

Resilient Cyber w/ Mark Simos - Cybersecurity Anti-Patterns
Oct 17, 2024
In this captivating discussion, Mark Simos, a Microsoft veteran with a wealth of experience in cybersecurity, shares insights from his provocative RSA Conference talk on common security anti-patterns. He emphasizes how a technology-centric mindset often neglects business assets, calls out the harmful 'silver bullet' mentality, and humorously addresses the paradox of blame in security settings. Mark also critiques the office of 'no' that resists new trends, urging a shift towards empathy and collaboration to break these recurring mistakes.
AI Snips
Chapters
Transcript
Episode notes
Microsoft Cybersecurity Journey
- Mark Simos has worked at Microsoft for 24 years, starting in support and later specializing in cybersecurity.
- He witnessed the growth of Microsoft's cybersecurity business from a small consulting service to a multi-billion dollar industry.
Anti-Patterns in SAF
- The Security Adoption Framework (SAF) arose from the need to efficiently explain common security mistakes.
- Anti-patterns in SAF provide shortcuts for discussions and faster understanding.
Technology-Centric Thinking
- Technology-centric thinking frames security as a technical issue, solvable with tools, neglecting business assets.
- This leads to applying technical solutions to non-technical problems, like business email compromise.