Category: Compliance

  • Tales From the Front Line

    Mortality and all that… It was my birthday recently – a major one! Thank you. That’s kind. Being a dutiful Dad, as my tachograph creeps inexorably towards the ‘mandatory end of journey’ marker, I’ve been spending a lot of time and pulling out a few more grey hairs, trying to make sure that my children…

  • Response to the Response to Panorama

    It’s been suggested that the media are to blame for mythologising cyber security. I don’t think so. The myths and distorted narrative start with an industry that presents the practice as something to be conducted solely by magicians – “It’s a dark art – most people won’t understand it”. And it is indeed a dark…

  • Costs and Benefits

    Getting to Zero Every so often, I see a post asking “How can we make [ransomware] [phishing] [cybercrime generally] (delete as appropriate) a thing of the past?” I very much doubt that you can. There are at least two reasons: So, Point One: there will always be cybercrime. There, I said it. Management Before asking…

  • Change is Hard

    There’s a strong argument that security comes about through negotiation, rather than calculation. If so, then it might be more productive to see the process of arriving at the state of security as a discussion between stakeholders. However, the current situation isn’t so much a negotiation. It’s more a lecture. Having a single very loud…

  • Why Security Change is Hard

    Doing the Basics It’s weird. Year after year, report after report concludes that most cyber incidents could be prevented through the application of basic hygiene. I mean, it’s not weird that the reports come to that conclusion. But it is weird that it’s still being reported. Source: Microsoft Digital Defence Report 2023 In 2021 the…