Come Join the Discussion

Add your comments to any of these postings or comments

Wednesday, May 11, 2022

Managers need to Manage, Not Rest on their Laurels

How often have we seen excellent practitioners promoted to management, and be so very unprepared for the job. Companies owe it to their people to train them if they are new to management. Empowering employees, mentoring them, and supporting them are key skills that are hard to come by, but are essential for any good manager. Think back to your experiences with some of your previous managers and I am sure you can have a wide variety of experiences.

Thursday, May 05, 2022

Russia vs Russians

So will it be a trend that will continue where all Rusians and Russian companies will be dropped? How do we balance being fair to people that have nothing to do with this horrible invasion with the desire to both punish Russia and protect our own interests and security?

OWASP LA is going LIVE and In-Person!

Big News from SoCal: the OWASP LA Chapter meeting May 25 at 5:30pm will be in-person in Santa Monica, hosted by Lawrence Harvey. We are looking for companies interested in providing food and drink for our attendees. Want to partner with us? Let me know. Thanks!

Thursday, January 20, 2022

Prettyfluid Technologies

I am excited to announce that I have joined the Advisory Board of an innovative and emerging software company, PrettyFluid Technologies (https://lnkd.in/gPVaa7c7), headquartered in Scottsdale Arizona. The company was founded by software and technology industry veterans, who have a passion for securing and protecting data. It’s flagship product, Zentinel, allows small-medium sized companies to protect customer information and eliminate business breach liability with the same level of security and compliance as Fortune 500 companies, but for a small fraction of the effort and cost. Personally, I am a huge consumer rights and data privacy advocate, and what I also love about Zentinel is it allows consumers to centrally manage their own data! PrettyFluid Technologies is committed to helping organizations to preserve revenue while addressing federal, state, and industry data privacy regulations such as GDPR, CMMC, CCPA, HIPAA, and others. I feel strongly about recommending this solution and company; check out https://www.prettyfluidtechnologies.com/ or feel free to contact me for an introduction.

Be Yourself

Reflecting on my long career, the most important aspect, as well as one of the toughest things to do, is to be yourself. People, particularly those who work for you, will see right through all your clever phycological machinations, no matter which advanced degree program or mentor you learned them from. Nothing resonates more than honesty, integrity, and being yourself.

Sunday, June 27, 2021

Preventing Ransomware Events

There is no special magic bullet to prevent ransomware. A good Information Security Plan covers all the things you need, but which sadly are not being done by so many companies and agencies. Here are a few key things that come to mind: 1. Don’t allow any unencrypted services, like telnet, on your network 2. Don’t use RDP, at least not without VPN 3. Advocate for your company's hardened systems only connecting to your network; otherwise implement good mitigating controls 4. Offline backups to restore data if attacked and data encrypted 5. Regular and tested patch management process 6. Use threat intelligence to block known bad sites 7. Require admins to only use privileged accounts when doing privileged tasks 8. Security awareness: don’t click that link or open that attachment! 9. Test your incident response and backup/restore plans 10. Use MFA 11. Use DMARC, SPF, and DKIM with your email domain so cybercriminals cannot spoof your email accounts.

Trump DOJ Secretly Seized Phone Records of NYTimes Journalists Reporting on Comey’s Clinton Investigation

And THIS is why we must staunchly fight for privacy rights. Power corrupts. Encryption back-doors can also be abused by those in power who are unscrupulous. https://www.newsandguts.com/deja-vu-trump-doj-secretly-seized-phone-records-of-nytimes-journalists-reporting-on-comeys-clinton-investigation/

Supreme Court sides with police officer who improperly searched license plate database

Better think about updating your policies! Proving violations of the Computer Fraud and Abuse Act just got a lot tougher. https://www.cnn.com/2021/06/03/politics/supreme-court-cybercrime-law-case/index.html

Sunday, March 28, 2021

Building Strong Teams

Building strong teams is probably the most important aspect of a successful leader's role. Choosing the right people and getting them all to blend together to work together for a common goal is more important than anything else you can do. None of this has anything to do with technology, but is clearly a human issue. When you are looking for good people, choose the best person available, not one who brings a very focused and specific set of skills, but might have character issues. Be flexible in your organizational structure and be willing to move people around to achieve harmony and success.

Wednesday, February 24, 2021

You Have Enemies?

"You have no enemies, you say? Alas, my friend, the boast is poor. He who has mingled in the fray of duty that the brave endure, must have made foes. If you have none, small is the work that you have done. You’ve hit no traitor on the hip. You’ve dashed no cup from perjured lip. You’ve never turned the wrong to right. You’ve been a coward in the fight." - Charles Mackay

Predictions for 2021

Predictions for 2021: 1) Rezoning of commercial districts to allow conversion of office space into residential condos. 2) Migration of professionals away from central cities, resulting in movement of some states from red to blue (reference Ga and Tx). 3) Lowering of salaries as companies will not have to pay big city rates. 4) Reduction in attendance at regional events in big cities 5) Increase in attendance at professional organization meetings in mid and small cities 6) Increase in hoteling workspaces in company offices as staff only will come to work physically 1-2 times/week.

Friday, January 22, 2021

Cyber Security and Cloud Podcast

I was very honored to be interviewed by ☁️ Francesco ☁️ Cipollone. We talked about many things, including #cybersecurity, #leadership #career #management #appsec #diversity and #pentesting. I would recommend a listen. https://www.nsc42.co.uk/cscp/episode/ded19a53/cscp-s02ep29-richard-greenberg-ciso-heatlhcare-community-owasp-and-issa

Thursday, January 07, 2021

Blackwater Contractors?

OK, so are there any connections to the trump pardon of the Blackrock 4 and the rioters scaling the walls of our nation's capital? Are there any further events planned utilizing any contractors?

Friday, December 04, 2020

Effective security patch management is probably the number one security control

Effective security patch management is probably the number one security control that can have the greatest impact in your company. It is crucial that you have processes in place to ensure regular, timely, and enterprise-wide patching. Always first test patches on a pilot group, and be sure to include third-party apps. We still see folks concentrating on MS patch Tuesday. The trickiest part will be minimizing the excluding of systems, as owners and certain vendors will still make claims that you can break their apps. Isolate systems that cannot be patched effectively, utilizing VLANS and firewall rules. Long term, look to replace these systems whenever possible. Actually, contact the vendor of these systems directly to discuss; do not take App owners’ or System Admins’ word on the patch issue. Companies are much more responsive now to demands from InfoSec. Good luck!!

InfoSec policies say “what”, procedures say “how”

InfoSec policies say “what”, procedures say “how”. We all know that we need to have a full set of Information Security policies. But, how many of us do not include procedures in policies? Getting a policy approved can be a big deal, often needing Exec Mgmt, HR, and possibly union approval. They typically do not change very often, but procedures change regularly. You don’t want to jump through all the approval hoops to make the required change in procedures. Keep them separate! Of course, you do want to review policies annually and when significant infrastructure changes occur. #informationsecurity #infosec #cybersecurity #dataprotection #policiesandprocedures

Are you practicing good configuration management?

Are you practicing good configuration management? Are you ensuring that a standard image is created, is regularly updated and tested, and is deployed everywhere, especially on admin and developer systems? Also, be diligent so all systems are hardened. Turn off all services that you will not be using. And for any changes, make sure that you have established and tested a change management process. Form a Change Management Board that meets regularly. Make sure the Board has key players from Application Security, Security, Field Support, System Administration, and Network Management. The Board needs to meet regularly (weekly?) to review all past and upcoming changes. A process should be established that classifies changes, so that minor updates/changes can be made in a timely fashion, without the Board having to meet. All changes need a back-out plan and should be as transparent to the users as possible. But all significant changes need to be announced ahead of time. Happy config/change management! #configurationmanagement #changemanagement #configmgr #hardening

Edmond Momartin, CISSP, CISA has been awarded ISSA Senior Member

With great pride we acknowledge a longtime volunteer and former ISSA Los Angeles Board member Edmond Momartin, CISSP, CISA for attaining Senior Member at Information Systems Security Association (ISSA). #issa #issala @issa @issala

Tuesday, February 05, 2019

Treasure Trove of Credentials Exposed

There are 773 million email addresses and 21 million passwords in a list circulating in the hacker community that is a compilation of many smaller lists taken from past breaches and has been in wide circulation. Some lists date back to 2015. Despite its recycling of previously breached credentials, the widely available list no doubt makes it easier than ever for even unskilled hackers to capitalize on the bevy of breaches that have occurred over the past decade. My personal advice for your accounts: 1) It’s important to change your passwords regularly, and to use different passwords for each service/site you frequent. That is almost impossible to manage. But, you can sign-up for a password manager (more on that below) 2) Enable two factor authentication for your password vault 3) Set a reminder each day to change AT LEAST ONE of your passwords to a string of 20+ random characters 4) Start enabling two factor authentication on sites that support it (email, online banking, social media) If you do this, you'll negate the black market value of credential dumps like this one. Use a Password Manager; many have free versions. https://www.cnet.com/news/the-best-password-managers-directory/ Want to check if your email account was discovered in any data breaches? Go to HIBP (Have I Been Pwned): https://haveibeenpwned.com/ Want to check if your passwords have been previously exposed in data breaches? Pwned Passwords has 551,509,767 real world passwords. If your password shows up, change it IMMEDIATELY.

Monday, October 01, 2018

The Evolving role of the CISO

The CISO's role has been evolving over the years. It is moving away from so much emphasis on compliance and monitoring towards a more strategic role, particularly as CISOs get more and more access to the C-Suite. A key to success as a CISO is collaboration with and understanding the work of other business units. A large part of the job is not about technology at all. It is about relationships, project management, and learning about several parts of the business. It is a good CISO's job to adequately assess and point out the risks to the business of various projects and business practices. What are other key elements that are part of the strategy of a successful CISO? Have you initiated a balanced Security Awareness Program? Is security baked in to your company's SDLC? Are you regularly running scans of both your network and your applications? Are you monitoring your network to detect unusual activity? What about when that dreaded intrusion into your network occurs? Do you know what to do? What about third party risk? Do you have adequate InfoSec policies, standards, and procedures?

Monday, March 05, 2018

Mental illness, Homelessness, and our Security

You might ask: Why are so may people with Mental Illness out on the streets or homeless? President Reagan has most of the responsibility why so many people with mental illness are homeless. At least one third of those living on the streets and half of our jailed population suffer from mental illness, and should be in institutions specifically designed to help these individuals. During his presidency in 1980 (a sad time), Regan stopped funding federal community mental health centers, thus removing services for those people who suffered with mental illness. While he was the governor of California, he had done something just as cruel and he released over half of the mental hospital patients in the state. He even passed legislation wiping out a requirement for involuntary hospitalization for those with mental illness. As so often is the case, as the president goes, so goes the country. As a result, states followed suite, and started to open the gates of mental institutions throughout the country. Ironically, in 1981, President Reagan was shot by John Hinckley Jr., who had mental illness. Is there a connection with so many of the shooters out and about hurting and killing so many innocent people and President Reagan? I think so!