PATCH Act: No More Phat Lootz?

It would be an understatement to say that people were upset about EternalBlue.  Microsoft apparently was already upset about it before WannaCry, but was even more upset afterwards, calling for a “Digital Geneva Convention.” If you haven’t been...

Musings on cyber “atomic bomb”

Do you remember this comment from Andrey Krutskikh back during Infoforum 2016? “You think we are living in 2016. No, we are living in 1948. And do you know why? Because in 1949, the Soviet Union had its first atomic bomb test. And if until that moment… the...

Not training… outcomes

Today I came across an article from Harvard Business Review stating that “The Best Cybersecurity Investment You Can Make Is Better Training”.  Is it?  Is it really?  The economic return of training – i.e. the value for money associated with security...

WannaCry lessons, patching redux

So I promised yesterday that I would continue the discussion of the rampant foolishness that is “WannaCry” – and more importantly the lessons that we can learn from it.  I talked yesterday about what I perceive to be issues with the way that we as an...

WannaCry: So much distraction

So you maybe noticed there was some ransomware going around recently?  Sure you did.  If you’ve been in a coma for the past three days, a few things you need to know: she isn’t really your fiance (and she’s going to wind up with Bill Pullman anyway...