Preventative maintenance, risk quantification, navigating the uncanny valley, continuous assurance, architectural choices to reduce whole classes of risk and more.
www.philvenables.com/post/securit...
Preventative maintenance, risk quantification, navigating the uncanny valley, continuous assurance, architectural choices to reduce whole classes of risk and more.
www.philvenables.com/post/securit...
philvenables.com/post/securit...
philvenables.com/post/securit...
Resilience is about capabilities not just plans.
www.philvenables.com/post/everyon...
Resilience is about capabilities not just plans.
www.philvenables.com/post/everyon...
A new NASEM report reveals the truth about #cybercrime stats: our data is fragmented, inconsistent, & underreported. We can't fight what we can't accurately measure.
www.philvenables.com/post/decodin...
A new NASEM report reveals the truth about #cybercrime stats: our data is fragmented, inconsistent, & underreported. We can't fight what we can't accurately measure.
www.philvenables.com/post/decodin...
A lot of premature CISO turnover is caused by the security program uncovering previously unknown risks and issues. So, paradoxically, the best CISOs make the situation *seem* worse before it then *actually* gets better.
www.philvenables.com/post/career-...
A lot of premature CISO turnover is caused by the security program uncovering previously unknown risks and issues. So, paradoxically, the best CISOs make the situation *seem* worse before it then *actually* gets better.
www.philvenables.com/post/career-...
My analysis of the recent Cyentia Institute report. Things are getting worse in absolute terms but it’s not clear (my take) they are getting worse relative to what the situation might be.
www.philvenables.com/post/cyber-i...
My analysis of the recent Cyentia Institute report. Things are getting worse in absolute terms but it’s not clear (my take) they are getting worse relative to what the situation might be.
www.philvenables.com/post/cyber-i...
Thinking about doctrine vs. structure is a useful mental model to validate a technology’s adequacy for a particular task. In short, to know whether we are jamming a square peg into a round hole.
www.philvenables.com/post/segment...
Thinking about doctrine vs. structure is a useful mental model to validate a technology’s adequacy for a particular task. In short, to know whether we are jamming a square peg into a round hole.
www.philvenables.com/post/segment...
www.philvenables.com/post/ciso---...
www.philvenables.com/post/ciso---...
Not many security books. Security leader challenges are mostly, well, leadership along with a healthy dose of program mgmt, culture, attention to detail, risk mgmt and more.
www.philvenables.com/post/leaders...
Not many security books. Security leader challenges are mostly, well, leadership along with a healthy dose of program mgmt, culture, attention to detail, risk mgmt and more.
www.philvenables.com/post/leaders...
This post explores the "flywheel" concept and its application to security, demonstrating how to create self-reinforcing cycles that improve effectiveness.
www.philvenables.com/post/turning...
This post explores the "flywheel" concept and its application to security, demonstrating how to create self-reinforcing cycles that improve effectiveness.
www.philvenables.com/post/turning...
www.philvenables.com/post/post-qu...
www.philvenables.com/post/post-qu...
In closing the year let’s take a look at the top 10 posts of 2024 in order of most read.
www.philvenables.com/post/top-ide...
In closing the year let’s take a look at the top 10 posts of 2024 in order of most read.
www.philvenables.com/post/top-ide...
Then take a listen to the 2024 season finale of the cloud security podcast.
cloud.withgoogle.com/cloudsecurit...
Then take a listen to the 2024 season finale of the cloud security podcast.
cloud.withgoogle.com/cloudsecurit...
- Year end review from AI to Threats
- Forecast for 2025
- AI ISO certifications
- NIS2 compliance
- Threat intel. program development
- Detection as code
- and much more….
cloud.google.com/blog/product...
- Year end review from AI to Threats
- Forecast for 2025
- AI ISO certifications
- NIS2 compliance
- Threat intel. program development
- Detection as code
- and much more….
cloud.google.com/blog/product...
sketchplanations.com/the-three-br...
sketchplanations.com/the-three-br...
Read more on what this means here:
cloud.google.com/blog/product...
Read more on what this means here:
cloud.google.com/blog/product...
- Forecasting 2025: Notes from the Field
- Open source security patch validation
- C2 in browser isolation environments
- Every CTO should be a CTSO
- and more......
cloud.google.com/blog/product...
- Forecasting 2025: Notes from the Field
- Open source security patch validation
- C2 in browser isolation environments
- Every CTO should be a CTSO
- and more......
cloud.google.com/blog/product...
Read here: www.theatlantic.com/sponsored/go...
Read here: www.theatlantic.com/sponsored/go...
Most cyber controls are relatively aligned. Calls for action on harmonization are really induced by obligations from other technology risk domains or broader. Focusing on reducing compliance toil is the right approach.
www.philvenables.com/post/regulat...
Most cyber controls are relatively aligned. Calls for action on harmonization are really induced by obligations from other technology risk domains or broader. Focusing on reducing compliance toil is the right approach.
www.philvenables.com/post/regulat...
www.ben-evans.com/presentations
www.ben-evans.com/presentations