Let's bring solutions on the table !
Alexandre BLANC Cyber Security
Advisor - ISO/IEC 27001 and 27701 Lead Implementer - Named security expert to follow on LinkedIn in 2024 - MCNA - MITRE ATT&CK - LinkedIn Top Voice 2020 in Technology - All my content is sponsored
I'm happy to bring Xygeni to you, in my newsletter and feed, as a new partner toward better #security and #privacy for the whole software development lifecycle (SDLC), aiming at better #cybersecurity practice !
As you know, I'm very picky on partnerships and solutions, as I want to see true value for a better and safer digital world, especially in the cloud wild west !
You know how much the digital world leaks, and a lot has to do with the lack of security by default and by design.
This is a tool, as for any project, it needs stakeholder willing to do things right, and the impact, the efficiency must be quantifiable, measurable, as in the core of ISO27001 approach.
Let's not take this and becomes a shelfware ! Use it to reduce liability, spot malwares, misconfigurations, templates or blueprint alteration or errors, it's about integrity !
How are you keeping an eye on your CI/CD stack ? (continuous integration / continuous delivery, damn acronyms ! )
You still need to manage your attack surface and validate your controls
While tools or platforms like Xygeni will support your development process security from source code to delivery, it's just a part of your security journey.
You still need to cover your global organization's attack surface, assess the risks, patch vulnerabilities, and bring the security and privacy by default and by design in the whole environment.
You'd use data classification tools that you really control, like Upperity , supporting you governance effort, data integrity and signatures in your information management stack, allowing to achieve compliance at the same time.
领英推荐
You'd still need to validate your actual production environment security controls with pentesting, posture assessment and more with companies like Orenda Security .
You'd still need to consider managed security solutions for your endpoints, email security and awareness, with companies like VARS Corporation .
You should consider protecting and tracking your external file transfer with solutions like Kiteworks .
#####################
That's about it, I decided to take a solution / partner approach, as the vulnerabilities, patches, incidents are covered in my feed, or in other newsletters.
As I have the chance to establish partnerships with solutions providers that makes sense in the digital world, I think it's good to bring them to you.
If you discover a solution that works for you great ! It will be my contribution to the enhancement of the digital landscape.
We still have to cover the basics, even if OpenAI just released the fake video factory, and overall crime is using AI automation for attacks. Actually, your posture should be even better in such context !
Have a good weekend all, thank you for reading ! Thanks you for commenting and sharing !
Beta-tester at Parrot Security* Polymath*
9 个月A large table ;-) TY Alexandre BLANC Cyber Security
Senior SOC analyst at Versant Health
9 个月How ofren is this phrase overused In our world today? I have attempted back to basics the past 4 years. Hard to build a foundation on sand... ill keep this in mind.
Protecting your digital assets
9 个月Agreed - AI makes it easier to automate the attacks and also to make them more authentic which may certainly fool the human in the loop a lot easier. The tools exist today to protect data but most businesses don't implement them so what chance when AI starts coming after their business?
Founder at DKW Online
9 个月Love this
Certificates: Security + ce-601, Certified Ethical Hacker (CEH), Certified Ethical Hacker Practical (CEH-Master), Certified Network Defender (CND), Microsoft AZ-900, Currently Enrolled EC-Council M.S. Cybersecurity
9 个月Love this