Some security weaknesses can't be found with a scan or a vulnerability assessment of the infrastructure. As a security manager, you have to keep your eyes open for things that aren't as secure as they should be, based on any evidence that comes your way. That happened to me a few weeks ago, in just about the best way possible. We were able to take steps to tighten security in a particular area after an incident that could have been damaging but actually wasn't. I wish all our security lessons could be so benign.
- Report: Security hole in macOS Keychain puts passwords at risk
- DDoS protection: CloudFlare drops surge pricing, Microsoft responds to AWS Shield
- The week in security: As business and CISOs struggle to unite, hackers scoring big hits
- Mass CCleaner malware attack actually targeted tech giants
- NotPetya costs FedEx $300m, now weighs up cyber insurance