Building Tanks
netspi.com | blog | #risk-management | #security-strategy | #defense-in-depth | #infosec-management | #brian-snow
Summary
A couple of months ago, I attended the Nuclear Energy Institute's Cyber Security Implementation Workshop in Baltimore.
- Published
- Collected
Related coverage
blog ·
netspi.com
The Value of Detective Controls
Preventative controls dominate security spending, but since not every attack can be stopped, detective controls deserve more attention — though noisy IDS/IPS and unreviewed logs often undercut them.
blog ·
netspi.com
Anthropic’s Mythos Announcement: What it Means for Security Teams
A measured take on Anthropic's Mythos: autonomously chaining four vulnerabilities is a real inflection point, but teams should build their own benchmarks and keep human verification central.
blog ·
netspi.com
Tackling Technical Debt before It Owns Your Roadmap
Prioritize high-impact pentest findings and technical debt over compliance tasks in Q1; deferred findings compound into costlier, architecture-level remediation problems later.
blog ·
netspi.com
Understanding Indirect Prompt Injection Attacks in LLM-Integrated Workflows
Indirect prompt injection hides malicious instructions in content LLMs later read—email footers, PDFs, web pages. Real Microsoft 365 Copilot attacks make defense in depth and AI monitoring essential.
blog ·
netspi.com
The Attack Surface is Changing – So Should Your Approach
Spreadsheets and fragmented point tools can't keep pace with today's expanding external attack surface. The article explains why manual asset inventories break down and what modern ASM requires.
blog ·
netspi.com
Attack Surface Management vs. External Network Penetration Testing
External network pentesting delivers deep point-in-time analysis of a defined scope, while ASM continuously discovers assets and exposures; together they close gaps from unknown assets.
Skip to content