Blog

  • Don’t Suck – STOP Paying Ransoms

    So, in case you haven’t heard, we have this problem. Yeah, there’s this thing called ransomware, and it’s sort of all over the news. The city of Baltimore is being held hostage by ransomware – The good: the city decided not to pay the 13 bitcoin (~$100,000 at the time) ransom. The bad: the city is still reeling, with the attack expected to cost more than…

  • Denver ISSA Incident Management Workshop Recap

    Finally. I’m finally getting around to posting about this event. The fine folks of the Denver ISSA chapter invited me to speak at their chapter event on May 23rd. The event was a three-hour incident management workshop (titled Incident Management – Panic or Plan). ‘Wait! What?! Three hours?! Yes. These poor folks endured three hours of my preaching. Read on… About Denver ISSA The Denver…

  • 2019 New Directions in IT Education Conference

    This was a wonderful opportunity to talk to some fascinating people; people tasked with helping us create the future talent of our industry. It was also the fourth talk at the fourth conference of the week, so things were getting a little weird. Regardless, I always enjoy this and I’m having fun! About the 2019 New Directions in IT Education Conference This is an annual…

  • 2019 Secure360

    Almost caught up with my conference and talk summaries from a couple weeks ago! Secure360 is arguably “the” security conference in the Twin Cities each year. 2019 was the 14thyear for the event and it was very well-attended. About Secure360 In the words of the Upper Midwest Security Alliance (“UMSA”): This marked the first year that the event was held at the Mystic Lake Center…

  • Loffler Tech Fest 2019

    Where does the time go? Loffler Tech Fest 2019 was held at the St. Paul (MN) RiverCentre on May 15th, and I couldn’t get around to writing this short summary until now. Ugh. This was the 2nd talk I gave (of five) that week, and the first of two I gave that day. This is my short summary. About Loffler Tech Fest It’s rare to find…

  • 2019 North America CACS Conference Recap

    Each year, the Information Systems Audit and Control Association (ISACA) puts on a really good event in North America; the CACS Conference. This year’s conference (2019) was held at the Anaheim Convention Center from May 13 – 15. Read the conference brochure here. This was my first time attending this conference. ISACA put on a great event in my opinion. Kudos to them and the…

  • OSINT (and Human Trafficking) Resources and Suggestions

    I’m writing this article for two reasons. To give props to our community and to summarize the quality responses that I got to a recent tweet. Props First off, I’d like to give HUGE props to our information security community. Last week I posted the following on Twitter. I use Twitter like many people do, I’ll respond to interesting topics and post thoughts about things….

  • #100DaysofTruth – Week One

    If you follow me on Twitter or LinkedIn, you may have noticed that I started a new campaign. The name of the campaign is #100DaysofTruth, and it’s a pretty simple concept. Each day at 8:00am CDT I’ll post a new truth about information security, one per day. See?! Simple. I have two reasons for doing the campaign: I want to educate. Over the years, it’s…