Sitemap - 2024 - Cyber Cyber Cyber Cyber

If Education is the Solution to Your Security Problem, Then You've Already Failed

SOC 2 in Crypto is Pointless

Make Sure We Never Get Hacked

CISOs Need to Speak the Language of Business

The Cyber CRO

Bottom-up Security Doesn't Work

The real impact of an onchain hack: A comprehensive study of hack damage from 2021 to 2023

Damn the Torpedoes, Full Speed Ahead!

The North Korean Love Triangle

Stop Focusing on Black Swans When There are Known Knowns to Deal With

Web3 Security: Brittle or Resilient?

Following the Herd is Dangerous in Cybersecurity

Everyone Thinks They're a Security Expert

My Talk at ETHCC[7]

I'll Be Speaking at ETHCC[7]

Binary Thinking is Bad

Unwitting snake oil?

Do the Obvious Right Thing

Reading Shadows

Never Fight on Terrain of Your Opponent's Choosing

How Managing Black Swan Risks Makes You a Better Leader

"Defense in Depth" is Wrong

Cybersecurity is Like Playing 9-D Chess

CISA: Certification Dinosaur

In Praise of Tabletops

Microsoft Doubles Down on Security... Again... Again...

Cyber Street Smarts

Preventing Crypto Armageddon: A retrospective on Immunefi, 3 years later

Infosec vs. Cyber

Clicked on a phishing link? You're fired!

CISOs, Practice Your Airline Pilot Voice

Meet Mr. Risk

Customers Don't Care About Cybersecurity

Every CISO is a Scapegoat-in-Waiting

As CISO, Leave your Ego and Emotions at the Door

Human Beings Underestimate Risk

Does a CISO need an MBA?

The CISO is a Business Executive

Cyber Risk Quantification Makes No Sense

No More Magical Security Tools

Your Hardest Problem as a CISO isn't Technical

Dogmatic CISOs are Dangerous

Bugs are Law

Cyber Risk Quantification is Stupid and Bad (Part 3)

Cyber Risk Quantification is Stupid and Bad (Part 2)

Cyber Risk Quantification is Stupid and Bad (Part 1)

Recipe for a CISO

Most Security Tools Suck at Crypto Security

Why I Took 7 AWS Certs in the Last 6 Months

Why Negotiating Contracts is Part of Your Job as a CISO

There's No Such Thing As an Entry-level Security Engineer

Dollah Dollah Bill Y'all

The CISO as Orchestra Conductor