Eric Parizo

2.1K posts

Eric Parizo

Eric Parizo

@EricParizo

Vendor content marketer; former industry analyst. I tweet on new #infosec research & market strategy. Snark warning always in effect.

Kansas, USA Katılım Ocak 2012
32 Takip Edilen728 Takipçiler
Eric Parizo
Eric Parizo@EricParizo·
.@RSAConference USA is officially bigger than ever: #RSAC2025 final attendance is just under 44k (43,500+), up from 41k attendees in 2024 & topping the previous all-time high of 42,500 in 2019. Also #RSAC2026 will be in calendar Q1, slated for March 23-26 in SF. #RSAC
RSAC@OneRSAC

#RSAC™ Conference Wraps 34th Annual Flagship Event with Many Voices, One Community. Read more: spr.ly/60102LUt2

English
0
1
0
74
Eric Parizo
Eric Parizo@EricParizo·
As #RSAC2025 begins, here's a great snapshot of what adversaries are now focused on, and in turn what CISOs should be pivoting to detect & prevent.
Florian Roth ⚡️@cyb3rops

We’re seeing a clear trend: attackers are bypassing the endpoint entirely. Not just avoiding traditional EDR-monitored systems by pivoting to embedded and edge devices, but now also operating purely in the cloud. No shell, no malware, no persistence on the endpoint. Just an OAuth token and full access to whatever’s in the victim’s Microsoft 365, Google Workspace, or AWS console. It’s a complete inversion of how things used to be. The endpoint, once the weakest link, is now usually the most monitored, most policy-enforced part of the infrastructure. You’ve got EDRs, SIEM integration, automation, threat hunting - the full stack. But attackers don’t need to touch it anymore. Instead, they go after the new soft spots: - Cloud platforms, where logging is limited, expensive, or off by default - Network devices and appliances, which are practically blind spots - obscure OSes, no EDRs, hard to monitor, hard to forensicate. - Embedded systems and IoT junk that no one really knows how to secure, but that sit in critical network paths. Cloud especially is a mess: - Logging tiers cost extra and the good stuff is behind paywalls. - Detection content is lacking, both from vendors and the community. - You don’t get memory dumps or full control like you do on endpoints. - You’re at the mercy of the provider when it comes to visibility and response. And that’s the shift: attackers aren’t hacking computers anymore. They’re hacking trust relationships, identities, and APIs. The whole idea of detection and response needs to evolve with that. Otherwise, we’re securing the hell out of endpoints while attackers happily fish through mailboxes and cloud shares from halfway across the planet.

English
0
0
0
36
Eric Parizo
Eric Parizo@EricParizo·
Best wishes to everyone attending #RSAC 2025 next week. I will be focusing on my new role, but will miss many friends, colleagues, and the buzz of the event. I will *not* miss making lap after lap in and around Moscone on foot!
English
0
0
0
41
Eric Parizo
Eric Parizo@EricParizo·
Important new primary research: The app for your internet-connected litter box should NOT require your wifi network password for connectivity. (Manufacturers should ensure the device can connect directly and securely w/o an app. Software is always the weakest link!) #IoTsecurity
English
0
0
0
44
Eric Parizo
Eric Parizo@EricParizo·
Great quote from special guest Venus Williams, borrowed from Billie Jean King: “Pressure is a privilege… it means that you’re doing things and going places.” #opentextworld
Eric Parizo tweet media
English
0
0
2
102
Eric Parizo
Eric Parizo@EricParizo·
Barrenechea on integration: "With enterprise security you need to compose a solution. No company can do it all. All the (technology) partners in your ecosystem throw off security events, so you have to do it in a composable way, connecting disconnected islands." #OpenTextWorld
Eric Parizo@EricParizo

Barrenechea on @OpenText security strategy: "We’re here to make security as important as anything we do... We think it’s no longer human vs machine, it’s machine vs machine." #OpenTextWorld

English
0
0
0
187
Eric Parizo
Eric Parizo@EricParizo·
Barrenechea: "We’re going to continue to extoll that security is job one… built all the way into the software, and it needs to work across multicloud." #OpenTextWorld
Eric Parizo@EricParizo

I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld

English
0
0
0
87
Eric Parizo
Eric Parizo@EricParizo·
I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld
Eric Parizo@EricParizo

Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld Key Qs: Is this *really* a security company vs an information management co w/ security? Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber

English
0
0
0
101
Eric Parizo
Eric Parizo@EricParizo·
Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld Key Qs: Is this *really* a security company vs an information management co w/ security? Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber
Eric Parizo tweet media
English
0
1
2
103