{"id":1699,"date":"2023-02-22T10:56:27","date_gmt":"2023-02-22T15:56:27","guid":{"rendered":"https:\/\/securityeverafter.com\/?p=1699"},"modified":"2023-02-27T08:21:31","modified_gmt":"2023-02-27T13:21:31","slug":"trust-but-verify","status":"publish","type":"post","link":"https:\/\/securityeverafter.com\/trust-but-verify\/","title":{"rendered":"Trust But Verify – Part 2"},"content":{"rendered":"
<\/p>\n
<\/p>\n
What if I told you you could install a new cybersecurity habit this week? What if I told you this habit was borrowed from a prominent political leader? This one is former US President Ronald Reagan. And his statement, trust, but verify. I’m sure you remember him and likely the conditions under which he uttered those now-famous words.<\/span><\/p>\n But how does this apply to cyber? I’m so glad you asked! I have an example that I hope will resonate. Well, it’s likely that in cyber, you have a dashboard. Honestly, you have a bunch of dashboards. And, when you look at your dashboard, it tells you how well things are doing, perhaps how well agents are phoning in and giving status or giving an update, and communicating into your dashboard.<\/span><\/p>\n Looking at your dashboard, things look like they’re updating, but how do you know? How do you\u00a0<\/span>really<\/span><\/u>\u00a0know? How might you not just trust but verify that they are actually? They are phoning into the dashboard or have done so in the last few hours. It reminds me of a question I created several years ago. Feel free to use it.<\/span><\/p>\n The question is this – “how long can you stand to not know”? As in, how long can you stand to not know those agents – you know, the ones I’m talking about – have not phoned in recently to your dashboard? So what’s the habit that I believe you can install this week?<\/span><\/p>\n It’s simple. Put a weekly recurring calendar reminder to do a manual check, a weekly calendar reminder to not just trust, but to verify those agents are phoning in, in this case, a check to make sure that the security agents that are supposed to report into your dashboard are well reporting into your dashboard.<\/span><\/p>\n Yes, there’s some manual labor. Yes, this practice has saved me more than just a few times to trust but verify. And when you do that, you can likely be more effective in cybersecurity and also get wisdom as cheaply as you can.\u00a0<\/span><\/p>\n