The WannaCry scramble

A couple of weeks ago, possibly every security manager in the world was dealing with the…

Email, email, in the cloud

As my company continues to move enterprise applications to the cloud, the latest development presents a…

Taming the SaaS security wilderness

The security risk that I am most focused on right now is this: Shadow IT and…

RSA Conference is a timesaver

I spent several days in San Francisco on my annual pilgrimage to the RSA security conference.Trouble…

Getting buy-in to combat risk

When I start at a new company, I make a point of meeting with key personnel…

The trouble with third-party assessments

When it comes to security, more is always better, right?That sounds good in the abstract, but…

Putting security risks on simmer with Chef

To remain PCI-compliant, I conduct quarterly security assessments of our infrastructure. This means external testing of…