27 Followers
63 Following
177 Posts
Security generalist with passion for detecting and stopping bad guys, especially in OT networks.
Bloghttps://safecontrols.blog/
AboutMehttps://safecontrols.blog/about/
Why availability and integrity are more important than confidentiality for OT - disabling safety systems and manipulate process control can lead to physical accidents.
When is an extra security control worth the cost?

There are many security controls to choose from, but they are not all created equal. We, as security experts, are not good at estimating or explaining what the security benefit of investing in a new control would be in business terms.

When data has little value to you but potentially high value to attackers, please consider deleting it.
If you are trying to enable the fingerprint reader on a ThinkPad on Ubuntu, this blog post is helpful: https://ubuntuhandbook.org/index.php/2024/02/fingerprint-reader-t480s/. Using the GUI settings is easier than fprintd-enroll, though.
Enable Fingerprint Reader in Ubuntu 24.04/22.04 for ThinkPad T480s | UbuntuHandbook

The #AIAct has been celebrated for protecting our rights, and condemned for killing all innovation in Europe. The good news: most of the requirements are already practices for organizations with robust corporate governance and cybersecurity practices! https://safecontrols.blog/2024/08/14/does-the-ai-act-make-it-illegal-to-use-ai-for-european-companies/
Does the AI act make it illegal to use AI for European companies?

The AI Act does not make it illegal to use AI, but it does regulate a lot of the use cases. As EU acts typically go, it makes it mandatory to do a lot of assessment, documentation and governance &#…

safecontrols
Favorite osint quick enumeration tool?
amass
0%
theHarvester
0%
Just google it
0%
Other (what? please comment!)
100%
Poll ended at .
Reading the AI Act. It has provisions to foster innovation and support startups and SME's, but reading the legalese brings feelings of trying to speedrun upstream a river of high density mud. The support is in form of conformity templates, awareness training and being prioritized for joining a regulatory sandbox.
What is the biggest security hurdle for CISO's?
Knowing the posture
11.8%
Finding the right controls
0%
Communicating with others
64.7%
Finding time to get things done
23.5%
Poll ended at .
I have a blog I have been publishing to a bit on and off since 2015. Today I looked at the statistics for the last 12 months. 15% of the posts got 80% of the views, and some of the more popular posts are quite old - from 2015, 2019, and from 2022. Take a look at https://safecontrols.blog if you are interested :)
safecontrols

Risk management, reliability and security

safecontrols
Cybersecurity requires everyone to help - and that's perhaps the hardest thing to achieve for security managers. Here's a guide to how you can approach that, including engaging top management and resolving apparent conflicts with other internal functions. #infosec #cybersecurity #management https://safecontrols.blog/2024/07/22/engaging-the-whole-workforce-in-cybersecurity-a-guide-for-security-managers/
Engaging the Whole Workforce in Cybersecurity: A Guide for Security Managers

Cybersecurity requires everyone to contribute but that is hard to achieve. In this post we look at how security managers can think like marketers to engage the management team, create strategic ali…

safecontrols