SlideShare a Scribd company logo
By Stephen Northcutt
Whether you want to be the next
CEO or don't want to be a manager
at all, every employee wants to be
treasured and doesn’t want to be
pushed around
They can’t easily fire you if
you are the best
 Business is like an action video game, keep
track of your health or life monitor status
 They will be hesitant to mess with you if
they know you can be employed elsewhere
quickly and are hard to replace
 It’s the economy: in good times there is less
scrutiny; in good times it is easier to build
skills with tools like training
 RSS every day, at a minimum USA Today Tech,
anytime we know less than USA Today, it is a
bad sign
 Know thy desktop, I was the first person at
SANS to run El Capitan
 Hot keys matter, life is a game of inches,
some favorites on the next slide
 It is crucial to keep looking at networks, because
assurance comes down to two things:
 Hardening our systems properly and keeping them
properly configured
 Knowing what traffic is coming in and out of our
systems in case the first rule fails
 AirPcap and Wireshark sure are fun
 Whenever you are troubleshooting make watching
traffic second nature
 If you don’t have a LinkedIn account with over 200
connections then start linking; I am “Stephen
Northcutt”
 Look at Google trends at least once a week, if you do
not recognize any of the top ten, that could be a clue
 Consider creating and posting a security video to
YouTube
 Think about your workplace, think about the folks that
just aren’t keeping up
Never speak to management
in hex
 Words are weapons, use language to your
advantage
 Learn, go back and read the emails you wrote in
critical situations, what could you have phrased
better
 We partly “know” or “esteem” ourselves by our
trade and skills, decide today that two of your skills
are speaking and writing
 Publish!
And so, my fellow Americans: ask not what
your country can do for you--ask what you
can do for your country.
My fellow citizens of the world: ask not what
America will do for you, but what together
we can do for the freedom of man.
 Pick a great intro, something that grabs the
audience’s attention
 Work on your outro, remind them of what
they have learned and end with a stirring
call to action
 Keep the intro and outro as close together as
possible
 Communication is the number one skill managers
want employees to have.
 Listen; listen more
 Make time for people
 Make the effort to be cogent and concise
 Express your values
 Give feedback, avoid surprises
 Practice speaking to groups as well as one on one
 Don’t overuse email, business is done by phone
I am Linda’s ski guide and tell her where to ski and when to turn; Linda is
blind. For over a year, I had never let Linda hit anything and she had
always immediately done what I asked her to. One day last year, Faith,
Linda’s daughter, was skiing with us, I had my first communication
problem with Linda, but it was a big one.
We came over a slight crest in the hill and I saw that Faith had fallen
down. I said, "Faith is down." I started telling Linda where and when to
turn. Then I said, "Okay, turn right, pull up and stop." She turned right,
aimed straight at Faith, but showed no sign of stopping. I yelled, "Stop!
Stop!" then screamed, "Sit!" just as Linda hit Faith. Sit is the last
desperate command that a guide can give to try to keep an accident from
happening. Linda sat, but it was not in time to avoid hitting her daughter.
Fortunately, neither one of them was hurt.
What went wrong? What can we learn from the story?
At any given time know what
the best selling security
books are
 Try to read a non-fiction book every two to three
weeks
 As you start to become more senior, alternate
management and leadership books with security
books
 I buy most of my books from Amazon so they can
develop a profile
 Try a search for “security”, then find the closest match
to your interests and click, see all 491,236 items
If you help people learn what
you know, they will help you
get the work done
 Think about how many things you do not know how to
do (code in java, reverse engineer, write a heap
overflow, cut the 11th column in vi ), so now give other
people some slack
 “Use the source, Luke” might have worked ten
years ago, but we are going faster than that today
 Now think about the things that you do know how to
do that you can show someone else
Bet on people and bet large
If you hold a position in a growing
organization
And you are not growing – yourself
What happens?
 I’ve invested in bonds and real estate and
done well
 Stocks and futures; mixed results
 The return on investing in people is so high, I
don’t spend much time thinking about
anything else. Two or three years from now
there will probably be 2000 people in the
Advisory Board and 100 SANS Instructors.
Be flexible, as long as you have
oxygen, power, water and
propellant you have options
 2008: Price of fuel skyrockets, airlines start charging
for second checked bag and policing carry-ons, others
file for Chapter 11
 At some point this will impact conference registrations
 We have had "Training Without Travel" options for
years, for just such a moment. At what point do we
push them?
 Listen harder! This talk has required you to
listen a number of times
 When you listen, you hear the nuances of
what people are saying, suggesting
 If you are having trouble finding options,
take a note from the original StarTrek series:
Kobayashi Maru
No sensible organization
wants to mess with a
rainmaker
Do they really need me operationally?
Do my efforts account for enough
revenue that cutting me will cost them
money
Do they know how I bring in money?
Avoid unplanned requests
for money
 Ask the smartest people you meet, where
will we be, what will we be doing
 At least once a quarter read a site like
futurist.com
 Ask your primary vendors for a briefing on
their roadmap, consider joining their
customer advisory board
 Make sure you know Ops tech refresh cycle
and plans
For any action you intend to take,
what are the most likely reactions,
what will you do in that case
Check your heart regularly, are you
trying to “Win” or are you trying to
“Win Win”
Would you rather spend
an hour with a whiner or a
go-getter?
 But I was AMAZED when I was describing my
struggles with a negative person to the executive I
admire the most and he replied “Let her go, I just don’t
tolerate a negative person”
 However, UNTIL you terminate them, learn to listen. A
negative person, poisonous attitude and all, can have a
legitimate complaint; just because they are negative
doesn’t mean they are stupid
No matter how smart you are,
the person next to you knows
something you don’t
Be patient with the set up time to
create a team
 You can be on five or six teams creating a lot of
productivity if you are organized
 LinkedIn helps, but it doesn’t keep overall status, so
that needs to be done in an outside document like the
Outlook Calendar/Contact Manager
 If you are on a virtual team, be creative with things like
time zones
 If you are on a virtual team, be quick to turn in your
comments; if a few people miss a data call, the team
has to be restarted
If you are following the first
ten laws, if someone does
something abusive to you,
push back
 Push back is a term we use at SANS
 Understand the bottom line before you begin, would you
leave a company or relationship over the issue
 Be respectful, push back is not intended to anger, but to
emphasize your point of view
 Restate what you think you have heard and ask, is this
correct? VERY IMPORTANT: Miscommunication is a big
reason for relationship degradation
 State your position
 IMPORTANT: You do not HAVE to win, sometimes you just
want to give them a chance to hear your position
When opportunity knocks,
be prepared to take
advantage of the moment
 A little sleep, a little slumber, A little folding of the
hands to rest, Then your poverty will come as a robber
And your want like an armed man. Proverbs 24:33-34
 We all have the same amount of time, it is how we
choose to spend it. There are tradeoffs, Kathy and I
gave up television.
 Gap Analysis time, where are you in your life? Where
do you want to be? What are the steps to get there?
What is the first step?
 Take the first step
 I can’t tell you how many conversations I have had
with people three or four years after I was able to offer
them a chance to team to do something together
 Some are thankful
 Some are regretful
 It’s not that you only have one chance in life, but you
do only have a finite number
 When the right opportunity comes along, JUMP
 What is your legacy?
 Live life on purpose!
 Live life out loud; be a voice that matters!
 Write down goals and share them with
another person. That is the single most
effective thing you can do.
 There is no time like the present to start!

More Related Content

What's hot

How To Avoid The Easy Trap Of Self Deception
How To Avoid The Easy Trap Of Self DeceptionHow To Avoid The Easy Trap Of Self Deception
How To Avoid The Easy Trap Of Self Deception
George Hutton
 
Leadership and Self-Deception
Leadership and Self-DeceptionLeadership and Self-Deception
Leadership and Self-Deception
The Meyvn Group
 
5 Steps to the Perfect Profile Picture
5 Steps to the Perfect Profile Picture 5 Steps to the Perfect Profile Picture
5 Steps to the Perfect Profile Picture
Vanessa Van Edwards
 
Captivate Slideshare Hacks
Captivate Slideshare HacksCaptivate Slideshare Hacks
Captivate Slideshare Hacks
Vanessa Van Edwards
 
24 emails 24 different email types geromesoriano selfhelpemails
24 emails 24 different email types geromesoriano selfhelpemails24 emails 24 different email types geromesoriano selfhelpemails
24 emails 24 different email types geromesoriano selfhelpemails
Gerome Soriano
 
10 Daily office struggles - and how to overcome them
10 Daily office struggles - and how to overcome them10 Daily office struggles - and how to overcome them
10 Daily office struggles - and how to overcome them
GetSmarter
 
How to boost your charisma ?
How to boost your charisma ? How to boost your charisma ?
How to boost your charisma ?
Good Morning Entrepreneur
 
Leadership and self deception
Leadership and self deceptionLeadership and self deception
Leadership and self deception
Jack (Yaakov) Bezalel
 
Etiquette
EtiquetteEtiquette
Etiquette
Ella Paterno
 
10 steps to your career makeover
10 steps to your career makeover10 steps to your career makeover
10 steps to your career makeover
GetSmarter
 
Secrets to a Great Team
Secrets to a Great TeamSecrets to a Great Team
Secrets to a Great Team
Elodie A.
 
Twelve valuable steps to raise your self esteem
Twelve valuable steps to raise your self esteemTwelve valuable steps to raise your self esteem
Twelve valuable steps to raise your self esteemRajThilak
 
Get Out of the Box
Get Out of the BoxGet Out of the Box
Get Out of the Box
Gregory Rowe, LSS, ITIL
 
On modeling the impossible and how to do anything live your legend
On modeling the impossible and how to do anything   live your legendOn modeling the impossible and how to do anything   live your legend
On modeling the impossible and how to do anything live your legendRoberto Alday Delgadillo
 
Ymag36
Ymag36Ymag36
Does what you’re doing actually matter (+ free workbook) live your legend
Does what you’re doing actually matter  (+ free workbook)   live your legendDoes what you’re doing actually matter  (+ free workbook)   live your legend
Does what you’re doing actually matter (+ free workbook) live your legendRoberto Alday Delgadillo
 
Self Defeating Behaviours
Self Defeating BehavioursSelf Defeating Behaviours
Self Defeating Behaviours
HETERO LABS LIMITED - India
 
Art & science part ii 2018
Art & science part ii 2018Art & science part ii 2018
Art & science part ii 2018
Cormac McGrath
 
Procrastinator's Guide To Goals
Procrastinator's Guide To GoalsProcrastinator's Guide To Goals
Procrastinator's Guide To Goals
Tom Fox
 
Stop the procrastination and start recording
Stop the procrastination and start recordingStop the procrastination and start recording
Stop the procrastination and start recording
Yogi's Podcast Network
 

What's hot (20)

How To Avoid The Easy Trap Of Self Deception
How To Avoid The Easy Trap Of Self DeceptionHow To Avoid The Easy Trap Of Self Deception
How To Avoid The Easy Trap Of Self Deception
 
Leadership and Self-Deception
Leadership and Self-DeceptionLeadership and Self-Deception
Leadership and Self-Deception
 
5 Steps to the Perfect Profile Picture
5 Steps to the Perfect Profile Picture 5 Steps to the Perfect Profile Picture
5 Steps to the Perfect Profile Picture
 
Captivate Slideshare Hacks
Captivate Slideshare HacksCaptivate Slideshare Hacks
Captivate Slideshare Hacks
 
24 emails 24 different email types geromesoriano selfhelpemails
24 emails 24 different email types geromesoriano selfhelpemails24 emails 24 different email types geromesoriano selfhelpemails
24 emails 24 different email types geromesoriano selfhelpemails
 
10 Daily office struggles - and how to overcome them
10 Daily office struggles - and how to overcome them10 Daily office struggles - and how to overcome them
10 Daily office struggles - and how to overcome them
 
How to boost your charisma ?
How to boost your charisma ? How to boost your charisma ?
How to boost your charisma ?
 
Leadership and self deception
Leadership and self deceptionLeadership and self deception
Leadership and self deception
 
Etiquette
EtiquetteEtiquette
Etiquette
 
10 steps to your career makeover
10 steps to your career makeover10 steps to your career makeover
10 steps to your career makeover
 
Secrets to a Great Team
Secrets to a Great TeamSecrets to a Great Team
Secrets to a Great Team
 
Twelve valuable steps to raise your self esteem
Twelve valuable steps to raise your self esteemTwelve valuable steps to raise your self esteem
Twelve valuable steps to raise your self esteem
 
Get Out of the Box
Get Out of the BoxGet Out of the Box
Get Out of the Box
 
On modeling the impossible and how to do anything live your legend
On modeling the impossible and how to do anything   live your legendOn modeling the impossible and how to do anything   live your legend
On modeling the impossible and how to do anything live your legend
 
Ymag36
Ymag36Ymag36
Ymag36
 
Does what you’re doing actually matter (+ free workbook) live your legend
Does what you’re doing actually matter  (+ free workbook)   live your legendDoes what you’re doing actually matter  (+ free workbook)   live your legend
Does what you’re doing actually matter (+ free workbook) live your legend
 
Self Defeating Behaviours
Self Defeating BehavioursSelf Defeating Behaviours
Self Defeating Behaviours
 
Art & science part ii 2018
Art & science part ii 2018Art & science part ii 2018
Art & science part ii 2018
 
Procrastinator's Guide To Goals
Procrastinator's Guide To GoalsProcrastinator's Guide To Goals
Procrastinator's Guide To Goals
 
Stop the procrastination and start recording
Stop the procrastination and start recordingStop the procrastination and start recording
Stop the procrastination and start recording
 

Similar to 12laws of IT Security Power

You Only Get One Chance Chapters 1 and 2 Preview
You Only Get One Chance Chapters 1 and 2 PreviewYou Only Get One Chance Chapters 1 and 2 Preview
You Only Get One Chance Chapters 1 and 2 Preview
Katey Bailin
 
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
Katey Bailin
 
5 Temptations of a CEO
5 Temptations of a CEO5 Temptations of a CEO
5 Temptations of a CEO
Rolf Crocker
 
Copywriting Champion.pdf
Copywriting Champion.pdfCopywriting Champion.pdf
Copywriting Champion.pdf
JohnHawkins13672
 
40 business lessons in 40 years
40 business lessons in 40 years40 business lessons in 40 years
40 business lessons in 40 years
Jonathan Patrick
 
Network marketing and prospecting
Network marketing and prospectingNetwork marketing and prospecting
Network marketing and prospecting
Neet Patel
 
Network marketing
Network marketing Network marketing
Network marketing
AlonBz2
 
Communication Hacks: Strategies for fostering collaboration and dealing with ...
Communication Hacks: Strategies for fostering collaboration and dealing with ...Communication Hacks: Strategies for fostering collaboration and dealing with ...
Communication Hacks: Strategies for fostering collaboration and dealing with ...
All Things Open
 
Marketing de réseau et prospection
Marketing de réseau et prospectionMarketing de réseau et prospection
Marketing de réseau et prospection
Lahcen Idar
 
The Digital Journeymen
The Digital JourneymenThe Digital Journeymen
The Digital Journeymen
Kay Lummitsch - Digital Journeyman
 
Writing Better e-Learning Scripts #Training18
Writing Better e-Learning Scripts #Training18Writing Better e-Learning Scripts #Training18
Writing Better e-Learning Scripts #Training18
Cammy Bean
 
Shiv Khera - You can Win.pdf
Shiv Khera - You can Win.pdfShiv Khera - You can Win.pdf
Shiv Khera - You can Win.pdf
PiyushPriyadarshi27
 
10 ways to be high potential!!
10 ways to be high potential!!10 ways to be high potential!!
10 ways to be high potential!!
Dr. Shalini Lal
 
Jobstreet Annual Sales Convention - Success In Sales
Jobstreet Annual Sales Convention - Success In SalesJobstreet Annual Sales Convention - Success In Sales
Jobstreet Annual Sales Convention - Success In SalesKenny Ong
 
Difficult Conversations
Difficult ConversationsDifficult Conversations
Difficult Conversationskktv
 
Difficult Conversations
Difficult ConversationsDifficult Conversations
Difficult Conversationskktv
 
Confident prospecting
Confident prospectingConfident prospecting
Confident prospecting
Flora Runyenje
 
Making Difficult Conversations Easier
Making Difficult Conversations EasierMaking Difficult Conversations Easier
Making Difficult Conversations EasierMostafa Ewees
 
20 Lessons Learned Article 2-19-15
20 Lessons Learned Article 2-19-1520 Lessons Learned Article 2-19-15
20 Lessons Learned Article 2-19-15Tony Streeter
 

Similar to 12laws of IT Security Power (20)

You Only Get One Chance Chapters 1 and 2 Preview
You Only Get One Chance Chapters 1 and 2 PreviewYou Only Get One Chance Chapters 1 and 2 Preview
You Only Get One Chance Chapters 1 and 2 Preview
 
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
You Only Get One Chance Unforgettable First Impression eBook Chapters 1 and 2...
 
5 Temptations of a CEO
5 Temptations of a CEO5 Temptations of a CEO
5 Temptations of a CEO
 
Copywriting Champion.pdf
Copywriting Champion.pdfCopywriting Champion.pdf
Copywriting Champion.pdf
 
40 business lessons in 40 years
40 business lessons in 40 years40 business lessons in 40 years
40 business lessons in 40 years
 
Network marketing and prospecting
Network marketing and prospectingNetwork marketing and prospecting
Network marketing and prospecting
 
Network marketing
Network marketing Network marketing
Network marketing
 
Communication Hacks: Strategies for fostering collaboration and dealing with ...
Communication Hacks: Strategies for fostering collaboration and dealing with ...Communication Hacks: Strategies for fostering collaboration and dealing with ...
Communication Hacks: Strategies for fostering collaboration and dealing with ...
 
Marketing de réseau et prospection
Marketing de réseau et prospectionMarketing de réseau et prospection
Marketing de réseau et prospection
 
The Digital Journeymen
The Digital JourneymenThe Digital Journeymen
The Digital Journeymen
 
Writing Better e-Learning Scripts #Training18
Writing Better e-Learning Scripts #Training18Writing Better e-Learning Scripts #Training18
Writing Better e-Learning Scripts #Training18
 
Shiv Khera - You can Win.pdf
Shiv Khera - You can Win.pdfShiv Khera - You can Win.pdf
Shiv Khera - You can Win.pdf
 
10 ways to be high potential!!
10 ways to be high potential!!10 ways to be high potential!!
10 ways to be high potential!!
 
Jobstreet Annual Sales Convention - Success In Sales
Jobstreet Annual Sales Convention - Success In SalesJobstreet Annual Sales Convention - Success In Sales
Jobstreet Annual Sales Convention - Success In Sales
 
Difficult Conversations
Difficult ConversationsDifficult Conversations
Difficult Conversations
 
Difficult Conversations
Difficult ConversationsDifficult Conversations
Difficult Conversations
 
Confident prospecting
Confident prospectingConfident prospecting
Confident prospecting
 
Making Difficult Conversations Easier
Making Difficult Conversations EasierMaking Difficult Conversations Easier
Making Difficult Conversations Easier
 
20 Lessons Learned Article 2-19-15
20 Lessons Learned Article 2-19-1520 Lessons Learned Article 2-19-15
20 Lessons Learned Article 2-19-15
 
Sales_Pro
Sales_ProSales_Pro
Sales_Pro
 

Recently uploaded

The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Product School
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
Elena Simperl
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
DianaGray10
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Product School
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
g2nightmarescribd
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 

Recently uploaded (20)

The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 

12laws of IT Security Power

  • 2. Whether you want to be the next CEO or don't want to be a manager at all, every employee wants to be treasured and doesn’t want to be pushed around
  • 3. They can’t easily fire you if you are the best
  • 4.  Business is like an action video game, keep track of your health or life monitor status  They will be hesitant to mess with you if they know you can be employed elsewhere quickly and are hard to replace  It’s the economy: in good times there is less scrutiny; in good times it is easier to build skills with tools like training
  • 5.  RSS every day, at a minimum USA Today Tech, anytime we know less than USA Today, it is a bad sign  Know thy desktop, I was the first person at SANS to run El Capitan  Hot keys matter, life is a game of inches, some favorites on the next slide
  • 6.  It is crucial to keep looking at networks, because assurance comes down to two things:  Hardening our systems properly and keeping them properly configured  Knowing what traffic is coming in and out of our systems in case the first rule fails  AirPcap and Wireshark sure are fun  Whenever you are troubleshooting make watching traffic second nature
  • 7.  If you don’t have a LinkedIn account with over 200 connections then start linking; I am “Stephen Northcutt”  Look at Google trends at least once a week, if you do not recognize any of the top ten, that could be a clue  Consider creating and posting a security video to YouTube  Think about your workplace, think about the folks that just aren’t keeping up
  • 8. Never speak to management in hex
  • 9.  Words are weapons, use language to your advantage  Learn, go back and read the emails you wrote in critical situations, what could you have phrased better  We partly “know” or “esteem” ourselves by our trade and skills, decide today that two of your skills are speaking and writing  Publish!
  • 10. And so, my fellow Americans: ask not what your country can do for you--ask what you can do for your country. My fellow citizens of the world: ask not what America will do for you, but what together we can do for the freedom of man.
  • 11.  Pick a great intro, something that grabs the audience’s attention  Work on your outro, remind them of what they have learned and end with a stirring call to action  Keep the intro and outro as close together as possible
  • 12.  Communication is the number one skill managers want employees to have.  Listen; listen more  Make time for people  Make the effort to be cogent and concise  Express your values  Give feedback, avoid surprises  Practice speaking to groups as well as one on one  Don’t overuse email, business is done by phone
  • 13. I am Linda’s ski guide and tell her where to ski and when to turn; Linda is blind. For over a year, I had never let Linda hit anything and she had always immediately done what I asked her to. One day last year, Faith, Linda’s daughter, was skiing with us, I had my first communication problem with Linda, but it was a big one. We came over a slight crest in the hill and I saw that Faith had fallen down. I said, "Faith is down." I started telling Linda where and when to turn. Then I said, "Okay, turn right, pull up and stop." She turned right, aimed straight at Faith, but showed no sign of stopping. I yelled, "Stop! Stop!" then screamed, "Sit!" just as Linda hit Faith. Sit is the last desperate command that a guide can give to try to keep an accident from happening. Linda sat, but it was not in time to avoid hitting her daughter. Fortunately, neither one of them was hurt. What went wrong? What can we learn from the story?
  • 14. At any given time know what the best selling security books are
  • 15.  Try to read a non-fiction book every two to three weeks  As you start to become more senior, alternate management and leadership books with security books  I buy most of my books from Amazon so they can develop a profile  Try a search for “security”, then find the closest match to your interests and click, see all 491,236 items
  • 16. If you help people learn what you know, they will help you get the work done
  • 17.  Think about how many things you do not know how to do (code in java, reverse engineer, write a heap overflow, cut the 11th column in vi ), so now give other people some slack  “Use the source, Luke” might have worked ten years ago, but we are going faster than that today  Now think about the things that you do know how to do that you can show someone else
  • 18. Bet on people and bet large
  • 19. If you hold a position in a growing organization And you are not growing – yourself What happens?
  • 20.  I’ve invested in bonds and real estate and done well  Stocks and futures; mixed results  The return on investing in people is so high, I don’t spend much time thinking about anything else. Two or three years from now there will probably be 2000 people in the Advisory Board and 100 SANS Instructors.
  • 21. Be flexible, as long as you have oxygen, power, water and propellant you have options
  • 22.  2008: Price of fuel skyrockets, airlines start charging for second checked bag and policing carry-ons, others file for Chapter 11  At some point this will impact conference registrations  We have had "Training Without Travel" options for years, for just such a moment. At what point do we push them?
  • 23.  Listen harder! This talk has required you to listen a number of times  When you listen, you hear the nuances of what people are saying, suggesting  If you are having trouble finding options, take a note from the original StarTrek series: Kobayashi Maru
  • 24. No sensible organization wants to mess with a rainmaker
  • 25. Do they really need me operationally? Do my efforts account for enough revenue that cutting me will cost them money Do they know how I bring in money?
  • 27.  Ask the smartest people you meet, where will we be, what will we be doing  At least once a quarter read a site like futurist.com  Ask your primary vendors for a briefing on their roadmap, consider joining their customer advisory board  Make sure you know Ops tech refresh cycle and plans
  • 28. For any action you intend to take, what are the most likely reactions, what will you do in that case Check your heart regularly, are you trying to “Win” or are you trying to “Win Win”
  • 29. Would you rather spend an hour with a whiner or a go-getter?
  • 30.  But I was AMAZED when I was describing my struggles with a negative person to the executive I admire the most and he replied “Let her go, I just don’t tolerate a negative person”  However, UNTIL you terminate them, learn to listen. A negative person, poisonous attitude and all, can have a legitimate complaint; just because they are negative doesn’t mean they are stupid
  • 31. No matter how smart you are, the person next to you knows something you don’t
  • 32. Be patient with the set up time to create a team
  • 33.  You can be on five or six teams creating a lot of productivity if you are organized  LinkedIn helps, but it doesn’t keep overall status, so that needs to be done in an outside document like the Outlook Calendar/Contact Manager  If you are on a virtual team, be creative with things like time zones  If you are on a virtual team, be quick to turn in your comments; if a few people miss a data call, the team has to be restarted
  • 34. If you are following the first ten laws, if someone does something abusive to you, push back
  • 35.  Push back is a term we use at SANS  Understand the bottom line before you begin, would you leave a company or relationship over the issue  Be respectful, push back is not intended to anger, but to emphasize your point of view  Restate what you think you have heard and ask, is this correct? VERY IMPORTANT: Miscommunication is a big reason for relationship degradation  State your position  IMPORTANT: You do not HAVE to win, sometimes you just want to give them a chance to hear your position
  • 36. When opportunity knocks, be prepared to take advantage of the moment
  • 37.  A little sleep, a little slumber, A little folding of the hands to rest, Then your poverty will come as a robber And your want like an armed man. Proverbs 24:33-34  We all have the same amount of time, it is how we choose to spend it. There are tradeoffs, Kathy and I gave up television.  Gap Analysis time, where are you in your life? Where do you want to be? What are the steps to get there? What is the first step?  Take the first step
  • 38.  I can’t tell you how many conversations I have had with people three or four years after I was able to offer them a chance to team to do something together  Some are thankful  Some are regretful  It’s not that you only have one chance in life, but you do only have a finite number  When the right opportunity comes along, JUMP
  • 39.  What is your legacy?  Live life on purpose!  Live life out loud; be a voice that matters!  Write down goals and share them with another person. That is the single most effective thing you can do.  There is no time like the present to start!

Editor's Notes

  1. Before we start there is something that I need to explain. There will be some times in this presentation where I say “I”. Or I say in “my experience”. This is a part of my life story, the only brain I have is the one on the top of my shoulders. But it isn’t ego either. In my technical career I have toggled between being a technically competent worker and a manager many times. I keep trying to understand, why does this person get the breaks, why does this person win, why does this person lose. Now as a senior manager, the more “winners” I have in the organization, the more the organization can accomplish. So please forgive the “I”s and the “my opinions” or “my experience”, ask anyone that has followed SANS for a long time and they will tell you, I just want you to become what you are capable of being. These ideas have been good for me, I hope they will be good for you.
  2. The world is hard, people get cranky, they get stressed out, they say things they shouldn’t. They say people do not leave companies, they leave bad bosses. Turnover in the work place is BAD! There are three exceptions to that: We hired wrong and got someone that cannot do the job, they simply lack the skills We hired and then later found that employee is bent on division, a negative person that causes trouble, get rid of them The employee is losing effectiveness, maybe substance abuse, bad divorce, or just getting lazy But, as an employee, at first it seems like turnover works for you: if it’s a good job market, you get a pay raise, what is not to like? However, when you find the right opportunity, the right company, you want to stay there. The trick is to make sure management knows you are valuable so you keep getting pay raises where you are.
  3. This page intentionally left blank
  4. Have you ever played one of those shoot ‘em up video games where you have a health status either for your armor or avatar body itself? That is how I like to think of myself at work. Are we fairly untouchable? Because in order to replace us, it would take three people and that would be a huge hit on the group’s payroll. Or, are we a commodity? If we are a commodity, then we would be wise to develop the hot skills our organization needs.
  5. This page intentionally left blank
  6. This page intentionally left blank
  7. This page intentionally left blank
  8. This page intentionally left blank
  9. This page intentionally left blank
  10. It was a cold, crisp wintry day Jan. 20, 1961, when President John F. Kennedy stepped onto the platform and delivered one of the most memorable inaugural addresses in history. No one knew about the long underwear he wore beneath his suit so he could remove his overcoat and appear to be the essence of youth and vitality. No one knew that Eleanor Roosevelt refused her place of honor because she was to be seated near the President’s father whom she despised. And Rose Kennedy fumed over her row-end seat. “There was a lot of bad blood on the podium. If its weight could’ve been felt, the podium would have collapsed,” writes Author Thurston Clarke in his book, “Ask Not: The Inauguration of John F. Kennedy and the Speech That Changed America.” The response to Kennedy’s speech, which was the first televised inaugural address, was immediate. “Americans longed for what he had to say,” Clarke said. "He prepared the audience for what he said in the speech in repeated themes and phrases from his campaign. People wanted to be roused. America was ready for Kennedy’s words." http://www.amazon.com/Ask-Not-Inauguration-Kennedy-Changed/dp/0805072136/
  11. This page intentionally left blank
  12. If you wanted to read that the number one skill to have is application pen testing, I am sorry, it is not. It is communication. We will talk about specific writing and speaking skills in a bit, but communication comes down to the simple act of wanting to receive and share ideas, observations, and experiences with other people. The majority of interpersonal problems in business come down to insufficient communication. Make a decision right now to be a better communicator. Consider the quote below: “Dean is a great communicator, with an ability to gain a strong sense of what the buyer/seller is looking for. “ http://www.deaninnes.com/testimonials.asp How does Dean have a strong sense of what the buyer/seller is looking for?
  13. Linda thought that I meant Faith was at the bottom of the slope when I said, "Faith is down." We were near the bottom of the run and she couldn't think of why I wanted her to stop instead of skiing to the bottom of the run first. She did not follow exactly what I said to do and I was not clear in my comments. http://terrax.org/teacher/lessons/pennantplan/story.aspx
  14. This page intentionally left blank
  15. This page intentionally left blank
  16. This page intentionally left blank
  17. This page intentionally left blank
  18. This page intentionally left blank
  19. This page intentionally left blank
  20. This page intentionally left blank
  21. This page intentionally left blank
  22. This page intentionally left blank
  23. This page intentionally left blank
  24. This page intentionally left blank
  25. This page intentionally left blank
  26. This page intentionally left blank
  27. This page intentionally left blank
  28. This page intentionally left blank
  29. This page intentionally left blank
  30. This page intentionally left blank
  31. This page intentionally left blank
  32. This page intentionally left blank
  33. This page intentionally left blank
  34. This page intentionally left blank
  35. This page intentionally left blank
  36. This page intentionally left blank
  37. This page intentionally left blank