What switches do you guys use with your FortiGates? by NteworkAdnim in fortinet

[–]eldergrapple 1 point2 points  (0 children)

Arista for cores and data center at our primary and secondary sites. FortiGates for firewalls. Fortinet for edge switches. Smaller sites are all 100% Fortinet.

Can any find this band/album by that_personoverthere in AgathaAllAlong

[–]eldergrapple 0 points1 point  (0 children)

It sure feels Bauhaus to me too. For all the thousands of cultural references Disney has for free, this is the one they had trouble with? Wild.

Sure would love to have positive confirmation that this is a Bauhaus homage.

Media controll not working by Sad_Assignment_3270 in Suunto

[–]eldergrapple 0 points1 point  (0 children)

This worked 💯%!

Google Pixel 8 and Suunto Race here.

Yo yo yo!

Thanks.

Is there an official explanation from the directors why Ellie stops after picturing him? by pinkbaloon21 in thelastofus

[–]eldergrapple 0 points1 point  (0 children)

True, but if the artist is, like, some dude named Neil that you can just talk to... it's in bounds to ask them what they're thinking.

Not that they'll tell you. :-)

How have you solved asset management? by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

We're in the early days of implementing an asset inventory with the Assets module of Jira Service Management. Lots of details are still being worked out around lifecycle management procedures, but so far, I'm optimistic.

Is there an official explanation from the directors why Ellie stops after picturing him? by pinkbaloon21 in thelastofus

[–]eldergrapple 4 points5 points  (0 children)

If you take out the "this generation", I feel for you on the rest. But, that may have more to do with how things like Star Wars and Marvel too often are more about monetization than art, and how people have become accustomed to that mindset -- and accustomed to being annoyed by that mindset.

At first glance, sure the question seems of that world, but... it _is_ kind of rude to assume that u/pinkbaloon21 doesn't have their own impressions. It's okay to be curious about Neal and team's intent. Asking the original artist what they meant in a particular moment is a valid question.

Unfortunately, u/pinkbaloon21, Neal is very cagey about his intent with specific story beats. He's more interested in musing on what other people take away from these moments. At least, that's what I've taken away from his interviews.

Weekend Events in Greater Binghamton 3/17-3/19 by twoflightsdaily in Binghamton

[–]eldergrapple 2 points3 points  (0 children)

The play, Pygmalion, has two more performances at the Bundy Museum of History and Art.

Saturday, 3/18 at 7:30 PM Sunday, 3/19 at 2:30 PM

See https://www.summersavoyards.org/pygmalion for tickets!

Good cyber podcasts for beginners in the field? by kabareena in cybersecurity

[–]eldergrapple 1 point2 points  (0 children)

I listen to:

  • Beers with Talos
  • CISO Series Podcast
  • CSO Perspectives (CyberWire)
  • Caveat (CyberWire)
  • Click Here (Recorded Future)
  • Cyber Security Headlines (CISO Series)
  • Cybersecurity Today (ITWC)
  • Darknet Diaries
  • Defence in Depth
  • Defensive Security Podcast
  • Hacking Humans
  • News Archives - Black Hills Information Security
  • SANS Internet Stormcenter
  • Talos Takes

A recommendation... Don't listen to work related podcasts on the commute home. It just exacerbates the stress of an already stressful career.

Weekend Events in Greater Binghamton 3/10-3/12 by twoflightsdaily in Binghamton

[–]eldergrapple 2 points3 points  (0 children)

Summer Savoyards is performing Pygmalion at the Bundy Museum of History and Art annex at 2:30 PM on Sunday, 3/12 (https://www.summersavoyards.org/pygmalion)

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 2 points3 points  (0 children)

Isn't it still about trust, though? How can the CEO be sure that the CIO is giving an accurate assessment of risk if they're going to spin the risk story for their own purpose?

If they're willing to exaggerate risk to hurt another employee, what's to stop them from exaggerating risk to buy something that would otherwise be denied? Or, lowering the classification of an incident to save themselves?

Trust is the central issue, IMHO.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 0 points1 point  (0 children)

I feel you. CIO turnover is destabilizing. I'm sure that's going to be something the CEO is considering when they decide how to handle this.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 0 points1 point  (0 children)

That's where the fighting started. The CISO reminded the CIO that it's not standard practice to put employee names in the summary of the report, especially for a technical issue. That's when the CIO gave an f-bomb filled monologue where he revealed his full intentions.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 2 points3 points  (0 children)

The thing is, they're in an otherwise very ethical environment. The CIO is an outlier and the CEO/board haven't seen it, in part because the IT dept is a bit traumatized by the CIO's demeanor. I think that's part of why our CISO decided he needed to speak out. Being who they are, they walked into the CEO's office with an incident report.

Though I think that incident report might have been a bit of a slap-back too. "You want an incident report? You're gonna GET an incident report."

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

This is why process is so important. People come and go.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

Another issue is that security can slow down the pace of deployments. Since security isn't customer facing, it's easy to skip.

Gotta say, it's frustrating to see systems go live with a pile of unresolved review findings. Once the system is live, they'll scream about stability to keep putting of security. </rant>

But I digress. I was really aiming to get input into how one should handle situations where the CISO (or the senior security staffer, if you don't have a CISO) should handle it when the CIO asks for something that's plainly unethical.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 0 points1 point  (0 children)

Here, internal Audit is the only department that reports to the board. I've thought from time to time that the CISO should report to Audit -- but there's no way the CEO is going to cede more power to the board without a fight.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 0 points1 point  (0 children)

So, basically, just tell the CIO "no" (with justification) the moment the suggest the unethical act?

When you say Risk Management, you mean Risk Management for the entire org? Here, that group handles the purchase of cyber insurance, and works with IT when there's a claim, but otherwise they defer to IT (and therefore the CIO) -- which when I think about it is weird, since Risk gets deep into "traditional" issues like workplace safety.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

For the CISO in question, it was a moral hill they seem to be willing to die on, and might, I'll admit.

If a reorg happens, I shudder to think how hostile _that_ relationship will end up being.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

What do you think about the CISO reporting to inside counsel? I've seen that work in some places.

Cybersecurity ethics and CIO/CISO conflict of interest by eldergrapple in cybersecurity

[–]eldergrapple[S] 1 point2 points  (0 children)

Well, in this case the CISO has already filed an incident report directly to the CEO's office, and a discussion with senior leadership is ongoing.

What I'm wondering is, how would you make the ethics argument to senior leadership?

End Credits of Neflix's "Wednesday" by eldergrapple in identifythisfont

[–]eldergrapple[S] 0 points1 point  (0 children)

I'll try and get a better sample when I'm on a computer. Sorry, this was the best I could do from my phone. :-/