Idea: A new #InfoSec conference called "The Boring Security Conference". It covers topics and hands-on advice that are what actually keeps organizations secure. No zero-days, no APTs and no "if the criminal does these 39 things in precise order and you're not watching your owned" talks.

@chetwisniewski We need to back to basics. What are the little things that admins can do with the limited time they have, which is short?

I worry many admins feel, I am never going to be on top of security, why bother. I would not want to be an admin any more.

I looked after 250 users with a decent it budget, but I still didn’t have a patching solution and relied on WSUS for Windows Updates.