Internal security trainings and awareness awards | ESM part 7

Conduct recurring security trainings Videos and online presentations are good, but nothing can really replace quality in-person meetups. Show as many demos as possible and don’t stick do overloaded PowerPoint presentations which put people to sleep. It’s fine to share raw technical details as a recap materials, but while starting out you must make people … Continue reading Internal security trainings and awareness awards | ESM part 7

Make security simple | ESM part 5

  Simplify it for them Security is often perceived as complex and cumbersome which makes engineers unwilling to work on it. In order to get things done you need to simplify and carefully explain your requirements. Strive to make it easier to build secure products because cheaper it is to add security, more likely it’ll get … Continue reading Make security simple | ESM part 5

Build credibility and learn business language | ESM part 3

  Avoid confusion and FUD at all cost Credibility is something you’re building from the day one to the last day of your career. Even if you’re great industry expert, you still need to build your internal reputation from the ground up by working nicely with people in your organization. Crucial thing you need to learn … Continue reading Build credibility and learn business language | ESM part 3

Guide into Effective Security Management

After 10+ years in IT and 5+ in InfoSec I’ve learnt that for security initiatives to be effective, security must one of the core values of corporate culture. Security professionals can’t achieve their greatness if they’re not being actively supported by all stakeholders across the entire organization and if other employees don’t feel ownership for … Continue reading Guide into Effective Security Management

Peerlyst ebook: Essentials of Cybersecurity

Essentials of CyberSecurity is a crowdsourced ebook written by @Peerlyst community. I wrote the chapter ‘Building corporate security culture’ with following preface, which should give you a solid context for the message I tried to convey in my article. All those years in InfoSec taught me that for security initiatives to be effective, security must … Continue reading Peerlyst ebook: Essentials of Cybersecurity

Hiring your first security professional

I really enjoy attending security/business conferences. But it’s not that I’m going there to learn how to do security, because if that would be the case then I’d go for DEFCON or Derbycon and learn from top hackers on the planet. I go to business conferences because I want to listen to the problems others … Continue reading Hiring your first security professional