read.cash Log in
@M.Rosenquist

@M.Rosenquist in September 2020

@M.Rosenquist

Smart Cities Keynote: Security and Privacy After 2020 I am looking forward to a great keynote conversation and Q&A session about the new normal for digital security & privacy of smart cities. As our cities embrace digital technologies to extend and improve services to its citizens, it is important to weave in security and privacy controls to reinforce trust. Come join my co-speakers Marcelo Peredo, the CISO of the City of San Jose, and Zulfikar Ramzan, the CTO of RSA, as we…

@M.Rosenquist

Defenders show up to the war on deepfakes Digitally altered and synthetic media are becoming more of a problem. Openly available tools, including AI Deep Learning, enable the easy modification of pictures and videos for distribution on the Internet. Most are benign; clearing up acne, improving image lighting, creating a funny meme, or perhaps narrowing a waistline for aesthetic reasons. More disturbing is the generation of videos of known personalities, making them appear to…

@M.Rosenquist

EC-Council Free Online Event for Cybersecurity Skills Development EC-Council is announcing the #TheNextBigThingInCyber skills development in a free online event on Sept 16th 9:30am EST. EC-Council's CEO, Jay Bavisi will discuss what it means to Humanize firewalls, build a new era of ethical hackers, empower cyber defenders, and the importance of great penetration testers. I am on the EC-Council International Advisory Board for CISOs and you can sign up to attend this online…

@M.Rosenquist

Intel patches 9 vulnerabilities in their management platform Intel has released patches for several security vulnerabilities in their Active Management Technology (AMT) and Intel Standard Manageability (ISM) platforms. One of them was a critical flaw in AMT that allowed remote privilege escalation CVE-2020-8758 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8758 It is nice to see more Intel product vulnerabilities are being addressed, especially those that reside in…

@M.Rosenquist

Painful IoT Security Lessons Highlighted by a Digital Padlock The first warning sign was “hackproof” in the **360Lock marketing materials**. As it turns out, with no surprise to any security professional, the NFC and Bluetooth enabled padlock proved to be anything but secure. https://www.kickstarter.com/projects/1686612613/360lock-1st-modular-smart-padlock-certified-by-blo **Straightforward penetration testing revealed** horrible logical and physical security for a padlock…

@M.Rosenquist

Podcast: Reactive to Proactive — The Evolution of Security and the CISO | with Matthew Rosenquist A free-flowing discussion about the past and future evolution of cybersecurity leadership. I had a great time sharing my personal experiences, industry insights, and a few rants in this podcast interview with Marco Ciappelli and Sean Martin of ITSPmagazine. https://www.itspmagazine.com/the-business-of-security We cover a lot of ground: The history before cybersecurity, how to…

@M.Rosenquist

Beware of Unified Cybersecurity Solutions Claiming to Help CISO's I am seeing many security vendors developing products to unify solutions into a single management interface. I fear this is just a sales tactic to gain greater market share and not intended to help the plight of CISO’s A recent article from ComputerWeekly highlights a vendor sponsored report that concludes forthcoming unified solutions are greatly desired by CISO’s and will be embraced by the industry. I am…

@M.Rosenquist

Tips for all of us to be more cyber secure There are many cybersecurity aspects we cannot control in our digital world. It can make anyone feel powerless. But we can control how we act and the decisions we make as we interact online. Secure behaviors are tremendously powerful when it comes to remaining safe and avoiding widespread attacks such as phishing, ransomware, email/web distributed malware, and other nasty things that bite. **Tips:** 1. Don't open attachments or…

@M.Rosenquist

We Don’t Want IoT Cybersecurity Regulations It simply makes no sense to call for IoT devices to be certified safe-and-secure. Before you get bent out of shape, hear me out. Regulations are unwieldy blunt instruments, best left as a last resort. Cybersecurity regulations are not nimble, tend to be outdated the day they are instituted, and become a lowest-common-threshold for an industry to follow. This stifles security innovation and the application of best practices. On the…