home.social

#securityculture — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityculture, aggregated by home.social.

fetched live
  1. I'm in love with the work of the No Trace Project, for example this text: To the International Anarchist Movement: Three Security Proposals

    notrace.how/blog/three-proposa

    #Anarchism #anarki #anarchismus #securityculture

  2. I'm in love with the work of the No Trace Project, for example this text: To the International Anarchist Movement: Three Security Proposals

    notrace.how/blog/three-proposa

    #Anarchism #anarki #anarchismus #securityculture

  3. I'm in love with the work of the No Trace Project, for example this text: To the International Anarchist Movement: Three Security Proposals

    notrace.how/blog/three-proposa

    #Anarchism #anarki #anarchismus #securityculture

  4. I'm in love with the work of the No Trace Project, for example this text: To the International Anarchist Movement: Three Security Proposals

    notrace.how/blog/three-proposa

    #Anarchism #anarki #anarchismus #securityculture

  5. I'm in love with the work of the No Trace Project, for example this text: To the International Anarchist Movement: Three Security Proposals

    notrace.how/blog/three-proposa

    #Anarchism #anarki #anarchismus #securityculture

  6. Let me present you the next part of the #peoplebehindosco series.

    Hi @nazneenr 👋

    Nazneen works at the intersection of security engineering, application security and cyber defense. Drawing on experience in software development, program management and security consulting, she enjoys building practical security programs that enable organisations to move fast while managing risk.

    Nazneen actively shares her experiences through conferences and community events, covering topics across cybersecurity and leadership. She believes the best ideas emerge from sharing knowledge and learning from the community. She is passionate about making security practical, fostering strong security cultures, and enabling teams to build secure software by design.

    Her tech chronicles (youtube.com/playlist?list=PL7E) can be found on Youtube and her insights on secure development and security culture are shared through blogs on Gitbook (nazneen-rupawalla.gitbook.io/l).

    More about her can be found at about.me (about.me/NazneenRupawalla).

    Her Tags: #AppSec #SecurityEngineering #ThreatInformedVulnerabilityManagement #WomenInTech #SecurityCulture #ThoughtLeadership

    Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.

    Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.

  7. Let me present you the next part of the #peoplebehindosco series.

    Hi @nazneenr 👋

    Nazneen works at the intersection of security engineering, application security and cyber defense. Drawing on experience in software development, program management and security consulting, she enjoys building practical security programs that enable organisations to move fast while managing risk.

    Nazneen actively shares her experiences through conferences and community events, covering topics across cybersecurity and leadership. She believes the best ideas emerge from sharing knowledge and learning from the community. She is passionate about making security practical, fostering strong security cultures, and enabling teams to build secure software by design.

    Her tech chronicles (youtube.com/playlist?list=PL7E) can be found on Youtube and her insights on secure development and security culture are shared through blogs on Gitbook (nazneen-rupawalla.gitbook.io/l).

    More about her can be found at about.me (about.me/NazneenRupawalla).

    Her Tags: #AppSec #SecurityEngineering #ThreatInformedVulnerabilityManagement #WomenInTech #SecurityCulture #ThoughtLeadership

    Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.

    Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.

  8. Let me present you the next part of the #peoplebehindosco series.

    Hi @nazneenr 👋

    Nazneen works at the intersection of security engineering, application security and cyber defense. Drawing on experience in software development, program management and security consulting, she enjoys building practical security programs that enable organisations to move fast while managing risk.

    Nazneen actively shares her experiences through conferences and community events, covering topics across cybersecurity and leadership. She believes the best ideas emerge from sharing knowledge and learning from the community. She is passionate about making security practical, fostering strong security cultures, and enabling teams to build secure software by design.

    Her tech chronicles (youtube.com/playlist?list=PL7E) can be found on Youtube and her insights on secure development and security culture are shared through blogs on Gitbook (nazneen-rupawalla.gitbook.io/l).

    More about her can be found at about.me (about.me/NazneenRupawalla).

    Her Tags: #AppSec #SecurityEngineering #ThreatInformedVulnerabilityManagement #WomenInTech #SecurityCulture #ThoughtLeadership

    Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.

    Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.

  9. Let me present you the next part of the #peoplebehindosco series.

    Hi @nazneenr 👋

    Nazneen works at the intersection of security engineering, application security and cyber defense. Drawing on experience in software development, program management and security consulting, she enjoys building practical security programs that enable organisations to move fast while managing risk.

    Nazneen actively shares her experiences through conferences and community events, covering topics across cybersecurity and leadership. She believes the best ideas emerge from sharing knowledge and learning from the community. She is passionate about making security practical, fostering strong security cultures, and enabling teams to build secure software by design.

    Her tech chronicles (youtube.com/playlist?list=PL7E) can be found on Youtube and her insights on secure development and security culture are shared through blogs on Gitbook (nazneen-rupawalla.gitbook.io/l).

    More about her can be found at about.me (about.me/NazneenRupawalla).

    Her Tags: #AppSec #SecurityEngineering #ThreatInformedVulnerabilityManagement #WomenInTech #SecurityCulture #ThoughtLeadership

    Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.

    Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.

  10. Let me present you the next part of the #peoplebehindosco series.

    Hi @nazneenr 👋

    Nazneen works at the intersection of security engineering, application security and cyber defense. Drawing on experience in software development, program management and security consulting, she enjoys building practical security programs that enable organisations to move fast while managing risk.

    Nazneen actively shares her experiences through conferences and community events, covering topics across cybersecurity and leadership. She believes the best ideas emerge from sharing knowledge and learning from the community. She is passionate about making security practical, fostering strong security cultures, and enabling teams to build secure software by design.

    Her tech chronicles (youtube.com/playlist?list=PL7E) can be found on Youtube and her insights on secure development and security culture are shared through blogs on Gitbook (nazneen-rupawalla.gitbook.io/l).

    More about her can be found at about.me (about.me/NazneenRupawalla).

    Her Tags: #AppSec #SecurityEngineering #ThreatInformedVulnerabilityManagement #WomenInTech #SecurityCulture #ThoughtLeadership

    Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.

    Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.

  11. Totalforsvar and Cybersecurity

    Cybersecurity is a team sport in which the most important player is the user. An informed user is therefore one of the cheapest and most effective security measures any organization can implement.

    This may sound straightforward, yet it follows the same principle underpinning national defense strategies such as the Norwegian concept of Totalforsvar (Total Defence). In simple terms, a nation’s ability to defend itself is not determined solely by its armed forces but by the combined capabilities and capacities of society as a whole. The distinction is important: capabilities describe what can be done, while capacities describe how much can be done.

    By extension, much of what is accepted as common wisdom within the cybersecurity community is true. Security is as much a matter of culture as it is of the systems designed to protect it. The quickest route to any asset you wish to defend is often through the people who already have access to it.

    Incidentally, this appears to be a problem intrinsically tied to the way Western societies have organized themselves. 

    To paraphrase Allen Dulles—former Director of the CIA and author of The Craft of Intelligence—an open society inevitably places many of its decisions, capabilities, and even aspects of its defense under public scrutiny which makes access to information on how to attack us more accessible to a potential adversary.

    This is not paranoia; it is simply a recognition that information is more readily available to us than it was to, say, a citizen of the USSR or Maoist China. Even today where information remains restricted, it is generally far easier to access than in more closed societies. Therefore, as a society, we are constantly exposed to OSINT strategies that, to thrive, depend on an uninformed public.

    Social cohesion is an important deterrent in such cases. If we all know that there is a dangerous adversary searching for a particular piece of information, it becomes easier to recognize the threat and prevent access to it.

    The patching of information systems also depends on similar principles, where collectively reported incidents shape the measures eventually implemented. Therefore, the more users actively collaborate around a system, the more robust that system becomes.

    This is even more visible in open-source software communities, which are not only aware of this mechanism but also dependent on it to function. The difference is that their participants have an arguably greater interest in, and competence with, technology than the average user, making their actions more effective despite their relatively small numbers.

    As we continue to digitalize and integrate our lives into the digital space, we may need to make the relationship between security and individuals far more explicit if we wish to safeguard the systems of tomorrow. 

    Our protection depends on it.

    Notes:

    • OSINT- Open Source Intelligence: Information in the public domain that can be collected and utilized by an adversary to carry an attack.
    • Patching- Updating a system to reduce or eliminate previous weaknesses.

    Coming soon!

    📕 The Pocket AI Governance Guide

    Building on the ideas explored in these articles, my upcoming book examines AI governance, digital resilience, cybersecurity, and the institutional challenges emerging in an AI-driven world.

    📘 The Pocket AI Guide is available now for readers looking for a practical introduction to artificial intelligence.

    📙 Amazon US: https://a.co/d/gCHHDax
    📗 Europe (Amazon Germany): https://amzn.eu/d/3cmlIqa
    (Also available through other Amazon stores.)

    Explore the free articles and resources available on this website.

    #cyberDefense #cyberResilience #cyberThreats #Cybersecurity #cybersecurityAwareness #digitalInfrastructure #digitalSociety #informationSecurity #informationWarfare #nationalResilience #OpenSourceIntelligence #openSourceSoftware #OSINT #publicResilience #securityCulture #securityGovernance #socialCohesion #TotalDefence #Totalforsvar #WesternSocieties
  12. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  13. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  14. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  15. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  16. *Fuck your online arrestee forms*

    "In the past few years there have been a lot of actions, mainly occupations and blockades, where online arrestee forms (also called RST forms) have been spread around. I think this is a bad development and here I'm going to tell you why.

    As a child growing up on the internet in the early 2000s I was taught not to share personal information with strangers on the internet. I still think this is good advice.

    Why is this a problem?

    Arrestee forms are typically used when people expect to get into a situation where they can be arrested or be exposed to police violence. The forms typically request personally identifiable information and contact information for someone close to you to be filled out. You should not share this information with strangers on the internet.

    It increases your workload and responsibility

    For the people doing arrestee support it potentially creates a lot of extra administration and organisational work. It also creates a lot of responsibility because suddenly you're in charge of processing people's personal information and destroying it at the right time. You have a better use of your time and energy, use it effectively. …"

    indymedia.nl/node/56663

    #arresteeForms #RSTforms #OpSec #SecurityCulture #activism

  17. *Fuck your online arrestee forms*

    "In the past few years there have been a lot of actions, mainly occupations and blockades, where online arrestee forms (also called RST forms) have been spread around. I think this is a bad development and here I'm going to tell you why.

    As a child growing up on the internet in the early 2000s I was taught not to share personal information with strangers on the internet. I still think this is good advice.

    Why is this a problem?

    Arrestee forms are typically used when people expect to get into a situation where they can be arrested or be exposed to police violence. The forms typically request personally identifiable information and contact information for someone close to you to be filled out. You should not share this information with strangers on the internet.

    It increases your workload and responsibility

    For the people doing arrestee support it potentially creates a lot of extra administration and organisational work. It also creates a lot of responsibility because suddenly you're in charge of processing people's personal information and destroying it at the right time. You have a better use of your time and energy, use it effectively. …"

    indymedia.nl/node/56663

    #arresteeForms #RSTforms #OpSec #SecurityCulture #activism

  18. *Fuck your online arrestee forms*

    "In the past few years there have been a lot of actions, mainly occupations and blockades, where online arrestee forms (also called RST forms) have been spread around. I think this is a bad development and here I'm going to tell you why.

    As a child growing up on the internet in the early 2000s I was taught not to share personal information with strangers on the internet. I still think this is good advice.

    Why is this a problem?

    Arrestee forms are typically used when people expect to get into a situation where they can be arrested or be exposed to police violence. The forms typically request personally identifiable information and contact information for someone close to you to be filled out. You should not share this information with strangers on the internet.

    It increases your workload and responsibility

    For the people doing arrestee support it potentially creates a lot of extra administration and organisational work. It also creates a lot of responsibility because suddenly you're in charge of processing people's personal information and destroying it at the right time. You have a better use of your time and energy, use it effectively. …"

    indymedia.nl/node/56663

    #arresteeForms #RSTforms #OpSec #SecurityCulture #activism

  19. *Fuck your online arrestee forms*

    "In the past few years there have been a lot of actions, mainly occupations and blockades, where online arrestee forms (also called RST forms) have been spread around. I think this is a bad development and here I'm going to tell you why.

    As a child growing up on the internet in the early 2000s I was taught not to share personal information with strangers on the internet. I still think this is good advice.

    Why is this a problem?

    Arrestee forms are typically used when people expect to get into a situation where they can be arrested or be exposed to police violence. The forms typically request personally identifiable information and contact information for someone close to you to be filled out. You should not share this information with strangers on the internet.

    It increases your workload and responsibility

    For the people doing arrestee support it potentially creates a lot of extra administration and organisational work. It also creates a lot of responsibility because suddenly you're in charge of processing people's personal information and destroying it at the right time. You have a better use of your time and energy, use it effectively. …"

    indymedia.nl/node/56663

    #arresteeForms #RSTforms #OpSec #SecurityCulture #activism

  20. *Fuck your online arrestee forms*

    "In the past few years there have been a lot of actions, mainly occupations and blockades, where online arrestee forms (also called RST forms) have been spread around. I think this is a bad development and here I'm going to tell you why.

    As a child growing up on the internet in the early 2000s I was taught not to share personal information with strangers on the internet. I still think this is good advice.

    Why is this a problem?

    Arrestee forms are typically used when people expect to get into a situation where they can be arrested or be exposed to police violence. The forms typically request personally identifiable information and contact information for someone close to you to be filled out. You should not share this information with strangers on the internet.

    It increases your workload and responsibility

    For the people doing arrestee support it potentially creates a lot of extra administration and organisational work. It also creates a lot of responsibility because suddenly you're in charge of processing people's personal information and destroying it at the right time. You have a better use of your time and energy, use it effectively. …"

    indymedia.nl/node/56663

    #arresteeForms #RSTforms #OpSec #SecurityCulture #activism

  21. *Leaked personal details during an XR action in The Hague - take action!*

    "As some of you know, last Tuesday (May 19th 2026) a link was shared during for action by XR in The Hague. This link was an online AG-form (also known as an arrestee form). Unfortunately through this link everyone could read information that people had written in the forms before. This means: if you filled in an online AG form it's possible that your personal information and your contact person's information has been read by others. …"

    indymedia.nl/node/56679

    *Gelekte persoonlijke gegevens tijdens actie van XR in Den Haag – Onderneem actie!*

    "Zoals sommigen van jullie weten, is tijdens een actie afgelopen dinsdag (19 mei 2026) een link verspreid voor deelname aan een actie van XR in Den Haag. Die link was naar een online AG-briefje (ook wel arrestee form genoemd). Via de link kon iedereen echter alle informatie lezen die mensen hadden ingevuld. Dat betekent dat als jij zo’n online AG-formulier hebt ingevuld, het mogelijk is dat jouw persoonlijke gegevens en die van jouw contactpersoon gelezen is door anderen. …"

    indymedia.nl/node/56679

    #XR #ExtinctionRebellion #securityCulture #opSec #AG #RSTform

  22. *Leaked personal details during an XR action in The Hague - take action!*

    "As some of you know, last Tuesday (May 19th 2026) a link was shared during for action by XR in The Hague. This link was an online AG-form (also known as an arrestee form). Unfortunately through this link everyone could read information that people had written in the forms before. This means: if you filled in an online AG form it's possible that your personal information and your contact person's information has been read by others. …"

    indymedia.nl/node/56679

    *Gelekte persoonlijke gegevens tijdens actie van XR in Den Haag – Onderneem actie!*

    "Zoals sommigen van jullie weten, is tijdens een actie afgelopen dinsdag (19 mei 2026) een link verspreid voor deelname aan een actie van XR in Den Haag. Die link was naar een online AG-briefje (ook wel arrestee form genoemd). Via de link kon iedereen echter alle informatie lezen die mensen hadden ingevuld. Dat betekent dat als jij zo’n online AG-formulier hebt ingevuld, het mogelijk is dat jouw persoonlijke gegevens en die van jouw contactpersoon gelezen is door anderen. …"

    indymedia.nl/node/56679

    #XR #ExtinctionRebellion #securityCulture #opSec #AG #RSTform

  23. *Leaked personal details during an XR action in The Hague - take action!*

    "As some of you know, last Tuesday (May 19th 2026) a link was shared during for action by XR in The Hague. This link was an online AG-form (also known as an arrestee form). Unfortunately through this link everyone could read information that people had written in the forms before. This means: if you filled in an online AG form it's possible that your personal information and your contact person's information has been read by others. …"

    indymedia.nl/node/56679

    *Gelekte persoonlijke gegevens tijdens actie van XR in Den Haag – Onderneem actie!*

    "Zoals sommigen van jullie weten, is tijdens een actie afgelopen dinsdag (19 mei 2026) een link verspreid voor deelname aan een actie van XR in Den Haag. Die link was naar een online AG-briefje (ook wel arrestee form genoemd). Via de link kon iedereen echter alle informatie lezen die mensen hadden ingevuld. Dat betekent dat als jij zo’n online AG-formulier hebt ingevuld, het mogelijk is dat jouw persoonlijke gegevens en die van jouw contactpersoon gelezen is door anderen. …"

    indymedia.nl/node/56679

    #XR #ExtinctionRebellion #securityCulture #opSec #AG #RSTform

  24. *Leaked personal details during an XR action in The Hague - take action!*

    "As some of you know, last Tuesday (May 19th 2026) a link was shared during for action by XR in The Hague. This link was an online AG-form (also known as an arrestee form). Unfortunately through this link everyone could read information that people had written in the forms before. This means: if you filled in an online AG form it's possible that your personal information and your contact person's information has been read by others. …"

    indymedia.nl/node/56679

    *Gelekte persoonlijke gegevens tijdens actie van XR in Den Haag – Onderneem actie!*

    "Zoals sommigen van jullie weten, is tijdens een actie afgelopen dinsdag (19 mei 2026) een link verspreid voor deelname aan een actie van XR in Den Haag. Die link was naar een online AG-briefje (ook wel arrestee form genoemd). Via de link kon iedereen echter alle informatie lezen die mensen hadden ingevuld. Dat betekent dat als jij zo’n online AG-formulier hebt ingevuld, het mogelijk is dat jouw persoonlijke gegevens en die van jouw contactpersoon gelezen is door anderen. …"

    indymedia.nl/node/56679

    #XR #ExtinctionRebellion #securityCulture #opSec #AG #RSTform

  25. *Leaked personal details during an XR action in The Hague - take action!*

    "As some of you know, last Tuesday (May 19th 2026) a link was shared during for action by XR in The Hague. This link was an online AG-form (also known as an arrestee form). Unfortunately through this link everyone could read information that people had written in the forms before. This means: if you filled in an online AG form it's possible that your personal information and your contact person's information has been read by others. …"

    indymedia.nl/node/56679

    *Gelekte persoonlijke gegevens tijdens actie van XR in Den Haag – Onderneem actie!*

    "Zoals sommigen van jullie weten, is tijdens een actie afgelopen dinsdag (19 mei 2026) een link verspreid voor deelname aan een actie van XR in Den Haag. Die link was naar een online AG-briefje (ook wel arrestee form genoemd). Via de link kon iedereen echter alle informatie lezen die mensen hadden ingevuld. Dat betekent dat als jij zo’n online AG-formulier hebt ingevuld, het mogelijk is dat jouw persoonlijke gegevens en die van jouw contactpersoon gelezen is door anderen. …"

    indymedia.nl/node/56679

    #XR #ExtinctionRebellion #securityCulture #opSec #AG #RSTform

  26. Impact vs Intent
    Just because a pattern looks suspicious
    doesn't mean someone meant it that way.
    People under stress act weird.
    People under threat act inconsistent.
    People under pressure make mistakes.
    People in danger look "guilty."
    Before you assign intent, separate the two signals:
    — Impact (what happened)
    — Intent (why it happened)
    Treat them as different questions.
    Because sometimes the person acting "off"
    isn't the threat —
    they're the one under threat.
    #purpleteam #SecurityCulture

  27. @kkarhan @GrapheneOS @tails_live @torproject @signalapp

    "GrapheneOS chose their requirements and they can happily design their own platform instead."

    There's no need to reinvent the wheel. AOSP is a secure, open-source platform that has been around for almost 20 years. I don't want to debate rumors that Google wants to make AOSP proprietary because there is no evidence to support this, especially since it would not benefit them in any way.

    "I just think that their stubbornness"

    It's not stubborness and I explained why.

    "They are the antithesis to #Tails when it comes to #UserFriendly-ness and approachability for #Normies and #TechIlliterates

    It's probably the first time I've seen “Tails” and “Normie” in the same sentence, It's not that Tails is difficult to use, but I'm really not sure that many “normies” use it or even know it exists. The user experience on GrapheneOS is almost identical to Pixel OS, the standard operating system for Google Pixel devices, so using GrapheneOS is likely to seem much simpler and familiar to normies, as they will already be used to it.

    "Espechally since the problems woth #MobilePhones and the underlying technology ain't fixable with an #AndroidROM

    GrapheneOS is not a ROM, Pixel OS is not a ROM, and LineageOS is not a ROM either, theses operating systems are not ROMs.

    "Instead we need to foster a #SecurityCulture and proper #ITsec, #InfoSec, #OpSec & #comsec

    Indeed, and what GrapheneOS does about security is completely appropriate, including informing people and giving them good advice.

    "Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…"

    Signal did not fail, and mentioning Encrochat, ANON, and honeypots in the same sentence is irrelevant. These things have absolutely nothing in common with Signal, you seem to be believing made-up stories.

  28. @kkarhan @GrapheneOS @tails_live @torproject @signalapp

    "GrapheneOS chose their requirements and they can happily design their own platform instead."

    There's no need to reinvent the wheel. AOSP is a secure, open-source platform that has been around for almost 20 years. I don't want to debate rumors that Google wants to make AOSP proprietary because there is no evidence to support this, especially since it would not benefit them in any way.

    "I just think that their stubbornness"

    It's not stubborness and I explained why.

    "They are the antithesis to #Tails when it comes to #UserFriendly-ness and approachability for #Normies and #TechIlliterates

    It's probably the first time I've seen “Tails” and “Normie” in the same sentence, It's not that Tails is difficult to use, but I'm really not sure that many “normies” use it or even know it exists. The user experience on GrapheneOS is almost identical to Pixel OS, the standard operating system for Google Pixel devices, so using GrapheneOS is likely to seem much simpler and familiar to normies, as they will already be used to it.

    "Espechally since the problems woth #MobilePhones and the underlying technology ain't fixable with an #AndroidROM

    GrapheneOS is not a ROM, Pixel OS is not a ROM, and LineageOS is not a ROM either, theses operating systems are not ROMs.

    "Instead we need to foster a #SecurityCulture and proper #ITsec, #InfoSec, #OpSec & #comsec

    Indeed, and what GrapheneOS does about security is completely appropriate, including informing people and giving them good advice.

    "Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…"

    Signal did not fail, and mentioning Encrochat, ANON, and honeypots in the same sentence is irrelevant. These things have absolutely nothing in common with Signal, you seem to be believing made-up stories.

  29. @kkarhan @GrapheneOS @tails_live @torproject @signalapp

    "GrapheneOS chose their requirements and they can happily design their own platform instead."

    There's no need to reinvent the wheel. AOSP is a secure, open-source platform that has been around for almost 20 years. I don't want to debate rumors that Google wants to make AOSP proprietary because there is no evidence to support this, especially since it would not benefit them in any way.

    "I just think that their stubbornness"

    It's not stubborness and I explained why.

    "They are the antithesis to #Tails when it comes to #UserFriendly-ness and approachability for #Normies and #TechIlliterates

    It's probably the first time I've seen “Tails” and “Normie” in the same sentence, It's not that Tails is difficult to use, but I'm really not sure that many “normies” use it or even know it exists. The user experience on GrapheneOS is almost identical to Pixel OS, the standard operating system for Google Pixel devices, so using GrapheneOS is likely to seem much simpler and familiar to normies, as they will already be used to it.

    "Espechally since the problems woth #MobilePhones and the underlying technology ain't fixable with an #AndroidROM

    GrapheneOS is not a ROM, Pixel OS is not a ROM, and LineageOS is not a ROM either, theses operating systems are not ROMs.

    "Instead we need to foster a #SecurityCulture and proper #ITsec, #InfoSec, #OpSec & #comsec

    Indeed, and what GrapheneOS does about security is completely appropriate, including informing people and giving them good advice.

    "Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…"

    Signal did not fail, and mentioning Encrochat, ANON, and honeypots in the same sentence is irrelevant. These things have absolutely nothing in common with Signal, you seem to be believing made-up stories.

  30. @kkarhan @GrapheneOS @tails_live @torproject @signalapp

    "GrapheneOS chose their requirements and they can happily design their own platform instead."

    There's no need to reinvent the wheel. AOSP is a secure, open-source platform that has been around for almost 20 years. I don't want to debate rumors that Google wants to make AOSP proprietary because there is no evidence to support this, especially since it would not benefit them in any way.

    "I just think that their stubbornness"

    It's not stubborness and I explained why.

    "They are the antithesis to #Tails when it comes to #UserFriendly-ness and approachability for #Normies and #TechIlliterates

    It's probably the first time I've seen “Tails” and “Normie” in the same sentence, It's not that Tails is difficult to use, but I'm really not sure that many “normies” use it or even know it exists. The user experience on GrapheneOS is almost identical to Pixel OS, the standard operating system for Google Pixel devices, so using GrapheneOS is likely to seem much simpler and familiar to normies, as they will already be used to it.

    "Espechally since the problems woth #MobilePhones and the underlying technology ain't fixable with an #AndroidROM

    GrapheneOS is not a ROM, Pixel OS is not a ROM, and LineageOS is not a ROM either, theses operating systems are not ROMs.

    "Instead we need to foster a #SecurityCulture and proper #ITsec, #InfoSec, #OpSec & #comsec

    Indeed, and what GrapheneOS does about security is completely appropriate, including informing people and giving them good advice.

    "Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…"

    Signal did not fail, and mentioning Encrochat, ANON, and honeypots in the same sentence is irrelevant. These things have absolutely nothing in common with Signal, you seem to be believing made-up stories.

  31. @kkarhan @GrapheneOS @tails_live @torproject @signalapp

    "GrapheneOS chose their requirements and they can happily design their own platform instead."

    There's no need to reinvent the wheel. AOSP is a secure, open-source platform that has been around for almost 20 years. I don't want to debate rumors that Google wants to make AOSP proprietary because there is no evidence to support this, especially since it would not benefit them in any way.

    "I just think that their stubbornness"

    It's not stubborness and I explained why.

    "They are the antithesis to #Tails when it comes to #UserFriendly-ness and approachability for #Normies and #TechIlliterates

    It's probably the first time I've seen “Tails” and “Normie” in the same sentence, It's not that Tails is difficult to use, but I'm really not sure that many “normies” use it or even know it exists. The user experience on GrapheneOS is almost identical to Pixel OS, the standard operating system for Google Pixel devices, so using GrapheneOS is likely to seem much simpler and familiar to normies, as they will already be used to it.

    "Espechally since the problems woth #MobilePhones and the underlying technology ain't fixable with an #AndroidROM

    GrapheneOS is not a ROM, Pixel OS is not a ROM, and LineageOS is not a ROM either, theses operating systems are not ROMs.

    "Instead we need to foster a #SecurityCulture and proper #ITsec, #InfoSec, #OpSec & #comsec

    Indeed, and what GrapheneOS does about security is completely appropriate, including informing people and giving them good advice.

    "Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…"

    Signal did not fail, and mentioning Encrochat, ANON, and honeypots in the same sentence is irrelevant. These things have absolutely nothing in common with Signal, you seem to be believing made-up stories.

  32. I feel non-security executives say “security is everyone’s responsibility” they often ends up meaning “security’s problem.”
    #SecurityCulture #Leadership #HonestSecurity

  33. I feel non-security executives say “security is everyone’s responsibility” they often ends up meaning “security’s problem.”
    #SecurityCulture #Leadership #HonestSecurity

  34. I feel non-security executives say “security is everyone’s responsibility” they often ends up meaning “security’s problem.”
    #SecurityCulture #Leadership #HonestSecurity

  35. I feel non-security executives say “security is everyone’s responsibility” they often ends up meaning “security’s problem.”
    #SecurityCulture #Leadership #HonestSecurity

  36. I feel non-security executives say “security is everyone’s responsibility” they often ends up meaning “security’s problem.”
    #SecurityCulture #Leadership #HonestSecurity

  37. I’ve met a few organization says they want (or have) a strong security culture… until security shows up to the meeting.
    #Leadership #SecurityCulture #CISOlife

  38. I’ve met a few organization says they want (or have) a strong security culture… until security shows up to the meeting.
    #Leadership #SecurityCulture #CISOlife

  39. "𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 𝙞𝙨 𝙖 𝙥𝙧𝙤𝙘𝙚𝙨𝙨, 𝙣𝙤𝙩 𝙖 𝙥𝙧𝙤𝙙𝙪𝙘𝙩."

    This simple, but powerful quote is from cybersecurity legend 𝗕𝗿𝘂𝗰𝗲 𝗦𝗰𝗵𝗻𝗲𝗶𝗲𝗿.

    Bruce is the author of not 1, not 2, but 3 books in our Hall of Fame.

    Check out our reviews, and please consider using our affiliate links below if you'd like to purchase and help support the Canon. 🙏

    𝗦𝗲𝗰𝗿𝗲𝘁𝘀 𝗮𝗻𝗱 𝗟𝗶𝗲𝘀:
    📝 cybercanon.org/secrets-and-lie
    🛍️ amzn.to/3JUlxu3

    𝗗𝗮𝘁𝗮 𝗮𝗻𝗱 𝗚𝗼𝗹𝗶𝗮𝘁𝗵:
    📝 cybercanon.org/data-and-goliat
    🛍️ amzn.to/4oDoDSb

    𝗖𝗹𝗶𝗰𝗸 𝗛𝗲𝗿𝗲 𝘁𝗼 𝗞𝗶𝗹𝗹 𝗘𝘃𝗲𝗿𝘆𝗯𝗼𝗱𝘆:
    📝 cybercanon.org/click-here-to-k
    🛍️ amzn.to/47YtxSU

    #CybersecurityBooks #SecurityCulture #SecurityAwareness #CyberCanonHallofFame

  40. "𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 𝙞𝙨 𝙖 𝙥𝙧𝙤𝙘𝙚𝙨𝙨, 𝙣𝙤𝙩 𝙖 𝙥𝙧𝙤𝙙𝙪𝙘𝙩."

    This simple, but powerful quote is from cybersecurity legend 𝗕𝗿𝘂𝗰𝗲 𝗦𝗰𝗵𝗻𝗲𝗶𝗲𝗿.

    Bruce is the author of not 1, not 2, but 3 books in our Hall of Fame.

    Check out our reviews, and please consider using our affiliate links below if you'd like to purchase and help support the Canon. 🙏

    𝗦𝗲𝗰𝗿𝗲𝘁𝘀 𝗮𝗻𝗱 𝗟𝗶𝗲𝘀:
    📝 cybercanon.org/secrets-and-lie
    🛍️ amzn.to/3JUlxu3

    𝗗𝗮𝘁𝗮 𝗮𝗻𝗱 𝗚𝗼𝗹𝗶𝗮𝘁𝗵:
    📝 cybercanon.org/data-and-goliat
    🛍️ amzn.to/4oDoDSb

    𝗖𝗹𝗶𝗰𝗸 𝗛𝗲𝗿𝗲 𝘁𝗼 𝗞𝗶𝗹𝗹 𝗘𝘃𝗲𝗿𝘆𝗯𝗼𝗱𝘆:
    📝 cybercanon.org/click-here-to-k
    🛍️ amzn.to/47YtxSU

    #CybersecurityBooks #SecurityCulture #SecurityAwareness #CyberCanonHallofFame

  41. "𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 𝙞𝙨 𝙖 𝙥𝙧𝙤𝙘𝙚𝙨𝙨, 𝙣𝙤𝙩 𝙖 𝙥𝙧𝙤𝙙𝙪𝙘𝙩."

    This simple, but powerful quote is from cybersecurity legend 𝗕𝗿𝘂𝗰𝗲 𝗦𝗰𝗵𝗻𝗲𝗶𝗲𝗿.

    Bruce is the author of not 1, not 2, but 3 books in our Hall of Fame.

    Check out our reviews, and please consider using our affiliate links below if you'd like to purchase and help support the Canon. 🙏

    𝗦𝗲𝗰𝗿𝗲𝘁𝘀 𝗮𝗻𝗱 𝗟𝗶𝗲𝘀:
    📝 cybercanon.org/secrets-and-lie
    🛍️ amzn.to/3JUlxu3

    𝗗𝗮𝘁𝗮 𝗮𝗻𝗱 𝗚𝗼𝗹𝗶𝗮𝘁𝗵:
    📝 cybercanon.org/data-and-goliat
    🛍️ amzn.to/4oDoDSb

    𝗖𝗹𝗶𝗰𝗸 𝗛𝗲𝗿𝗲 𝘁𝗼 𝗞𝗶𝗹𝗹 𝗘𝘃𝗲𝗿𝘆𝗯𝗼𝗱𝘆:
    📝 cybercanon.org/click-here-to-k
    🛍️ amzn.to/47YtxSU

    #CybersecurityBooks #SecurityCulture #SecurityAwareness #CyberCanonHallofFame

  42. "𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 𝙞𝙨 𝙖 𝙥𝙧𝙤𝙘𝙚𝙨𝙨, 𝙣𝙤𝙩 𝙖 𝙥𝙧𝙤𝙙𝙪𝙘𝙩."

    This simple, but powerful quote is from cybersecurity legend 𝗕𝗿𝘂𝗰𝗲 𝗦𝗰𝗵𝗻𝗲𝗶𝗲𝗿.

    Bruce is the author of not 1, not 2, but 3 books in our Hall of Fame.

    Check out our reviews, and please consider using our affiliate links below if you'd like to purchase and help support the Canon. 🙏

    𝗦𝗲𝗰𝗿𝗲𝘁𝘀 𝗮𝗻𝗱 𝗟𝗶𝗲𝘀:
    📝 cybercanon.org/secrets-and-lie
    🛍️ amzn.to/3JUlxu3

    𝗗𝗮𝘁𝗮 𝗮𝗻𝗱 𝗚𝗼𝗹𝗶𝗮𝘁𝗵:
    📝 cybercanon.org/data-and-goliat
    🛍️ amzn.to/4oDoDSb

    𝗖𝗹𝗶𝗰𝗸 𝗛𝗲𝗿𝗲 𝘁𝗼 𝗞𝗶𝗹𝗹 𝗘𝘃𝗲𝗿𝘆𝗯𝗼𝗱𝘆:
    📝 cybercanon.org/click-here-to-k
    🛍️ amzn.to/47YtxSU

    #CybersecurityBooks #SecurityCulture #SecurityAwareness #CyberCanonHallofFame