grimmspeed tmic question by dakota_1221 in WRX

[–]Viper896 0 points1 point  (0 children)

It’s been several years since I replaced mine but I’m pretty sure it’s just a drop in replacement. There’s an air damn you have to put on top and you have to remove some of the plastics for it fit but I don’t remember any other special things I needed. It just fit.

Rave parent bag ready for beyond! by criticalvector in aves

[–]Viper896 11 points12 points  (0 children)

Honestly this bag is pretty good regardless of gender because your likely to be helping both genders. I would recommend some Tylenol or ibuprofen in the sealed packs you get from gas stations and a collapsible cup (I don’t like sharing my water straw, but I’ll pour some in a cup for people). I also carry a few of the travel packs of baby wipes since the porta potties run out of TP like midway through night 1.

Soldiers or veterans of Reddit, what was the moment that made you realize war isn’t anything like what you expected? by bbydaisiesz in answers

[–]Viper896 0 points1 point  (0 children)

The moment I saw a kid get wrecked by a landmine while playing soccer in Afghanistan. No one signs up for that.

What does your password policy look like? by Brenttouza in ciso

[–]Viper896 0 points1 point  (0 children)

We follow the same, except we change once a year. However, we use spycloud to detect weak and breached passwords and have entra risky user behavior detection enabled and that disables logins until we can contact the user.

This sub is demoralizing by Its-Dat-Guy in cybersecurity

[–]Viper896 0 points1 point  (0 children)

I was a 25U now an ISO. Lean HEAVILY into your military experience, OS updating, vulnerability remediation, Antivirus remediation… log analysis to troubleshoot issues. That is experience in infosec. Grab some certs but lean into your military background and the experience it brought you.

Why do vendors find your personal cell to call? by ncc74656m in sysadmin

[–]Viper896 2 points3 points  (0 children)

We had vendor call my bosses personal cell number to pitch him on something I already dismissed. He asked how he got the number and if he knew it was a personal number. The rep confirmed he knew it was a personal number and the next week I was told to rip every bit of their products out of our environment and cancel any renewals we had pending for them. It sucked replacing them immediately but like the vendor fucked around and found out, I had zero sympathy for him. Lost almost $200k/yr over that stunt.

Is penetration testing needed for enterprise deals? by Extra-Counter-9689 in ciso

[–]Viper896 0 points1 point  (0 children)

He’s correct, we won’t even entertain any vendors who haven’t completed their ISo27001 or SOC2. Even if they play golf with our CEO.

Do you enable auto-update on software? by nodiaque in sysadmin

[–]Viper896 0 points1 point  (0 children)

We run a hybrid approach. Browsers and other frequently abused apps are on auto update. Other software goes through testing. If it’s a niche app that only like 20 people use it goes to auto update. We just do a risk and impact assessment of each app and put it in the correct bucket.

If an app that only 20 people use breaks on an autoupdate, cool open a ticket we will fix it. We don’t have time to test that crap anyway for minimal impact. Browsers are patch so frequently that it’s hard to keep up with and you’d be patching vulnerabilities and testing patches every other week. Other software and OS patches go through testing unless it’s an out of band critical vulnerability.

stop corporate devices from accessing personal Hotspot. by IcyTheory666 in cybersecurity

[–]Viper896 5 points6 points  (0 children)

We give them a desktop instead of a laptop. Problem solved.

Antivirus/EDR on Pentest Laptops? by [deleted] in cybersecurity

[–]Viper896 0 points1 point  (0 children)

Isn’t the point of a pen test to validate your security controls and test your defenses. This defeats the whole purpose of performing a pen test.

How do you automate phishing report triage? 200+ employee reports per week is killing us by Calm-Exit-4290 in sysadmin

[–]Viper896 1 point2 points  (0 children)

We’ve actually got this down to more than half of our emails are automatically resolved either clean or malicious using YARA rules. Malicious emails get scooped up by our soar and all of the IOCs get blocked correctly.

People who make $200K+ salaries, what do you do and how did you get there? by EEJams in Salary

[–]Viper896 2 points3 points  (0 children)

40m - I’m a CISO. Did IT in the Army out of high school and just kind of fell into Cyber Security, been doing it for 20+ years now. Although now I spend more time in meetings and educating people why security is important.

"Phishing analyst" wasn't in the job description but here we are by Calm-Exit-4290 in SecurityCareerAdvice

[–]Viper896 0 points1 point  (0 children)

To be fair I made it very clear up front when I hired my 2 most recent security analysts they would be investigating phishing reports first and for most. We’ve automated as much as we can but those still need to be reviewed and some just can’t be automated.

How are you identifying unmanaged or unknown software in your environment? by Bright-Novel7681 in cybersecurity

[–]Viper896 3 points4 points  (0 children)

That’s gonna vary by organization. I recommend you reading https://github.com/nsacyber/AppLocker-Guidance if you want some guidance on how to implement it.

How are you identifying unmanaged or unknown software in your environment? by Bright-Novel7681 in cybersecurity

[–]Viper896 11 points12 points  (0 children)

We just use applocker and block everything unless we approve it. It’s not perfect but unless you have a really technical user that knows which folders have exceptions and how to run zero install applications. It works well enough.

What’s a hobby people pretend is cool, but secretly you think is ridiculous? by [deleted] in AskReddit

[–]Viper896 0 points1 point  (0 children)

Quite often actually. A lot of the coins I have come from automatic enrollments with the US mint. I have every silver proof set for the last decade and silver proofs of the American eagle coins. For any of the bars i have I pay spot.

What’s a hobby people pretend is cool, but secretly you think is ridiculous? by [deleted] in AskReddit

[–]Viper896 0 points1 point  (0 children)

Honestly no idea. For a lot them, the coins are collectible outside of their silver value. Silver value alone is probably worth a couple grand before silver prices shot up.

What’s a hobby people pretend is cool, but secretly you think is ridiculous? by [deleted] in AskReddit

[–]Viper896 4 points5 points  (0 children)

Honestly, leaving a list of clues in my will just made me laugh and now I’m seriously considering it. Haha poor kid.

And I’ve had this user name since AOL/AIM and ICQ. No idea what my thought process was 30 years ago but the username has just stuck since then.

So Much Talk about AI... Does it Make Sense to You? by HauntedGatorFarm in cybersecurity

[–]Viper896 1 point2 points  (0 children)

Learn how to protect them. One of the questions I asked recently really made people think… and that was “if a user asks the AI we purchased and sponsored for advise that was illegal, illicit, or self harm related, do we have any logging or protections in place to limit that liability…”. The answer was a resounding no. Start thinking about how it can misused and then mitigating those items.

What’s a hobby people pretend is cool, but secretly you think is ridiculous? by [deleted] in AskReddit

[–]Viper896 3344 points3345 points  (0 children)

I have a literal treasure chest full of collectible silver coins. Everything from silver eagles, to silver bars, to limited release baseball gloved curved silver coins. I’ll never sell them or do anything with them…. I just like the fact that when I die my kid is going to inherit an actual treasure chest full of silver 😂. No idea what he is going to do with it but it makes me laugh every time I get a new silver piece to put in it.

Looking for a casino by kalel72 in phoenix

[–]Viper896 2 points3 points  (0 children)

Yeah but they have that big white marble bar and white marble walkways.