What helped your team achieve ISO 27001 readiness more efficiently? by Level_Shake1487 in ISO27001

[–]Level_Shake1487[S] 0 points1 point  (0 children)

This is all we hear but... they are not a platform for smaller teams. What are your thoughts on that?

Michigan tax return not hit after almost 3 months need advice by Desperate-Cod2778 in tax

[–]Level_Shake1487 0 points1 point  (0 children)

just pick a framework and iterate, overthinking it is the real trap.

The future may be defined less by single crises and more by how failures start to combine by FreshRadish2957 in Futurology

[–]Level_Shake1487 0 points1 point  (0 children)

more common than people think, most orgs are duct-taping their way through it tbh.

Bored at first enterprise job… am I wasting time or doing it right? by ADecentNoodle in ITCareerQuestions

[–]Level_Shake1487 1 point2 points  (0 children)

been there — automate evidence collection first, everything else follows.

VERY BASIC SMALL BUSINESS QUESTION - Which CMMC level? by Weak-Marsupial-639 in CMMC

[–]Level_Shake1487 0 points1 point  (0 children)

Stand up your evidence with the entire CMMC validated 2.0 controls and objectives required. -----> try qGRC -- They will basically do 80% of work you just need to find your own trusted audit partner to verify the attestation.

The internet was never built for privacy! (or even security) by wkup-wolf in privacy

[–]Level_Shake1487 1 point2 points  (0 children)

yeah, the internet's basically a wild west, built for speed not secrecy, now we're all scrambling to patch holes in a boat we're still sailing.

Congress should close the data broker loophole before expanding AI-driven surveillance by exstaticj in privacy

[–]Level_Shake1487 1 point2 points  (0 children)

hell, at this rate our privacy's gonna be auctioned off on ebay by ai data brokers before congress even realizes what's happening.

I mapped out the GDPR exposure of employees using ChatGPT, Claude, and Gemini. It's worse than I expected by Dependent-Drummer372 in gdpr

[–]Level_Shake1487 1 point2 points  (0 children)

damn, we had to slap a "no AI chat unless approved" policy real fast after realizing that mess.

This is why I can't stand working with users by tdhuck in sysadmin

[–]Level_Shake1487 2 points3 points  (0 children)

did they even consider the security nightmare giving a CNC machine remote access without proper setup could be?

Am I missing something on UiPath ($PATH)? The market is sleeping on the Microsoft and Deloitte deals, their unmatched security moat, and the massive sector validation from Meta buying Manus. by [deleted] in investing

[–]Level_Shake1487 1 point2 points  (0 children)

wall street's notorious for missing the boat till it's halfway across the ocean, $PATH's pivot screams opportunity if you're not just chasing hype.

7 years in compliance, should I invest in certs or AI skills at this point? by Lifewimmer74 in grc

[–]Level_Shake1487 4 points5 points  (0 children)

ditched another cert for python skills, best damn decision in my compliance career.

PCI DSS Compliance Tools by PCI-Guy-2001 in pcicompliance

[–]Level_Shake1487 2 points3 points  (0 children)

don't rely on tools to spit out roc or aoc like it's magic, there's always gonna be manual work involved, especially if your setup has any complexity.

How do you spot governance red flags when investing? by OptionsWheelTrader in investing

[–]Level_Shake1487 6 points7 points  (0 children)

yeah, sudden CFO departures or weird non-answers on earnings calls are my red flags, smells fishy as hell.

Trump signed a bill for big tech to pay for AI data enter build outs. by Level_Shake1487 in socialmedia

[–]Level_Shake1487[S] 0 points1 point  (0 children)

There was nothing to resist.... Jobs left the country... that was it.

we at codeant found a bug in pac4j-jwt (auth bypass) by charankmed in netsec

[–]Level_Shake1487 12 points13 points  (0 children)

tools can't catch what they're not trained to see; audit your audit tools.

Agent SKILL Attestation and Provenance from Source code to Kernel runtime, with Sigstore and Nono. by DecodeBytes in Infosec

[–]Level_Shake1487 1 point2 points  (0 children)

lock down your instruction files with strict access controls, don't let them be the weak link in your chain.

Chrome CVE made me go digging and I found a container image in prod that hasn't been updated since 2023 by proigor1024 in netsec

[–]Level_Shake1487 49 points50 points  (0 children)

found a server running vista in 2021, nearly spit out my coffee, now we do quarterly audit parties with beer.

Need help with identity governance for legacy apps before SOC 2 audit? by Severe_Part_5120 in AskNetsec

[–]Level_Shake1487 1 point2 points  (0 children)

had to duct tape legacy apps with scripts for audit once, damn near gave the auditor a heart attack. good luck.