You Cannot Block Infinity

We should block the RMM! We should block that IP! We should block that port! The trouble is; there’s 65535 ports per protocol (TCP/UDP), there’s billions of IPs (dynamic and rotating infra are a thing), and well that’s a lot of work, neve ending, in fact!!

This topic has come up a number of times recently so I thought I’d put it into a blog, so I had Claude generate this based on my quick fire views:

Read more “You Cannot Block Infinity”

You Can’t Defend Everything: Threat Modelling as an Economics…

In a world now seemingly filled with mad probability robots you might think this makes the world simpler, I’m not so sure…. More code, faster, more tools, faster, more technical debt, faster… and then what of the erosion of the human importance? Well human 2.0 is probably augmented not redundant… and who doesn’t love a bit of Deus Ex! Now full disclosure this blog is guided by me but written by Claude (mostly), why? Why not? I’m still here, guiding things, writing this intro by hand, but the concepts of cyber security, the foundations and underpinning logic, well they are probably older than me! I’m not talking about castles and moats, but even they play a part in our understanding of attack and defence. There’s even a bit of a public wifi link here if you read between the lines. Not every threat actors is all knowing and all powerful (in fact no one is!). So let’s see what Claude Opus 4.8 has to say about the topic:

Read more “You Can’t Defend Everything: Threat Modelling as an Economics Problem”

Cyber Myth: Attackers only have to be right once,…

Our cyber world is full of myths and FUD:

Attackers only have to be right once, Defenders have to be right all the time!

Firstly, let’s cut straight to the chase, I can only assume that someone who says this is ignoring or is unaware of how computer systems and intrusions work. But surely this is a true phrase, I’ve seen it repeated over and over again on LinkedIn, so it must be true right?

Read more “Cyber Myth: Attackers only have to be right once, Defenders have to be right all the time!”

Email Security: An Enablement Journey, Not a Maturity Ladder

Most organizations treat email authentication as a checkbox exercise. Deploy SPF, publish DMARC in reporting mode, call it done. But the real story isn’t about maturity tiers—it’s about what you unlock at each phase of implementation. And frankly, the gap between where organizations are and where they need to be is brutal.

This post outlines an enablement journey: each phase builds on the previous one and creates new capabilities that weren’t possible before.

Read more “Email Security: An Enablement Journey, Not a Maturity Ladder”

DNSSEC

‘You are totally compromised!’ because you don’t have DNSSEC configured on domain…..

The implication is that you’re one packet away from catastrophe. It’s alarming. It’s also, for the overwhelming majority of organisations, not true. I have been talking about this for years and years!

Here’s the quickest way to see through it. I scanned the Majestic Million – the top one million domains on the internet – for DNSSEC. About 6.75% were signed (around 8.2% if you only count domains that actually resolve). The .com zone, which is half the list, sits at 4.6%. And the unsigned set includes google.com, amazon.com and microsoft.com.

So if “no DNSSEC” means “totally compromised,” then the three most-attacked, best-defended companies on the planet are totally compromised, and have been for years, on purpose. They aren’t. The finding is measuring conformance to a checklist, not risk. Let’s understand why this is!

Read more “DNSSEC”

The danger of internet exposed RDP

There’s lots of things in cyber security to consider when looking at how to defend a network, and whilst the world goes mad about public wifi and juice jacking, the real threats are often far simpler. Imagine having say an Active Directory domain member, or even controller exposed to the internet with Remote Desktop Protocol? Might sound insane but this is a common route for entry for ransomware actors.

Read more “The danger of internet exposed RDP”

The cost of resetting a password

If someone asked you how much the cost of a task is, I bet you would struggle to given them an accurate response, the default position of most people is to underestimate a cost of doing something (but estimation science show’s us that it tends to vary based on role e.g. project managers are risk averse, engineers think they can solve things faster than they can and executives often just want it to be cheaper for the sake of it being cheaper – Parkinsons Squeeze I think that is called)

Years ago I stared looking at total cost of ownership (TCO) and Return on Investment modelling (I mean a lot of years ago….) and I’ve created a range of models for organisations for:

  • Sales Estimation
  • Business Cases
  • Budget Planning
  • Project Planning
  • System Optimisation Analysis
Read more “The cost of resetting a password”

Cybercrime and data theft

During an incident it’s one of the first questions people ask, what did the attacker do? Did they steal any data? How did they do it?

All of which are typically rather difficult to answer in the first, probably week of an incident (incidents vary, sometimes it’s very obvious, other times you can’t be 100% sure on some details!)

But recently I’ve been talking lots about the way organisations communicate during incidents to their customers and the public etc. I’ve been explaining that the day 0 comms of ‘no data was stolen’ followed by a ‘lots of data was stolen’ in say day zero plus five… well it doesn’t help with my my trust in the victim organisation. Which to me, seems like an odd strategy for organisations to take. They have options:

Read more “Cybercrime and data theft”

What if breach communications were honest?

Armed with my trusty sidekick, this morning I thought I would see what an LLM would make if I asked it to create public comms for common cyber incidents…. for basically every scenario… it really wanted to tell everyone no data was accessed! Which is amazing, because in almost every incident I’ve seen: Data is accessed!

In a business email compromise (BEC) scenario…. the clue is in the name, it’s already a compromise of confidentiality!

Read more “What if breach communications were honest?”

Using cyber security investments as a business enabler

Making security both an organisational support capability but also enabling business is not easy. Lots of the security activity is for obvious reasons not totally transparent. However one thing I want to show people is how you might want to tell existing and prospective customers about the way you approach security within your organisation. One way to do this is to show people how you align to the NCSC 14 Cloud Security Provider Principles.

Read more “Using cyber security investments as a business enabler”