Daniel Woods รีทวีตแล้ว
Daniel Woods
883 posts

Daniel Woods
@IelTop
I research the economics of cybersecurity & privacy Cyber risk science at @SolveCyberRisk @EdinburghUni My own thoughts
เข้าร่วม Nisan 2011
793 กำลังติดตาม798 ผู้ติดตาม

I moved to <the other platform> and hope others will join.
@CDra_90n set up a "security economics" follower-pack so you can quickly build a network of WEIS-y people.
Contact one of us if you join <the other platform> and want to be added to the starter-pack.
English

@RobTerrin Apparently it's the old number because that was 2004!
Buffet as an unlikely Gen Z who thinks you need $500k a year for a comfortable life.
English

Wait... $10M is the new number for "so they can do anything but not enough that they can do nothing"!?!?
Evan@StockMKTNewz
Warren Buffett who is currently the 7th richest person in the world worth $150,000,000,000.00 just sent out this letter explaining his thoughts on distributing his wealth after he passes away A thread 🧵⬇️
English

@rossjanderson @CDra_90n also scraped a bunch of descriptive stats on team size, finding that the biggest teams have 500+ members.

English

My favourite finding is that these teams function like labour unions in negotiating with large tech companies to receive fair bug bounty payouts.
This fighting for the little guy was very much @rossjanderson.
English

Very proud of @CDra_90n who had his first article accepted at @IEEESSP.
The paper looks at the role of hacker teams in the Chinese bug bounty ecosystem.
We very sadly lost @rossjanderson mid way through this project.
computer.org/csdl/proceedin…
English

@RobTerrin @ravirockks @ollieatnowhere The real question is what's more expensive. Paying an InfoSec person not to do Infosec and instead learn a bit of insurance, or to pay an Insurance person to learn a bit of InfoSec 😀
English

Some points on whether insurance data is good data for general cyber risk modelling.
@ollieatnowhere, @IelTop, any views?
@TindrasGrove/113517028907060506" target="_blank" rel="nofollow noopener">infosec.exchange/@TindrasGrove/…
English

@ravirockks @ollieatnowhere The points about InfoSec expertise bothered me more, as if the industry hasn't thought about hiring/acquiring outside insurance.
English

@IelTop @ollieatnowhere Yeah, agree re the pessimism of the tone.
I mean, the samples in the Coalition, etc reports aren't tiny.
English
Daniel Woods รีทวีตแล้ว

The entire 3rd-edition of @rossjanderson's "Security Engineering" is available free as PDFs now!
cl.cam.ac.uk/archive/rja14/…
English

Interested in pursuing an MSc in Cyber Security, Privacy and Trust, freshly certified by @NCSC?
Register for our virtual open day next week to hear more: informatics.ed.ac.uk/postgraduate-v…
@InfAtEd @EdinburghUni

English

Overview of the recent (lack of) progress towards establishing a software liability regime.
therecord.media/cybersecurity-…
English
Daniel Woods รีทวีตแล้ว

📅 Join us on 29 October for an online panel on the cyber insurance industry’s efforts to shape global cybersecurity governance. Find our more on our website.
🗣Speaker include: @josephinecwolff, @IelTop, and @tjohansmeyer.
my.rusi.org/events/webinar…
English

@ale_paulus @CyberStatecraft This kind of argument has been made for over a decade, but the availability of info has changed in the last few years.
For example, Sezaneh Seymour and I assembled info on security control efficacy in our 2024 article: tandfonline.com/doi/full/10.10…
English

"Policymakers and practitioners currently lack the capacity to evaluate the cybersecurity ecosystem and assess [...] which policies work and how well. The need for such an understanding is fundamental."
Good read by @CyberStatecraft 's Stew Scott.
lawfaremedia.org/article/counti…
English

@ravirockks @jamiemaccoll @arekfurt @jamiemaccoll will be able to speak to how insurers influence DFIR firms on payment decisions, but the influence won't be via wordings
English

@ravirockks @jamiemaccoll @arekfurt I think insurance wordings/disputes are a red herring.
They've made a court acknowledge the elephant in the room, e.g. that OFAC don't enforce ransomware sanctions. But that doesn't mean the specific wordings matter much.
English

@Maxwsmeets What do you see as the gold standard for estimating ransomware trends?
English

I appreciate IST's work and @craignewmark efforts but these statistics can be misleading without proper context.
The source of data matters; aggregated from leak sites.
craig newmark@craignewmark
#Ransomware attacks increased by 73% across the world in 2023, @IST_org and the #RansomwareTaskForce report. Once again, governments and hospitals were among the most targeted industries. Check out their map and learn more about how we can combat ransomware: securityandtechnology.org/blog/2023-rtf-…
English

