Doing things right is not always enough

Doing things right is not always enough

All we can do is do our best, when we do things right, sometimes it's not enough, because we don't control everything.

Can we plan for the worst ? Can we try to anticipate situations and have plans ? Yes, that's about reducing the risks, and likelihood of incident.

When we do so, we work both on the preventive and the corrective side, because we know, preventing is only risk reduction.

To reduce the risk in software development, you can use Anomaly detection :


You can try to patch these Zero days, or try to compensate when there is not patch available : Palo Alto newtork PAN-OS zero day unpatched CVS 10

Sometimes we can't do anything when the game is rigged and the authentication of your so trusted cloud is granting access to attackers : Why CISA is Warning CISOs About a Breach at Sisense

Quoting Brian's update in the article : "Also, Sisense’s CISO Dash just sent an update to customers directly. The latest advice from the company is far more detailed, and involves resetting a potentially large number of access tokens across multiple technologies, including Microsoft Active Directory credentials, GIT credentials, web access tokens, and any single sign-on (SSO) secrets or tokens."

I'll stop here, and let you find what you have to find, and take action where you have to take action.

Good luck for the weekend cloud lovers and SSO fans ! I always said, SSO is cute, but it's also a universal access to all when corrupted.

Planning for the worst and anticipating potential challenges can indeed help mitigate risks and improve our readiness to handle adverse situations.

Mohammad Hasan Hashemi

Entrepreneurial Leader & Cybersecurity Strategist

5 个月

This proactive approach involves both preventive measures, such as anomaly detection in software development, and corrective actions, such as patching zero-day vulnerabilities or responding to breaches.

回复
Tereston Bertrand Sr. SABSA SCF, CISSP, TOGAF, cRBIA

Advisor-Business Driven Security-SABSA-The Agile Security System (TASS)

5 个月

Thanks ...and true, reason why you should focus your activities and behavior on the things you control, yes the things you can readily start and stop at anytime,, and allow your behavior and activities to influence the things you can't control and when we do we will be doing our best and will be enough. We need to refocus, we are chasing too many things we can control.

回复
Katalin Kish

★ I create value by turning complex info into actionable insights using technology & Maths. MBA, Global E-Commerce Champion

5 个月

I love how elegantly you deliver this important message about expectation management! My added mantra is to focus more on resilience, less on trying achieve absolute cyber-security. No one knows at any point in time what tech is already in crime arsenals, so no one knows what is "secure".

Jan B.

Beta-tester at Parrot Security* Polymath*

6 个月

要查看或添加评论,请登录

Alexandre BLANC Cyber Security的更多文章

  • Exposure management conf, UltraAV and more

    Exposure management conf, UltraAV and more

    Happy to meet you here again ! Thank you 49632 subscribers at the time I'm typing this..

    5 条评论
  • The not so weekly Cyber is here ! What's new...

    The not so weekly Cyber is here ! What's new...

    I'm lucky this time, not only you get a newsletter, but it is sponsored by listen.dev ! 80% of organizations rely on…

    9 条评论
  • Speaking at 3 Cyber security conferences THIS WEEK !

    Speaking at 3 Cyber security conferences THIS WEEK !

    Yes, that's a rodeo of Cyber Conferences for me this week ! Can you make it ? Tomorrow, August 27th at 1PM ET - Solving…

    11 条评论
  • Cyber news catch up as I'm back

    Cyber news catch up as I'm back

    No longer on the road for a few days, and as I was catching up with many things, I didn't share about the latest news…

    18 条评论
  • Cyber catch up from the last days and conf

    Cyber catch up from the last days and conf

    While I'm on the way back, I wanted to announce a coming live ahead, which I'm excited about, as I'm invited to speak…

    8 条评论
  • Cyber security news catch up from the camp

    Cyber security news catch up from the camp

    Funnily, it seems I blew up Microsoft AI limit using some very insulting wording as you can see : At least I'm not…

    6 条评论
  • Cyber news catch up from the camp

    Cyber news catch up from the camp

    I'm still on the road, and here is a catch up wrap in regards to the cyber news over the past days. Storing passwords…

    7 条评论
  • Cyber update from the rainy forest !

    Cyber update from the rainy forest !

    Had a long day yesterday, biking couple dozen miles, hiking, nice day, but at night, the cloud came and leaked all this…

    7 条评论
  • Tuesday cyber news wrap, on the road

    Tuesday cyber news wrap, on the road

    While I did hit my first stop, I'm writing this wrap as I review what happened today. Thanks to modern technology, and…

    12 条评论
  • Monday news wrap as I'm hitting the road

    Monday news wrap as I'm hitting the road

    Here's what are the news and cyber highlight for today, as I've packed my stuff and about to hit the road. I had a good…

    9 条评论

社区洞察

其他会员也浏览了