home.social

#securityleadership — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityleadership, aggregated by home.social.

fetched live
  1. A secsolutionforum Ligotti Academy - Human Performance Lab: la Security protegge l’impresa. Ma chi prepara l’impresa a evolvere?: A secsolutionforum 2026, il 7 e 8 ottobre prossimi a BolognaFiere, Ligotti Academy Human Performance Lab presentera’ la propria Faculty e un modello formativo...
    #secsolutionforum #LigottiAcademy–HumanPerformanceLab #SecurityLeadership #AIGovernance #welfare dlvr.it/TVY4Y3

  2. New article: When AI Hallucinations Turn Into Phishing Infrastructure — An examination of how AI hallucinations are reshaping phishing tactics and expanding attacker toolkits. This piece covers attacker techniques, practical mitigations, and detection priorities for security teams and executives. Read the full post: wix.to/UHfPXOu

    #AI
    #Phishing
    #ThreatIntel
    #Cybersecurity
    #RiskManagement
    #SecurityLeadership

  3. 🎙️ New FIRST Impressions Podcast Episode: John Hollenberger (Fortinet)

    Recorded live at FIRSTCON26, John Hollenberger of Fortinet explores how organizations can make tabletop exercises more realistic, and ultimately more valuable.

    In this episode, John introduces ChaosStack, an approach that recreates the stress, competing priorities, and decision fatigue teams experience during real cyber incidents. The discussion explores how better exercises lead to stronger teamwork, better decision-making, and greater organizational resilience.

    As a Founding Supporter and Launch Partner of the *FIRST CORE Program*, Fortinet's commitment extends beyond technology to strengthening cybersecurity capacity around the world. Through FIRST CORE, supporters help expand incident response capabilities, education, and community building in regions where resources are limited—helping make the global cybersecurity community stronger together.

    🎧 Listen now for practical insights on preparing your team for the moments that matter most.
    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #TabletopExercises #Fortinet #FIRSTCORE #CyberResilience #SecurityLeadership

  4. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  5. When an executive rejects a security recommendation, it's worth asking what would need to change for a different answer. That question reveals constraints we didn't see and persuasion paths we didn't consider.

    zeltser.com/rejected-security-

    #cybersecurity #securityleadership #CISO #infosec

  6. A practical rubric by Ben Vierck lets SaaS vendors assess their product strategy against AI-driven commoditization. Applied to cybersecurity, it reveals where a strategy holds and where it needs work.

    zeltser.com/scoring-security-p

    #cybersecurity #infosec #productmanagement #AI #securityleadership

  7. Agentic AI represents a paradigm shift in cyber threats — autonomous agents can scale attacks, exploit identity systems, and bypass many existing controls. This article breaks down the tactical and strategic implications and offers mitigation guidance for security leaders. Read more: wix.to/bcyQWwD

    #AI
    #AgenticAI
    #CyberRisk
    #InformationSecurity
    #SecurityLeadership

  8. AI is making commodity software nearly free to produce, exposing security vendors without real moats. Feature lists stopped being a reliable signal of which products will hold their position as commoditization sorts the market. If you were anxious about "SaaSpocalypse," here's a practical way to understand and handle it:

    A seven-dimension rubric from Ben Vierck scores software products from 1 to 3 across each dimension. Three cybersecurity-specific dynamics raise scores for products with compounding defensibility. For example, an EDR platform with a shared data layer can score 20 out of 21 because its dimensions reinforce each other. Enterprise buyers generate telemetry that sharpens detection, which strengthens the compliance posture that attracts the next buyer.

    Product managers and founders can apply the rubric to their own product, while buyers can apply it to their vendor shortlist. A low score names a dimension that needs investment, or a vendor likely to be bundled, absorbed, or replaced. Running the exercise honestly identifies the gaps worth examining.

    zeltser.com/scoring-security-p

    #cybersecurity #infosec #productmanagement #AI #securityleadership

  9. Now you can receive my blog posts via email. Go ahead and sign up: zeltser.com/newsletter

    I've enjoyed writing more frequently and deeply than I have in recent years, and I'm glad to have more ways to get those articles in front of readers who want them.

    All of my posts will continue to reside on my site, but I want to make it easy for people to read them in a way that works for them, whether on social media, in their RSS reader, or in their email inbox.

    I decided to maintain my own website and newsletter platform rather than using services such as Medium and Substack so I can shape the reading experience and keep it free of paywalls and ads.

    #infosec #cybersecurity #securityleadership

  10. We invest hours analyzing a security risk, and that effort makes us overvalue the recommendation. An executive who hasn't shared that analysis weighs the same risk differently, and they might be right.

    zeltser.com/rejected-security-

    #cybersecurity #securityleadership #CISO #infosec

  11. As we automate more security work, stakeholders trust what they can see. Making them feel secure is as much our job as making them secure.

    zeltser.com/importance-of-feel

    #cybersecurity #infosec #securityleadership

  12. When DevOps overwhelmed security reviews, the same velocity let teams patch in minutes instead of waiting for quarterly releases. Vibe coding by non-developers is the next shift where that speed works in our favor.

    zeltser.com/security-governanc

    #cybersecurity #infosec #securityleadership #AI

  13. We adapted security governance to SaaS adoption and DevOps velocity. Vibe coding by non-developers is the next comparable shift, and those transitions give us a starting approach, even though the timeline is shorter.

    zeltser.com/security-governanc

    #cybersecurity #infosec #securityleadership #AI

  14. Every organization has a “Mike.”

    The one who knows how everything works.

    That’s not a strength. That’s a risk.

    New article: When Security Architecture Depends on Tribal Knowledge

    jimguckin.com/2026/03/19/when-

    #CyberSecurity #SecurityArchitecture #InfoSec #SecurityLeadership

  15. Liat Hayun, SVP Product Management at Tenable, on ownership and exposure:
    Remove “someone should fix this.”

    Adopt “I am the only one who will fix this.”
    “A vulnerability in a vacuum is just a line of code.”

    Security teams are drowning in signals. Context defines actionability.

    Read: technadu.com/from-national-sec

    #WomenInCyber #ExposureManagement #SecurityLeadership #LeadHerInSecurity #Tenable

  16. The U.S. is reframing cyber strategy from pure resilience to coordinated deterrence.
    At the Munich Cyber Security Conference, Sean Cairncross outlined a whole-of-government cyber approach integrating law enforcement, offensive capabilities, diplomacy, and industry collaboration.

    Key focus areas:
    • Raising attacker cost calculus
    • Enhanced public-private intel sharing
    • Addressing nation-state & ransomware ecosystems
    • Promoting a “clean” allied tech stack

    Is deterrence achievable in cyberspace - or structurally limited?

    Source: therecord.media/us-wants-cyber

    Security leaders, weigh in below.
    Follow @technadu for strategic cyber intelligence.

    #InfoSec #CyberStrategy #ThreatIntelligence #CISO #CyberOperations #DigitalSovereignty #Ransomware #CyberPolicy #SecurityLeadership #CyberDeterrence

  17. What if the CISO's real job is calibrating the right amount of insecurity? Information must flow. Apps must be used. Links must be clicked. To calibrate the right level of insecurity we should:

    1. Learn how fast the business wants to move.
    2. Define how much insecurity the organization can absorb.
    3. Measure the gap between current and acceptable insecurity.

    zeltser.com/chief-insecurity-o

    #infosec #cybersecurity #securityleadership #CISO

  18. Not all #AI belongs in security decision making, and that is where many teams go wrong.

    In this Brand Highlight, Sean Martin, CISSP is joined by Michael Roytman , CTO of Empirical Security, to talk about why purpose built models matter in preventative security. We cover prediction vs summarization, why retraining matters, and how data driven modeling changes security outcomes.

    🎥 Watch the full conversation here: youtu.be/2sH5PQMHna8

    Do you have a good story to tell?
    We would love to help!
    ✨ studioc60.com

    #cybersecurity #genai #machinelearning #riskmanagement #securityleadership #infosec #infosecurity

  19. More ITSPmagazine's Remote - yet amazing - CyberCon Melbourne Coverage!

    Sean Martin, CISSP and I reconnected with our friend Tim Brown, CISO at SolarWinds, who is keynoting the event talking about Leading Through Crisis, Trust, Context, and Resilience.

    Tim Brown's job changed overnight. December 11th, he was managing security operations at SolarWinds. December 12th, he was leading response to one of cybersecurity's most scrutinized incidents.

    We caught up with our longtime friend from New York and Florence to Melbourne ahead of his keynote at #AISA CyberCon. Tim became the first CISO ever charged by the SEC—a distinction nobody wants, but one that shaped his mission to help others prepare for their own crisis moments.

    What saved SolarWinds? Implicit trust. The war room team operated without second-guessing because relationships were built before December 2020.

    Tim's CIO handled deployment. Engineering investigated the build system. Marketing and legal managed their domains. Everyone knew their role.

    "400 engineers focused completely on security for six months in pure focus.

    When you say it with emotion, it conveys the real cost," Tim explains. Written communication failed during the incident. People needed to hear, to feel the weight of decisions in real time.

    Tim now mentors aspiring #CISOs through the RSA Conference CISO Bootcamp, teaching the non-technical aspects of security leadership: board communication, managing stress, building culture. He's candid about the toll—including a heart attack in Zurich the week his SEC charges were announced—and why finding your safe place isn't a luxury, it's survival.

    His CyberCon keynote covers incident response stages and how culture determines who steps up versus who runs away when crisis hits.

    Watch or listen:

    🎬 Full Interview: youtu.be/4jqx_IshhWI

    🎧 Podcast: itspradio.com/episodes/first-c

    🎬 Highlights: youtu.be/z5_GJEuBNdU

    Click here for the full coverage with more interviews with Jacqueline Jayne, Amberley Brady, and more to come!

    If you're leading security teams or aspiring to, Tim's lessons are essential. Build trust now, before you need it.

    #CISO #Leadership #IncidentResponse #Cybersecurity #CyberConMelbourne #SolarWinds #CrisisManagement #SecurityLeadership #infosec