My top security topics
One of the best things about working in cybersecurity is that it's always changing. There are always new things to learn and think about. Here are some of the areas of security that I'm thinking about the most right now:Securing the digital supply chainThe evolution of cloud-native securityInternet of Things (IoT) securityThe human element of securitySecuring web3 and blockchainI'll take them one by one this week and share some quick thoughts on why I think they're interes...
Poor man’s Gong
If you’re someone who works with me, you may have noticed that I ask to record our Zoom calls more often than I used to. There’s a reason for this. While I can’t justify the cost of a revenue intelligence platform like Gong for my small shop, I made up my own poor man’s version. Here’s how it works.Download and install Descript. (There’s a free version.)Hit the record button on a Zoom call and pick the “Record on this computer” option.After the Zoom call ends, drag the video file that Zoom sp...
Welcome to the simulation
OK, now that the marketing guy explained what Zero Trust is, let’s get into some ways to give security buyers a plan for it (that hopefully includes some of you). There’s a real danger that this could get boring in a hurry, so here’s what I’m thinking. Over the next few days, I’ll give you my quick take on what I like and don’t like about the three possible starting points I mentioned. I’m not going to regurgitate every detail, but I’ll try to give you the gist. Then, I’m going to make up a f...
I share daily thoughts about cybersecurity and emerging technology. [Subscribe](https://daily.axalane.com) or [hire me](https://axalane.com)
My top security topics
One of the best things about working in cybersecurity is that it's always changing. There are always new things to learn and think about. Here are some of the areas of security that I'm thinking about the most right now:Securing the digital supply chainThe evolution of cloud-native securityInternet of Things (IoT) securityThe human element of securitySecuring web3 and blockchainI'll take them one by one this week and share some quick thoughts on why I think they're interes...
Poor man’s Gong
If you’re someone who works with me, you may have noticed that I ask to record our Zoom calls more often than I used to. There’s a reason for this. While I can’t justify the cost of a revenue intelligence platform like Gong for my small shop, I made up my own poor man’s version. Here’s how it works.Download and install Descript. (There’s a free version.)Hit the record button on a Zoom call and pick the “Record on this computer” option.After the Zoom call ends, drag the video file that Zoom sp...
Welcome to the simulation
OK, now that the marketing guy explained what Zero Trust is, let’s get into some ways to give security buyers a plan for it (that hopefully includes some of you). There’s a real danger that this could get boring in a hurry, so here’s what I’m thinking. Over the next few days, I’ll give you my quick take on what I like and don’t like about the three possible starting points I mentioned. I’m not going to regurgitate every detail, but I’ll try to give you the gist. Then, I’m going to make up a f...
Share Dialog
Share Dialog
I share daily thoughts about cybersecurity and emerging technology. [Subscribe](https://daily.axalane.com) or [hire me](https://axalane.com)

Subscribe to Doug Lane

Subscribe to Doug Lane
<100 subscribers
<100 subscribers
Let's kick off this week's run through my top security topics with securing the digital supply chain.
What does it actually mean?
These days, nearly every technology product or service is built through collaboration across multiple companies. So securing them effectively requires tools and practices that extend across organizational boundaries. And guess what: this doesn't happen very much.
Why is it interesting?
Two of the most catastrophic security incidents of the last several years, SolarWinds and Log4Shell, were supply chain attacks.
Managing security across organizational silos within a single company is hard enough. Coordinating across companies takes the degree of difficulty much higher.
We're already getting clobbered on software supply chain attacks alone. But as I'll dive deeper into tomorrow, this is just one of several possible supply chain attack vectors.
-Doug
Let's kick off this week's run through my top security topics with securing the digital supply chain.
What does it actually mean?
These days, nearly every technology product or service is built through collaboration across multiple companies. So securing them effectively requires tools and practices that extend across organizational boundaries. And guess what: this doesn't happen very much.
Why is it interesting?
Two of the most catastrophic security incidents of the last several years, SolarWinds and Log4Shell, were supply chain attacks.
Managing security across organizational silos within a single company is hard enough. Coordinating across companies takes the degree of difficulty much higher.
We're already getting clobbered on software supply chain attacks alone. But as I'll dive deeper into tomorrow, this is just one of several possible supply chain attack vectors.
-Doug
No activity yet