
The cloud security emperor has no pants
“Shared responsibility” usually means that no one is responsible for minding the gap. Don’t fall in.

The security user experience (SUX)
Security processes that treat the very users we protect as unwanted burdens and alienate them in the process are a path to failure.

CISOs are still chiefs in name only
If you’re not in the meeting where decisions are made, then you’re not part of the C-Suite—whatever your title may be.

Drop the SBOM
Software bills of material are having a moment, but the costs of an externally visible SBOM are likely to outweigh the benefits, says Andy Ellis.

Vulnerabilities don’t count
No one outside the IT department cares about your vulnerability metrics (or they shouldn’t, anyway). They care about efficacy. And traditional stats don’t show that.