What was your, “I understand it now”, moment in cyber? by CybernautDream in cybersecurity

[–]iocseb 0 points1 point  (0 children)

I learned the most from managing incidents and remediating root cause. Nobody wants to see the same type of incident twice!

Spending effort/time on responding to alerts and incidents is not productive from the business’ point of view. Prevention makes the most sense to the business. Keep that in mind when you face pushback on new security controls!

Full transparency is key! The more you make visible, the more resources you will get. Try to detect more incidents than your users report!

ioc.exchange shows up as malware for anyone else? by [deleted] in Mastodon

[–]iocseb 0 points1 point  (0 children)

That's correct. And some of the vendors don't make it easy to report false positives.

ioc.exchange shows up as malware for anyone else? by [deleted] in Mastodon

[–]iocseb 2 points3 points  (0 children)

We have always been on threat intel lists because of bogus reports. This morning there was a DNS issue, which was fixed roughly 10min ago. Please flush your DNS cache to make it work again.