Attack Surface Reduction By Dynamic Compilation

1850 words, 9 1⁄2 minutes. …or, how the cave fish lost his eyes. This post follows directly from the last. In that post we learned that everyone could do something to reduce their attack surface and decrease the likelihood of breach. I’m going to show you what that winning system looks like when taken to its ultimate logical conclusion. The logic goes something like this: Software security flaws are commonplace. »

Winning Systems & Security Practitioners 7. Attack Surface Reduction

2000 words, 10 minutes. Attack Surface Reduction “Out of every hundred men, ten shouldn’t be there, eighty are just targets” Heraclitus 535 - 475 BC. My posts on Winning Systems for Cyber Security Practitioners are my most popular. In them I attempt to change your perspective on the relative importance of products and skills in securing what’s precious to you. I make the case for using systems (in the broadest sense of the word) not goals. »

Geopolitics For Fun & Profit

1750 words, 9 minutes. “Who rules East Europe commands the Heartland. Who rules the Heartland commands the World-Island. Who rules the World-Island commands the world.” - Sir Halford Mackinder, Democratic Ideals and Reality. 1919. Do you work in technology, are you building a company? You should think about how your product or service fits with the wider world, because aligning with large movements is a winning system. Amongst my tweets on Cyber Security, Product Management, and company building, I occasionally mention International Relations or Geopolitics. »

A Universal Lemma For Compliance

2500 words, 12 minutes. Here I describe a lemma1 or helping theorem for technical compliance of IT with a focus on Information Security. It’s an approach for all compliance regimes whether regulatory or corporate. It doesn’t date, nor is it predicated on a technology or platform. It isn’t a trick. It doesn’t provide cover for inadequate security or incompetent staff. If you’re looking to evade compliance, disguise incompetence, or shirk accountability then you’re in the wrong article. »

The Largest Open Goal In Cyber Security

1000 words, 5 minutes. “But how was one to explain repeated instances of derisive laughter at melodramas and films that hardly set out to be funny?” - Prof. Eric Rentschler1 Out of place laughter is an anarchist in the dark. Someone who refuses to let the film cast its spell. Imagery is important. Moving or still. Whether it be religious iconography, depictions of national myth, a coat of arms, a rallying military standard, your company’s brand, or something as incidental as clip art. »