Podcast: DevSecOps
I recently chatted with Mark Miller over at DevSecOps
I recently chatted with Mark Miller over at DevSecOps

Innovation, regulation, and more.

What comes easily should still be taught and elaborated upon.

An unexpected book review.
What if we gamified security?
Reasons for failure in real-world security

Exploring threat models as code.

My Linkedin Learning course is getting really strong positive feedback. Today, I want to peel back the cover a bit, and talk about how it came to be.
I’m excited to be able to share “Announcement: IriusRisk Threat Modeling Platform 2.0 Released.”

For the last few years, I've been delivering in-person threat modeling training. I've trained groups ranging from 2 to 100 people at a time, and I've done classes as short as a few hours and as long as a week.

Happy Holidays!
Discussing the value of Security Advisory Boards

A new game from SANS for understanding pen test methodology, tactics, and tools.
The Threat Modeling Book has been featured on a list of resources by Digital Guardian.

The House Oversight Committee has released a scathing report on Equifax...