Sign in

Jim Guckin

@jimguckin.bsky.social
23 followers 9 following 134 posts

Infosec evangelist, father, nerd, mentor, idiot linktr.ee/jimguckin

PostsRepliesMedia
Jim Guckin @jimguckin.bsky.social · 03/10/2026
Space Marines have ten thousand years of doctrine and still charge in with chainswords. Somewhere in the Imperium there's a Codex Astartes appendix called "Lessons Learned" that nobody has ever opened. I relate.
020
Jim Guckin @jimguckin.bsky.social · 03/10/2026
Friday night options: new episode of something, finish painting a squad, or "just check one thing" in the SIEM. We all know which one I'll end up doing. I'm not proud of it.
000
Jim Guckin @jimguckin.bsky.social · 02/10/2026
Lex Luthor is a billionaire convinced he alone can protect the world from a threat nobody else takes seriously. Every conference season I walk past a few of his booths.
000
Jim Guckin @jimguckin.bsky.social · 02/10/2026
Awareness month tip: if you want people to report phishing, don't let the report button send their email into a void. Nobody keeps calling the fire department if the trucks never show up. #CybersecurityAwarenessMonth
001
Jim Guckin @jimguckin.bsky.social · 02/10/2026
Half the Enterprise's security incidents start with some alien simply talking to the ship's computer until it does what they want. Star Trek was writing about prompt injection decades before we had a name for it.
010
Jim Guckin @jimguckin.bsky.social · 01/10/2026
It's also Hacktoberfest. If you've ever opened a GitHub issue that just said "doesn't work," consider this your month of atonement. Go send a real PR to a project you depend on. Maintainers are tired.
010
Jim Guckin @jimguckin.bsky.social · 01/10/2026
Unpopular opinion: Loki is the most realistic insider threat in the MCU. Trusted access, legitimate credentials, deep knowledge of the environment… and a grudge. That's not a villain. That's a risk register entry.
000
Jim Guckin @jimguckin.bsky.social · 30/09/2026
Baring my soul on this one. I’m not a thought leader. Just a guy with 20+ years of mistakes and a keyboard. Sharing them might save you a few. jimguckin.com/2026/09/30/i... #Cybersecurity #Leadership
jimguckin.com
I'm Not a Thought Leader. I'm Just a Guy Who Keeps Getting Things Wrong. – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
000
Jim Guckin @jimguckin.bsky.social · 30/09/2026
The Adeptus Mechanicus won't touch a system without prayers, incense and a chant to the Machine Spirit. Honestly? Still a more consistent change management process than some places I've worked.
010
Jim Guckin @jimguckin.bsky.social · 30/09/2026
Tomorrow kicks off Cybersecurity Awareness Month. Get ready for a lot of posters telling people not to click things. (I'll be making some of those posters. I'm not above it.) The real test is whether anything changes in November.
001
Jim Guckin @jimguckin.bsky.social · 30/09/2026
R2-D2 plugs into any Imperial terminal in the galaxy and gets full access. The Empire had the budget for two Death Stars and never once thought about port security.
000
Jim Guckin @jimguckin.bsky.social · 29/09/2026
Scotty padding every repair estimate by a factor of four is still the most accurate portrayal of project management in all of science fiction. (I've done it. You've done it. Kirk knew.)
010
Jim Guckin @jimguckin.bsky.social · 28/09/2026
Best finding I ever saw in a pen test report wasn't clever at all. Default creds on a device everyone assumed somebody else owned. The exploit was an org chart problem.
110
Jim Guckin @jimguckin.bsky.social · 28/09/2026
Monday reminder: an alert nobody looks at isn't detection. It's a diary.
000
Jim Guckin @jimguckin.bsky.social · 27/09/2026
Sunday plan: paint minis, rewatch something I've already seen nine times, ignore the inbox. Security people need a hobby that doesn't involve logs. Mine just happens to involve tiny armies. What's yours?
000
Jim Guckin @jimguckin.bsky.social · 27/09/2026
Batman keeps a contingency plan to take down every member of the Justice League. People call that paranoid. I call it the only superhero with a documented incident response plan.
000
Jim Guckin @jimguckin.bsky.social · 27/09/2026
Tony Stark built an AI with root on a global defense network, no change control and no second reviewer… and we act surprised by Ultron. (I've sat in that architecture review. Different suits, same energy.)
000
Jim Guckin @jimguckin.bsky.social · 26/09/2026
Hot take I'll defend over lunch: the Empire didn't lose to the Rebels. It lost because nobody threat modeled a thermal exhaust port. Two meters wide, unshielded, straight to the reactor. Somebody signed off on that design review.
000
Jim Guckin @jimguckin.bsky.social · 26/09/2026
Started a new Warhammer 40k army this week. (I have not finished painting the last one. Or the one before that.) The pile of shame isn't a phase. It's a lifestyle.
020
Jim Guckin @jimguckin.bsky.social · 25/09/2026
Every Star Trek away team: captain, first officer, chief medical officer and chief engineer all beam down to the unknown planet together. That's not a landing party. That's your entire DR plan standing in one blast radius.
010
Jim Guckin @jimguckin.bsky.social · 25/09/2026
Friday change freeze is the most honest security control most of us have. Nobody wrote it down as a control… but everybody follows it. That's more than I can say for half the policies in the binder.
000
Jim Guckin @jimguckin.bsky.social · 23/09/2026
The hardest security decisions don’t end when you make the call. They stay with you. A Star Trek scene got me thinking about uncertainty, accountability, and the courage to sit back down tomorrow. My latest: jimguckin.com/2026/09/23/t...
jimguckin.com
The Chair, the Call, and What Comes After – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
011
Jim Guckin @jimguckin.bsky.social · 20/08/2026
An executive went to a conference. Now you need an “AI Transformation Roadmap.” Before spending the money, ask: What specific problem are we solving? If the room goes quiet, there’s your answer. jimguckin.com/2026/08/20/s...
jimguckin.com
Stop Adopting AI Because Someone Read an Article About It – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
020
Jim Guckin @jimguckin.bsky.social · 12/08/2026
We trained users not to click the link. Russia found a workaround: just open the email. OWAReaper changes the rules of phishing, persistence, and incident response. jimguckin.com/2026/08/11/y... #Cybersecurity #Infosec
jimguckin.com
You Trained Them Not to Click, and Russia Found a Way Around That – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
010
Jim Guckin @jimguckin.bsky.social · 05/08/2026
Nation-state attackers didn't need zero-days to disrupt 30+ Minnesota water systems. They needed exposed PLCs and weak security. My latest article explains why this should concern every security leader. jimguckin.com/2026/08/05/t... #CyberSecurity #OTSecurity
jimguckin.com
The Faucet, the PLC, and the Nation-State That Turned It Off – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
010
Jim Guckin @jimguckin.bsky.social · 30/07/2026
CVE-2026-10702: A JIT flaw in Firefox's SpiderMonkey engine means visiting a malicious webpage is enough. No clicks, no downloads. Tor Browser inherited it. Patches exist. Firefox 151.0.3, Tor 15.0.19. If you haven't updated…do it now gbhackers.com/hackers-can-... #InfoSec #Firefox #TorBrowser
gbhackers.com
Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw
Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a serious vulnerability in Mozilla Firefox’s…
000
Jim Guckin @jimguckin.bsky.social · 29/07/2026
In Jurassic Park...John Hammond spared no expense on the dinosaurs. The IT infrastructure ran on one resentful guy with keys to everything. I keep seeing the same pattern with AI deployments. New post: jimguckin.com/2026/07/29/spare-no-expense-ai-security/
jimguckin.com
"Spared No Expense" (Except Where It Mattered) – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
000
Jim Guckin @jimguckin.bsky.social · 22/07/2026
"Ship it." Those might be the most dangerous words in software development when AI writes the code. My latest article explores why vibe coding is accelerating development... but can also accelerate security mistakes if we're not careful. jimguckin.com/2026/07/21/y... #AI #AppSec #DevSecOps
jimguckin.com
You Vibe Coded Your Way Into a Security Nightmare ... And You Don't Even Know It Yet – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
140
Jim Guckin @jimguckin.bsky.social · 24/06/2026
Security awareness training isn't supposed to embarrass people. It's supposed to help them make better decisions. jimguckin.com/2026/06/24/s... #CyberSecurity #SecurityAwareness #InfoSec #CISSP
jimguckin.com
Security Awareness Training That Doesn’t Embarrass Anyone – Jim Guckin
Print PDF eBook Can I tell you about a phishing simulation I ran early in my career that I am not particularly proud of (I wasn’t perfect, nor am I now). We had just rolled out a new security…
000
Jim Guckin @jimguckin.bsky.social · 29/04/2026
Every zero trust rollout I've seen starts the same way. Board meeting. Vendor briefing. Budget line. Working group. And everyone quietly assuming they're running a technology project. They're not. jimguckin.com/2026/04/29/w... #ZeroTrust #CyberSecurity #InfoSec #SecurityLeadership
jimguckin.com
What Zero Trust Actually Requires That Nobody Wants to Talk About – Jim Guckin
Print PDF eBook Am I the only one who has experienced this…usually after a board meeting or a vendor briefing, where someone announces that the company is going to implement zero trust. The room…
000
Jim Guckin @jimguckin.bsky.social · 19/04/2026
You know it’s bad when… the issue gets escalated and nobody wants to own it. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 18/04/2026
You know it’s bad when… someone asks “when did this start?” and no one knows. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 17/04/2026
You know it’s bad when… the alert you ignored yesterday suddenly makes sense. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 16/04/2026
You know it’s bad when… the “test system” has production data. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 15/04/2026
You know it’s bad when… someone says “we’ve never seen this before.” #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 15/04/2026
Your dashboards look great, your alerts are firing. But here’s were I think there is a problem… Detection without understanding is just noise. New article: jimguckin.com/2026/04/15/w... #CyberSecurity #SecurityOps #InfoSec
jimguckin.com
010
Jim Guckin @jimguckin.bsky.social · 14/04/2026
You know it’s bad when… the logs don’t agree with each other. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 13/04/2026
You know it’s bad when… the incident bridge suddenly gets very quiet. #CyberSecurity #IncidentResponse #ITLife
000
Jim Guckin @jimguckin.bsky.social · 08/04/2026
Ownership gets assigned all the time. Accountability? That’s a different story. New article: Ownership Was Assigned… Accountability Is Another Story jimguckin.com/2026/04/08/o... #CyberSecurity #RiskManagement #SecurityLeadership #Governance
jimguckin.com
Ownership was Assigned….accountability is another story – Jim Guckin
Print PDF eBook There is a conversation that happens in almost every organization I have ever encountered, usually in a conference room, usually after something has gone sideways, backward and upside…
000
Jim Guckin @jimguckin.bsky.social · 01/04/2026
Your security program might look great… but who is it actually optimized for? Audits matter, but they’re not the finish line. Too many programs drift into proving security instead of improving it. jimguckin.com/2026/04/01/y... #CyberSecurity #RiskManagement #CISO #Leadership
jimguckin.com
Your Security Program Looks Great… For the Audit – Jim Guckin
Post navigation
000
Jim Guckin @jimguckin.bsky.social · 28/03/2026
From the security team’s perspective: “It’s just a test system” has entered the chat… with production data. #CyberSecurity #DataSecurity #ITLife
000
Jim Guckin @jimguckin.bsky.social · 27/03/2026
From the security team’s perspective: “The vendor handles security” is where the real investigation usually starts. #CyberSecurity #ThirdPartyRisk #RealityCheck
000
Jim Guckin @jimguckin.bsky.social · 27/03/2026
We keep calling them leaders… But a lot of them are just managing. A manager tells you what to do. A leader helps you grow. New article: Not Every Manager Is a Leader (And That’s the Problem) jimguckin.com/2026/03/27/n... #Leadership #Mentorship #CareerGrowth
jimguckin.com
Not Every Manager Is a Leader (And That’s the Problem) – Jim Guckin
Print PDF eBook I had the opportunity to have a run in with an old colleague (he’s not old, we’ve just haven’t seen each out in a while) and we got to talking about everything that has been going on…
000
Jim Guckin @jimguckin.bsky.social · 26/03/2026
From the security team’s perspective: “Read-only access” somehow still finds a way to cause problems. #CyberSecurity #IAM #SecurityL
000
Jim Guckin @jimguckin.bsky.social · 25/03/2026
From the security team’s perspective: “We’ll fix it later” has a remarkable ability to become “we never fixed it.” #CyberSecurity #TechDebt #Reality
001
Jim Guckin @jimguckin.bsky.social · 24/03/2026
From the security team’s perspective: “The system is isolated” is more of a suggestion than a fact. #CyberSecurity #NetworkSecurity #HardTruths
000
Jim Guckin @jimguckin.bsky.social · 23/03/2026
From the security team’s perspective: “If everything is a priority” usually means nothing is. #CyberSecurity #RiskManagement #Leadership
010
Jim Guckin @jimguckin.bsky.social · 22/03/2026
From the security team’s perspective: “That quick change” is never quick and never just one change. #CyberSecurity #SecurityLife #ITTruths
000
Jim Guckin @jimguckin.bsky.social · 21/03/2026
Information Security terms that sound fake but aren’t: “Smishing.” Yes, it sounds ridiculous. No, it’s not a typo. It’s phishing… but through SMS. #CyberSecurity #Phishing #SecurityAwareness #SecurityTermsThatSoundFake
000
Jim Guckin @jimguckin.bsky.social · 21/03/2026
From the security team’s perspective: “We’ll fix it later” has a remarkable ability to become “we never fixed it.” #CyberSecurity #TechDebt #Reality
000