Tag: security

  • Teaching to the Test. Why It Security Audits Aren’t Making Stuff Safer – Bullshit Work in enterprise security. // Plus, why not start with basics before going advanced: ‘The world would be better off if organizations stopped wasting so much time and money on these vendor solutions and instead stuck to much more basic solutions.…

    Read more

  • Kubernetes Security Report: Evolving Landscape of DevSecOps – Red Hat Kubernetes surveys results, here, looking at the security part. The theory is: there’s too many different parties working on security, causing “confusion and delay.”

    Read more

  • AWS CISO: In AI gold rush, folks forget application security – “the places where we’re seeing the security gaps first are actually at the application layer”

    Read more

  • Don’t freak out too much about Kubernetes and security, it’s just like any new technology that’s early in usage

    Don’t freak out too much about Kubernetes and security, it’s just like any new technology that’s early in usage

    … Here’s a little interview I did with Torsten Volk at EMA research. We talked about security concerns with Kubernetes. He’s done a great, very thorough look at Kubernetes usage and the state of things. You can get it for free thanks to my work. Not enough failure yet to be perfect As ever with…

    Read more

  • UK.gov efficiency hurt as legacy tech upgrades stall – Security is always the FUD-stick: “Dame Meg Hillier MP, PAC chair, said: ‘Whitehall’s digital services, far from transforming at the pace required, are capable of only piecemeal and incremental change. Departments’ future-proofing abilities are hobbled by staff shortages, and a lack of support, accountability and focus…

    Read more

  • Shadow IT guidance – Advice from the UK government: “Though clearly not desirable, the existence of shadow IT presents your organisation with learning opportunities. If employees are having to resort to insecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make…

    Read more

  • What the Government Email Account Hack Says About the Future of Cybersecurity – Always be securing all the things.

    Read more

  • Security Team Culture Matters – Being in security should be a happy job. // “Security and risk teams are more motivated and purpose-driven than others. As a 25-year cybersecurity veteran, this totally checks out for me. “Almost everyone I know in [IT security] is mission- and purpose-driven. They took on this job to protect others!”

    Read more

  • Summarizing Articles with ChatGPT Works Again

    Summarizing Articles with ChatGPT Works Again

    Our final talk in our software stuff for financial organizations is coming up tomorrow. Above is a little anecdote that Darran made to me as we were working on it. If you’re into security, compliance, that kind of thing, check out the third part of our series: “How Cloud Native Improves & Ensures Security, Governance,…

    Read more

  • Adopt Platform Engineering to Scale Application Security Practices – “Gartner Survey Data Reveals a Missed Opportunity – Platform teams focus on improving developer experience, developer productivity, software quality and delivery speed. According to Gartner’s 2022 Software Engineering Leaders Role Survey, only 25% of respondents cited “reduced security risks’’ as one of the top three goals…

    Read more

  • Catching up on the HOT links

    Catching up on the HOT links

    Do you like words like: security – governance – PCI – regulation – SBOMs?! Then you should attend our talk series on cloud native app development in banks, insurance companies, and financial services. It’s online and, of course, free. Relevant to your interests The Quest for Better, Faster Deals – The highest quality deals are…

    Read more

  • The Care and Feeding of Internal Developer Platforms – Five benefits of monitoring and managing internal developer platforms are noted: improved system performance, cost reduction, scalability, enhanced security, and improved feedback loops. Achieving these benefits entails securing deployment environments, establishing system baselines, setting up alerting rules, monitoring application performance, and automating processes.

    Read more

  • 2023-05-30 day note

    I recorded a podcast today on security in cloud native. Security can seem like an incomprehensible complexity from the outside, but when you ask an expert to break it down, it’s simple. Sure, lengthy and tedious and precise, but not impossible. I’ll post it in the Tanzu Talk podcast feed sometime this week. I spent…

    Read more

  • Thinking Strategically About Software Bills of Materials (SBOMs) – As with most things, the whole SBOM push is probably a lot simpler to solve than it seems. Also, a delightful “old man yells at secure software supply chain hype” vibe as only Jon could do well.

    Read more

  • Setting the Record Straight on Cloud Computing ROI – Ability to add new features(quickly), access to new tech, scaling and performance, toil reduction to focus on things valuable to the business or competitive advantage, better security. Of course reducing costs (or “efficiency” if you’re forced to feel the “do more with the same/less” vibe) is…

    Read more

  • Enterprise interest in sovereign cloud on the rise, survey – “In a poll of 1,000 enterprise leaders from 10 countries, including Australia, France, Germany, India, and the UK and US, 69% of respondents cited potential exposure to extra-territorial laws when using cloud as being a top concern.”

    Read more

  • AI at KubeCon EU, Security and Governance Kubernetes Koncerns

    AI at KubeCon EU, Security and Governance Kubernetes Koncerns

    Kubernetes Security and Governance Tools on the Rise This is an excerpt from a series analyzing the VMware State of Kubernetes 2023 survey. It’s a three part blog series that’ll be published over the next three weeks or so. I hope! Anyhow, in the meantime: From the VMware State of Kubernetes Survey 2023. People are…

    Read more

  • IT is asked to do more, and sometimes with more budget!

    IT is asked to do more, and sometimes with more budget!

    Updates to the VMware app runtimes If you’re into platform engineering, the two VMware platforms have some announcements today that you’ll be interested in: Tanzu Application Platform v1.5 – There’s faster ways to get it installed, security improvements, tighter integration with Spring Boot apps, and a lot more. Rita gives some highlights: “Enhanced IDE support…

    Read more

  • SpringOne stickers.gif

    Security is only a problem with open source if you do nothing

    It’s hard to know if there’s too much stuff should be doing, or if I have it project managed well enough that I don’t need to worry about it right now. Below, a little bit on being cool with security in open source usage (survey says!) and the usual collection of interesting words seen, stuff…

    Read more

  • What is DevSecOps? Coté’s Commonplace Book – Issue #65

    What is DevSecOps? Coté’s Commonplace Book – Issue #65

    OMGWTFBBQDEVSECOPS; how to give a DevOpsDays vendor pitch; The Difference Between DevOps & DevSecOps In this longer blog post, I go over how I’ve finally come to think about what DevSecOps is. A summary of what the post covers: A secure software supply chain – This is a fancy way of saying “we know all…

    Read more