Stories by Derek Slater

Containerization and mobile threats

By Derek Slater | 20 December, 2012 15:21

For a short and very enjoyable history lesson, watch this Youtube video.

In Pictures: A walking tour - 33 questions to ask about your company's security

By Derek Slater | 14 December, 2012 08:40

Get out of the office, look around, and get a fresh perspective on protecting employees, assets, and data

Taking a risk on risk management

By Derek Slater | 05 December, 2012 20:18

Greg Kaden is a lawyer specializing in corporate bankruptcy at Goulston and Storrs. Seeing changes and trends in risk management and insurance, Kaden and a few colleagues pitched the creation of a subsidiary called Fort Hill Risk Management.

I like risk

By Derek Slater | 04 December, 2012 15:36

Many chess players--and I'm sure you are going to find this hard to believe--are boring. Even to their fellow chess players.

Working the kinks out of your supply chain

By Derek Slater | 27 November, 2012 15:40

Resilience, speed and visibility. Those are three magic words that make any supply chain manager's ears perk up.

Opinion: Chef Ramsay will see you now

By Derek Slater | 18 October, 2012 20:18

Sometimes agents of change have to turn up to volume. And sometimes not.

Decade of the CSO

By Derek Slater | 01 October, 2012 15:43

Security as a profession has come a long way in the last decade. This is not just noteworthy, it's also worth celebrating.

Cloud control

By Derek Slater | 26 September, 2012 15:15

I had the pleasure of sharing the stage at the Cloud Leadership Forum with John Howie. Howie is the newly minted chief operating officer for the Cloud Security Alliance. He came to the CSA after a tenure at "a large cloud provider"--very large indeed--and was able to address both my questions and those from the audience in excellent, useful detail.

Pulling it all together: A special report on GRC

By Derek Slater | 22 August, 2012 19:12

I like the concept of governance, risk and compliance (GRC) for two reasons. One reason is completely tactical, the other completely conceptual. First, the tactical: compliance complexity reduction. This garbled regulatory compliance landscape is madness. Madness! Every year for six years running, more than half of our State of the CSO survey respondents have said they will spend an increasing amount of time on regulatory compliance work.

Getting unstuck

By Derek Slater | 06 July, 2012 14:54 | 2 Comments

The rate of change these days is so high that occasionally I think: "I'm just looking for a nice rut to fall into. Six months in a rut sounds really relaxing right now."

Disaster recovery is a success just waiting to happen

By Derek Slater | 17 May, 2012 10:28

Security--the topic, and thus the department--sometimes gets pigeonholed as a downer. Maybe from time to time you notice a coworker avoiding getting in the elevator with you. A CSO once told me it's even worse when you get in the elevator and some wiseacre turns to put his hands on the wall--as if expecting you to frisk him.

Let's not bicker and argue about who killed who

By Derek Slater | 06 April, 2012 05:22

I have a degree in Linguistics. (But I have a job anyway! Rimshot!) So I have some training in arguing about semantics.

Debriefing: Laws and orders (the quiz)

By Derek Slater | 17 March, 2012 07:23

1. The Senate bill called the Public Company Accounting Reform and Investor Protection Act became law under the name...

Tangled web: Facebook, SEO, and black-hat tactics colliding (still)

By Derek Slater | 16 March, 2012 02:29

A few decades ago, some genius had this outrageous idea: "Let's put everything online." Everything. Measureless reams of information all piled up on the World Wide Web. The audacity of this concept should not go unappreciated.

A clear-eyed look at APT

By Derek Slater | 13 March, 2012 01:06

Security is occasionally susceptible to two afflictions: 1. Hype. 2. Semantic arguments.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Enterprise Security for Endpoints

Think your endpoints are secure? Think again. Learn why Trend Micro can help.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.