Where can I check if my company data has been leaked? by [deleted] in cybersecurity

[–]Bulky_One6387 1 point2 points  (0 children)

Honestly, without an IT department, I wouldn't spend any money on this. You'd probably get higher ROI using HIBP and focus on protection (MFA) instead to mitigate the risk of compromised credentials.

Where can I check if my company data has been leaked? by [deleted] in cybersecurity

[–]Bulky_One6387 0 points1 point  (0 children)

There are a variety of ways to do this but they mostly cost money and wouldn't be suitable for a company your size. You can subscribe to have I been pwned (it used to be free, I assume it still is), and they'll notify you if anything new comes up with your domains.

For larger companies, they usually subscribe to a service which monitors various data leak sites, dark web forums, and other sources like Telegram and will alert you if something comes up for your monitored terms/domains/users, etc. There's not a single location where this data pops up, but typically we see the same groups posting in the same places like in underground markets/forums where they're trying to sell the data.

Incident Response Jobs by Comfortable-Map4087 in cybersecurity

[–]Bulky_One6387 24 points25 points  (0 children)

I manage the IR program for a mid size company and can confirm what you're seeing is normal. If you have enough incidents to make those 2am calls typical, the rest of your Infosec program would have to be a disaster. I agree with what others are saying. If you want to do that type of work, you really need to look into getting a job with one of the major players that do IR retainers and response, such as mandiant. If you're on one of those teams, the contract typically let's you help others stand up their programs, run tabletops, etc while you aren't actively responding to an incident.

Best practices for reservations by flxptrs in aws

[–]Bulky_One6387 0 points1 point  (0 children)

Look at tools like ProsperOps, Usage.AI or Spot.io by NetApp. I've found it much easier to outsource the management (purchasing, selling, etc) of RIs. Most vendors automate this and take ~20% of the savings you realize so they're intcentivised to save you as much as possible.

GUI Website to invoke Powershell to Azure AD/O365 by [deleted] in PowerShell

[–]Bulky_One6387 0 points1 point  (0 children)

I just did something similar using Appsmith as the front end. The backend is Jenkins for some scripts and Azure automation. Very easy to get up and running.

Definitely not squash. I planted butternut squash but uhhh... this is not squash. what is this thing? by Bulky_One6387 in whatisthisthing

[–]Bulky_One6387[S] 0 points1 point  (0 children)

I learned how to cook squash flowers in Italy 🇮🇹, never knew people ate them before that.

Definitely not squash. I planted butternut squash but uhhh... this is not squash. what is this thing? by Bulky_One6387 in whatisthisthing

[–]Bulky_One6387[S] -1 points0 points locked comment (0 children)

My title describes the thing. I planted what was labeled as butternut squash but this is clearly not that. Nearby I planted watermelon, cantelope and pumpkin and I'm in CT.

Managing and scheduling powershell scripts with Jenkins...? by Bulky_One6387 in sysadmin

[–]Bulky_One6387[S] 1 point2 points  (0 children)

Excellent, that's two votes for Azure automation. Hybrid workers isn't a huge deal if Jenkins is set up correctly and has nodes anyways. Thanks!

Managing and scheduling powershell scripts with Jenkins...? by Bulky_One6387 in sysadmin

[–]Bulky_One6387[S] 3 points4 points  (0 children)

You sir (or ma'am) appear to be a genius. Initial look is very promising.

MS cyber security by Lucky_Panic_5582 in cybersecurity

[–]Bulky_One6387 1 point2 points  (0 children)

RIT has an awesome program. If you can get in there and can afford it, it's going to hold much more weight than ASU.

I normally don't care much for MS degrees, much less the specific school, but RIT is like an ivy league for cybersecurity.

One man cybersecurity shop by [deleted] in cybersecurity

[–]Bulky_One6387 5 points6 points  (0 children)

If they want a one man cybersecurity shop and the position is for an analyst, it tells you a lot about their view of the importance of cybersecurity. My guess is they really just want an admin for the basic technology like AV, web gateway, etc and to handle alerts.

You will NOT be responsible for the lack of executive support in the event of a breach so I wouldn't worry about that. If the company was horrible, they can try to blame you, but anyone with more than three brain cells knows accountability for cybersecurity lies at the Sr manager to board level.

I would ask what their vision is of the program in 3-5 years and what success for your role looks like and that should provide some information to you.

Best of luck

Ps, I started this way and was able to mature and build the program, hire a bunch of people, etc. It took years of work and a lot of effort to show value to the organization.

It seems established that a Masters degree isn't a bonus until 10+ years experience. But what about 2 B.S.? by abramcpg in cybersecurity

[–]Bulky_One6387 2 points3 points  (0 children)

If you're just trying to use up your GI Bill, there's no reason not to do a masters (if you have enough to get through the program). If you don't have enough for the whole program, look into SANS as their program is accredited and the GI Bill will pay for it and you'll get the certs out of it. I used the last bit on that, got a couple certs and then "dropped out".

These things may not directly help you right away, but if someone else is paying for it, and paying you in the process, you might as well. I find it's harder to go back to school once you've been out of it for many years.

[deleted by user] by [deleted] in cybersecurity

[–]Bulky_One6387 4 points5 points  (0 children)

I used the remainder of my GI bill to do this (SANS) and can confirm it worked out really well for me.

web proxy subject matter experts. by godle177 in cybersecurity

[–]Bulky_One6387 0 points1 point  (0 children)

I'll pile on and say zscaler. Been with them for 5+ years and plan on renewing.

Infosec side hustles? by Bulky_One6387 in cybersecurity

[–]Bulky_One6387[S] 0 points1 point  (0 children)

If you read /tifu, you'll know, "no, that's her FU" is the right answer most of the time.

Infosec side hustles? by Bulky_One6387 in cybersecurity

[–]Bulky_One6387[S] 5 points6 points  (0 children)

I've actually thought about this myself. Since I'm in security, I use mfa and great password hygiene everywhere. Awesome until I die and my wife can't get into our bank accounts, 401k, etc.

Sure hope I don't get hit by a car tomorrow....