Welcome! I am the Harbinger. A "harbinger" is someone or something that announces the approach of another. That is the goal of this blog. I will be providing a look ahead at the future of cyber security and at the forces that are shaping the future of this technological age.
Sociotechnical Project Video
Get link
Facebook
X
Pinterest
Email
Other Apps
-
This video is created for Unit 5 Discussion Board 2 post on our Sociotechnical Project.
Before World War II , France poured its military resources into building the Maginot Line, a massive chain of fortifications designed to prevent a German invasion. It was an engineering marvel and a symbol of confidence in modern defense strategy. But it failed. Germany bypassed the Maginot Line by advancing through the Ardennes Forest, an area France had deemed too rugged and irrelevant to defend. That assumption proved fatal. By ignoring an older vulnerability in favor of a newer, more "obvious" threat vector, France left itself open to a devastating attack. In cybersecurity, we’re making the same mistake. Just a few years ago, I was purchasing books on pentesting IoT devices and completing Udemy courses on IoT security. It felt like the next big cybersecurity frontier, a sprawling, vulnerable ecosystem of smart locks, thermostats, TVs, and routers, all running outdated firmware and barely protected APIs. But over time, that focus faded. The industry shifted almost ent...
There is probably no topic of contention that I encounter more as an IT security consultant and auditor than mobile device security. People and organizations just don’t want to secure themselves against mobile devices. The excuses are numerous: · Regulating employee mobile devices will lower morale. · Employees will think we are spying on them. · Other organizations allow their employees to use mobile devices freely. · No one worries about mobile device security anymore. I have even heard many of these statements from other information security professionals, including the last statement. DON’T BE FOOLED! Mobile devices are a serious risk to your organization. I have appeared on the news three times in the last few years to speak about attacks and threats targetin...
While serving as the head of an Information Security department, I once had a Chief Technology Officer (CTO) tell me, "The organization doesn't need security controls as long as they have security awareness training." The statement will seem naïve and even laughable to many security professionals. However, his words reflect a growing misconception shared by technology leaders in a time where everyone is worried about employees clicking on ransomware, visiting infected websites, or compromising a network over the VPN. Even my own Doctoral Dissertation is about the need for mandatory cybersecurity awareness training courses in middle schools. Yet, a look at the news reminds us that securing employees inside a company is not enough to secure the company. One of the most concerning stories hitting the news this month is how ransomware groups are turning their focus toward firmware attacks. Leaked chats from the Conti ransomware group reveal that the organization is acti...
Comments
Post a Comment