Stephen Lawton

43 Followers
21 Following
58 Posts
I am a technology journalist and a cybersecurity subject matter expert. Comments are my own; normal disclaimers apply.

CVEs likely will reach an all-time high this year, perhaps surpassing 40,000. What's the cyber insurance take on all this and the growing number of vulnerabilities? What must boards, CISOs & CIOs know? Check out my latest in @DarkReading. #CyberInsurance

https://www.darkreading.com/cyber-risk/more-cves-cyber-insurers-arent-altering-policies

Are data brokers misbehaving when it comes to compliance with CCPA? Are their actions sinister or simply part of their learning curve? A UCI study looked at these data brokers' actions. Here's my take in #DarkReading

https://www.darkreading.com/data-privacy/gaps-in-california-privacy-law-half-of-data-brokers-ignore-requests

Happy Canada Day!

Considering how many lies we've heard from ICE, Trump, and others in this administration, ICE denying it tried to enter Dodger Stadium sounds hollow. Men in unmarked cars and masks are the trademark of ICE raids - and kidnappers.

We require a federal law that says federal agents not working undercover must have badges, their names, their agency and their face clearly visible during a police action.

Time for a history lesson, folks. After WW2, Nazi soldiers and officers were brought to trial in Nuremberg. When asked why they committed the atrocities they did, they said they were only following orders. It didn't wash with the judges and a great many were convicted.

Will the Marines in Los Angeles try to use the same defense if they break the laws? I hope these American soldiers remember they swore an oath to the Constitution, not Trump.

In my latest Dark Reading piece, I look at how CISOs & enterprise security will be affected by digital certificates with shorter lifecycles. Managing the possible thousands of certs could be easier than you think, even for SMBs. #cybersecurity #risk

https://www.darkreading.com/vulnerabilities-threats/digital-certificate-shorter-lifespan-reduces-security-vulnerabilities

Shorter Lifespan Reduces Digital Certificate Vulns

Proposals from Google and Apple drastically reduce the life cycle of certificates, which should mean more oversight — and hopefully better control.

In my latest piece for CSOonline, I update an article on network tools. If you are responsible for managing corporate networks, this can help bring clarity to chaos. 13 essential enterprise security tools — and 10 nice-to-haves

https://www.csoonline.com/article/566389/10-essential-enterprise-security-tools-and-11-nice-to-haves.html

13 essential enterprise security tools — and 10 nice-to-haves

Do you have the right tools to handle a changing threat landscape, tougher regulatory climate, and increasing IT infrastructure complexity? Here are the must-have security tools for meeting today's challenges.

CSO Online
Does anyone know why nearly every image in my feed is blurred out? Even some of my own posts are blurred out. Is this the best Mastodon can do as a Twitter alternative? Not impressed.

In my latest @DarkReading story, I look at how #deepfakes work & what can be done to defend against them. I also touch on how they can be used legitimately in business. As Prof. Yu Chen said, "We cannot believe our eyes anymore. What you see is not real." #cybersecurity

https://www.darkreading.com/data-privacy/regulators-combat-deepfakes-anti-fraud-rules

Regulators Combat Deepfakes With Anti-Fraud Rules

Despite the absence of laws specifically covering AI-based attacks, regulators can use rules around fraud and deceptive business practices to fight AI-based fraud and deepfakes.

If you are a cybersecurity exec, board member or C-suite exec and you're concerned about being ready for quantum computing, check out my latest in @CSOonline. I offer up multiple actions you can take immediately to prepare for the potential PQC threats.

https://www.csoonline.com/article/3552701/the-cisos-guide-to-establishing-quantum-resilience.html

The CISO’s guide to establishing quantum resilience

Security leaders must help their orgs prepare immediately for a post-quantum environment. Here are the steps and strategies CISOs, security teams, and C-suite colleagues must take and shape — starting with facilitating a board-down cultural shift.

CSO Online