Posts

Adventures in post-pandemic Asian travel.

I found myself taking a new job this fall. One surprising aspect of that job was they had scheduled a company all-hands in Kuala Lumpur (KL) in mid-September. So after our family trip to Amsterdam, Finland, Sweden, and Estonia, I now had a trip to South East Asia on my calendar. This post is mainly intended as random travel advice for visiting Malaysia, flying SkyTeam, dealing with internet access, etc. There will be minimal if any, cloud security content.

Finland - 2022

This is part two of Baltic Adventures. Part One captured the chaos of post-pandemic travel and our bonus tour of Amsterdam. This post will cover our 4 days in Finland.

Adventures in post-pandemic travel

This will be the first in a series of travel-related posts. I found a distinct lack of information on the internet about some specific logistical things around international travel. I hope these posts are useful to whoever finds them via some Google-fu.

This summer, myself, my wife, and the 10-year-old are on a three-country, four-city tour of the Baltics. We picked this itinerary because 1) we found a good price on Delta One, and 2) at the time we booked it, we wanted to visit some countries that geopolitical affairs might make impossible in the future. So we’re going to Finland, Sweden, and Estonia!


Ghost of CloudSec Yet to Come

A cheerful ghost of cloud security yet to come. I’ll talk about where CloudSec really needs to focus - on the pipeline and ultimately on the cloud developer or engineer. Finally, I’ll close out with a one-year roadmap for how I’d build a third (fourth) program if I’m crazy enough to do this again at my next job.

The Philosphy of Prevention

Following up on the Tar-Pit of CSPM, I feel the need to offer something more constructive for CloudSecurity practitioners to do. Cloud Security Posture Monitoring is “here’s a spreadsheet of issues, go fix them”. There are other ways, but none of them are a panacea.

The Tar Pit of CSPM

It’s been a little less than five years since I moved from a media production cloud nerd to a cloud security nerd. As I ponder what I’m going to do next, I want to reflect on some of the things I got right and some that didn’t work out as expected.

SECCDC 2022 - The Rise of Fooli

The Southeast Collegiate Cyber Defense Competition is an annual competition where eight teams from various colleges have to defend their systems from Red Team attacks while also executing on management-type business challenges. This is my second year helping Kennesaw State University run the SECCDC in AWS. This year we not only ran the Regional competition on-site at KSU, but we also hosted 26 teams for the preliminary round. In previous years the scenario was HALCORP, a fictional company that did nothing but generate compliance paperwork.