Mark Simos @markasimos.bsky.social · 27/09/2026One way to visualize why organizations must view IT systems as business assets, must own all the risks including security, and must shift security integration left is to take a long view over the asset's lifetime. 100
Mark Simos @markasimos.bsky.social · 25/09/2026The recording for "Security is team sport, but we aren’t planning like a team" is now live! Recording - www.youtube.com/watch?v=l0cC... Slides - www.slideshare.net/slideshow/se... 100
Mark Simos @markasimos.bsky.social · 22/09/2026I recently released a new video "Know Your Attacker" that covers who the attackers we face are, why they do it, and how they approach attack operations (including how they are using generative AI today), and what this means for you. www.youtube.com/watch?v=fgPv... 100
Mark Simos @markasimos.bsky.social · 21/09/2026I just released a new video "Zero Trust Explained" www.youtube.com/watch?v=6bqf... It covers ► What Zero Trust is (fixing broken assumptions from classic security) ► How this concept evolved, how Zero Trust is required for AI security (and is accelerated by AI) ⬇️ 101
Mark Simos @markasimos.bsky.social · 18/09/2026One of the first videos I posted is "Cybersecurity explained" that covers the basics of what cybersecurity is, what success looks like (attacker failure), and what it takes to build organizational resilience www.youtube.com/watch?v=iOfg...youtube.comCybersecurity ExplainedYouTube video by Mark Simos 100
Mark Simos @markasimos.bsky.social · 13/09/2026I've been a little bit quiet lately because I've been (re)building my YouTube channel - Mark on Cybersecurity I just posted the first 3 new videos. Share and Enjoy! MarkonCyber.com 110
Mark Simos @markasimos.bsky.social · 04/09/2026Hey all, I recorded a short video with a preview of the sessions and standards we will talking about at the FREE Security Forum event in Arlington, VA (near Washington DC) meet.opengroup.org/event/cbab26... Registration closes September 7 Would love to see you there! 100
Mark Simos @markasimos.bsky.social · 03/09/2026Come hear the authors in speak in person (and ask them questions) on the upcoming Security Matrix standard. We will be live at the upcoming Security Forum event in Washington DC on September 15-17. (technically Arlington, VA) Agenda & register here - meet.opengroup.org/event/cbab26... 100
Mark Simos @markasimos.bsky.social · 01/09/2026If you are in the Washington DC area, you are invited to a free vendor-neutral event focused on the toughest cybersecurity challenges Sep 15-17 aka.ms/TOGevent I would love to see you all there! 100
Mark Simos @markasimos.bsky.social · 30/08/2026One of the things its easy to forget about cybersecurity is that our adversaries are creative and intelligent humans with goals, talents, preferences, limitations, blind spots, etc. just like us. 100
Mark Simos @markasimos.bsky.social · 23/08/2026I am going to be talking on just about every aspect of security in person over 2 days at the free security forum event from The Open Group You can register for FREE for this Washington DC event here: meet.opengroup.org/event/cbab26... Would love to see you there! 000
Mark Simos @markasimos.bsky.social · 20/08/2026New headshot! Who dis? Time catches up with us all. I didn't quite realize how old my headshot was (circa 2012) until I calculated that one of my teenage kids wasn't even born when my last headshot was taken. 😂 011
Mark Simos @markasimos.bsky.social · 20/08/2026Join me in person for a full-day vendor-neutral FREE security event! We are holding the inaugural Security Forum event in Arlington, VA to share the work we are doing at The Open Group. You can access the agenda and register here: meet.opengroup.org/event/cbab26...meet.opengroup.orgHome - The Open Group Security ForumJoin us at The Open Group events covering topics from Enterprise Architecture, AI, Digital Transformation, Open Standards, Cybersecurity, and more. Register Today! 131
Mark Simos @markasimos.bsky.social · 19/08/2026What should a board be looking for in their oversight of security management? What does good look like? The Open Group provides a standard definition as part of the accountabilities of board members - see Part 3.1 of publications.opengroup.org/s252 100
Mark Simos @markasimos.bsky.social · 15/08/2026Do you want to be a CISO that can block projects? No! You don't! CISOs don't want this authority unless you want to own all their other outcomes/risks of the project (financial targets, safety, legal, personnel, etc.), which would make them a business leader, not a CISO 🧵 100
Mark Simos @markasimos.bsky.social · 31/07/2026One thing SAF does well is to help you connect business priorities to architecture, controls, processes, operations (as well as Microsoft implementation guidance). We many programs struggle with this. See aka.ms/SAF (no paywall, no registration) 000
Mark Simos @markasimos.bsky.social · 29/07/2026Controlling access requires a subject, verb, and object (regardless of whether it involves humans, AI agents, data, deterministic systems, or physical objects) - Who or what is requesting access? - What action are they taking? - What business asset are they touching? 200
Mark Simos @markasimos.bsky.social · 28/07/2026The “keeping secrets from family” antipattern in SAF captures a common failure: incident learnings stay trapped inside SecOps a short 🧵 110
Mark Simos @markasimos.bsky.social · 21/07/2026Trying to communicate security & risk better with business colleagues? Microsoft published tips, learnings, and best practices as part of the new Security Adoption Framework (SAF) guidance. (no ads, no registration) learn.microsoft.com/en-us/securi... 000
Mark Simos @markasimos.bsky.social · 20/07/2026We need to have an honest conversation about legacy systems… Most organizations have unsupported systems that they aren’t able to change or move and this creates business risk. This is normal and common, no surprise. 🧵 100
Mark Simos @markasimos.bsky.social · 11/07/2026The Azure Security Podcast episode just dropped for the new Security Adoption Framework (SAF) documentation. Podcast - azuresecuritypodcast.azurewebsites.net Docs - aka.ms/SAF 122
Mark Simos @markasimos.bsky.social · 10/07/2026Are you still applying security patches as an exception? or patching by default? One of the biggest impacts of Mythos, MDASH, and other AI vuln discovery/exploit technologies is that you have to get really good at all aspects of software vulnerability management. 🧵 101
Mark Simos @markasimos.bsky.social · 02/06/2026The SAF documentation site and June 2026 MCRA just went live on Microsoft Learn! Check it out and let us know what you think! aka.ms/SAF Note: This is the first release and we will be continuing to add to it. Send us your feedback, requests, and ideas. 132
Mark Simos @markasimos.bsky.social · 31/05/2026Hey y'all I just recorded my first video in my new 'Mark on Cybersecurity' YouTube channel! Lots more to come! Let me know what you think and what topics you would like me to cover youtu.be/gKRWhAFQk4Yyoutu.beMark on Cybersecurity - Ep 1YouTube video by Mark Simos 111
Mark Simos @markasimos.bsky.social · 29/05/2026I keep hearing people are "Automating Tier 1 with AI" (or some other job) and I think words really matter here. ◾ Are you trying to replace a human person with AI? Assigning a human role to AI? ◾ Are you automating the tasks currently being done by people? a short 🧵 111
Mark Simos @markasimos.bsky.social · 26/05/2026Security can never “win the game” - it's not the job we signed up for. We are the defense squad so we don't score goals or points - we just keep opponents from scoring points. 110
Mark Simos @markasimos.bsky.social · 23/05/2026One of the most critical skillsets for CISOs is their ability to navigate the power structure of an organization (e.g. politics) I included this slide in my recent Tampa BSides talk (slides posted, recording pending) - zerotrustplaybook.com/events/ 🧵 110
Mark Simos @markasimos.bsky.social · 21/05/2026Understanding and using the Why/What/How Chain is critical for everyone in security. I covered this in my Tampa BSides talk. Link to download the slides (and other past slides) here - zerotrustplaybook.com/events/ 🧵 100
Mark Simos @markasimos.bsky.social · 18/05/2026I just posted the slides for my 'Security is a Team Sport (but we are NOT playing like a team)' session at BSides Tampa Check out the Events page for the link to those slides as well as videos/slides from previous talks. zerotrustplaybook.com/events/ 110
Mark Simos @markasimos.bsky.social · 15/05/2026Just putting the finishing touches on slides for my BSides Tampa talk "Security is a Team Sport ... but we are NOT playing as a team" Hope to see you there on Saturday! 110
Mark Simos @markasimos.bsky.social · 12/05/2026"Somebody should do this" means "Nobody will do this" unless you assign a name. 000
Mark Simos @markasimos.bsky.social · 10/05/2026I just posted the slides for my BSides South Florida talk on the events page zerotrustplaybook.com/events/ 110
Mark Simos @markasimos.bsky.social · 04/05/2026I recently did an interview-style session for an internal Microsoft team on why end to end security is so important and thought I would share my notes on the points to cover. 🧵 100
Mark Simos @markasimos.bsky.social · 03/05/2026Each day is life www.linkedin.com/pulse/each-d...linkedin.comEach day is lifeEach day the eyes open Each day may bring work or reward or both Each day is surviving and maybe thriving Each day may be routine or an adventure to explore Each day is putting one foot in front of th... 000
Mark Simos @markasimos.bsky.social · 03/05/2026The Zero Trust Playbook site is live! It currently has a summary of the series, the outline of the first book, some information on the authors, and an events page with upcoming events and recordings. Much more to come in time! 110
Mark Simos @markasimos.bsky.social · 30/04/2026The full length video has been posted for the announcement of the security roles and glossary standard! ◾ Video - www.youtube.com/watch?v=bMRr... ◾ Slides - www.slideshare.net/slideshow/se... 100
Mark Simos @markasimos.bsky.social · 29/04/2026Are the people in your organization rewarded to ignore security? 110
Mark Simos @markasimos.bsky.social · 28/04/2026One of the statements that really stuck with me from this episode was around the 'advanced persistent threat' terminology. Paraphrasing - the persistence is more important to attacker success than the advanced. I definitely recommend listening thecyberwire.com/podcasts/aft... 010
Mark Simos @markasimos.bsky.social · 24/04/2026The full length video has been posted for the Security and Zero Trust body of knowledge session! www.youtube.com/watch?v=WaF6...youtube.comSecurity and Zero Trust Body of KnowledgeYouTube video by The Open Group 100
Mark Simos @markasimos.bsky.social · 31/03/2026AI Inherits speed and scale from the GPUs it runs on, but it inherits unpredictability from the (social) human data it was trained on. a short 🧵 110
Mark Simos @markasimos.bsky.social · 23/03/2026What does a CEO need to know about cybersecurity? See the (draft) Security Roles and Glossary standard for what knowledge, skills, & abilities are required of CEOs, board members, and other leaders (as well as accountabilities, fiduciary duty, & more). publications.opengroup.org/s252 010
Mark Simos @markasimos.bsky.social · 16/03/2026Cybersecurity is often incorrectly seen as a 'technical problem' that can be 'solved' (it isn't!) by business leaders & others. *Security is an ongoing risk that requires ongoing work.* Security leaders often accidentally create or reinforce this misperception. a short 🧵 100
Mark Simos @markasimos.bsky.social · 14/03/2026Think security can do it all on our own? WRONG! We must recognize that we are part of a larger team and each of us has a different part to play in protecting the organization. short 🧵 110
Mark Simos @markasimos.bsky.social · 13/03/2026Want to lead Zero Trust marketing at Microsoft? apply.careers.microsoft.com/careers/job/...apply.careers.microsoft.comSenior Product Marketing Manager | Microsoft CareersPartner with Product Management and Engineering to shape the Zero Trust for AI product strategy, roadmap alignment, and customer-facing vision. * Lead cross-portfolio Zero Trust messaging and position... 010
Mark Simos @markasimos.bsky.social · 13/03/2026The video for my 'What's my job again' talk from BSides Tampa has posted Video - www.youtube.com/watch?v=uVAA... Slides - www.slideshare.net/slideshow/wh... Roles standard - publications.opengroup.org/s252 100
Mark Simos @markasimos.bsky.social · 10/03/2026Ever been tempted to call people "stupid users" because they make a basic security or technology mistake? I would advise against saying this and encourage you to change your thinking patterns. A short 🧵 110
Mark Simos @markasimos.bsky.social · 07/03/2026I recently realized that the 'autonomous SOC' idea is the same old snake oil packaged up with a fancier and more intellectual-sounding name The 'technology can prevent attacks / stop breaches' claim that has been disproven over and over (similar to compliance claims) a 🧵 110
Mark Simos @markasimos.bsky.social · 26/02/2026I am excited to talk about one of my favorite topics at BSides Tampa on May 16! *Security is a team sport (and we are NOT playing like a team)* 110
Mark Simos @markasimos.bsky.social · 09/02/2026Pursuing perfect solutions is a perfect waste From Chapter 6 - How to Scope, Size, and Start Zero Trust (Page 78) of www.amazon.com/Zero-Trust-O... 🧵 100
Mark Simos @markasimos.bsky.social · 08/02/2026Security is often incorrectly perceived as a 'technical problem' that can be 'solved' (it isn't!) by business leaders. *Security is an ongoing risk that requires ongoing work.* This misperception is often accidentally created or reinforced by the security team. 🧵 110