Open in app

Sign in

Write

Sign in

Ryan McGeehan
Ryan McGeehan

2.9K followers

Home

About

Starting Up Security

Published in

Starting Up Security

Prioritizing Detection Engineering

Detection Engineering is a concept that has emerged in the detection space. It acknowledges the complexity of a detection stack and the…

Sep 10, 2024
1
Sep 10, 2024
1
Starting Up Security

Published in

Starting Up Security

Managing a quarterly security review

I like an approach that combines my favorite quarterly review practices I’ve been exposed to. Here’s the general meeting structure:

Aug 14, 2024
Managing a quarterly security review
Managing a quarterly security review
Aug 14, 2024
Starting Up Security

Published in

Starting Up Security

Follow-Up: SolarWinds Response to SEC Lawsuit

SolarWinds has responded on their blog regarding the SEC’s lawsuit against them following their breach. Here is some analysis:

Nov 9, 2023
Nov 9, 2023
Starting Up Security

Published in

Starting Up Security

Lessons from the SEC’s Lawsuit against SolarWinds and Tim Brown

A few days ago, the SEC filed a lawsuit against SolarWinds and their CISO that shares some similarities with the blameless post-mortem of…

Nov 6, 2023
Lessons from the SEC’s Lawsuit against SolarWinds and Tim Brown
Lessons from the SEC’s Lawsuit against SolarWinds and Tim Brown
Nov 6, 2023
Starting Up Security

Published in

Starting Up Security

Vulnerability Management: You should know about EPSS

The Exploit Prediction Scoring system (EPSS) is great. You might like it, too, if you deal with large amounts of vulnerabilities.

Oct 9, 2023
2
Vulnerability Management: You should know about EPSS
Vulnerability Management: You should know about EPSS
Oct 9, 2023
2

Beyond Controls: The Power of Risk Scenarios

Scenarios are an underappreciated way to model infosec risk. A scenario is simply a future, consequential event you write to express a risk…

Aug 24, 2023
1
Beyond Controls: The Power of Risk Scenarios
Beyond Controls: The Power of Risk Scenarios
Aug 24, 2023
1
Starting Up Security

Published in

Starting Up Security

Talking about risk with thresholds 🔥

Imagine you encounter a fire in the woods. You’d instinctively decide to do one of two things:

Mar 20, 2023
1
Talking about risk with thresholds 🔥
Talking about risk with thresholds 🔥
Mar 20, 2023
1
Starting Up Security

Published in

Starting Up Security

A blameless post-mortem of USA v. Joseph Sullivan

Our industry deserves a complete retrospective into the incidents behind the criminal case against Uber’s former Chief Security Officer.

Dec 8, 2022
1
A blameless post-mortem of USA v. Joseph Sullivan
A blameless post-mortem of USA v. Joseph Sullivan
Dec 8, 2022
1
Starting Up Security

Published in

Starting Up Security

Endpoint Security: Intuition around the Mudge Disclosures

The Mudge disclosures bring up specific pain points around how endpoint security is measured and communicated and what baselines are…

Aug 24, 2022
Endpoint Security: Intuition around the Mudge Disclosures
Endpoint Security: Intuition around the Mudge Disclosures
Aug 24, 2022

How to estimate legal costs from a data breach.

We need budget and headcount to mitigate risks. Larger risks should encourage more resources towards mitigation efforts.

Nov 15, 2021
How to estimate legal costs from a data breach.
How to estimate legal costs from a data breach.
Nov 15, 2021
Ryan McGeehan

Ryan McGeehan

2.9K followers

Writing about risk, security, and startups at scrty.io

Following
  • Sarah Fluchs

    Sarah Fluchs

  • Cassie Kozyrkov

    Cassie Kozyrkov

  • Marcel Laverdet

    Marcel Laverdet

  • Scott Winicour

    Scott Winicour

  • Amir Michael

    Amir Michael

See all (186)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech