GDPR Achieving GDPR Compliance: Episode III It's my third instalment in the epic series that is our journey towards compliance with the GDPR. We're about to be externally audited.
InfoSec Something's Rotten In The State of InfoSec Like most other spaces, InfoSec isn't without its issues and dramas. In this post, I explore a few examples and offer my views.
InfoSec Security versus Compliance In this post, I talk about what drives a more secure organisation. Is it by doing all the right things, ticking all the boxes or a pragmatic blend of the two?
AppSec Using components with known vulnerabilities In this post, I talk about how using components in your technology with known vulnerabilities can really hurt you.
GDPR Achieving GDPR compliance: Episode II Episode II of our voyage towards GDPR compliance. This covers board level buy in.
InfoSec Information Security as a Team (ISaaT) Corporate information security is *everyone's* responsibility. You hear that said a lot, but does it actually mean anything?
InfoSec Managing PCI DSS Compliance This might seem a pretty dry subject, but if your company processes card payments, then it needs to comply the the Payment Card Industry Data Security Standard.
GDPR Achieving GDPR compliance: Episode I The first in a series of posts around the GDPR and how I'm supporting my organisation on its journey towards compliance.
AppSec The (Great) Web Application Firewall In this post I talk about our experimentation with web application firewalling, the subsequent implementation and what we might do in the future.
Cons Attending InfoSec Events I attended my first InfoSec event recently and found it to be rather life changing. Read on...
AppSec Dynamic Application Security Testing In this post, I talk about dynamic application security testing and why Netsparker is my weapon of choice.
AppSec OWASP, My Membership And Why I Value It In this post, I talk about OWASP, how it's changed web application security where I work, why I became a member and find it important.
AppSec AppSec Basics - Still Overlooked The message I'm trying to get over in this post is that there are some very common different problems other than injection out there that could lead to some pretty disastrous outcomes and in fact most of them are easy to fix.
Mike Honourable Mentions At the end of my last post, I said that in this one I'd talk about some of the people that I've come into contact with during my career, whom have been critical to my development. Let me elaborate on this a little...
Mike Who Am I? I’m Mike and I’m an information security analyst, working for a mid-sized UK based telecoms and internet service provider. My career contains a lot of variety, so here in my first post, I’d like to share some of that journey.