Ryan McGeehan

254 Followers
122 Following
28 Posts
Former FB / Coinbase security leadership. Writes "Starting Up Security" @ http://scrty.io.
Writinghttps://scrty.io
Twitterhttps://twitter.com/magoo
Tabletopshttps://twitter.com/badthingsdaily

I wish all security pros practiced a scenario-first mindset. Explanations based on risk scenarios before jumping to best practices, gaps, controls, compliance etc. I wrote an essay to coach on this: "Writing a risk scenario"

https://medium.com/starting-up-security/writing-a-risk-scenario-bdbe6e20bfcb

Writing a risk scenario

A risk scenario is a fictional but plausible event that could harm your organization. Writing one well improves communication with others…

Medium

I wrote about that moment every security team faces when someone asks if they can work from China for a while, and then everyone freaks out.

https://magoo.medium.com/the-working-from-china-problem-18045ca8060a

The “Working from China” Problem - Ryan McGeehan - Medium

Companies restrict work laptops and remote access from countries they consider risky, particularly China. Where does a travel policy like this come from? Companies debate how much risk actually…

Medium

I wrote about how detection engineering should be prioritized in a security program. Feedback and discussion welcome!

https://medium.com/starting-up-security/prioritizing-detection-engineering-b60b46d55051

Prioritizing Detection Engineering - Starting Up Security - Medium

Detection Engineering is more than code and platforms. How should a security program prioritize it?

Starting Up Security

Writing about risk because I haven't written in a while.

Here's "Beyond Controls: The Power of Risk Scenarios"

It's some stuff about boosting "scenario" usage in everyday security work.

https://magoo.medium.com/beyond-controls-the-power-of-risk-scenarios-218b9acc93f8

Wrote about risk communication: Talking about risk with thresholds.

Feedback welcome, thanks!

https://magoo.medium.com/talking-about-risk-with-thresholds-61011be2898f

Talking about risk with thresholds 🔥 - Ryan McGeehan - Medium

This essay is about openly acknowledging these thresholds exist in security risk conversations. It’s a communication tactic that helps manage the work you aren’t doing, and gives others a chance to…

Medium

So in late November, a panel of 26 of us ended up forecasting a 76% chance that Twitter would have an outage by Jan 30, which happened. Wrote about it here: https://magoo.github.io/risk-measurement/blog/forecasting-a-twitter-outage/

Condition #1 easily passed - several newspapers of record called it a widespread outage.
Condition #2 passes, though, DownDetector being the "measurement" that the newspapers cited just barely passes the rules as written.
Condition #3 was easy - could not read or write tweets.

The rules were written to capture a real gnarly outage, and this one sorta squeaked by right over the bar.

In the future, we might be able to use panels like this for more objective measurements of downtime: https://deadbird.singlepane.io/d/hI9vrUO4k/home?orgId=4&refresh=30s

Thanks to all the 🍕 panelists who participated!

Forecasting a Twitter Outage

Will Twitter experience a severe outage before January 30? (UPDATED)

Risk Measurement

CircleCI breach retrospective w/ IOCs and TTPs

Quick TLDR:

1. Malware on eng laptop
2. Stole active SSO session for a remote session
4. Generated production access tokens
5. Exfil'd customer ENVs, tokens, keys.
6. CircleCI encryption keys exfil'd too.

https://circleci.com/blog/jan-4-2023-incident-report/

CircleCI incident report for January 4, 2023 security incident

Read the complete incident report from CircleCI’s January 4, 2023 security alert.

CircleCI
Tabletop Scenarios on Twitter

“Your CI/CD servers are compromised. All environment variables and secrets involved in your build have leaked to an attacker.”

Twitter
CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 13)

Read CircleCI’s security alerts from January 2023. Last updated 1/13/2023.

CircleCI