Security & Generative AI

In the past 2 years, there has been a surge in GenAI and its security implications. I developed the following framework to categorize the blogs, tools, and resources I have been exploring to make it easier to navigate and understand. Everything related to GenAI and Security can be put in these 3 pillars: Security of…

Security Awareness Training

๐€๐ฅ๐ฅ ๐ž๐ฆ๐ฉ๐ฅ๐จ๐ฒ๐ž๐ž๐ฌ ๐ฆ๐ฎ๐ฌ๐ญ ๐œ๐จ๐ฆ๐ฉ๐ฅ๐ž๐ญ๐ž ๐ญ๐ก๐ž ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐š๐ฐ๐š๐ซ๐ž๐ง๐ž๐ฌ๐ฌ ๐ญ๐ซ๐š๐ข๐ง๐ข๐ง๐  ๐ฐ๐ข๐ญ๐ก๐ข๐ง ๐Ÿ‘๐ŸŽ ๐๐š๐ฒ๐ฌ ๐จ๐Ÿ ๐จ๐ง๐›๐จ๐š๐ซ๐๐ข๐ง๐  ๐š๐ง๐ ๐š๐ง๐ง๐ฎ๐š๐ฅ๐ฅ๐ฒ ๐ญ๐ก๐ž๐ซ๐ž๐š๐Ÿ๐ญ๐ž๐ซ.Sound familiar? Despite being a hard requirement and many organizations spending thousands of dollars on implementing the Learning Management System (LMS), tracking completion rates, and sometimes enforcing sanctions for not completing the training – this has always been a point…

Note to self

I did not speak a full sentence in English until I was 20, and I am pretty sure the recruiter at HSBC only hired me because I told him my uncle worked there. I did not write my first blog post until Dec 2018 in an effort to make sense of all the InfoSec jargons…

Compliance โ‰  Security

As we enter the new year, many of us will start the annual third-party attestations. Itโ€™s important toย remember that holding a third-party attestation provides a baseline assurance on the effective implementation of management, operational, and technical controls. Compliance demonstrated by a clean SOC 2 report, ISO 27001 certification, HITRUST certification, etc. does not equate to…