Jim Guckin @jimguckin.bsky.social · 03/10/2026Space Marines have ten thousand years of doctrine and still charge in with chainswords. Somewhere in the Imperium there's a Codex Astartes appendix called "Lessons Learned" that nobody has ever opened. I relate. 020
Jim Guckin @jimguckin.bsky.social · 03/10/2026Friday night options: new episode of something, finish painting a squad, or "just check one thing" in the SIEM. We all know which one I'll end up doing. I'm not proud of it. 000
Jim Guckin @jimguckin.bsky.social · 02/10/2026Lex Luthor is a billionaire convinced he alone can protect the world from a threat nobody else takes seriously. Every conference season I walk past a few of his booths. 000
Jim Guckin @jimguckin.bsky.social · 02/10/2026Awareness month tip: if you want people to report phishing, don't let the report button send their email into a void. Nobody keeps calling the fire department if the trucks never show up. #CybersecurityAwarenessMonth 001
Jim Guckin @jimguckin.bsky.social · 02/10/2026Half the Enterprise's security incidents start with some alien simply talking to the ship's computer until it does what they want. Star Trek was writing about prompt injection decades before we had a name for it. 010
Jim Guckin @jimguckin.bsky.social · 01/10/2026It's also Hacktoberfest. If you've ever opened a GitHub issue that just said "doesn't work," consider this your month of atonement. Go send a real PR to a project you depend on. Maintainers are tired. 010
Jim Guckin @jimguckin.bsky.social · 01/10/2026Unpopular opinion: Loki is the most realistic insider threat in the MCU. Trusted access, legitimate credentials, deep knowledge of the environment… and a grudge. That's not a villain. That's a risk register entry. 000
Jim Guckin @jimguckin.bsky.social · 30/09/2026Baring my soul on this one. I’m not a thought leader. Just a guy with 20+ years of mistakes and a keyboard. Sharing them might save you a few. jimguckin.com/2026/09/30/i... #Cybersecurity #Leadershipjimguckin.comI'm Not a Thought Leader. I'm Just a Guy Who Keeps Getting Things Wrong. – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 000
Jim Guckin @jimguckin.bsky.social · 30/09/2026The Adeptus Mechanicus won't touch a system without prayers, incense and a chant to the Machine Spirit. Honestly? Still a more consistent change management process than some places I've worked. 010
Jim Guckin @jimguckin.bsky.social · 30/09/2026Tomorrow kicks off Cybersecurity Awareness Month. Get ready for a lot of posters telling people not to click things. (I'll be making some of those posters. I'm not above it.) The real test is whether anything changes in November. 001
Jim Guckin @jimguckin.bsky.social · 30/09/2026R2-D2 plugs into any Imperial terminal in the galaxy and gets full access. The Empire had the budget for two Death Stars and never once thought about port security. 000
Jim Guckin @jimguckin.bsky.social · 29/09/2026Scotty padding every repair estimate by a factor of four is still the most accurate portrayal of project management in all of science fiction. (I've done it. You've done it. Kirk knew.) 010
Jim Guckin @jimguckin.bsky.social · 28/09/2026Best finding I ever saw in a pen test report wasn't clever at all. Default creds on a device everyone assumed somebody else owned. The exploit was an org chart problem. 110
Jim Guckin @jimguckin.bsky.social · 28/09/2026Monday reminder: an alert nobody looks at isn't detection. It's a diary. 000
Jim Guckin @jimguckin.bsky.social · 27/09/2026Sunday plan: paint minis, rewatch something I've already seen nine times, ignore the inbox. Security people need a hobby that doesn't involve logs. Mine just happens to involve tiny armies. What's yours? 000
Jim Guckin @jimguckin.bsky.social · 27/09/2026Batman keeps a contingency plan to take down every member of the Justice League. People call that paranoid. I call it the only superhero with a documented incident response plan. 000
Jim Guckin @jimguckin.bsky.social · 27/09/2026Tony Stark built an AI with root on a global defense network, no change control and no second reviewer… and we act surprised by Ultron. (I've sat in that architecture review. Different suits, same energy.) 000
Jim Guckin @jimguckin.bsky.social · 26/09/2026Hot take I'll defend over lunch: the Empire didn't lose to the Rebels. It lost because nobody threat modeled a thermal exhaust port. Two meters wide, unshielded, straight to the reactor. Somebody signed off on that design review. 000
Jim Guckin @jimguckin.bsky.social · 26/09/2026Started a new Warhammer 40k army this week. (I have not finished painting the last one. Or the one before that.) The pile of shame isn't a phase. It's a lifestyle. 020
Jim Guckin @jimguckin.bsky.social · 25/09/2026Every Star Trek away team: captain, first officer, chief medical officer and chief engineer all beam down to the unknown planet together. That's not a landing party. That's your entire DR plan standing in one blast radius. 010
Jim Guckin @jimguckin.bsky.social · 25/09/2026Friday change freeze is the most honest security control most of us have. Nobody wrote it down as a control… but everybody follows it. That's more than I can say for half the policies in the binder. 000
Jim Guckin @jimguckin.bsky.social · 23/09/2026The hardest security decisions don’t end when you make the call. They stay with you. A Star Trek scene got me thinking about uncertainty, accountability, and the courage to sit back down tomorrow. My latest: jimguckin.com/2026/09/23/t...jimguckin.comThe Chair, the Call, and What Comes After – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 011
Jim Guckin @jimguckin.bsky.social · 20/08/2026An executive went to a conference. Now you need an “AI Transformation Roadmap.” Before spending the money, ask: What specific problem are we solving? If the room goes quiet, there’s your answer. jimguckin.com/2026/08/20/s...jimguckin.comStop Adopting AI Because Someone Read an Article About It – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 020
Jim Guckin @jimguckin.bsky.social · 12/08/2026We trained users not to click the link. Russia found a workaround: just open the email. OWAReaper changes the rules of phishing, persistence, and incident response. jimguckin.com/2026/08/11/y... #Cybersecurity #Infosecjimguckin.comYou Trained Them Not to Click, and Russia Found a Way Around That – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 010
Jim Guckin @jimguckin.bsky.social · 05/08/2026Nation-state attackers didn't need zero-days to disrupt 30+ Minnesota water systems. They needed exposed PLCs and weak security. My latest article explains why this should concern every security leader. jimguckin.com/2026/08/05/t... #CyberSecurity #OTSecurityjimguckin.comThe Faucet, the PLC, and the Nation-State That Turned It Off – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 010
Jim Guckin @jimguckin.bsky.social · 30/07/2026CVE-2026-10702: A JIT flaw in Firefox's SpiderMonkey engine means visiting a malicious webpage is enough. No clicks, no downloads. Tor Browser inherited it. Patches exist. Firefox 151.0.3, Tor 15.0.19. If you haven't updated…do it now gbhackers.com/hackers-can-... #InfoSec #Firefox #TorBrowsergbhackers.comHackers Can Compromise Tor Browser Users by Exploiting Firefox JIT FlawTor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a serious vulnerability in Mozilla Firefox’s… 000
Jim Guckin @jimguckin.bsky.social · 29/07/2026In Jurassic Park...John Hammond spared no expense on the dinosaurs. The IT infrastructure ran on one resentful guy with keys to everything. I keep seeing the same pattern with AI deployments. New post: jimguckin.com/2026/07/29/spare-no-expense-ai-security/jimguckin.com"Spared No Expense" (Except Where It Mattered) – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 000
Jim Guckin @jimguckin.bsky.social · 22/07/2026"Ship it." Those might be the most dangerous words in software development when AI writes the code. My latest article explores why vibe coding is accelerating development... but can also accelerate security mistakes if we're not careful. jimguckin.com/2026/07/21/y... #AI #AppSec #DevSecOpsjimguckin.comYou Vibe Coded Your Way Into a Security Nightmare ... And You Don't Even Know It Yet – Jim GuckinJim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong. 140
Jim Guckin @jimguckin.bsky.social · 24/06/2026Security awareness training isn't supposed to embarrass people. It's supposed to help them make better decisions. jimguckin.com/2026/06/24/s... #CyberSecurity #SecurityAwareness #InfoSec #CISSPjimguckin.comSecurity Awareness Training That Doesn’t Embarrass Anyone – Jim GuckinPrint PDF eBook Can I tell you about a phishing simulation I ran early in my career that I am not particularly proud of (I wasn’t perfect, nor am I now). We had just rolled out a new security… 000
Jim Guckin @jimguckin.bsky.social · 29/04/2026Every zero trust rollout I've seen starts the same way. Board meeting. Vendor briefing. Budget line. Working group. And everyone quietly assuming they're running a technology project. They're not. jimguckin.com/2026/04/29/w... #ZeroTrust #CyberSecurity #InfoSec #SecurityLeadershipjimguckin.comWhat Zero Trust Actually Requires That Nobody Wants to Talk About – Jim GuckinPrint PDF eBook Am I the only one who has experienced this…usually after a board meeting or a vendor briefing, where someone announces that the company is going to implement zero trust. The room… 000
Jim Guckin @jimguckin.bsky.social · 19/04/2026You know it’s bad when… the issue gets escalated and nobody wants to own it. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 18/04/2026You know it’s bad when… someone asks “when did this start?” and no one knows. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 17/04/2026You know it’s bad when… the alert you ignored yesterday suddenly makes sense. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 16/04/2026You know it’s bad when… the “test system” has production data. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 15/04/2026You know it’s bad when… someone says “we’ve never seen this before.” #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 15/04/2026Your dashboards look great, your alerts are firing. But here’s were I think there is a problem… Detection without understanding is just noise. New article: jimguckin.com/2026/04/15/w... #CyberSecurity #SecurityOps #InfoSecjimguckin.com 010
Jim Guckin @jimguckin.bsky.social · 14/04/2026You know it’s bad when… the logs don’t agree with each other. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 13/04/2026You know it’s bad when… the incident bridge suddenly gets very quiet. #CyberSecurity #IncidentResponse #ITLife 000
Jim Guckin @jimguckin.bsky.social · 08/04/2026Ownership gets assigned all the time. Accountability? That’s a different story. New article: Ownership Was Assigned… Accountability Is Another Story jimguckin.com/2026/04/08/o... #CyberSecurity #RiskManagement #SecurityLeadership #Governancejimguckin.comOwnership was Assigned….accountability is another story – Jim GuckinPrint PDF eBook There is a conversation that happens in almost every organization I have ever encountered, usually in a conference room, usually after something has gone sideways, backward and upside… 000
Jim Guckin @jimguckin.bsky.social · 01/04/2026Your security program might look great… but who is it actually optimized for? Audits matter, but they’re not the finish line. Too many programs drift into proving security instead of improving it. jimguckin.com/2026/04/01/y... #CyberSecurity #RiskManagement #CISO #Leadershipjimguckin.comYour Security Program Looks Great… For the Audit – Jim GuckinPost navigation 000
Jim Guckin @jimguckin.bsky.social · 28/03/2026From the security team’s perspective: “It’s just a test system” has entered the chat… with production data. #CyberSecurity #DataSecurity #ITLife 000
Jim Guckin @jimguckin.bsky.social · 27/03/2026From the security team’s perspective: “The vendor handles security” is where the real investigation usually starts. #CyberSecurity #ThirdPartyRisk #RealityCheck 000
Jim Guckin @jimguckin.bsky.social · 27/03/2026We keep calling them leaders… But a lot of them are just managing. A manager tells you what to do. A leader helps you grow. New article: Not Every Manager Is a Leader (And That’s the Problem) jimguckin.com/2026/03/27/n... #Leadership #Mentorship #CareerGrowthjimguckin.comNot Every Manager Is a Leader (And That’s the Problem) – Jim GuckinPrint PDF eBook I had the opportunity to have a run in with an old colleague (he’s not old, we’ve just haven’t seen each out in a while) and we got to talking about everything that has been going on… 000
Jim Guckin @jimguckin.bsky.social · 26/03/2026From the security team’s perspective: “Read-only access” somehow still finds a way to cause problems. #CyberSecurity #IAM #SecurityL 000
Jim Guckin @jimguckin.bsky.social · 25/03/2026From the security team’s perspective: “We’ll fix it later” has a remarkable ability to become “we never fixed it.” #CyberSecurity #TechDebt #Reality 001
Jim Guckin @jimguckin.bsky.social · 24/03/2026From the security team’s perspective: “The system is isolated” is more of a suggestion than a fact. #CyberSecurity #NetworkSecurity #HardTruths 000
Jim Guckin @jimguckin.bsky.social · 23/03/2026From the security team’s perspective: “If everything is a priority” usually means nothing is. #CyberSecurity #RiskManagement #Leadership 010
Jim Guckin @jimguckin.bsky.social · 22/03/2026From the security team’s perspective: “That quick change” is never quick and never just one change. #CyberSecurity #SecurityLife #ITTruths 000
Jim Guckin @jimguckin.bsky.social · 21/03/2026Information Security terms that sound fake but aren’t: “Smishing.” Yes, it sounds ridiculous. No, it’s not a typo. It’s phishing… but through SMS. #CyberSecurity #Phishing #SecurityAwareness #SecurityTermsThatSoundFake 000
Jim Guckin @jimguckin.bsky.social · 21/03/2026From the security team’s perspective: “We’ll fix it later” has a remarkable ability to become “we never fixed it.” #CyberSecurity #TechDebt #Reality 000