J. 🧢

8.3K posts

J. 🧢 banner
J. 🧢

J. 🧢

@CxOSidekick

'You've been making the wrong mistakes' - Thelonious Monk

Katılım Ocak 2012
714 Takip Edilen901 Takipçiler
J. 🧢 retweetledi
Alex
Alex@alexanderjaeger·
How to use AI / LLM in incident response: security.googleblog.com/2024/04/accele… Yes it makes our job really faster. I am glad it can be shared, so folks can take it as inspiration where AI is potentially useful. Kudos to all people involved, the authors of the post and the whole team.
English
2
39
129
51.2K
J. 🧢
J. 🧢@CxOSidekick·
@mattjay You need to work with a dev team who have a reputation for being unresponsive to any ask from security. Scanners shows multiple high sev findings for their services. You randomly find yourself stuck in a lift with the manager. What's your pitch to get a meeting with them?
English
0
0
1
264
Matt Johansen
Matt Johansen@mattjay·
What is your favorite question to ask someone when interviewing them for a job in infosec?
English
101
19
146
102.8K
J. 🧢
J. 🧢@CxOSidekick·
@philvenables As @Dantiumpro once told me, operators know it's not a single pane of glass to look through, but 'a single place to stand' from where they can ask many questions of the territory.
English
0
0
3
0
Phil Venables
Phil Venables@philvenables·
Security management. When I see orgs focusing on getting to a "single pane of glass" all they get is a "single pain of glass" that they have to constantly push to one side to get to the underling functions of the abstracted tools that they need when responding to an event.
English
12
18
123
0
J. 🧢
J. 🧢@CxOSidekick·
Great thread!
English
0
0
2
0
J. 🧢
J. 🧢@CxOSidekick·
@alexhutton I divide into 4 key folders / subfolders (sfs) - Team (sfs = hiring, updates, goals) - Processes (sfs = names of cyclical operational recurring processes) - Projects (sfs = names of projects) - Tools (sfs = names of each tech) - Legal (anything from Legal)
English
0
0
2
0
J. 🧢
J. 🧢@CxOSidekick·
@Beaker I guess a different view on that is 'diversity' should not mean 'disorder'. Diverse things that interact are more complex. If you can manage that, then you have good feedback loops. If you don't, you have chaos. Reduction of disorder over time != Standardization in all cases.
English
1
0
1
0
Christofer Hoff
Christofer Hoff@Beaker·
(2/2) Since we are told “defense in depth” is important and that diversity in suppliers is, too, how does one thread the needle here? A mono-ish-culture also presents a risk. Anyone have e.g. of where complexity increased attacker cost & thus improved security? I do 😜 #debate
English
1
1
1
0
Christofer Hoff
Christofer Hoff@Beaker·
(1/2) I just read an interesting story about how to improve a company’s security posture: “Standardize—The cost of security increases as the complexity of the environment increases.” <- OK, but what from nature or recent attacks would suggest a downside here of fewer “things”?
English
1
1
2
0
J. 🧢
J. 🧢@CxOSidekick·
Access control has, traditionally, been a strong point of system design.
English
0
0
0
0
J. 🧢
J. 🧢@CxOSidekick·
@Beaker Don't do today what you can put off until tomorrow.
English
0
0
0
0
Christofer Hoff
Christofer Hoff@Beaker·
I resemble this remark. Entirely.
English
5
1
24
0
J. 🧢
J. 🧢@CxOSidekick·
@Beaker But yet I tentatively accept, like I perhaps intenta.
English
1
0
2
0
Christofer Hoff
Christofer Hoff@Beaker·
If you send a meeting request with no agenda, then I no-attenda.
English
5
17
183
0
J. 🧢
J. 🧢@CxOSidekick·
Trip home this weekend.
J. 🧢 tweet media
English
0
0
4
0
J. 🧢
J. 🧢@CxOSidekick·
The lost art of security project management is making it easy for teams to do the work, and making the work easy for them to do.
English
0
0
1
0
J. 🧢
J. 🧢@CxOSidekick·
@forrestdougan Ha, brilliant. Thanks for sharing that. The reality of what gets results vs the dogma of dashboards never ceases to amaze!
English
0
0
1
0
J. 🧢
J. 🧢@CxOSidekick·
What if the answer was never a dashboard after all, but a tailored set of personalized actionable insights delivered via email to 100s of management inboxes, all done from a cheap Windows machine using Pandas and 20 .csv downloads?
English
1
5
17
0
J. 🧢
J. 🧢@CxOSidekick·
@jack_naglieri pretty sure that's what every VC promises with their 'platform'
English
1
0
0
0
Jack
Jack@jack_naglieri·
is there stackoverflow for startups
English
1
0
1
0
J. 🧢
J. 🧢@CxOSidekick·
@gableingaround 100 pages? Now you're just being silly. Although if not, Pandas would actually let you do that. Also, pesky line graphs. Think how much shorter your docs would be with pie charts.
English
0
0
0
0
J. 🧢
J. 🧢@CxOSidekick·
@forrestdougan I assume comedy snark, but if instead this was a mocking tweet I can point you in the direction of some reading material
English
1
0
0
0