Perhaps you want to be a better CISO? In many cases, you could pick up a book, attend a conference or even talk to some peers and colleagues. Of course, there will be some good advice in these approaches too, but you don't want to be just any CISO; you want to be THE CISO.

Risky Business

Risk is a topic that I like to talk about a lot, mainly because I managed to get it 'wrong' for a very long time, and when I finally did realise what I was missing, everything else I struggled with fell into place around it. For me, therefore, Risk is the tiny cog in the big machine that, if it is not understood, greased and maintained, will snarl up everything else.

Document and Review

It's unlikely that you will read a more dull and despairing title for a practical blog series than "Document & Review", and there is a high chance that you will even consider skipping this one. If you do, however, you will be missing the most foundational aspect of your entire information security programme.