Resilient Cyber

Resilient Cyber w/ Mark Simos - Cybersecurity Anti-Patterns

Oct 17, 2024
In this captivating discussion, Mark Simos, a Microsoft veteran with a wealth of experience in cybersecurity, shares insights from his provocative RSA Conference talk on common security anti-patterns. He emphasizes how a technology-centric mindset often neglects business assets, calls out the harmful 'silver bullet' mentality, and humorously addresses the paradox of blame in security settings. Mark also critiques the office of 'no' that resists new trends, urging a shift towards empathy and collaboration to break these recurring mistakes.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Microsoft Cybersecurity Journey

  • Mark Simos has worked at Microsoft for 24 years, starting in support and later specializing in cybersecurity.
  • He witnessed the growth of Microsoft's cybersecurity business from a small consulting service to a multi-billion dollar industry.
INSIGHT

Anti-Patterns in SAF

  • The Security Adoption Framework (SAF) arose from the need to efficiently explain common security mistakes.
  • Anti-patterns in SAF provide shortcuts for discussions and faster understanding.
INSIGHT

Technology-Centric Thinking

  • Technology-centric thinking frames security as a technical issue, solvable with tools, neglecting business assets.
  • This leads to applying technical solutions to non-technical problems, like business email compromise.
Get the Snipd Podcast app to discover more snips from this episode
Get the app