<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Luck and Skill</title>
    <description>Success comes from some combination of luck and skill; we are right to be  proud of our skill, but we should also remember to be humble about our luck. 
</description>
    <link>https://luckandskill.io/</link>
    <atom:link href="https://luckandskill.io/feed.xml" rel="self" type="application/rss+xml"/>
    <pubDate>Fri, 26 Dec 2025 15:49:34 +1100</pubDate>
    <lastBuildDate>Fri, 26 Dec 2025 15:49:34 +1100</lastBuildDate>
    <generator>Jekyll v3.10.0</generator>
    
      <item>
	
          <title>Career advice: Deciding what job to aim for next</title>
	  
        <description>&lt;p&gt;One of the things I love most about my work is that people ask me to help them think through challenges and opportunities. And I’ve gotten to a point in my working life where people often ask for career advice. I don’t necessarily feel like my career is itself under control, so I always caveat the advice, but I’m really happy to share what I’ve learned along the way&lt;sup id=&quot;fnref:career&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:career&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;

&lt;p&gt;In these conversations, one of the most common questions is “How do I work out what job to go for next?”. I really respect the complexity of the question, since:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;there are so many kinds of possible jobs,&lt;/li&gt;
  &lt;li&gt;they become available pretty much unpredictably (although subject to economic cycles, etc),&lt;/li&gt;
  &lt;li&gt;the path to developing the skills and experience for them can be wildly different, and&lt;/li&gt;
  &lt;li&gt;you don’t have infinite time to build the skills to be credible at everything.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It’s also really hard to work out if you’ll like a job before you start it - and everyone has heard a horror story about a new job not being what they expected.&lt;/p&gt;

&lt;p&gt;In these conversations, I usually recommend that people with those questions try three exercises: get more clarity about what you (really) want, then reduce the possibilities, then talk to people.&lt;/p&gt;

&lt;h2 id=&quot;working-out-what-you-want--three-column-exercise&quot;&gt;Working out what you want — Three column exercise&lt;/h2&gt;

&lt;p&gt;Try this exercise. It’s my version of what is essentially a skills audit - with explicit focus on how you feel about those skills.&lt;/p&gt;

&lt;p&gt;If you can, try to get a bit of quiet time for this, at least initially - maybe head to a coffee shop or a library; somewhere out of your usual spaces. It could also be something that you could do on a commute.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Grab a blank sheet of paper, turn it to landscape, and then divide the page into three columns&lt;sup id=&quot;fnref:paper&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:paper&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;.&lt;/li&gt;
  &lt;li&gt;In the middle column, put “Skills and Experiences that I have, which I want to use ✅”. In this column, you’re going to collect all the things that you’re good at, which you want to keep using. These are the skills that help you work out which roles you can contribute strongly to on day one, and that are going to provide great stories to tell in the interview.&lt;/li&gt;
  &lt;li&gt;On the left column, put “Skills I’m leaving behind 🚩”. We’ve all got skills that we’re kind of done with, that we don’t want to do any more&lt;sup id=&quot;fnref:visio-story&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:visio-story&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;, and that’s okay. Being clear about what those skills are is helpful, as it can then help you assess (and filter) potential roles against how many of these skills they’re going to ask you to use.&lt;/li&gt;
  &lt;li&gt;On the right column, put “Skills and experiences I want to acquire 📈”. The neat inverse of those red flags is growth — most of us get a sense of accomplishment, even joy, from acquiring new skills and demonstrating mastery. Changing roles can be a particularly intense source of new skill development opportunities, so knowing what kinds of opportunities you’re interested in can really help you find the best opportunity.
&lt;img src=&quot;/assets/job-skills-exercise-2025-12-26.png&quot; alt=&quot;Visual outline of the three-column exercise described above&quot; /&gt;&lt;/li&gt;
  &lt;li&gt;Start brainstorming into each of those columns. The critical thing here is &lt;em&gt;being honest&lt;/em&gt; - this isn’t for anyone else to see, so your only audience is yourself. Don’t write what society, or your colleagues, or your boss, or your parents told you should write. Don’t write what you think the “right” answer is. Write what your heart and mind tell you is true for you. In all the years I’ve been encouraging others to do this exercise, nobody has &lt;em&gt;ever&lt;/em&gt; shown me their answers to these questions — and that’s totally okay.&lt;/li&gt;
  &lt;li&gt;Carry it around for a few days (or a photo of it, if you don’t want to carry the paper itself), and add things as they occur to you. Very often, you’ll get the first 80% out in a burst of activity, and then your subconscious will keep thinking about it - make sure you can capture those thoughts as they appear.&lt;/li&gt;
  &lt;li&gt;Once you’re done, you’ll have something that can help you navigate toward what you want, and away from the things that are going to drain you.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2 id=&quot;reducing-the-search-space--crossing-off-what-you-dont-want&quot;&gt;Reducing the search space — Crossing off what you don’t want&lt;/h2&gt;

&lt;p&gt;Many years ago, I read &lt;a href=&quot;https://www.penguin.com.au/books/the-now-habit-9781529146684&quot;&gt;&lt;em&gt;The Now Habit&lt;/em&gt; by Neil Fiore&lt;/a&gt;, a book about understanding what drives the difficulty some people feel about starting tasks and recommending some tactics for reducing that difficulty. One of the core tactics is The “Unschedule” - essentially, putting all the non-work things that you need to do (including rest!) into your calendar, as a way of visualising how much time you &lt;em&gt;don’t&lt;/em&gt; have available, to help you create the feeling of time pressure sooner and therefore get started earlier.&lt;/p&gt;

&lt;p&gt;You can take a similar approach to working out what jobs you might be interested in. It’s okay if you don’t even know what roles exist — this exercise will help you to get a sense of the landscape.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Grab the biggest list of relevant jobs that you can find – if you work for a big company and they have a standardised list of job titles/roles, that’s a great option; else, look at an industry framework like &lt;a href=&quot;https://sfia-online.org/en/sfia-9/sfia-views/sfia-9-multi-view/sfia-9-en-summary-chart-with-roles&quot;&gt;SFIA for IT&lt;/a&gt;, &lt;a href=&quot;https://sfia-online.org/en/sfia-9/sfia-views/sfia-9-multi-view/sfia-cyber-en-summary-chart-with-roles&quot;&gt;SFIA for Cyber&lt;/a&gt;. If you’re not in tech, look for your industry’s equivalent.&lt;/li&gt;
  &lt;li&gt;Cross off every job you definitely don’t want. Be ruthless. Again, this is for you and nobody else ever needs to know. You’re not making value judgements about the people who are in those roles, you’re just trying to work out what’s right for you.&lt;/li&gt;
  &lt;li&gt;Of the jobs you haven’t crossed off, circle the groups that are most interesting to you - with a particular focus on those you know least about. What are the questions you would ask the people who are experienced experts in those jobs? Would you want to know what the work involves day-to-day? Or which skills are most important? Or how they developed their personal credibility for the role?&lt;/li&gt;
&lt;/ol&gt;

&lt;h2 id=&quot;reducing-the-uncertainty---talk-to-people&quot;&gt;Reducing the uncertainty - Talk to people&lt;/h2&gt;

&lt;p&gt;Once you’ve got a list of interesting roles and questions you want to ask, there’s one more step: go find friendly people in those roles, ask those questions and make friends.&lt;/p&gt;

&lt;p&gt;Finding people can be a bit varied. Again, if you have the benefit of working somewhere large, you can often just look them up in your internal directory and reach out.&lt;/p&gt;

&lt;p&gt;Many people are really quite happy to talk about their roles – particularly what they find most interesting about it, how they got into it, what they’ve learned. So, you should assume that it’s probably safe to gently ask, maybe something like “I’m really interested in moving into a role in your field, but I don’t know a lot about it - what do you find most interesting about your work?”, and go from there. If you show them genuine curiosity and ask the follow-on questions, it’s not unusual for the conversation to run for a while. And if they don’t want to talk about it, that’s fine - just gently move on to the next person when you can, and try again.&lt;/p&gt;

&lt;p&gt;Otherwise, industry associations and interest groups can be great sources for this kind of thing - anything that runs meetings or gatherings of people. Helpfully, the kind of people that will go to a gathering tend to be extroverts (or outgoing introverts&lt;sup id=&quot;fnref:EI&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:EI&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;4&lt;/a&gt;&lt;/sup&gt;) that are going to those meetings to talk, so you don’t have to wonder about whether they want to talk.&lt;/p&gt;

&lt;p&gt;(If you (like me) are in that introvert group, then I know cold outreach can feel impossible - often grounded in concern that you might be bothering the other person. Often though, people are not bothered by a question about their work from someone genuinely interested, and they can be delighted to chat. So, please experiment with asking.)&lt;/p&gt;

&lt;h2 id=&quot;final-thought&quot;&gt;Final thought&lt;/h2&gt;

&lt;p&gt;A few years ago, I was on an internal leadership development course at my organisation where we heard from most of the EVPs about their career journeys. I was really struck that none of them said they had a specific plan for their careers, given how ubiquitous that career advice is; instead, they consistently said that they had navigated by their principles (of various kinds), and that they had reached very senior executive roles. One said “I know how I want to contribute and I know what I’m good at, and I look for my next role to match that” (approximately).&lt;/p&gt;

&lt;p&gt;That was helpful for me in two ways. It gave me permission to not have a plan, and to put down the guilt I had felt about not having a clear idea of what I wanted. And more importantly, it prompted me to focus on creating clarity around how I want to contribute, what my principles are, and to sharpen what I’m good at. That’s served me well since.&lt;/p&gt;

&lt;p&gt;(Of course, these are the people who made it, so take it with appropriate salt. This isn’t proof that you will be successful if you don’t have a plan; just proof that you don’t necessarily have to have a plan to be successful.)&lt;/p&gt;

&lt;p&gt;So, if you’re at a bit of a career crossroads, you’re not alone. It’s a normal part of working life. Hopefully, those tactics will be useful to you in collecting some information and in focusing your search for what you might choose to do next. Best of luck!&lt;/p&gt;

&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:career&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;And one of the things I’ve learned along the way is that (approximately) &lt;em&gt;nobody&lt;/em&gt; feels like their career is fully under control. &lt;a href=&quot;#fnref:career&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:paper&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;You can do this on a computer if you want to, but it seems to work much better on paper, particularly in the initial drafting phase. &lt;a href=&quot;#fnref:paper&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:visio-story&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;I often tell the story from early in my career where I was asked to create an updated system diagram - the company had a printout of the old one, but nobody could find the Visio file - so I sat in a meeting room for a couple of hours while a dozen people each explained their bit of the system and how it all connected; I tended to be more cautious about admitting I could use Visio after that. &lt;a href=&quot;#fnref:visio-story&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:EI&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;For those that don’t know me personally, some context: I’m an introvert, I have anxiety, and I find events with lots of people daunting. And: I really enjoy connecting with people individually, and my job often requires me to go to those kinds of events - where I often find that I get chances to have really interesting conversations. So, I am in that “outgoing introvert” - I can find great joy in those conversations, and I ~always need recovery time afterward. &lt;a href=&quot;#fnref:EI&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</description>
        <pubDate>Fri, 26 Dec 2025 15:48:00 +1100</pubDate>
        <link>https://luckandskill.io/2025/12/26/career-advice-three-exercises.html</link>
        <guid isPermaLink="true">https://luckandskill.io/2025/12/26/career-advice-three-exercises.html</guid>
        
        
      </item>
    
      <item>
	
          <title>Getting better at saying &quot;no&quot;</title>
	  
        <description>&lt;p&gt;I really like to help people - it feels good, and it generates value.  Fortunately, work is full of lots of opportunities to help people.  Unfortunately, I also tend to be wildly optimistic about how much capacity I actually have - underestimating how long it will take to help with something, and underestimating my existing commitments. The intersection of those various things means that I sometimes get wildly overcommitted - and have to work silly hours to dig my way back out of those commitments. That works &lt;em&gt;okay, I guess&lt;/em&gt;… but I’m not in my 20s any more (or my 30s), and I’d prefer to reduce how often this happens.&lt;/p&gt;

&lt;p&gt;Improving things has meant:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Moving to a single view of all of my existing commitments, so that I can see at a glance how much is already on my plate.&lt;/li&gt;
  &lt;li&gt;Sharpening my decision algorithm from “Could I help with this?” to “Am I the &lt;em&gt;best person&lt;/em&gt; to help with this?” (and “best person” doesn’t mean “most experienced” – routing work to people who want to grow in that area is a gift to them).&lt;/li&gt;
  &lt;li&gt;Changing my capacity attribute from “Will I have time?” to “Will I have both time and &lt;em&gt;energy&lt;/em&gt;?”.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All of those are habit changes, so it’s a bit of an iterative change process - but those habits are starting to shift. As a result, that decision process is increasingly telling me I should say “no” to more requests.&lt;/p&gt;

&lt;p&gt;At the same time, I have a lot of anxiety about disappointing people or saying the wrong thing. Saying “no” feels like it is going to be disappointing. And coming up with the right thing to say can be a bit agonising - it’s not unusual for me to spend five minutes rewriting a “Sorry, this isn’t something I can help with right now” email. All that means that I sometimes end up saying “yes” when I don’t want to, because saying “no” burns up too much energy.&lt;/p&gt;

&lt;p&gt;A colleague brought this up at a dinner the other night and had come up with a great tactic: “We just have a list of standard ways to say “no” to meeting requests - and we pick one at random each time!” Simple, brilliant. Even if you don’t use the templated phrase exactly, you’re not starting with a blank page, so it’s much easier to get it done. I wanted that list too.&lt;/p&gt;

&lt;p&gt;In parallel, I’ve been experimenting with using LLM chatbots for more things at home to get a sense of where they can be helpful. Anthropic’s &lt;a href=&quot;https://claude.ai&quot;&gt;Claude&lt;/a&gt; Sonnet 3.7 is currently my default for anything complex that requires an online model. Asking Claude:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Come up with a phrase book for how to gently say “no” in various contexts at work. (Context: I’m a professional manager with [n] direct reports and about [n] people overall, and I’m in [country].) Include at least 40 phrases overall, all professional, and include a mix of “no”, “not now”, delegation and other scenarios.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;emitted a surprisingly useful list of 50 phrases in about five categories. That inspired some other categories, so a few more requests caused Claude to add some other categories and phrases. I printed a copy and put it next to my desk.&lt;/p&gt;

&lt;p&gt;A few days later, I was running an errand and got a question which was best delegated – but I didn’t have the list handy. I copied the list into Notes.app, but then thought that it’d be cute if it was a basic web app too. Fortunately, Claude is now really good at this too. I asked it:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Create a simple, plain Javascript web page based on the attached Markdown file, which prompts the user to select a list, and then shows a randomly-selected item from the list.&lt;/p&gt;

  &lt;p&gt;Items are grouped into lists under second-level headings (starting with “## “). Each list should be shown as a big button, with the name of the list appearing as the title on the button.&lt;/p&gt;

  &lt;p&gt;Lists are grouped into topics under first-level headings (starting with “# “). Each group should be shown as a box around the list buttons for that group, with the name of the group appearing in the top left of the box. Each group should have a different color, and the list buttons in that group are that color.&lt;/p&gt;

  &lt;p&gt;When the user presses a button, the app randomly selects one quote from that list, covers the page with a large, semi-transparent box, and prints the quote in large text in that box. The quote text should be large enough to easily read, but still all fit on one screen. Within that box, underneath the quote, two buttons appear: “Retry” and “Close”. If the user clicks “Retry”, the app selects a different quote from the same list, and updates the large quote text to that value. If the user clicks “Close”, the app removes the large quote box and returns to its original state.&lt;/p&gt;

  &lt;p&gt;The app should be entirely contained in no more than three files: an HTML file, a CSS file, and a JavaScript file.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The result was impressively functional - about 95% right in one shot. A few adjustments to the phrasing of the quotes, reorganising the categories to make them a little more consistent, and the layout of the CSS, and it was good enough to call &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;v0.1&lt;/code&gt;. I was really impressed at what Claude can churn out quickly – building this myself would realistically have taken a couple of hours, rather than the ~15 minutes it took using the LLM.&lt;/p&gt;

&lt;p&gt;You can play with the resulting app at &lt;a href=&quot;https://no.luckandskill.io&quot;&gt;no.luckandskill.io&lt;/a&gt;, and the code is available on &lt;a href=&quot;https://github.com/caelyx/no&quot;&gt;GitHub&lt;/a&gt;. I hope it helps lower the friction on saying “no”, so you can make more progress on the things that really need your attention.&lt;/p&gt;
</description>
        <pubDate>Sat, 08 Mar 2025 16:15:00 +1100</pubDate>
        <link>https://luckandskill.io/opinion/2025/03/08/getting-better-at-saying-no.html</link>
        <guid isPermaLink="true">https://luckandskill.io/opinion/2025/03/08/getting-better-at-saying-no.html</guid>
        
        <category>productivity</category>
        
        <category>generative-ai</category>
        
        <category>tools</category>
        
        
        <category>opinion</category>
        
      </item>
    
      <item>
	
          <title>→ NYT Opinion: America Isn’t Ready for What’s Coming</title>
	  
        <description>&lt;p&gt;&lt;a href=&quot;https://www.nytimes.com/2022/03/04/opinion/ive-dealt-with-foreign-cyberattacks-america-isnt-ready-for-whats-coming.html&quot;&gt;Glenn S. Gerstell writing in NYT Opinion&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Last week President Biden warned Mr. Putin against Russian cyberattacks on the United States’ critical infrastructure. But American businesses aren’t ready for a war in cyberspace. Although Mr. Biden designated the Department of Homeland Security to lead what he vowed would be a forceful response to any such aggression, this isn’t enough. The D.H.S. doesn’t have the legal authority to order the private sector to follow its lead. More broadly, the federal government, even if warned by companies like Microsoft of incoming cyberattacks, doesn’t have the necessary infrastructure in place to protect American businesses from many of these attacks.&lt;/p&gt;

  &lt;p&gt;That the United States has to resort to threats of retaliation is itself a problem. America should already be cyberattack-proof, but coordinating these efforts across the country has been an uphill battle.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;There’s much in this article that’s good – particularly the proposal to rationalise per-sector cyber regulation with a single, cross-sector cyber regulator. Simplifying the regulatory landscape would help US firms cut the complexity of understanding and complying with cyber obligations.&lt;/p&gt;

&lt;p&gt;That said, I’m somewhat bewildered at the absence of any mention of software quality from the piece. Nothing about enforceable minimum standards and requirements (e.g., 2FA on email services), or fines for critical vulnerabilities, or even removing software liability waivers. Software remains the only industry where you can sell a $1 bn of something to someone, and assert zero guarantee that it works or is fault-free, and everyone seems to be fine with that. It seems surreal that the problem could be so critical that the regulators should be unified and the private sector should have their cyber defences regulated, but that we would still do nothing to regulate the root cause issue: software vulnerability (code or configuration).&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The weekly reports of ransomware attacks and data breaches make it clear that we’re losing this battle.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is a common assertion, but there’s not much evidence for the claim. Since the early-2000s, there has been a constant battle with cybercrime, but the criminals are not &lt;em&gt;winning&lt;/em&gt;. Instead, there’s equilibrium point that moves as attackers and defenders each improve. The widespread adoption of cyber insurance moved that equilibrium point, making it more practical for criminals to attack companies (rather than just consumers). Attacks on companies for multi-million dollar ransoms are far more newsworthy than small-scale fraud, so public awareness has been easier to raise; that creates the impression that it’s bigger than before.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(Thanks to James for the prompt.)&lt;/em&gt;&lt;/p&gt;

</description>
        <pubDate>Sun, 06 Mar 2022 10:15:35 +1100</pubDate>
        <link>https://luckandskill.io/link/2022/03/06/nyt-opinion-america-isn-t-ready-for-what-s-coming.html</link>
        <guid isPermaLink="true">https://luckandskill.io/link/2022/03/06/nyt-opinion-america-isn-t-ready-for-what-s-coming.html</guid>
        
        <category>vulnerabilities</category>
        
        <category>regulation</category>
        
        <category>critical infrastructure</category>
        
        
        <category>link</category>
        
      </item>
    
      <item>
	
          <title>Sprinting a marathon: scaling vulnerability management</title>
	  
        <description>&lt;p&gt;If your patching teams are reporting that they’re exhausted, they’ve got good reason. If you haven’t already, it’s time to invest in automation – regression testing and continuous deployment – to help them cope.&lt;/p&gt;

&lt;p&gt;NIST publishes the &lt;a href=&quot;https://nvd.nist.gov/&quot;&gt;National Vulnerability Database&lt;/a&gt;, which provides a pretty good index of all known vulnerabilities. It counts vulnerabilities, each identified by a &lt;a href=&quot;https://cve.mitre.org/docs/docs-2000/cerias.html&quot;&gt;Common Vulnerabilities Enumeration&lt;/a&gt; (CVE) number.&lt;/p&gt;

&lt;p&gt;Over the last six months, NVD has recorded about 2,000 new vulnerabilities per month, including about 250 critical&lt;sup id=&quot;fnref:critical&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:critical&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; vulnerabilities per month (remote code execution, which might mean emergency patching).  That’s about &lt;strong&gt;12 new critical vulnerabilities per week day&lt;/strong&gt; and about 90 less-serious vulnerabilities. That’s a pretty high workload for a triage team, much less the patching teams.&lt;/p&gt;

&lt;style&gt;
th, td { padding-left: 15px; padding-right: 15px }
tr:nth-child(even) {background-color: #eeeeee; }
&lt;/style&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Month&lt;/th&gt;
      &lt;th style=&quot;text-align: right&quot;&gt;Critical CVEs&lt;/th&gt;
      &lt;th style=&quot;text-align: right&quot;&gt;Total CVEs&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;2021-08&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;252&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;2236&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2021-09&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;219&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;1917&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2021-10&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;202&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;1708&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2021-11&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;219&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;1610&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;2021-12&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;343&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;2400&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;That’s already not great, but the problem is intensifying. Here’s a graph&lt;sup id=&quot;fnref:graph-src&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:graph-src&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;2&lt;/a&gt;&lt;/sup&gt; of critical and total vulnerabilities published per year.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/2022-02-06-CVE-yearly.png&quot; alt=&quot;CVEs per year graph&quot; /&gt;
&lt;em&gt;Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/data-feeds&quot;&gt;NIST NVD Data&lt;/a&gt;; our analysis&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The trend line on critical vulnerabilities suggests this is going to get worse. Treat it as approximate&lt;sup id=&quot;fnref:trendline&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:trendline&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;, but it suggests that you should expect the number of critical vulnerabilities per year to increase by about ~250 per year. &lt;strong&gt;In 2022, we should expect nearly 3,000 critical vulnerabilities&lt;/strong&gt; to be released.&lt;/p&gt;

&lt;p&gt;So, how do you deal with this kind of volume?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Problem one: discovering that you’ve got something that needs patching&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;There are three useful capabilities here, in decreasing utility (and usefully decreasing cost):&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;A comprehensive inventory;&lt;/li&gt;
  &lt;li&gt;Vulnerability management (scanning) systems; and&lt;/li&gt;
  &lt;li&gt;Monitoring for advisories.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The ideal primary control is a comprehensive inventory of your estate. You could then check a daily extract of the NVD against that inventory, and create work tickets for every team that owns a newly-vulnerable component. In an ideal world, your CMDB is even automating this for you. That said, there’s pretty good chance that practitioners will have either scoffed or grumbled when I said “comprehensive inventory”; I’m not aware of an organisation that thinks it has solved this.&lt;/p&gt;

&lt;p&gt;Given that nobody fully trusts their inventory, many organisations augment it with scanning. Typically, this is implemented with a vulnerability management system. Network-based VMS are common, but these can struggle with reachability and completeness (particularly if scans aren’t authenticated). With the &lt;a href=&quot;/opinion/2022/01/06/2021-the-end-of-supply-chain-confidence.html&quot;&gt;increasing frequency and severity of library-level issues&lt;/a&gt;, it’s also worth augmenting your network VMS with something that’s keeping an eye on vulnerable libraries; one open source option is Anchore’s &lt;a href=&quot;https://github.com/anchore/grype/&quot;&gt;grype&lt;/a&gt;, which can scan container images and file systems.&lt;/p&gt;

&lt;p&gt;The third layer of detection is inexpensive but narrow: relying on your vendors telling you, whether that’s through predictable schedules (e.g., Microsoft Patch Tuesday) or mailing lists. That’s probably best thought of as only being for your most critical and/or widely deployed software, given that it’s unstructured data and difficult to scale.&lt;/p&gt;

&lt;p&gt;That said, those answers aren’t particularly satisfying. Hopefully, the state of the art in both automated inventories and vulnerability management will continue to improve completeness and granularity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Problem two: patching it&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Once you know you’ve got something to patch, the hard work begins.&lt;/p&gt;

&lt;p&gt;Patching teams typically struggle with the volume of required patching because patching processes are traditionally manual and involve a lot of analysis. A typical process might look like:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Triage team says a patch is available.&lt;/li&gt;
  &lt;li&gt;Analyse patch and perform criticality analysis. (“Do we need to patch this? How quickly?”)&lt;/li&gt;
  &lt;li&gt;Deploy patch to development/test environment.&lt;/li&gt;
  &lt;li&gt;Perform manual regression testing in dev/test environment.&lt;/li&gt;
  &lt;li&gt;Review regression test results; plan for production release.&lt;/li&gt;
  &lt;li&gt;Deploy patch to production environments.&lt;/li&gt;
  &lt;li&gt;Perform manual regression testing in production environment.&lt;/li&gt;
  &lt;li&gt;Monitor for performance impacts.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;We can make life easier for ourselves if we make two changes – one cultural, one technical.&lt;/p&gt;

&lt;p&gt;The cultural change sounds simple: don’t decide per patch, just patch everything, continuously. If we deploy every available patch, every month, we might have more patching failures but that is offset by freeing up significant time by no longer performing analysis. As a bonus, it also becomes much easier to stay in a supported state.&lt;/p&gt;

&lt;p&gt;The technical change requires some capex: automate regression testing and deployment. If you reduce the friction of patch deployment (and roll-backs when necessary), your ability to patch everything continuously dramatically improves.&lt;/p&gt;

&lt;p&gt;Those two go together: if you don’t have great regression testing, automatically patching can increase your &lt;a href=&quot;/opinion/2022/01/06/2021-the-end-of-supply-chain-confidence.html&quot;&gt;software supply chain risks&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;But where you can implement these two changes, the reward is a much simpler process:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Detect that patch is available (triage controls above).&lt;/li&gt;
  &lt;li&gt;Automated deployment of new version to development/test environment.&lt;/li&gt;
  &lt;li&gt;Automated regression test passes (or blocks the pipeline and generates an alarm).&lt;/li&gt;
  &lt;li&gt;Automated deployment of new version to production environments.&lt;/li&gt;
  &lt;li&gt;Monitor for performance impacts.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;You’re down to two manual processes – kicking off the process, and handling any exceptions.&lt;/p&gt;

&lt;p&gt;Migrating legacy applications to pipelines can be an expensive one-off change, but given the increasing number of vulnerabilities every year, it’s worth considering.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;My thanks to Cole for providing feedback which helped improve this post.&lt;/em&gt;&lt;/p&gt;

&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:critical&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;In those numbers, we have counted vulnerability as “critical” if it has a CVSSv3 severity of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CRITICAL&lt;/code&gt;; or a CVSSv2 base score of 10 if the record has no CVSSv3 score. Typically, those are remote code execution vulnerabilities – the patches you need to get implemented &lt;em&gt;right now&lt;/em&gt;, to stop a system compromise. &lt;a href=&quot;#fnref:critical&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:graph-src&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;The code to generate the graphs is &lt;a href=&quot;https://github.com/caelyx/CVE-Volumes&quot;&gt;here&lt;/a&gt;, if you’d like to tinker with it. &lt;a href=&quot;#fnref:graph-src&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:trendline&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;The linear regression has an R² value of only about 0.81. &lt;a href=&quot;#fnref:trendline&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</description>
        <pubDate>Sun, 06 Feb 2022 15:49:16 +1100</pubDate>
        <link>https://luckandskill.io/opinion/2022/02/06/sprinting-a-marathon-vulnerability-numbers-accelerating.html</link>
        <guid isPermaLink="true">https://luckandskill.io/opinion/2022/02/06/sprinting-a-marathon-vulnerability-numbers-accelerating.html</guid>
        
        <category>vulnerabilities</category>
        
        <category>software supply chain</category>
        
        
        <category>opinion</category>
        
      </item>
    
      <item>
	
          <title>→ White House Meeting on Software Security</title>
	  
        <description>&lt;p&gt;Following on from the &lt;a href=&quot;/link/2021/12/19/links.html&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; vulnerabilities&lt;/a&gt; of late last year, the White House held a meeting on software security with government, private sector and &lt;em&gt;open source&lt;/em&gt; representatives. (&lt;a href=&quot;https://twitter.com/caelyxsec/status/1481797611518857217&quot;&gt;I was wrong&lt;/a&gt;: they invited the Apache Software Foundation).&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.whitehouse.gov/briefing-room/statements-releases/2022/01/13/readout-of-white-house-meeting-on-software-security/&quot;&gt;readout provided by the White House&lt;/a&gt; sounds like the conversation was directionally positive, and developed a useful framework for how to proceed:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The discussion focused on three topics: Preventing security defects and vulnerabilities in code and open source packages, improving the process for finding defects and fixing them, and shortening the response time for distributing and implementing fixes.&lt;/p&gt;

  &lt;p&gt;In the first category, participants discussed ideas to make it easier for developers to write secure code by integrating security features into development tools and securing the infrastructure used to build, warehouse and distribute code, like using techniques such as code signing and stronger digital identities.&lt;/p&gt;

  &lt;p&gt;In the second category, participants discussed how to prioritize the most important open source projects and put in place sustainable mechanisms to maintain them.&lt;/p&gt;

  &lt;p&gt;In the final category, participants discussed ways to accelerate and improve the use of Software Bills of Material, as required in the President’s Executive Order, to make it easier to know what is in the software we purchase and use.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The participants from ApacheSF published their &lt;a href=&quot;https://cwiki.apache.org/confluence/display/COMDEV/Position+Paper&quot;&gt;Position Paper&lt;/a&gt; in the lead in to the conversation, which is interesting reading. The paper is cogent and worth reading.&lt;/p&gt;

&lt;p&gt;That said, it seems determined to perpetuate a “buyer beware” approach to software, which is isn’t great. It’s entirely understandable that an open source organisation like ASF can’t exactly offer a warranty for their software, but that same belief bleeds into commercial software and is one of the root causes of our global cyber problems.&lt;/p&gt;

&lt;p&gt;The other theme that comes through the paper is a frustration with how few &lt;em&gt;users&lt;/em&gt; of open source software then also become &lt;em&gt;contributors&lt;/em&gt; to open source (particularly large companies which rely on those components to generate revenue). This is a theme that seems to be burning quietly underground in a few parts of the community, occasionally appearing as spot fires, like &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/&quot;&gt;the deliberate corruption of two &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;npm&lt;/code&gt; libraries&lt;/a&gt; as a protest over a lack of funding. Here’s hoping that we’re on an inflection point around making open source more sustainable, this isn’t a sign that the great open source experiment isn’t on the precipice of a slow collapse.&lt;/p&gt;
</description>
        <pubDate>Sat, 15 Jan 2022 18:54:23 +1100</pubDate>
        <link>https://luckandskill.io/link/2022/01/15/readout-of-white-house-meeting-on-software-security.html</link>
        <guid isPermaLink="true">https://luckandskill.io/link/2022/01/15/readout-of-white-house-meeting-on-software-security.html</guid>
        
        <category>vulnerabilities</category>
        
        <category>software supply chain</category>
        
        <category>tools</category>
        
        
        <category>link</category>
        
      </item>
    
      <item>
	
          <title>Centralised decentralisation: blockchain&apos;s promises are hard to keep</title>
	  
        <description>&lt;p&gt;There has been a few great articles on the web3 movement and blockchain proponents recently, which draw out a couple of themes.&lt;/p&gt;

&lt;p&gt;Molly White’s &lt;a href=&quot;https://blog.mollywhite.net/blockchains-are-not-what-they-say/&quot;&gt;Blockchain-based systems are not what they say they are&lt;/a&gt; sets out a useful structure:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;If you go out seeking to learn from their proponents why blockchains and the systems built atop them are apparently the future of our web, you’ll begin to see some common themes. Two of the ones I see most frequently are:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;Decentralization: data in blockchains are distributed across innumerable servers run by innumerable people and organizations, rather than stored on servers controlled by one organization&lt;/li&gt;
    &lt;li&gt;Immutability: what is written to a blockchain cannot be changed or deleted, unlike more traditional databases
These fall apart under further scrutiny.&lt;/li&gt;
  &lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;The analysis that follows is cogent and clear, and leads to a conclusion that:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Blockchain technologies have somehow managed to land in the worst of both worlds—decentralized but not really, immutable but not really.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This aligns with Moxie Marlinspike’s &lt;a href=&quot;https://moxie.org/2022/01/07/web3-first-impressions.html&quot;&gt;“first impressions of web3”&lt;/a&gt;. He sets out a quick summary of web1 and web2, including two forces that shaped them:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;ol&gt;
    &lt;li&gt;People don’t want to run their own servers, and never will.&lt;/li&gt;
    &lt;li&gt;A protocol moves much more slowly than a platform.&lt;/li&gt;
  &lt;/ol&gt;
&lt;/blockquote&gt;

&lt;p&gt;He then explores how those forces are shaping web3’s reality. In a practical sense, the former means that most people access web3 through a small number of value-adding services — as a result, the lived experience isn’t the decentralised blockchain but the centralised service. Once that starts to happen, he argues, those central services become platforms which out-innovate the underlying decentralised protocol, meaning that the value consumers receive increasingly comes from the centralised services (and we’re back to a web2 world).&lt;/p&gt;

&lt;p&gt;The other common thread from both authors’ accounts is the tendency of web3 proponents to talk in the abstract. Moxie notes the tendency to focus on the future value of their systems, as a way of deflecting criticism about their current state, with the catch-cry “it’s early days still”. Molly observes a similar tendency to “switch between discussing the theoretical implementations […] and the ecosystems we have today as it suits their argument”. In both cases, those signals suggest that these systems are still bleeding edge, and best thought of as emerging.&lt;/p&gt;
</description>
        <pubDate>Sat, 15 Jan 2022 18:46:00 +1100</pubDate>
        <link>https://luckandskill.io/link/2022/01/15/centralised-decentralisation-blockchain-s-promises-are-hard-to-keep.html</link>
        <guid isPermaLink="true">https://luckandskill.io/link/2022/01/15/centralised-decentralisation-blockchain-s-promises-are-hard-to-keep.html</guid>
        
        <category>blockchain</category>
        
        <category>web3</category>
        
        <category>encryption</category>
        
        
        <category>link</category>
        
      </item>
    
      <item>
	
          <title>2021: The end of software supply chain confidence</title>
	  
        <description>&lt;p&gt;Human brains love heuristics and assumptions. Thinking about everything, all at once, is exhausting (see &lt;a href=&quot;https://en.wikipedia.org/wiki/Thinking,_Fast_and_Slow&quot;&gt;Kahneman&lt;/a&gt;’s System 1 vs System 2). So we use assumptions to simplify the problem space to something we can manage.&lt;/p&gt;

&lt;p&gt;Cyber is full of humans, and so has plenty of these assumptions too. And a common assumption is that &lt;strong&gt;the security of the software supply chain is good &lt;em&gt;enough&lt;/em&gt;&lt;/strong&gt;. Not great, but okay. Certainly, it’s a lesser evil than known vulnerabilities, hence the frequent mantra to turn on automatic updates everywhere you can.&lt;/p&gt;

&lt;p&gt;Unfortunately, 2021 was the year when that assumption really came under pressure — the software supply chain is under active attack, from a motivated and broadening set of adversaries. So cyber people now need to adjust our approach to defending our organisations. Let’s talk about those attacks, and then about some adjustments to defences.&lt;/p&gt;

&lt;!--more--&gt;

&lt;h2 id=&quot;mainstream-software-supply-chain-attacks&quot;&gt;Mainstream software supply chain attacks&lt;/h2&gt;

&lt;p&gt;There have been rumours (e.g., &lt;a href=&quot;https://www.nytimes.com/2008/05/09/business/worldbusiness/09iht-cisco.4.12745413.html&quot;&gt;one&lt;/a&gt;, &lt;a href=&quot;https://en.wikipedia.org/wiki/NSA_ANT_catalog&quot;&gt;two&lt;/a&gt;, &lt;a href=&quot;https://www.bloomberg.com/news/features/2018-10-04/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies&quot;&gt;three&lt;/a&gt;) for years of supply chain attacks, particularly against hardware. Typically, though, this was nation-state-on-nation-state stuff — industrial spying, making use of the ability to subvert manufacturers or redirect shipping.&lt;/p&gt;

&lt;p&gt;2021 opened, though, with a massive software supply chain attack. An adversary allegedly compromised the software development systems of SolarWinds, placing malicious code into the source of their Orion product, and pushing it out through their legitimate software update mechanism. As organisations dutifully updated to the latest (compromised) version, the malicious code was installed. From there, the attacker targeted some particular organisations of interest (&lt;a href=&quot;https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach&quot;&gt;Wikipedia&lt;/a&gt;), and executed broad-ranging campaigns of lateral movement to gain access to systems and data of interest (&lt;a href=&quot;https://www.justice.gov/opcl/department-justice-statement-intrusion-department-s-microsoft-o365-email-environment&quot;&gt;for example&lt;/a&gt;).  The collateral impact was significant — lots of large organisations use the affected product, and had to rapidly undertake incident response and digital forensics to work out if they were affected, and to clean up and patch.&lt;/p&gt;

&lt;p&gt;So, we now had malware distributed through a trusted commercial software product.&lt;/p&gt;

&lt;p&gt;2021 continued with a criminal (as opposed to nation state) attack on Kaseya (&lt;a href=&quot;https://en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack&quot;&gt;Wikipedia&lt;/a&gt;). Kaseya provides a cloud service that helps organisations manage their endpoints&lt;sup id=&quot;fnref:endpoint&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:endpoint&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;, including software distribution and patching.  For some subset of Kaseya’s customers, the attackers then allegedly used their access to install ransomware into those customers’ computers, taking them over and demanding payment to restore access. They also offered a sort of bulk discount: for a much larger amount they would provide a key that would restore access for all the affected organisations.  Ultimately, that bulk key was made available (&lt;a href=&quot;https://www.bbc.com/news/technology-57946117&quot;&gt;BBC&lt;/a&gt;), although Kaseya has &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/kaseya-obtains-universal-decryptor-for-revil-ransomware-victims/&quot;&gt;declined to comment on whether a ransom was paid&lt;/a&gt;.&lt;sup id=&quot;fnref:insurers&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:insurers&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;So, we now had malware distributed through a trusted IT management service.&lt;/p&gt;

&lt;p&gt;Third, there’s been an increasing set of attacks on open source components that are commonly incorporated into software.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Malicious commits&lt;/strong&gt; – An attacker &lt;a href=&quot;https://arstechnica.com/gadgets/2021/03/hackers-backdoor-php-source-code-after-breaching-internal-git-server/&quot;&gt;attempted to compromise the PHP language interpreter&lt;/a&gt;, by attacking the PHP core team’s software repository. While it was detected and blocked, if successful this could have provided a backdoor into lots of internet-facing systems, once they were updated.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Maintainer account takeover&lt;/strong&gt; – In perhaps the most direct attacks, some attackers are targeting maintainers of common packages directly. If an attacker can gain access to these accounts, they may be able to push malware through the same Continuous Integration/Continuous Distribution (CI/CD) and build mechanisms. A good example of this was &lt;a href=&quot;https://github.com/advisories/GHSA-pjwm-rvh2-c87w&quot;&gt;the attack on the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ua-parser-js&lt;/code&gt; library&lt;/a&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;npm&lt;/code&gt;, through &lt;a href=&quot;https://github.com/faisalman/ua-parser-js/issues/536#issuecomment-949742904&quot;&gt;an attack on the maintainer&lt;/a&gt; by compromising his account.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Dependency confusion&lt;/strong&gt; – Alex Birsan &lt;a href=&quot;https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610&quot;&gt;published a Medium article&lt;/a&gt; showing that they were able to inject arbitrary code into several organisations’ proprietary software. The attack relied on registering targeted, public versions of private libraries with higher version numbers. Many modern organisations use CI/CD pipelines to automatically build, test and deploy their applications, and these often pull down new versions of libraries as part of each build — because the rules about what to download and incorporate were insufficiently specific, they could be tricked into downloading and using a malicious version instead of the intended one.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So, we now have malware being distributed through open source components – whether that’s at the source, by compromise of the legitimate library, or through dependency confusion.&lt;/p&gt;

&lt;p&gt;Finally, the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; incidents at the end of 2021 were an extraordinary way to wrap the year. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; is a common library for logging (a common task) in Java (a common language). It was also commonly incorporated into other software components and frameworks (e.g. &lt;a href=&quot;https://struts.apache.org/announce-2021#a20211212-2&quot;&gt;Struts&lt;/a&gt;); one &lt;a href=&quot;https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html&quot;&gt;Google analysis&lt;/a&gt; found it was included in 4% of the libraries in Maven, at an average of five layers deep.  As a result, it was incorporated in lots of software — both commercial products and proprietary code. Vendors as big as &lt;a href=&quot;https://www.vmware.com/security/advisories/VMSA-2021-0028.html&quot;&gt;VMWare&lt;/a&gt;, &lt;a href=&quot;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd&quot;&gt;Cisco&lt;/a&gt; and &lt;a href=&quot;https://forums.ivanti.com/s/article/Security-Bulletin-CVE-2021-44228-Remote-code-injection-in-Log4j?language=en_US&quot;&gt;MobileIron&lt;/a&gt; issued emergency patches or workarounds; the &lt;a href=&quot;https://github.com/NCSC-NL/log4shell/blob/main/software/README.md&quot;&gt;NCSC-NL started maintaining a list&lt;/a&gt; of all the known vulnerable and not-vulnerable products, as did &lt;a href=&quot;https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md&quot;&gt;US CISA&lt;/a&gt; and &lt;a href=&quot;https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/&quot;&gt;Royce Williams&lt;/a&gt;. Every cyber and IT team jumped in to find and crash-patch everything they had.&lt;/p&gt;

&lt;p&gt;So, this was a useful demonstration of how much open source there is in commercial software products, even though that’s typically opaque to the customer.&lt;/p&gt;

&lt;p&gt;What do we draw from all this? In 2021 we had malware distributed through:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;trusted commercial software products.&lt;/li&gt;
  &lt;li&gt;trusted management services.&lt;/li&gt;
  &lt;li&gt;trusted open source components.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And we had a sharp reminder about how much we don’t know about what’s embedded in commercial software.&lt;/p&gt;

&lt;p&gt;So, it’s no longer credible to assume that the software you’re getting from others is safe or trusted. (If it ever was.)&lt;/p&gt;

&lt;h2 id=&quot;now-what&quot;&gt;Now what?&lt;/h2&gt;

&lt;p&gt;There’s a lot of talk about “assumed breach” in the cyber community. Usually, that means assuming that attackers have gained access to some accounts or installed some malware, and being constantly vigilant.&lt;/p&gt;

&lt;p&gt;If you haven’t already, it’s probably time to move  a step further: to “assumed compromise” in software and software components – whether commercial or open source.&lt;/p&gt;

&lt;p&gt;As much as that’s a big challenge technically, it’s an even larger cultural change, particularly among your developers and IT ops people.  Developers are implicitly taught to trust software libraries, and are often under time pressure to ship features as quickly as possible. IT ops people are taught to trust commercial software and services.  Turning this around is going to require concerted effort. Particularly in re-setting the “speed vs safety” trade-off in software development.&lt;/p&gt;

&lt;p&gt;Beyond the cultural element, here are three suggestions for what you can do right now to improve your position:&lt;/p&gt;

&lt;p&gt;First – focus on implementing/strengthening the fundamental controls that reduce the impact of software vulnerability. By “fundamental”, I mean those things which are continuously active and are attack-independent (i.e. don’t have known-bad lists or “signatures” of any form). Perhaps the best hardening-per-dollar is egress filtering on all your systems particularly internet-facing applications, but work your way back through the rest of your systems too. If a system doesn’t &lt;em&gt;need&lt;/em&gt; to be able to initiate outbound connections, don’t let it; and if it does, limit it to only those required. If your SolarWinds Orion instance can’t respond to an attacker’s request, you had extra time to patch it; if your application using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; can’t resolve DNS or reach out to an external LDAP system, you’ve got extra time to patch it.&lt;/p&gt;

&lt;p&gt;Second – get clear on what software components you’re incorporating in your software, and build automated telemetry that tells you what’s used where. That might mean instrumenting your CI/CD pipelines to record what libraries are downloaded and ensuring that the version rules are written defensively. If you’re still using manual or local builds, now is the right time to move that to a CI/CD pipeline, to build up that central visibility and control.&lt;/p&gt;

&lt;p&gt;Third – start moving toward being able to patch everything you have within 24 hours. Yes, everything. Yes, 24 hours. Yes, that’s a huge, expensive sentence, perhaps to the point of being impractical for most organisations. But that’s where the attackers are driving us. Two things go into that:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Ensure everything you have is actively maintained, and that you can deploy upgrades. Does every application and system have a working deployment process, that can be activated on demand? While that’s almost certainly true for your critical and modern systems, it also needs to extend to all the user-developed applications, the apps that the business bought a decade ago without telling IT, and so on.&lt;/li&gt;
  &lt;li&gt;Wherever possible, automate that deployment, &lt;em&gt;including regression testing&lt;/em&gt;. The faster, easier, and more reliable it is to upgrade, the more likely you are to be able to confidently upgrade in the face of a vulnerability, rather than having to do risk-reward calculus under stress. Again, now is a great time to migrate everything you can to pipelines.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;More generally, use your purchasing power to help improve things for everyone. &lt;em&gt;Reach out to your vendors and ask them what they’re doing.&lt;/em&gt; When will they provide a software bill of materials for the products you use, so that you know what’s in them? What are they doing to strengthen the security around their code repositories, and their build and distribution mechanisms? Have they got two-factor authentication in place for all their employee access to those systems? What quality tests are they putting in place to ensure their software isn’t subverted? And how are they contributing back to improving the security of the open source components they rely on?&lt;/p&gt;

&lt;p&gt;2021 was the year the software supply chain security assumption was invalidated; the urgent work of 2022 is building resilience against it.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;My thanks to Jordan and James for reading and providing feedback on the draft of this post.&lt;/em&gt;&lt;/p&gt;
&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:endpoint&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;Endpoints: servers, desktops, laptops, etc. &lt;a href=&quot;#fnref:endpoint&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
    &lt;li id=&quot;fn:insurers&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;For the sake of staying on topic, I’m not going to comment here on the interaction between cyber insurance and ransomware, but it would seem to be a factor. &lt;a href=&quot;#fnref:insurers&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</description>
        <pubDate>Thu, 06 Jan 2022 00:00:00 +1100</pubDate>
        <link>https://luckandskill.io/opinion/2022/01/06/2021-the-end-of-supply-chain-confidence.html</link>
        <guid isPermaLink="true">https://luckandskill.io/opinion/2022/01/06/2021-the-end-of-supply-chain-confidence.html</guid>
        
        <category>strategy</category>
        
        <category>vulnerabilities</category>
        
        <category>software supply chain</category>
        
        
        <category>opinion</category>
        
      </item>
    
      <item>
	
          <title>More log4j vulnerability links</title>
	  
        <description>&lt;!--more--&gt;

&lt;p&gt;A few more links:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Akamai’s security team &lt;a href=&quot;https://www.akamai.com/blog/security/threat-intelligence-on-log4j-cve-key-findings-and-their-implications#.YcHHLN2wkDg.twitter&quot;&gt;published some interesting analysis&lt;/a&gt; of the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; related traffics they’re seeing across their networks. Figure 1 is titled “A mild start, then a global tsunami of malicious activity”, which seems to capture the mood.&lt;/li&gt;
  &lt;li&gt;ZDNet has &lt;a href=&quot;https://www.zdnet.com/article/log4j-flaw-10-questions-you-should-be-asking/#ftag=RSSbaffb68&quot;&gt;a good primer&lt;/a&gt; for people just catching up, anchored around the &lt;a href=&quot;https://www.ncsc.gov.uk/blog-post/log4j-vulnerability-what-should-boards-be-asking&quot;&gt;UK NCSC advice to boards&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Cisco Talos has a good &lt;a href=&quot;https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html&quot;&gt;omnibus page&lt;/a&gt; with lots of useful content. Their &lt;a href=&quot;https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html#mitigations&quot;&gt;current guidance&lt;/a&gt; section is a useful summary of the three vulnerabilities and what the patches do to resolve them, and they also share &lt;a href=&quot;https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html#exploitactivity&quot;&gt;examples of exploitation activity&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;The &lt;a href=&quot;https://www.zdnet.com/article/belgian-defense-ministry-confirms-cyberattack-through-log4j-exploitation/&quot;&gt;Belgian Defence Ministry&lt;/a&gt;  has announced that they were affected by an attack using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt;. &lt;a href=&quot;https://www.zdnet.com/article/belgian-defense-ministry-confirms-cyberattack-through-log4j-exploitation/&quot;&gt;Original article&lt;/a&gt;, &lt;a href=&quot;https://www-standaard-be.translate.goog/cnt/dmf20211220_92316559?_x_tr_sl=auto&amp;amp;_x_tr_tl=en&amp;amp;_x_tr_hl=en-GB&quot;&gt;Google Translation&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/log4j-vulnerability-now-used-to-install-dridex-banking-malware/&quot;&gt;Reports&lt;/a&gt; of an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;RMI&lt;/code&gt; exploit being used to download Dridex.&lt;/li&gt;
&lt;/ul&gt;
</description>
        <pubDate>Tue, 21 Dec 2021 23:27:00 +1100</pubDate>
        <link>https://luckandskill.io/link/2021/12/21/more-log4j.html</link>
        <guid isPermaLink="true">https://luckandskill.io/link/2021/12/21/more-log4j.html</guid>
        
        <category>vulnerabilities</category>
        
        <category>attacks</category>
        
        
        <category>link</category>
        
      </item>
    
      <item>
	
          <title>log4j vulnerability links, plus some interesting tools</title>
	  
        <description>&lt;p&gt;In dealing with the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; problem, some links that turned up in searching or that others shared.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Anchore’s &lt;a href=&quot;https://github.com/anchore/grype/&quot;&gt;grype&lt;/a&gt; scans container images, JAR files, etc for known-vulnerable versions of Java packages (among other things). They also have &lt;a href=&quot;https://github.com/anchore/syft&quot;&gt;syft&lt;/a&gt; which generates software bill of materials (SBOM) reports. (Hat tip to the ACSC for pointing to the latter.)&lt;/li&gt;
  &lt;li&gt;Google’s security team has published &lt;a href=&quot;https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html&quot;&gt;an interesting article&lt;/a&gt; assessing the breadth of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log4j&lt;/code&gt; usage in other packages, including the complexity of transitive dependencies: “For greater than 80% of the packages, the vulnerability is more than one level deep, with a majority affected five levels down (and some as many as nine levels down).”&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://lgtm.com/projects/g/apache/logging-log4j2/alerts/?mode=list&amp;amp;id=java%2Fjndi-injection&quot;&gt;This LGTM report&lt;/a&gt; suggests Apache log4j 2.17 might still have some JNDI things to check.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://log4shell.huntress.com/&quot;&gt;Huntress log4j tester&lt;/a&gt; might be useful for quickly checking your own internet-facing systems.&lt;/li&gt;
  &lt;li&gt;@nathanqthai at &lt;a href=&quot;https://www.greynoise.io/&quot;&gt;Grey Noise Intelligence&lt;/a&gt; has &lt;a href=&quot;https://gist.github.com/nathanqthai/197b6084a05690fdebf96ed34ae84305&quot;&gt;published examples&lt;/a&gt; of attempted exploitation of the log4j vulnerability in the wild&lt;/li&gt;
  &lt;li&gt;AWS is apparently &lt;a href=&quot;https://github.com/corretto/hotpatch-for-apache-log4j2&quot;&gt;hotpatching their services&lt;/a&gt;, with coverage in &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/AWS-2021-006/&quot;&gt;this advisory&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;CyberCX NZ has a &lt;a href=&quot;https://blog.cybercx.co.nz/log4j-critical-vulnerability-cve-2021-44228-planning-for-the-holidays&quot;&gt;useful article&lt;/a&gt; with suggestions for how to handle the remaining marathon on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2021-44228&lt;/code&gt; without burning people out.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Some other security resources:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://cvetrends.com/&quot;&gt;CVE Trends&lt;/a&gt; is a quick dashboard of which CVEs people are talking about on Twitter.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/cisagov/crossfeed&quot;&gt;CISA Crossfeed&lt;/a&gt; is an open source external VMS/attack surface enumerator.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/OWASP/Amass&quot;&gt;OWASP Amass&lt;/a&gt; is also for enumerating attack surface.&lt;/li&gt;
  &lt;li&gt;Rapid7 &lt;a href=&quot;https://www.rapid7.com/research/project-sonar/&quot;&gt;Project Sonar&lt;/a&gt; is scanning the internet and making the data available &lt;a href=&quot;https://opendata.rapid7.com&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/projectdiscovery/nuclei&quot;&gt;Nuclei&lt;/a&gt; does non-invasive vulnerability testing.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://getgophish.com&quot;&gt;GoPhish&lt;/a&gt; is an open source phishing simulation system. CISA has some &lt;a href=&quot;https://github.com/cisagov/gophish-tools&quot;&gt;tools for working with it&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.google.com/presentation/d/165aynAErTyYdymaoqwBuguVXJNia3CdqYSZiL6RJMPM/edit#slide=id.gd3ffd1da6a_0_124&quot;&gt;This presentation&lt;/a&gt; is a useful intro to Velociraptor, an endpoint DFIR tool.&lt;/li&gt;
  &lt;li&gt;Microsoft provides &lt;a href=&quot;https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/&quot;&gt;free, time-limited virtual machines&lt;/a&gt; containing Microsoft Windows and Edge/IE11 for testing.&lt;/li&gt;
&lt;/ul&gt;
</description>
        <pubDate>Sun, 19 Dec 2021 11:03:00 +1100</pubDate>
        <link>https://luckandskill.io/link/2021/12/19/links.html</link>
        <guid isPermaLink="true">https://luckandskill.io/link/2021/12/19/links.html</guid>
        
        <category>vulnerabilities</category>
        
        <category>software supply chain</category>
        
        <category>tools</category>
        
        
        <category>link</category>
        
      </item>
    
      <item>
	
          <title>RSA Conference vendors — 2014 vs 2016</title>
	  
        <description>&lt;p&gt;The security market is changing, and quickly. Each year, the RSA Conference hosts tens of thousands of delegates and hundreds of security vendors. In a conversation yesterday, John Stewart suggested that it might be an interesting idea to look at how the vendor population had changed over time, to get a sense for how the security market was moving.&lt;/p&gt;

&lt;p&gt;To that end, the exhibitor lists are available online: &lt;a href=&quot;http://www.rsaconference.com/events/us14/exhibitors-sponsors/exhibitor-list&quot;&gt;2014&lt;/a&gt;, &lt;a href=&quot;http://www.rsaconference.com/events/us16/expo-sponsors/exhibitor-list&quot;&gt;2016&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I’ve run a diff between the two years, and manually cleaned up duplicates that weren’t exact matches (e.g. where an ‘Inc.’ suffix had been added or removed). There may, therefore, be some errors in the data; corrections welcome to the email address in the footer.&lt;/p&gt;

&lt;p&gt;That left 151 companies that were exhibitors in 2014, who were not present in 2016. Astonishingly, 307 companies exhibiting in 2016 were not present in 2014. The full lists are below.&lt;/p&gt;

&lt;p&gt;Some interesting research possibilities:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;What happened to the companies that left? Are they still around, and just not exhibiting? Were they acquired (e.g. Trusteer)? How many folded, and why?&lt;/li&gt;
  &lt;li&gt;How do the removed and new companies fit into a capability map of the security market? Can we infer useful market trends from the overall movements? Does this data help us start to model how consolidation within a category behaves, or when a category is likely to become an acquisition target by the security conglomerates?&lt;/li&gt;
  &lt;li&gt;The underlying data also includes each stand location – from this, we could probably infer some signal about stand cost (e.g. the very outer edge is cheapest, and the price goes up as you move inward). It would be interesting to see the migration patterns for companies year-on-year, and whether this was correlated with anything interesting (e.g. revenue). It feels like there would be a cool chart in here.&lt;/li&gt;
  &lt;li&gt;Can we infer anything interesting from the intersection of the two above? e.g. does a series of new companies in the same category appearing in the outer edge in one year indicate that a smaller number will make it into the next inward ring next year? Once a company moves outward, how likely is it to be able to recover?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Happy to contribute to a paper if anyone is interested.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Present in 2014, missing in 2016.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;10ZIG Technology Inc.&lt;/li&gt;
  &lt;li&gt;21CT, Inc.&lt;/li&gt;
  &lt;li&gt;3M Privacy Solutions&lt;/li&gt;
  &lt;li&gt;6WIND&lt;/li&gt;
  &lt;li&gt;AFORE&lt;/li&gt;
  &lt;li&gt;Accellion&lt;/li&gt;
  &lt;li&gt;AccessData&lt;/li&gt;
  &lt;li&gt;Accuvant&lt;/li&gt;
  &lt;li&gt;Adallom&lt;/li&gt;
  &lt;li&gt;Agiliance&lt;/li&gt;
  &lt;li&gt;AhnLab&lt;/li&gt;
  &lt;li&gt;AirWatch&lt;/li&gt;
  &lt;li&gt;AlephCloud&lt;/li&gt;
  &lt;li&gt;Alert Logic&lt;/li&gt;
  &lt;li&gt;AlertEnterprise&lt;/li&gt;
  &lt;li&gt;AppRiver&lt;/li&gt;
  &lt;li&gt;Attachmate&lt;/li&gt;
  &lt;li&gt;Authentify&lt;/li&gt;
  &lt;li&gt;Axway, Inc.&lt;/li&gt;
  &lt;li&gt;Barracuda Networks&lt;/li&gt;
  &lt;li&gt;Beijing Zhongguancun Overseas Science Park&lt;/li&gt;
  &lt;li&gt;Bit9, Inc.&lt;/li&gt;
  &lt;li&gt;Black Lotus&lt;/li&gt;
  &lt;li&gt;BlueCat&lt;/li&gt;
  &lt;li&gt;Brainloop&lt;/li&gt;
  &lt;li&gt;CHERRY&lt;/li&gt;
  &lt;li&gt;CORISECIO GmbH&lt;/li&gt;
  &lt;li&gt;CSG Invotas&lt;/li&gt;
  &lt;li&gt;Celestix&lt;/li&gt;
  &lt;li&gt;Champlain College&lt;/li&gt;
  &lt;li&gt;Click Security&lt;/li&gt;
  &lt;li&gt;Collective Software&lt;/li&gt;
  &lt;li&gt;Coverity, Inc.&lt;/li&gt;
  &lt;li&gt;Covertix Ltd.&lt;/li&gt;
  &lt;li&gt;Cryptography Research, Inc.&lt;/li&gt;
  &lt;li&gt;Cryptomathic&lt;/li&gt;
  &lt;li&gt;CyFIR&lt;/li&gt;
  &lt;li&gt;Cyberoam Inc.&lt;/li&gt;
  &lt;li&gt;Cyvera Ltd&lt;/li&gt;
  &lt;li&gt;DBAPP Security&lt;/li&gt;
  &lt;li&gt;DaoliCloud Information Technology (Beijing) Co., LTD.&lt;/li&gt;
  &lt;li&gt;Defence Intelligence&lt;/li&gt;
  &lt;li&gt;Deja vu Security&lt;/li&gt;
  &lt;li&gt;DeviceLock&lt;/li&gt;
  &lt;li&gt;DynamiCode Company Limited&lt;/li&gt;
  &lt;li&gt;Emerging Threats&lt;/li&gt;
  &lt;li&gt;Endace Division of Emulex&lt;/li&gt;
  &lt;li&gt;Enforcive&lt;/li&gt;
  &lt;li&gt;Fiberlink&lt;/li&gt;
  &lt;li&gt;FileTrek&lt;/li&gt;
  &lt;li&gt;Fox Technologies, Inc.&lt;/li&gt;
  &lt;li&gt;Freescale&lt;/li&gt;
  &lt;li&gt;Glimmerglass Optical Cyber Solutions&lt;/li&gt;
  &lt;li&gt;GreenSQL.com&lt;/li&gt;
  &lt;li&gt;Guardian Analytics&lt;/li&gt;
  &lt;li&gt;HBGary&lt;/li&gt;
  &lt;li&gt;Halon Security, Inc.&lt;/li&gt;
  &lt;li&gt;Heshengda Information Security Technology Co., Ltd&lt;/li&gt;
  &lt;li&gt;HitmanPro&lt;/li&gt;
  &lt;li&gt;InfoExpress, Inc.&lt;/li&gt;
  &lt;li&gt;Information Security Media Group (ISMG)&lt;/li&gt;
  &lt;li&gt;Intellicus&lt;/li&gt;
  &lt;li&gt;Ionic&lt;/li&gt;
  &lt;li&gt;Ipswitch File Transfer&lt;/li&gt;
  &lt;li&gt;IronKey&lt;/li&gt;
  &lt;li&gt;KS Mobile&lt;/li&gt;
  &lt;li&gt;Key Source International&lt;/li&gt;
  &lt;li&gt;Klocwork&lt;/li&gt;
  &lt;li&gt;LOGbinder&lt;/li&gt;
  &lt;li&gt;Link11&lt;/li&gt;
  &lt;li&gt;Lumension&lt;/li&gt;
  &lt;li&gt;LynuxWorks, Inc.&lt;/li&gt;
  &lt;li&gt;MITRE&lt;/li&gt;
  &lt;li&gt;Malcovery Security&lt;/li&gt;
  &lt;li&gt;Marble Security&lt;/li&gt;
  &lt;li&gt;Metaforic&lt;/li&gt;
  &lt;li&gt;MicroStrategy&lt;/li&gt;
  &lt;li&gt;MirageWorks&lt;/li&gt;
  &lt;li&gt;Mocana&lt;/li&gt;
  &lt;li&gt;Modulo&lt;/li&gt;
  &lt;li&gt;Mycroft Inc.&lt;/li&gt;
  &lt;li&gt;NSA&lt;/li&gt;
  &lt;li&gt;NagraID Security&lt;/li&gt;
  &lt;li&gt;Nallatech Inc.&lt;/li&gt;
  &lt;li&gt;Narus, Inc.&lt;/li&gt;
  &lt;li&gt;National Institute of Standards and Technology&lt;/li&gt;
  &lt;li&gt;Net Optics, Inc.&lt;/li&gt;
  &lt;li&gt;NetCitadel&lt;/li&gt;
  &lt;li&gt;NetIQ&lt;/li&gt;
  &lt;li&gt;NetScout&lt;/li&gt;
  &lt;li&gt;New Horizons Computer Learning Centers&lt;/li&gt;
  &lt;li&gt;Norman Shark&lt;/li&gt;
  &lt;li&gt;Northrop Grumman&lt;/li&gt;
  &lt;li&gt;Oberthur Technologies&lt;/li&gt;
  &lt;li&gt;One World Labs, Inc.&lt;/li&gt;
  &lt;li&gt;PORTCULLIS&lt;/li&gt;
  &lt;li&gt;Paraben Corporation&lt;/li&gt;
  &lt;li&gt;PerspecSys Inc.&lt;/li&gt;
  &lt;li&gt;Phoenix TS&lt;/li&gt;
  &lt;li&gt;Pike Enterprises, Inc.&lt;/li&gt;
  &lt;li&gt;Portnox&lt;/li&gt;
  &lt;li&gt;PrivateCore&lt;/li&gt;
  &lt;li&gt;Procera Networks&lt;/li&gt;
  &lt;li&gt;Protected-networks.com GmbH&lt;/li&gt;
  &lt;li&gt;QIHU Technology Co., Ltd.&lt;/li&gt;
  &lt;li&gt;Quotium&lt;/li&gt;
  &lt;li&gt;Riscure North America&lt;/li&gt;
  &lt;li&gt;Riverbed Technology&lt;/li&gt;
  &lt;li&gt;SYSMATE&lt;/li&gt;
  &lt;li&gt;SafeNet, Inc.&lt;/li&gt;
  &lt;li&gt;Seccuris USA Inc.&lt;/li&gt;
  &lt;li&gt;Seculert&lt;/li&gt;
  &lt;li&gt;Secunia&lt;/li&gt;
  &lt;li&gt;Secure Access Technologies, Inc.&lt;/li&gt;
  &lt;li&gt;Shape Security&lt;/li&gt;
  &lt;li&gt;SilverSky&lt;/li&gt;
  &lt;li&gt;Sims Recycling Solutions&lt;/li&gt;
  &lt;li&gt;SmartDisplayer Technology&lt;/li&gt;
  &lt;li&gt;SnoopWall&lt;/li&gt;
  &lt;li&gt;Software Diversified Services&lt;/li&gt;
  &lt;li&gt;SolarWinds&lt;/li&gt;
  &lt;li&gt;Solutionary&lt;/li&gt;
  &lt;li&gt;Soonr&lt;/li&gt;
  &lt;li&gt;Sourcefire&lt;/li&gt;
  &lt;li&gt;SpectorSoft Corporation&lt;/li&gt;
  &lt;li&gt;StrikeForce Technologies, Inc.&lt;/li&gt;
  &lt;li&gt;Symplified&lt;/li&gt;
  &lt;li&gt;Sypris&lt;/li&gt;
  &lt;li&gt;TIBCO Software&lt;/li&gt;
  &lt;li&gt;TalariaX sendQuick&lt;/li&gt;
  &lt;li&gt;The Hacker Academy&lt;/li&gt;
  &lt;li&gt;Threat Stack&lt;/li&gt;
  &lt;li&gt;ThreatSim&lt;/li&gt;
  &lt;li&gt;ThreatTrack Security&lt;/li&gt;
  &lt;li&gt;Tilera Corporation&lt;/li&gt;
  &lt;li&gt;TrulyProtect&lt;/li&gt;
  &lt;li&gt;Trusteer, an IBM Company&lt;/li&gt;
  &lt;li&gt;Unisys&lt;/li&gt;
  &lt;li&gt;Venustech Cybervision Co., Ltd&lt;/li&gt;
  &lt;li&gt;Verdasys, Inc.&lt;/li&gt;
  &lt;li&gt;Viewfinity&lt;/li&gt;
  &lt;li&gt;Visible Statement&lt;/li&gt;
  &lt;li&gt;Voltage Security&lt;/li&gt;
  &lt;li&gt;WWPass Corporation&lt;/li&gt;
  &lt;li&gt;Watchdata Technologies&lt;/li&gt;
  &lt;li&gt;Wave Systems Corp.&lt;/li&gt;
  &lt;li&gt;Websense&lt;/li&gt;
  &lt;li&gt;Wontok&lt;/li&gt;
  &lt;li&gt;Xceedium, Inc.&lt;/li&gt;
  &lt;li&gt;itWatch&lt;/li&gt;
  &lt;li&gt;nPulse Technologies&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Present in 2016, but not present in 2014.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;2FA&lt;/li&gt;
  &lt;li&gt;360 Total Security&lt;/li&gt;
  &lt;li&gt;5nine Software&lt;/li&gt;
  &lt;li&gt;A10 Networks&lt;/li&gt;
  &lt;li&gt;ADLINK Technology&lt;/li&gt;
  &lt;li&gt;AHA Products Group&lt;/li&gt;
  &lt;li&gt;Abatis (UK) Ltd&lt;/li&gt;
  &lt;li&gt;Absolute&lt;/li&gt;
  &lt;li&gt;Acunetix&lt;/li&gt;
  &lt;li&gt;Agari&lt;/li&gt;
  &lt;li&gt;Ahope&lt;/li&gt;
  &lt;li&gt;AirCUVE&lt;/li&gt;
  &lt;li&gt;Allot Communications&lt;/li&gt;
  &lt;li&gt;AppViewX&lt;/li&gt;
  &lt;li&gt;Area 1 Security&lt;/li&gt;
  &lt;li&gt;Arellia&lt;/li&gt;
  &lt;li&gt;Artifex Software Inc.&lt;/li&gt;
  &lt;li&gt;Attivo Networks&lt;/li&gt;
  &lt;li&gt;Audit Square&lt;/li&gt;
  &lt;li&gt;Auth0&lt;/li&gt;
  &lt;li&gt;AuthLite&lt;/li&gt;
  &lt;li&gt;Avanan Inc.&lt;/li&gt;
  &lt;li&gt;AvePoint&lt;/li&gt;
  &lt;li&gt;Avecto&lt;/li&gt;
  &lt;li&gt;Avira Operations GmbH &amp;amp; Co. KG&lt;/li&gt;
  &lt;li&gt;BT&lt;/li&gt;
  &lt;li&gt;BUFFERZONE&lt;/li&gt;
  &lt;li&gt;Balabit&lt;/li&gt;
  &lt;li&gt;Basis Technology&lt;/li&gt;
  &lt;li&gt;Bastille&lt;/li&gt;
  &lt;li&gt;Beijing Huajia Technology&lt;/li&gt;
  &lt;li&gt;Beijing Venustech Inc.&lt;/li&gt;
  &lt;li&gt;Beijing Watchsmart Technologies&lt;/li&gt;
  &lt;li&gt;Biscom&lt;/li&gt;
  &lt;li&gt;BitSight Technologies&lt;/li&gt;
  &lt;li&gt;Bitglass&lt;/li&gt;
  &lt;li&gt;BittWare&lt;/li&gt;
  &lt;li&gt;Bivio Networks&lt;/li&gt;
  &lt;li&gt;Black Duck Software&lt;/li&gt;
  &lt;li&gt;BluVector&lt;/li&gt;
  &lt;li&gt;BlueTalon&lt;/li&gt;
  &lt;li&gt;Bluebox Security&lt;/li&gt;
  &lt;li&gt;Blueliv&lt;/li&gt;
  &lt;li&gt;Boldon James&lt;/li&gt;
  &lt;li&gt;Bomgar&lt;/li&gt;
  &lt;li&gt;BooleBox&lt;/li&gt;
  &lt;li&gt;Boxcryptor&lt;/li&gt;
  &lt;li&gt;Bricata&lt;/li&gt;
  &lt;li&gt;BrightPoint Security&lt;/li&gt;
  &lt;li&gt;CENTRI Technology&lt;/li&gt;
  &lt;li&gt;CYBERBIT&lt;/li&gt;
  &lt;li&gt;Cambridge Intelligence&lt;/li&gt;
  &lt;li&gt;Capgemini&lt;/li&gt;
  &lt;li&gt;Carbon Black&lt;/li&gt;
  &lt;li&gt;Carr &amp;amp; Ferrell LLP&lt;/li&gt;
  &lt;li&gt;Cavium, Inc.&lt;/li&gt;
  &lt;li&gt;Centre for Secure Information Technologies (CSIT)&lt;/li&gt;
  &lt;li&gt;Centripetal Networks, Inc.&lt;/li&gt;
  &lt;li&gt;Certified Security Solutions (CSS)&lt;/li&gt;
  &lt;li&gt;Cheetah Mobile&lt;/li&gt;
  &lt;li&gt;CloudPassage&lt;/li&gt;
  &lt;li&gt;Cloudera&lt;/li&gt;
  &lt;li&gt;Cloudpath Networks&lt;/li&gt;
  &lt;li&gt;CoSoSys&lt;/li&gt;
  &lt;li&gt;Colopoint GmbH&lt;/li&gt;
  &lt;li&gt;Comcast Business Enterprise Solutions - MSuite&lt;/li&gt;
  &lt;li&gt;Confer Technologies&lt;/li&gt;
  &lt;li&gt;Covata&lt;/li&gt;
  &lt;li&gt;Cradlepoint&lt;/li&gt;
  &lt;li&gt;CrowdStrike&lt;/li&gt;
  &lt;li&gt;Cryptsoft&lt;/li&gt;
  &lt;li&gt;Cryptzone&lt;/li&gt;
  &lt;li&gt;CyberInt&lt;/li&gt;
  &lt;li&gt;CyberSponse&lt;/li&gt;
  &lt;li&gt;Cybereason&lt;/li&gt;
  &lt;li&gt;Cylance&lt;/li&gt;
  &lt;li&gt;D3 Security&lt;/li&gt;
  &lt;li&gt;DBAPPSecurity&lt;/li&gt;
  &lt;li&gt;DarkMatter&lt;/li&gt;
  &lt;li&gt;DataBlink, Inc.&lt;/li&gt;
  &lt;li&gt;DataLocker Inc.&lt;/li&gt;
  &lt;li&gt;Deep Instinct&lt;/li&gt;
  &lt;li&gt;Department of Homeland Security, Science &amp;amp; Technology&lt;/li&gt;
  &lt;li&gt;Detack GmbH&lt;/li&gt;
  &lt;li&gt;Digital Guardian&lt;/li&gt;
  &lt;li&gt;Digital Shadows&lt;/li&gt;
  &lt;li&gt;Dispersive Technologies&lt;/li&gt;
  &lt;li&gt;Distil Networks&lt;/li&gt;
  &lt;li&gt;Dome9 Security&lt;/li&gt;
  &lt;li&gt;Druva&lt;/li&gt;
  &lt;li&gt;ECI Telecom Ltd.&lt;/li&gt;
  &lt;li&gt;ETRI(Electronics and Telecommunications Research Institute)&lt;/li&gt;
  &lt;li&gt;EZchip&lt;/li&gt;
  &lt;li&gt;Early Warning&lt;/li&gt;
  &lt;li&gt;EdgeWave&lt;/li&gt;
  &lt;li&gt;Egis Technology Inc.&lt;/li&gt;
  &lt;li&gt;EgoSecure&lt;/li&gt;
  &lt;li&gt;Encode UK Limited&lt;/li&gt;
  &lt;li&gt;Endgame&lt;/li&gt;
  &lt;li&gt;Engage Communication&lt;/li&gt;
  &lt;li&gt;Enigmedia&lt;/li&gt;
  &lt;li&gt;Exabeam&lt;/li&gt;
  &lt;li&gt;Executive Women’s Forum&lt;/li&gt;
  &lt;li&gt;Fastly, Inc.&lt;/li&gt;
  &lt;li&gt;Federal Reserve Bank of San Francisco&lt;/li&gt;
  &lt;li&gt;FinalCode&lt;/li&gt;
  &lt;li&gt;Fireglass&lt;/li&gt;
  &lt;li&gt;Flexera Software&lt;/li&gt;
  &lt;li&gt;Flowmon Networks&lt;/li&gt;
  &lt;li&gt;Forcepoint, Powered by Raytheon&lt;/li&gt;
  &lt;li&gt;Fornetix&lt;/li&gt;
  &lt;li&gt;Fortscale Security&lt;/li&gt;
  &lt;li&gt;Fox-IT&lt;/li&gt;
  &lt;li&gt;GB&amp;amp;Smith&lt;/li&gt;
  &lt;li&gt;Gemalto&lt;/li&gt;
  &lt;li&gt;Geninetworks&lt;/li&gt;
  &lt;li&gt;Global Learning Systems&lt;/li&gt;
  &lt;li&gt;GlobalSCAPE&lt;/li&gt;
  &lt;li&gt;Great Bay Software&lt;/li&gt;
  &lt;li&gt;Green Hills Software&lt;/li&gt;
  &lt;li&gt;Ground Labs&lt;/li&gt;
  &lt;li&gt;Guardicore&lt;/li&gt;
  &lt;li&gt;H3C Technologies Co., Ltd.&lt;/li&gt;
  &lt;li&gt;HAWK Network Defense, Inc.&lt;/li&gt;
  &lt;li&gt;Happiest Minds Technologies&lt;/li&gt;
  &lt;li&gt;Heat Software&lt;/li&gt;
  &lt;li&gt;Hexadite, Inc.&lt;/li&gt;
  &lt;li&gt;Hitachi ID Systems&lt;/li&gt;
  &lt;li&gt;Hypori, Inc.&lt;/li&gt;
  &lt;li&gt;IBASE Technology, Inc.&lt;/li&gt;
  &lt;li&gt;IDenticard&lt;/li&gt;
  &lt;li&gt;INCA Internet Co., Ltd&lt;/li&gt;
  &lt;li&gt;INSIDE Secure&lt;/li&gt;
  &lt;li&gt;IPOQUE GmbH&lt;/li&gt;
  &lt;li&gt;Idappcom Ltd.&lt;/li&gt;
  &lt;li&gt;Illumio&lt;/li&gt;
  &lt;li&gt;Illusive Networks&lt;/li&gt;
  &lt;li&gt;Inspired eLearning&lt;/li&gt;
  &lt;li&gt;IntelliGo Networks, LLC&lt;/li&gt;
  &lt;li&gt;International Association of Privacy Professionals&lt;/li&gt;
  &lt;li&gt;Interrmedia.net, Inc.&lt;/li&gt;
  &lt;li&gt;Interset&lt;/li&gt;
  &lt;li&gt;Invincea&lt;/li&gt;
  &lt;li&gt;Invotas International&lt;/li&gt;
  &lt;li&gt;Israel Export Institute&lt;/li&gt;
  &lt;li&gt;Janus Technologies, Inc.&lt;/li&gt;
  &lt;li&gt;KISA(Korea Internet &amp;amp; Security Agency)&lt;/li&gt;
  &lt;li&gt;KOTRA&lt;/li&gt;
  &lt;li&gt;Kalray, Inc.&lt;/li&gt;
  &lt;li&gt;KnowBe4&lt;/li&gt;
  &lt;li&gt;LastPass Enterprise&lt;/li&gt;
  &lt;li&gt;Level 3 Communications&lt;/li&gt;
  &lt;li&gt;Lockheed Martin&lt;/li&gt;
  &lt;li&gt;Logtrust&lt;/li&gt;
  &lt;li&gt;Lookingglass&lt;/li&gt;
  &lt;li&gt;Luxar Tech&lt;/li&gt;
  &lt;li&gt;Lynx Software Technologies, Inc.&lt;/li&gt;
  &lt;li&gt;MIRACL&lt;/li&gt;
  &lt;li&gt;Malwarebytes&lt;/li&gt;
  &lt;li&gt;ManagedMethods&lt;/li&gt;
  &lt;li&gt;MediaPro, Inc.&lt;/li&gt;
  &lt;li&gt;Menlo Security&lt;/li&gt;
  &lt;li&gt;MessageSolution, Inc.&lt;/li&gt;
  &lt;li&gt;Minerva Labs Ltd&lt;/li&gt;
  &lt;li&gt;Morphick Inc&lt;/li&gt;
  &lt;li&gt;NC4&lt;/li&gt;
  &lt;li&gt;NCC Group&lt;/li&gt;
  &lt;li&gt;NIARA Inc.&lt;/li&gt;
  &lt;li&gt;NIST&lt;/li&gt;
  &lt;li&gt;NRI SecureTechnologies&lt;/li&gt;
  &lt;li&gt;NSRI(National Security Research Institute)&lt;/li&gt;
  &lt;li&gt;NTT Group Security&lt;/li&gt;
  &lt;li&gt;National Security Agency&lt;/li&gt;
  &lt;li&gt;Negev Telcom&lt;/li&gt;
  &lt;li&gt;NetLib&lt;/li&gt;
  &lt;li&gt;Netskope&lt;/li&gt;
  &lt;li&gt;Netsparker&lt;/li&gt;
  &lt;li&gt;Netwrix&lt;/li&gt;
  &lt;li&gt;Nexusguard&lt;/li&gt;
  &lt;li&gt;Niagara Networks&lt;/li&gt;
  &lt;li&gt;Novetta&lt;/li&gt;
  &lt;li&gt;NowSecure&lt;/li&gt;
  &lt;li&gt;Nubo Software Ltd.&lt;/li&gt;
  &lt;li&gt;Nuix&lt;/li&gt;
  &lt;li&gt;ObserveIT&lt;/li&gt;
  &lt;li&gt;Office of the Comptroller of the Currency&lt;/li&gt;
  &lt;li&gt;One Scorpion Security&lt;/li&gt;
  &lt;li&gt;Onspring&lt;/li&gt;
  &lt;li&gt;Ontario, Canada Delegation&lt;/li&gt;
  &lt;li&gt;Optimal IdM&lt;/li&gt;
  &lt;li&gt;Optiv&lt;/li&gt;
  &lt;li&gt;Osirium Ltd&lt;/li&gt;
  &lt;li&gt;Outpost 24&lt;/li&gt;
  &lt;li&gt;PFP Cybersecurity&lt;/li&gt;
  &lt;li&gt;PKWARE&lt;/li&gt;
  &lt;li&gt;Palamida, Inc&lt;/li&gt;
  &lt;li&gt;Palerra&lt;/li&gt;
  &lt;li&gt;Palo Alto Networks&lt;/li&gt;
  &lt;li&gt;Peach Fuzzer&lt;/li&gt;
  &lt;li&gt;Penn State Univerisity&lt;/li&gt;
  &lt;li&gt;Phantom&lt;/li&gt;
  &lt;li&gt;PhishLabs&lt;/li&gt;
  &lt;li&gt;PhishLine&lt;/li&gt;
  &lt;li&gt;Plixer&lt;/li&gt;
  &lt;li&gt;Pradeo&lt;/li&gt;
  &lt;li&gt;Prelert&lt;/li&gt;
  &lt;li&gt;Prevoty&lt;/li&gt;
  &lt;li&gt;Prosoft Systems Intl.&lt;/li&gt;
  &lt;li&gt;ProtectWise&lt;/li&gt;
  &lt;li&gt;Protegrity&lt;/li&gt;
  &lt;li&gt;Protiviti&lt;/li&gt;
  &lt;li&gt;Pulse Secure&lt;/li&gt;
  &lt;li&gt;Quick Heal Technologies&lt;/li&gt;
  &lt;li&gt;Rambus Cryptography Research&lt;/li&gt;
  &lt;li&gt;Recorded Future&lt;/li&gt;
  &lt;li&gt;Red Hat&lt;/li&gt;
  &lt;li&gt;RedOwl&lt;/li&gt;
  &lt;li&gt;RedVector&lt;/li&gt;
  &lt;li&gt;Resilient Systems&lt;/li&gt;
  &lt;li&gt;Return Path&lt;/li&gt;
  &lt;li&gt;RiskSense&lt;/li&gt;
  &lt;li&gt;RiskVision (Formerly Agiliance)&lt;/li&gt;
  &lt;li&gt;Rogue Wave Software&lt;/li&gt;
  &lt;li&gt;Rook Security&lt;/li&gt;
  &lt;li&gt;SAP SE&lt;/li&gt;
  &lt;li&gt;SAS&lt;/li&gt;
  &lt;li&gt;SAVIYNT&lt;/li&gt;
  &lt;li&gt;SOTI&lt;/li&gt;
  &lt;li&gt;SS8&lt;/li&gt;
  &lt;li&gt;SaferZone&lt;/li&gt;
  &lt;li&gt;SailPoint Technologies&lt;/li&gt;
  &lt;li&gt;Savvius, Inc.&lt;/li&gt;
  &lt;li&gt;SecuGen Corp.&lt;/li&gt;
  &lt;li&gt;SecurEnvoy&lt;/li&gt;
  &lt;li&gt;SecureLink, Inc.&lt;/li&gt;
  &lt;li&gt;Security Compass&lt;/li&gt;
  &lt;li&gt;Security First Corp.&lt;/li&gt;
  &lt;li&gt;Secusmart GmbH&lt;/li&gt;
  &lt;li&gt;SentinelOne&lt;/li&gt;
  &lt;li&gt;ServiceNow&lt;/li&gt;
  &lt;li&gt;Siemplify&lt;/li&gt;
  &lt;li&gt;Silobreaker&lt;/li&gt;
  &lt;li&gt;Simeio Solutions&lt;/li&gt;
  &lt;li&gt;Skyport Systems&lt;/li&gt;
  &lt;li&gt;Soha Systems, Inc.&lt;/li&gt;
  &lt;li&gt;Sparkle Power&lt;/li&gt;
  &lt;li&gt;Sqrrl&lt;/li&gt;
  &lt;li&gt;Staminus&lt;/li&gt;
  &lt;li&gt;SuperCom&lt;/li&gt;
  &lt;li&gt;Surevine&lt;/li&gt;
  &lt;li&gt;SurfWatch Labs&lt;/li&gt;
  &lt;li&gt;Synopsys&lt;/li&gt;
  &lt;li&gt;TICTO&lt;/li&gt;
  &lt;li&gt;TRUSTe&lt;/li&gt;
  &lt;li&gt;TaaSera&lt;/li&gt;
  &lt;li&gt;TeachPrivacy&lt;/li&gt;
  &lt;li&gt;Telecom Brokers&lt;/li&gt;
  &lt;li&gt;Telefonica&lt;/li&gt;
  &lt;li&gt;Telesoft-Technologies Ltd&lt;/li&gt;
  &lt;li&gt;Terranova WW Corporation&lt;/li&gt;
  &lt;li&gt;The Media Trust&lt;/li&gt;
  &lt;li&gt;The Open Group&lt;/li&gt;
  &lt;li&gt;ThetaRay&lt;/li&gt;
  &lt;li&gt;ThreatBook&lt;/li&gt;
  &lt;li&gt;ThreatConnect&lt;/li&gt;
  &lt;li&gt;ThreatQuotient&lt;/li&gt;
  &lt;li&gt;ThreatSTOP&lt;/li&gt;
  &lt;li&gt;ThreatStream&lt;/li&gt;
  &lt;li&gt;ThreatTrack&lt;/li&gt;
  &lt;li&gt;Titan IC Systems&lt;/li&gt;
  &lt;li&gt;Titania&lt;/li&gt;
  &lt;li&gt;TrapX Security&lt;/li&gt;
  &lt;li&gt;Trusted Knight&lt;/li&gt;
  &lt;li&gt;UKTI Defence &amp;amp; Security Organisation&lt;/li&gt;
  &lt;li&gt;Untangle&lt;/li&gt;
  &lt;li&gt;Utimaco Inc.&lt;/li&gt;
  &lt;li&gt;VMray GmbH&lt;/li&gt;
  &lt;li&gt;Verint&lt;/li&gt;
  &lt;li&gt;ViaSat, Inc.&lt;/li&gt;
  &lt;li&gt;Votiro&lt;/li&gt;
  &lt;li&gt;Vysk Communications&lt;/li&gt;
  &lt;li&gt;Waratek&lt;/li&gt;
  &lt;li&gt;Watchful Software&lt;/li&gt;
  &lt;li&gt;WebRAY(BeiJing)Tech Co.,Ltd.&lt;/li&gt;
  &lt;li&gt;Wheel Systems&lt;/li&gt;
  &lt;li&gt;WhiteHat Security Inc.&lt;/li&gt;
  &lt;li&gt;WhiteSource&lt;/li&gt;
  &lt;li&gt;Whitewood&lt;/li&gt;
  &lt;li&gt;WinMagic&lt;/li&gt;
  &lt;li&gt;WireX&lt;/li&gt;
  &lt;li&gt;X15 Software&lt;/li&gt;
  &lt;li&gt;Yubico&lt;/li&gt;
  &lt;li&gt;Zenedge, Inc.&lt;/li&gt;
  &lt;li&gt;Zentera Systems&lt;/li&gt;
  &lt;li&gt;Zertificon Solutions&lt;/li&gt;
  &lt;li&gt;Zhongguancun Overseas Science Park&lt;/li&gt;
  &lt;li&gt;Ziften&lt;/li&gt;
  &lt;li&gt;Zimperium&lt;/li&gt;
  &lt;li&gt;Zonefox&lt;/li&gt;
  &lt;li&gt;digitronic computersysteme gmbh&lt;/li&gt;
  &lt;li&gt;gateprotect GmbH&lt;/li&gt;
  &lt;li&gt;iSIGHT Partners&lt;/li&gt;
  &lt;li&gt;iovation&lt;/li&gt;
  &lt;li&gt;itWatch GmbH&lt;/li&gt;
  &lt;li&gt;secunet&lt;/li&gt;
  &lt;li&gt;tyntec&lt;/li&gt;
  &lt;li&gt;whiteCryption&lt;/li&gt;
&lt;/ul&gt;
</description>
        <pubDate>Wed, 13 Apr 2016 18:56:08 +1000</pubDate>
        <link>https://luckandskill.io/opinion/2016/04/13/rsa-conference-vendors-2014-vs-2016.html</link>
        <guid isPermaLink="true">https://luckandskill.io/opinion/2016/04/13/rsa-conference-vendors-2014-vs-2016.html</guid>
        
        <category>vendors</category>
        
        
        <category>opinion</category>
        
      </item>
    
  </channel>
</rss>
