People Over Policies, Pt. 4 — Culture Is Your Strongest Firewall

Firewalls block packets.Culture blocks complacency. You can deploy every control in the book—MFA, EDR, SIEM, SOAR—but if your people don’t care, don’t ask questions, or don’t feel safe reporting mistakes… you’ve already been breached. Over the years, I’ve learned that the strongest defense isn’t at the perimeter—it’s in the mindset of your team.It’s the engineer […]

Read more "People Over Policies, Pt. 4 — Culture Is Your Strongest Firewall"

People Over Policies, Pt. 3 — The First 24 Hours of an Incident Response

People Over Policies, Pt. 3 — The First 24 Hours of an Incident Response No policy survives first contact with an incident. When a breach, outage, or ransomware alert hits, every second counts—and every assumption gets tested.The playbooks are important, but what really matters in those first 24 hours isn’t the policy binder.It’s the people […]

Read more "People Over Policies, Pt. 3 — The First 24 Hours of an Incident Response"

How Network Isolation Saved Us: How a 2014 Compliance Requirement Became Our 2018 Ransomware Recovery Plan

The Air-gap Network That Saved Us How a 2014 Compliance Requirement Became Our 2018 Ransomware Recovery Plan In cybersecurity, you don’t always build systems for the problems you expect.Sometimes, the thing that saves you was never meant to exist for that reason at all.That’s exactly what happened to us. 2014 — A Contract, a Quake, […]

Read more "How Network Isolation Saved Us: How a 2014 Compliance Requirement Became Our 2018 Ransomware Recovery Plan"

That One Time I Was a One-Person Cybersecurity Department

That One Time I Was a One-Person Cybersecurity Department I saw this post from Kaaviya Balaji saying: “If you’re looking for someone who knows SIEM, SOAR, EDR, XDR, IAM, MFA, SSO, Cloud (AWS, Azure, GCP), Firewalls, Compliance (ISO, NIST, GDPR, PCI-DSS), Incident Response, Threat Intel, and more…That’s not a Cybersecurity Analyst.That’s an entire Cybersecurity Department.” […]

Read more "That One Time I Was a One-Person Cybersecurity Department"

Closing the Gaps: How We Reduced Our Managed Risk Score from 7.9 to 5.7 and Reached 100% Coverage

Cybersecurity & Operations Excellence. In cybersecurity, numbers tell stories — but not the whole story.The summer we dropped our Arctic Wolf Managed Risk Score from 7.9 to 5.7 and raised our Coverage Score from 70% to 100% wasn’t just about metrics. It was about culture, consistency, and the quiet discipline of doing the hard things […]

Read more "Closing the Gaps: How We Reduced Our Managed Risk Score from 7.9 to 5.7 and Reached 100% Coverage"

Case Study: From 76 to 94 — Turning Security Findings into Business Resilience

Author: Brian NicholsTitle: Director of Infrastructure & CISOCompany: Select Data, LLCFramework Alignment: NIST CSF v1.1 | ISO 27002 | HITRUST | OWASP Challenge: When Cyber Insurance Meets Real Accountability In 2024, Select Data’s cyber insurance provider introduced a new requirement for policy renewal: “Enroll with SecurityScorecard and improve your external cybersecurity rating.” At the time, […]

Read more "Case Study: From 76 to 94 — Turning Security Findings into Business Resilience"