Cybersecurity
8 posts in this category.
Coordinated disclosure: a year of reports
We received 31 reports last year through security@terravek.com. Here is what happened to them.
Read post →Hiring for security in a small team
What I look for when the security engineering team is three people and every hire is a quarter of the function.
Read post →Notes from the Baltic Security Conference
Ingrid and I spoke about running a SOC for a distributed company. The questions afterwards were better than the talk.
Read post →Transitioning to ISO/IEC 27001:2022
The control set went from 114 to 93. Here is what that actually means for an organisation already certified.
Read post →What our customers' security questionnaires taught us
I have answered several hundred security questionnaires. The good ones and the bad ones differ in one specific way.
Read post →ISO/IEC 27001: what recertification actually involves
We have held 27001 since 2015. Here is an honest account of what the audit cycle looks like from the inside.
Read post →Phishing simulations: we were doing them wrong
Our click rate went down and our reporting rate went down with it. That is the wrong outcome, and it took us a year to notice.
Read post →Building a security operations centre from two people up
Seven months in, some notes on what worked and what I would do differently starting a SOC inside a 430-person company.
Read post →