Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity@infosec.exchange . Cloud Security Posture Chiropractor.
Posts
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
🎵 Hello con flu, my old friend... so sad we had to meet again... 🎵
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
TFW I realized I'll miss the @riskybusiness@infosec.exchange @riskybiz@infosec.exchange live podcast recording at RSAC because it is EXACTLY at the same time as I'm on stage presenting.
I mean, anything else I could have tried to move around. This is THE ONE THING I can't reschedule... 😢
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
RE: @TenchiSecurity@infosec.exchange
Looking forward to talking to everyone at the FS-ISAC Spring Summit about how much better TPCRM can be. Stop by our booth and say hi!
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
If you are attending #RSAC this year, Alex Pinto and I are presenting session CLS-W09 "The Impact of Security Usability Challenges in Cloud Environments".
We will present research that reviews 500+ organizations and 5,000+ distinct #cloud environments that demonstrate how the available secure configuration options are being used and reveals how usability, standardization choices in UI / #UX can shape #security outcomes.
Learn more and register now at https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755192044047001WRoa
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
The second episode of the Alice in Supply Chains podcast is out!
This is a podcast where @sawaba@infosec.exchange and I discuss what we consider some of most important news related to Third-Party Cyber Risk Management from the previous month.
You can check it out on the major podcast platforms.
Youtube: https://www.youtube.com/watch?v=CMYDeb56FWs
Spotify: https://open.spotify.com/episode/7qPB7IauZ1QGdmuczircB8?nd=1&dlsi=7972d56c585442c6
Apple Music: https://podcasts.apple.com/br/podcast/episode-2-february-2025/id1791990827?i=1000694446509
Amazon Music: https://music.amazon.com.br/podcasts/baac01b9-a19b-4c3a-837b-637fad39be4d/alice-in-supply-chains
This is based on the longer monthly newsletter of the same name published by @TenchiSecurity@infosec.exchange on LinkedIN. You can find the latest edition at https://www.linkedin.com/pulse/issue-30-february-2025-tenchisecurity-aejkf/
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Happy to announce the launch of the Alice in Supply Chains #podcast, posted monthly, focusing on topical discussions on the top news relevant to Third-Party Cyber Risk Management.
"Plant a tree, have a child, and write a book. These all live on after us, insuring a measure of immortality." We all know that these days, the writing a book part would probably be replaced with "host a podcast".
Given that inevitability, I have finally decided to face my impostor syndrome and my non-native and accented English and give that a go. Standing on the shoulders of the collective effort we do at @TenchiSecurity@infosec.exchange on publishing high-quality content on Third-Party Cyber Risk Management in the Alice in Supply Chains newsletter, and counting on the vast experience and expertise of my good friend and co-host @sawaba@infosec.exchange .
Please check it out and let us know what you think, we are really at the beginning of the learning curve here and can use the feedback. Hope you like it!
Youtube: https://www.youtube.com/playlist?list=PL22qeD49pJIix3gpBoeYvzcdATBhCoGLR
Amazon: https://music.amazon.com.br/podcasts/baac01b9-a19b-4c3a-837b-637fad39be4d/alice-in-supply-chains
Apple: https://podcasts.apple.com/us/podcast/alice-in-supply-chains/id1791990827
If you haven't subscribed to the newsletter yet, you can do so now at https://podcasts.apple.com/us/podcast/alice-in-supply-chains/id1791990827
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Wow, @TenchiSecurity@infosec.exchange 's monthly newsletter of curated Third-Party Cyber Risk Management news has reached 12,000 subscribers!
This is a low-volume, high signal newsletter for the time strapped risk manager, highlighting breaches, regulatory changes and more.
Issue 27 is out, check it out and let me know what you think! https://www.linkedin.com/pulse/issue-27-november-2024-tenchisecurity-qhl8f/ #tprm #tpcrm #cyber #risk #compliance
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
The #CFP for @TenchiSecurity@infosec.exchange 's #TPCRM #Conference is open! If you have experience to share in this field, either with technical insights, GRC or privacy expertise we'd love for you to apply to our call for papers!
We would love to have international speakers join us with an audience of some of the leading financial services, telecom and healthcare providers in Latin America to a content-focused discussion Third-party Cyber Risk Management in São Paulo, Brazil this November 5th.
You can apply now at https://docs.google.com/forms/d/e/1FAIpQLSc9aK5UafStfv3QHH9tWfYjt0OPKhgbnG8CATowd6-BASxDIw/viewform
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Google Workspace seems to have bungled their planned enforcement of #2FA for administrators (see https://support.google.com/a/answer/175197#2SV).
Here at @TenchiSecurity@infosec.exchange we had already had OU-level policies enforcing 2FA for all users, including the administrators. So when we got the e-mail saying it would be turned on for us on July 3rd, we expected that nothing would change. 😎
However our product Zanshin, which we use to perform daily checks of our Google Workspace and other #SaaS #security settings, started alerting on that date that 2FA was no longer enforced for our admin accounts. 🤔
Since this is the opposite of what we expected, we initially thought this was a false positive in our product. It wasn't. Since Google turned on the "enforcement" for our organization, our OU policies were being ignored and Google Workspace was itself reporting on its console that 2FA was indeed not enforced for our admins. We were even able to (temporarily) disable 2FA on one of the admin accounts, which was not possible before! 😱
So the change Google implemented did the opposite of what was intended. Our organization is now less secure - not only is Google Workspace not enforcing 2FA for our admins, it's even ignoring our OU policies to that effect. 🤦♂️
We have reached out to Google's support team and they were as surprised as we were, but told us they confirmed the findings with a test org they control. Tickets are now being escalated. Not sure if this was something that only happened to us (unlikely at their scale) or because very few people double-check this like we do daily with Zanshin so we were among the first to notice it.
Let me know in the comments if your organization was impacted by this problem as well, and boost for visibility. Additional checks around admin accounts might be needed until Google sorts this out.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
I had a blast talking to Harry Baldwin and Daisy Steel on the Cyber Security Matters podcast about being an entrepreneur in cyber security, the crazy stuff we are doing here at @TenchiSecurity@infosec.exchange and much more!
Spotify - https://open.spotify.com/episode/3b2cyCuiImceEfLPQixX5u?si=200c183553334a93
Apple Podcast - https://podcasts.apple.com/gb/podcast/the-cyber-security-matters-podcast/id1636880033?i=1000654255273
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Here at @TenchiSecurity@infosec.exchange our product is built on #AWS #serverless workloads, but we also use AWS #Batch to execute a few container-based tasks on #StepFunctions.
This blog post from Luis F. Pontes from our #DevOps team describes problems we encountered with inactive AWS Batch Job Definition revisions, due to a long known quirk in #CloudFormation. Plus, it presents a workaround we successfully implemented, with code examples.
Check it out at https://www.tenchisecurity.com/fixing-aws-step-function-errors-due-to-reference-to-inactive-aws-batch-job-definition-revisions/
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Thank you to @sawaba@infosec.exchange and @txs@infosec.exchange for the shout out to @TenchiSecurity@infosec.exchange ‘s Series A on the Enterprise Security Weekly podcast! https://youtu.be/V8mq50nCR30?si=xZ_ndB1RTr5Nf8-U&t=1145
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Super happy about this milestone on the @TenchiSecurity@infosec.exchange journey! We just raised a $7MM Series A from Bradesco PE&VC, L4 Venture Builder and Accenture.
The company was on a solid financial footing, and did not need to raise a round. But we decided to anyway once we found investor partners who saw the value in what we are doing and bring much more than "just" capital, and will help us strategically in executing our thesis.
The additional funding will allow us to accelerate product development, sales and marketing. Our goal? To be a proudly Brazilian global cyber security player, and disrupt the Third Party Cyber Risk Management space.
Huge thanks to all the customers, partners and team members who put their trust in us. Rest assured we will continue working hard to exceed your expectations.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Interesting statistics related to Third Party Cyber Risk Management on the World Economic Forum's Global Cybersecurity Outlook 2024 report.
54% of organizations have insufficient visibility of the vulnerabilities of their supply chains, including 64% of executives who believe their own organizations meet their minimum resilience requirements.
To me this clearly shows just how big of a blind spot #TPCRM still is for most companies. After all only companies that don't outsource any critical functions and don't give any third parties access to critical data could simultaenously believe that a) they meet their resilience requirements and b) they don't understand their third parties' vulnerabilities... and how many of those are out there? I have personally never bumped into any companies this vertically integrated, even in regulated markets.
The report also highlights the real impacts of neglecting this discipline. It claims 41% of companies that suffered a material impact from a cyberattack said it originated from a third party. This dovetails nicely from data we've seen elsewhere, including a figure that incidents originated at third parties were the leading source of cyber insurance claims in Q2 of last year.
You can read the full report here: https://www.weforum.org/publications/global-cybersecurity-outlook-2024/
This is why here at @TenchiSecurity@infosec.exchange we decided to tackle #TPCRM, which is gradually starting to get the visibility and prioritization it deserves. Get in touch if you want to learn more about how we are disrupting this market by going beyond risk reporting and focusing on risk reduction through a cooperative approach.
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Issue #11 of Alice in Supply Chains, @TenchiSecurity@infosec.exchange 's monthly newsletter about the latest third-party cyber risk management news, is now available!
You can read it now at https://linkedin.com/pulse/issue-11-july-2023-tenchisecurity
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Issue #10 of the @TenchiSecurity@infosec.exchange newsletter on Third Party Cyber Risk Management is now available!
This is ad-free and focused on curating news stories related to #TPRM and #TPCRM topics such as incidents, regulatory developments and more.
You can read it and subscribe to future issues at https://www.linkedin.com/pulse/issue-10-june-2023-tenchisecurity/
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.
Had a wonderful time talking to Robert Martin from @mitrecorp@bird.makeup about their new Supply Chain Security framework System of Trust (https://sot.mitre.org/).
I truly believe this has the potential of catching on in a big way with the risk management and #TPRM #TPCRM community much the same way the ATT&CK framework caught on the security monitoring and testing folks, and for the same reasons.
Watch it now at https://www.youtube.com/watch?v=Fpjq1FhNCes
Information security entrepreneur and early stage investor. Co-Founder @TenchiSecurity . Cloud Security Posture Chiropractor.