Tag: Decisions

  • Social Construction

    If you’ve worked in Government security, you’ll be aware of the process of reviewing independent third party vulnerability assessments. Line item by line item, the report is reviewed and discussed, usually by the approval authority, the project and the test team. The test team may arrive with the objective of making sure that their commercial…

  • Costs and Benefits

    Getting to Zero Every so often, I see a post asking “How can we make [ransomware] [phishing] [cybercrime generally] (delete as appropriate) a thing of the past?” I very much doubt that you can. There are at least two reasons: So, Point One: there will always be cybercrime. There, I said it. Management Before asking…

  • Environmental Concerns

    Egon Brunswick (1903-1955) argued that organisms (read “people”) exist within an environment with which they interact, and which in part shapes their behaviour. So the idea has been around for a while now, but security practitioners don’t seem to have caught on to its relevance to cyber. Instead, users are given advice based on the…

  • That’s why they call it research…

    Research, at least as far as the cyber industry is concerned, seems to take a limited number of forms. For the most part, it seems to be about looking for technical vulnerabilities. Sometimes it appears as a sentence starting “Research proves that…”, usually in a message from a cyber company with kit to sell. Occasionally…