PacketNut; Confessions of an Enterprise Information Security Architect

A blog for Security Architects, CISOs and anyone else responsible for protecting their organisation's information assets

Useful Info

  • Home
  • Companies that interest me

Thursday, 26 December 2019

12 Threat Modelling Techniques

https://insights.sei.cmu.edu/sei_blog/2018/12/threat-modeling-12-available-methods.html

Posted by Tony Brown at 07:39 2 comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Friday, 20 December 2019

Zero Trust

https://www.ncsc.gov.uk/blog-post/zero-trust-architecture-design-principles

Posted by Tony Brown at 06:19 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Newer Posts Older Posts Home
Subscribe to: Comments (Atom)

Security News

  • IBTimes.co.uk : Technology
    'Jujutsu Kaisen' Season 3 English Dub Release Date Following Subbed Version Launch This Week
    8 hours ago
  • Latest news and stories from BleepingComputer.com
    Microsoft is retiring 'Send to Kindle' in Word
    9 hours ago
  • Security Boulevard
    Ai Proofing Your It/cyber Career: The Human Only Capabilities That Matter
    13 hours ago
  • Techdirt.
    This Week In Techdirt History: January 4th – 10th
    13 hours ago
  • The Hacker News
    MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
    23 hours ago
  • The Register - Security
    UK government exempting itself from flagship cyber law inspires little confidence
    1 day ago
  • Schneier on Security
    Friday Squid Blogging: The Chinese Squid-Fishing Fleet off the Argentine Coast
    1 day ago
  • Latest topics for ZDNet in Security
    Five CES 2026 products I'd buy as soon as they'd take my money
    1 day ago
  • IT SECURITY GURU
    Keeper Security Launches JetBrains Extension
    1 day ago
  • SecurityWeek RSS Feed
    In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
    1 day ago
  • Cybercrime Magazine
    From deepfakes to ransomware, what Australia’s SMEs should watch for in 2026
    1 day ago
  • SearchSecurity: Security Wire Daily News
    News brief: AI threats to shape 2026 cybersecurity
    1 day ago
  • ComputerWeekly: IT security
    From promise to proof: making AI security adoption tangible
    2 days ago
  • Graham Cluley
    pcTattletale founder pleads guilty in rare stalkerware prosecution
    2 days ago
  • Cisco Blog
    Navigating E-rate for FY2026: Key Deadlines and New Opportunities
    2 days ago
  • Krebs on Security
    Who Benefited from the Aisuru and Kimwolf Botnets?
    2 days ago
  • Cybercrime | The Guardian
    Alleged scam kingpin Chen Zhi arrives in China after extradition from Cambodia
    2 days ago
  • Daniel Miessler
    Claude Code Addiction is Addiction to Creation
    2 days ago
  • Troy Hunt
    Weekly Update 485
    4 days ago
  • Risky Business
    How the World Got Owned Episode 1: The 1980s
    4 days ago
  • Google Online Security Blog
    HTTPS certificate industry phasing out less secure domain validation methods
    4 weeks ago
  • EFF Press Releases
    EFF Launches Age Verification Hub as Resource Against Misguided Laws
    4 weeks ago
  • NCSC Site
    Provisioning and managing certificates in the Web PKI
    4 weeks ago
  • Cybersecurity Zen
    How to Choose a Philly Trucking Job: Bridges & Tolls, Tight Docks, Warehouse Hotspots
    3 months ago
  • Hacker Combat - Cyber Security and Hacking News | HackerCombat
    Snowflake Data Breach: What Happened and How to Prevent It
    5 months ago
  • Cybersecurity Insiders
    Catfishing via ChatGPT: A Deep Cybersecurity Concern
    7 months ago
  • Security Intelligence
    How to craft a comprehensive data cleanliness policy
    1 year ago
  • Cybersecurity
    We're buying the recent dips on 2 stocks in the most oversold market in over a year
    1 year ago
  • Motherboard US - Hacking US
    The Teenager Who Lived a Secret Double Life as a Millionaire Crypto Bandit
    1 year ago
  • Latest Security Articles from ComputerworldUK
    Kill meetings (before meetings kill your company)
    1 year ago
  • Errata Security
    C can be memory safe, part 2
    1 year ago
  • Dark Reading:
    The Role of the CISO in Digital Transformation
    2 years ago
  • Light Reading:
    Energy- and Space-Efficient Security in Telco Networks
    2 years ago
  • News – SC Media
    New AI phishing tool FraudGPT tied to same group behind WormGPT
    2 years ago
  • CSO Online
    Most popular generative AI projects on GitHub are the least secure
    2 years ago
  • Softpedia News / Security
    Google Expands End-to-End Encryption for Gmail on the Web
    3 years ago
  • Threatpost | The first stop for security news
    Student Loan Breach Exposes 2.5M Records
    3 years ago
  • DDoS Attacks
    Link11 Discovers Record Number of DDoS Attacks in First Half of 2021
    4 years ago
  • Feedspot Blog
    Top 5 Ayurveda Forums, Discussions, Message Boards To Follow in 2021
    4 years ago
  • Computer Business Review
    Network transformation: The foundation for digital business
    4 years ago
  • RSA Conference Blog
    A WORD OF CAUTION: AVOID SCAMMERS CLAIMING TO HAVE THE RSAC ATTENDEE LIST
    4 years ago
  • Bad Packets Report
    Over 3,000 F5 BIG-IP endpoints vulnerable to CVE-2020-5902
    5 years ago
  • Ars Technica » Risk Assessment
    What the newly released Checkra1n jailbreak means for iDevice security
    6 years ago
  • US-CERT Tips
    Privacy and Mobile Device Apps
    6 years ago
  • Infosecurity Europe Blog
    Infosecurity Magazine takes over Infosecurity North America 2018
    6 years ago
  • CRN
    WATCH: Digital Guardian Exec On How Its Move To The Cloud Benefits Partners
    7 years ago
  • SecurityRoundTable.org
    Why A ‘Cloud Architect’ Should Be on Your Hiring Agenda
    7 years ago
  • WIRED » Threat Level
    Feds Charge NSA Contractor Accused of Exposing Russian Hacking
    8 years ago
  • Security | The Silicon Review
    Is it true that internet has penetrated only to handful of the Indian population?!
    9 years ago
  • Latest articles from SC Magazine UK
    400% increase in POS malware variants across US Thanksgiving weekend
    9 years ago
  • Forbes - Security
    Slice Offers On-Demand Insurance To Cover Home Sharing Hell
    9 years ago
  • Blog - devsecops
    Securing the Continuous Integration Continuous Deployment (CICD) Pipeline
    9 years ago
  • AlienVault Blogs
Show 10 Show All

Vendors

  • Rapid7 Blog
    Metasploit Wrap-Up 01/09/2026
    1 day ago
  • Varonis Blog
    Cybercrime Predictions for 2026: What We’re Seeing from the Frontlines
    1 day ago
  • AWS Security Blog
    AWS named Leader in the 2025 ISG report for Sovereign Cloud Infrastructure Services (EU)
    1 day ago
  • Malwarebytes Unpacked
    pcTattletale founder pleads guilty as US cracks down on stalkerware
    1 day ago
  • SentinelOne
    The Good, the Bad and the Ugly in Cybersecurity – Week 2
    1 day ago
  • The Akamai Blog
    Why VM Shapes Matter: New Compute Plans Deliver Predictable Performance
    1 day ago
  • Centrify Cloud Service Status - Incident History
    Privileged Access Service / Cloud Suite - Pod34 Emergency Maintenance
    2 days ago
  • Recorded Future
    Digital Threat Detection Tools & Best Practices
    2 days ago
  • TaoSecurity
    Happy 23rd Birthday TaoSecurity Blog
    2 days ago
  • CyberArk
    Inside CyberArk Labs: the evolving risks in AI, browsers and OAuth
    2 days ago
  • Cisco Blog » Security
    Three Benefits of Segmentation
    2 days ago
  • Palo Alto Networks Blog
    Prisma AIRS Secures the Power of Factory’s Software Development Agents
    2 days ago
  • We Live Security » Languages » English
    Credential stuffing: What it is and how to protect yourself
    2 days ago
  • CloudFlare
    A closer look at a BGP anomaly in Venezuela
    5 days ago
  • Tenable Blog
    Cybersecurity Snapshot: Predictions for 2026: AI Attack Acceleration, Automated Remediation, Custom-Made AI Security Tools, Machine Identity Threats, and More
    1 week ago
  • ThreatConnect | Enterprise Threat Intelligence Platform
    How Threat-Informed Response Slashes MTTR — and Boosts MSSP Margins
    1 week ago
  • Arbor Networks Threat Intelligence
    DDoS-for-Hire and the Evolving Use of AI
    3 weeks ago
  • Imperva Cyber Security Blog
    Black Friday 2025 in Review: What Retailers Need to Know About This Year’s Holiday Shopping Season
    3 weeks ago
  • Heimdal Security Blog
    How to Avoid Holiday Shopping Scams (From a Former Cyber Detective)
    4 weeks ago
  • Packet Pushers - Briefings In Brief
    Tech Bytes: How to Get DPUs from Niche to Transformative (Sponsored)
    4 weeks ago
  • Check Point Blog
    AI Has Become the New Enterprise Perimeter — and Gemini 3 Pro Just Proved It
    1 month ago
  • ClearSky Cybersecurity
    Houthi Influence Campaign
    9 months ago
  • Darktrace Blog
    Darktrace Recognized as the Only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS Protection Platforms
    9 months ago
  • Darktrace Blog
    Darktrace Recognized as the Only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS Protection Platforms
    9 months ago
  • Fooling the Interpreter
    Bypassing Whitelists With XSS Payloads in Attributes
    1 year ago
  • Liquidmatrix Security Digest
    Liquidmatrix Security Digest Podcast – Episode 7E
    1 year ago
  • Postmodern Security
    Let’s Stop the Security Shaming
    1 year ago
  • Errata Security
    C can be memory safe, part 2
    1 year ago
  • Naked Security
    Update on Naked Security
    2 years ago
  • Anomali Blog
    Anomali Cyber Watch: Cadet Blizzard - New GRU APT, ChamelDoH Hard-to-Detect Linux RAT, Stealthy DoubleFinger Targets Cryptocurrency
    2 years ago
  • Securosis Highlights
    The THIRTEENTH Annual Disaster Recovery Breakfast: Changing of the Guard
    2 years ago
  • blog.trendmicro.co.uk
    Delivering visibility, control and simplified security to Bathgate Group
    3 years ago
  • TrendLabs Security Intelligence Blog
    Finest Free Torrenting VPNs
    4 years ago
  • AlienVault Blogs
    This feed has moved and will be deleted soon. Please update your subscription now.
    4 years ago
  • Carbon Black
    VMware Carbon Black Delivers High-Fidelity Insight at Every Step of MITRE Engenuity ATT&CK® Evaluation
    4 years ago
  • CipherCloud
    CipherCloud and Lookout Blaze a New Path Together – Redefining Security from Endpoint to Cloud
    4 years ago
  • Inside The Threat Blog by Lancope
    This feed has moved and will be deleted soon. Please update your subscription now.
    5 years ago
  • Skybox Security Blog – Cybersecurity from The Skybox View
    Salt Vulnerabilities Exploited with Targeted Cryptomining Attack on DigiCert
    5 years ago
  • Zscaler Research
    Frenchy – Shellcode in the Wild
    5 years ago
  • Cisco Blog » Threat Research
    C2 With It All: From Ransomware To Carding
    6 years ago
  • Preempt Blog
    Why Insider Threat Denial is Everyone’s Problem
    6 years ago
  • Network Security Blog
    Lucky Break
    7 years ago
  • Threat Research
    BIOS Boots What? Finding Evil in Boot Code at Scale!
    7 years ago
  • Threat Intelligence
    Lojack Becomes a Double-Agent
    7 years ago
  • Fortinet Blog
    Securing the Network: What Three Key Verticals Require
    7 years ago
  • Cyphort
    Equifax Breach: The News We All Dreaded to Hear.
    8 years ago
  • Speaking of Security - The RSA Blog and Podcast
    A Security Decision – Build or Buy
    8 years ago
  • Metasploit
    Metasploit Wrapup
    8 years ago
  • Threat Geek
    Reducing Detection from Months to Minutes: Detecting Credentials in the Clear
    8 years ago
  • Lockheed Martin Cybersecurity Blog
    How Threat Intelligence Can Increase an Organization’s Cybersecurity Maturity
    9 years ago
  • iSIGHT Partners
    ThreatScape Media Highlights Update – Week Of June 8th
    9 years ago
  • LogRhythm: The Dialog - The Security Intelligence Company
    Getting Started with Threat Intelligence
    10 years ago
  • IBM Internet Security Systems Internet Threat Information
    Multiple Adobe Flash Player code execution vulnerabilities
    10 years ago
  • Cylance Blog
  • Farsight Security Blog
  • Our Blog | Core Security
  • Comments on: The Top 10 AlgoSec Blog Posts From 2018
  • Trustwave Newsroom
Show 10 Show All

Blog Archive

  • ►  2020 (2)
    • ►  May (2)
  • ▼  2019 (35)
    • ▼  December (2)
      • 12 Threat Modelling Techniques
      • Zero Trust
    • ►  November (2)
    • ►  October (6)
    • ►  September (5)
    • ►  August (1)
    • ►  June (1)
    • ►  February (4)
    • ►  January (14)
  • ►  2018 (4)
    • ►  December (2)
    • ►  September (1)
    • ►  April (1)
  • ►  2017 (6)
    • ►  August (5)
    • ►  July (1)
  • ►  2016 (1)
    • ►  January (1)
  • ►  2015 (4)
    • ►  September (4)
  • ►  2013 (3)
    • ►  April (1)
    • ►  March (1)
    • ►  February (1)

About Me

Tony Brown
Enterprise Security Solutions Architect at global service provider. CCIE #8767. CISSP. Chartered Engineer. MSc. in Information Security. CCDE 2011:6 Chartered IT Professional. Member of the Institute of Information Security Professionals. Blah blah blah
View my complete profile
Awesome Inc. theme. Powered by Blogger.