The challenge with this EO and all aspirational security pronouncements is their focus on outcomes while avoiding implementation details, trade offs and resources.
It’s as if nobody asked WHY zero trust and MFA are not already pervasive in the Federal Government. Legacy systems are going to be incredibly difficult and expensive to rearchitect for ZTA. Despite HSPD-12 (CAC and PIV authentication and access) being over a decade old, some parts of government refuse to use a smart card plus password for MFA. I wonder why? It is not simply because “government doesn’t understand computers.” The core issue is leadership. There is no benefit for executives to point out the constraints, like usability, cost or talent, that ensure that good ideas in principle will be adopted incorrectly and incompletely.
That said, there is some stuff worth cheering. The CSRB is much overdue and the elevation in status of cybersecurity as a critical function is directionally correct.
Much of whether these aspirations will be possible hinges on legislative budget decisions and ultimately sweeping reform of the government hiring system.
First, congrats on making it this far! That's amazing and a huge feat.
Second, no you're not crazy. It is risky, but not crazy. Are there a few things you can do to derisk your decision? Identify what you would need to know to feel comfortable and work back from that to form testable hypotheses. Then figure out how much time/money/effort it would cost to test those hypotheses.
If that seems like too much work, or you still won't have the certainty, I wouldn't go all in, but there's one other option before shutting it down. Can you sell the business? Maybe to a search fund or a small investor? I'd get in touch with Arvid Kahl, here or on Twitter if I were you.
Cybersecurity engineers proficient in application security, cloud security, identity and access management, and operations. Fintech experience preferable, with a minimum of a few years focused on security.
Having run a cybersecurity services business for three years and previously working for federal clients, I know that government and large banks are sucking the talent up, leaving fintechs two options: ignore security or overpay.
On the reverse side, there are lots of talented independent providers who simply need somebody to vouch for their skills. We meet with and vet everybody on our platform to make sure they have the capabilities.
Will be launching a prototype to replace this landing page shortly. If you're in the New York area and are either looking for cybersecurity contractors or looking for a project, I would love to get your input!
Any advice on how to find the right person to talk to at these firms? I used to work at Deloitte, and even there I haven't figured out how to sub on something.
How have you gone about doing this? I used to work for Deloitte, and haven't had much success finding people to sub to. Any advice would be much appreciated.
We're a cybersecurity services firm (www.tailrisk.com) that is New York based and got all of our work as the prime contractor through our networks, reputation and skills.
First, pick a very specific niche that you know has demand, ideally by asking potential customers and then positioning yourself in that niche.
You say "sysadmin stuff, troubleshooting and cloud," but clients want to know specific platforms you know well, software you've implemented and types of problems you can solve.
Make sure you are targeting a market where they are interested in "dating not marriage." Many places will not outsource their sysadmin and try to hire you full time instead of as a consultant.
Finally, this comes from my experience running Tail Risk (www.tailrisk.com) a cybersecurity services firm. We have excess project work, tools, templates and playbooks we would like to share with independent (security) consultants. Is that something that interests anybody on this thread? If so, please reach out.
The articles going around about insurers not paying cyber claims that cite Mondelez are disingenuous. The Mondelez policy was a property & casualty (P&C) policy with an extension for some data property, not a separate cyber insurance policy. It's quite possible that insurers would balk at the claim considering it an act of war, but they haven't done it yet. In my opinion, this case is more about the wrong type of coverage. Mondelez should have purchased a stand alone policy.
"[Andreessen Horowitz] aims to flip the venture industry on its head by acting more like a talent agency - specifically Creative Artists Agency, which became so prominent in Hollywood that it was hard to do deals without them being involved."
Property tax reform could work for single family homes if we decoupled property tax from land tax. NYS should only raise taxes on the value of land given the surrounding population density, natural properties and accessibility to public infrastructure. Check out some Henry George, if you're interested in learning more.
There are plenty of religions that offer a more flexible interpretation of "God" that might better suit your world view. You may want to check out Quakerism, the Bahá'í Faith and Buddhism. These are just three that come to mind, but there are many more.
I would also add that predestination is a particularly Calvinist protestant belief. Many religions that rely on good works, such as Jesuit Catholicism and Quakerism can provide meaning and sense of purpose without the offensive belief that one has no self determination or choice about being a good person in life.
Can somebody recommend a person or company that they like for this task? I have a company brand, good enough customer flow to stay afloat, but extra hours I could put towards more work.
We offer cybersecurity services and due diligence for financial institutions, healthcare and acquirers, so it's a pretty specialized target market.
Read Progress and Poverty, he predicted it all over 100 years ago, and provided the solution. https://oll.libertyfund.org/title/george-progress-and-povert...