Sign in

Mark Simos

@markasimos.bsky.social
570 followers 11 following 740 posts

Lead Cybersecurity Architect • Executive and Board Advisor • Keynote Speaker • Professional Storyteller www.youtube.com/@MarkonCybersecurity

PostsRepliesMedia
Mark Simos @markasimos.bsky.social · 04/10/2026
Note: This is part of the first videos on the channel on basic cybersecurity assumptions & definitions that are different from what many people were taught so I don't have to keep re-explaining these in later videos on advanced topics. www.youtube.com/watch?v=iOfg...
youtube.com
Cybersecurity Explained
YouTube video by Mark Simos
000
Mark Simos @markasimos.bsky.social · 04/10/2026
I talk about this more in my "Cybersecurity Explained" video in my new YouTube channel including the 'infinite playlist dynamic', the different security disciplines that must work together, and more.
100
Mark Simos @markasimos.bsky.social · 04/10/2026
Ideally we are so successful at cybersecurity that attackers give up and open a fruit stand, but that is pretty unlikely so let's stay practical and focus on increasing their failure / decreasing their success.
100
Mark Simos @markasimos.bsky.social · 04/10/2026
'Attacker failure' is driving up cost and friction to remove the cheap, easy, and reliable attack techniques from their menu with both effective prevention and response (and working as a team to help everyone get better)
100
Mark Simos @markasimos.bsky.social · 04/10/2026
What is success in cybersecurity? Rapid incident response and remediation? Preventing things from going bump in the night? Both of are part of it as they contribute to overall security success of attacker failure. Video - www.youtube.com/watch?v=iOfg...
100
Mark Simos @markasimos.bsky.social · 03/10/2026
We must understand why these humans do what they do, what they are after, how they operate to achieve their goals, & the consistent attack methodology they use across attacks and attack techniques (plan, enter, traverse, execute objectives). video here - www.youtube.com/watch?v=fgPv...
youtube.com
Know Your Attacker
YouTube video by Mark Simos
000
Mark Simos @markasimos.bsky.social · 03/10/2026
Attack operators are humans - creative and intelligent humans with motivations, habits, strategies, and operating models that guide who they attack and how they attack.
100
Mark Simos @markasimos.bsky.social · 03/10/2026
Understanding and predicting attacker behavior requires much more than just the techniques that attackers use (or that they use AI/Agents to automate)
100
Mark Simos @markasimos.bsky.social · 03/10/2026
ATT&CK does an awesome job of driving a standard language and taxonomy for the proven technical attack techniques (even though it has never become a formal 'standard') but... ⬇️
100
Mark Simos @markasimos.bsky.social · 03/10/2026
I love MITRE ATT&CK …but it doesn't tell the whole story I recently published a video on YouTube describing a 3-D view of adversaries we face, how it relates to & expands on ATT&CK (+ legacy Lockheed Martin kill chain), & how they are using AI today. www.youtube.com/watch?v=fgPv...
110
Mark Simos @markasimos.bsky.social · 27/09/2026
This is captured in a 'tale of two systems' diagram in the Microsoft Security Adoption Framework (SAF) documentation - learn.microsoft.com/en-us/securi...
learn.microsoft.com
Integrate OT/IoT security into the Infrastructure/Networking discipline
Use the Microsoft security adoption model to secure OT/IoT assets and resources across the business, based on Zero Trust principles.
000
Mark Simos @markasimos.bsky.social · 27/09/2026
An expensive piece of equipment that can't be secured (patched/etc.) creates a business disruption and risk later in life when support runs out. Avoiding requires security requirements/mitigations in contract negotiations (when vendor is willing to concede things to close a sale)
100
Mark Simos @markasimos.bsky.social · 27/09/2026
One way to visualize why organizations must view IT systems as business assets, must own all the risks including security, and must shift security integration left is to take a long view over the asset's lifetime.
100
Mark Simos @markasimos.bsky.social · 25/09/2026
➕ A 'tale of two cities' style case study of doing security right/wrong ➕ Aome age of empires 2 references ➕ ...and a bunch more.
000
Mark Simos @markasimos.bsky.social · 25/09/2026
This talk covered ➕ Hard-won career tips and learnings for practitioners and leaders ➕ Security roles and responsibilities ➕ How to avoid the blame game that undermines everything security does ➕ A whole bunch of security antipatterns
101
Mark Simos @markasimos.bsky.social · 25/09/2026
The recording for "Security is team sport, but we aren’t planning like a team" is now live! Recording - www.youtube.com/watch?v=l0cC... Slides - www.slideshare.net/slideshow/se...
100
Mark Simos @markasimos.bsky.social · 22/09/2026
I also describe the main attack/kill chains and relative advantages/limitations of each
000
Mark Simos @markasimos.bsky.social · 22/09/2026
I recently released a new video "Know Your Attacker" that covers who the attackers we face are, why they do it, and how they approach attack operations (including how they are using generative AI today), and what this means for you. www.youtube.com/watch?v=fgPv...
100
Mark Simos @markasimos.bsky.social · 21/09/2026
► Key principles and guiding commandments ► How it looks different to a business leader, security/technology leader, or security/technology practitioner ► Real world examples
000
Mark Simos @markasimos.bsky.social · 21/09/2026
I just released a new video "Zero Trust Explained" www.youtube.com/watch?v=6bqf... It covers ► What Zero Trust is (fixing broken assumptions from classic security) ► How this concept evolved, how Zero Trust is required for AI security (and is accelerated by AI) ⬇️
101
Mark Simos @markasimos.bsky.social · 18/09/2026
6:10 Prevent, Respond, and Learn Across the Lifecycle 9:15 Build Organizational Resilience 11:10 Use End-to-End Security Architecture 15:15 Focus on People, Teamwork, and Continuous Adaptation 🔚
000
Mark Simos @markasimos.bsky.social · 18/09/2026
This is a pretty short video that hits on stuff that some folks get wrong (or were never taught): 0:00 Cybersecurity Explained 0:11 Threat Actors, Attack Operations, and Business Risk 4:20 Security Success Means Attacker Failure ⬇️
100
Mark Simos @markasimos.bsky.social · 18/09/2026
One of the first videos I posted is "Cybersecurity explained" that covers the basics of what cybersecurity is, what success looks like (attacker failure), and what it takes to build organizational resilience www.youtube.com/watch?v=iOfg...
youtube.com
Cybersecurity Explained
YouTube video by Mark Simos
100
Mark Simos @markasimos.bsky.social · 13/09/2026
I have a bunch of ideas in the works, but I am also very interested in hearing what you want me to cover so send me questions, suggested topics, etc.
001
Mark Simos @markasimos.bsky.social · 13/09/2026
I will mostly share what I have learned over the years about cybersecurity as well as how I turn these learnings into actionable guidance through professional storytelling, share some career tips and advice, and other stuff I have learned along the way.
100
Mark Simos @markasimos.bsky.social · 13/09/2026
The plan for my little corner on YouTube is to share what I have learn about making the complex topic of cybersecurity simple, clear, and practical. There are no ads or sponsorship, it’s just me. Feel free to subscribe.
100
Mark Simos @markasimos.bsky.social · 13/09/2026
I've been a little bit quiet lately because I've been (re)building my YouTube channel - Mark on Cybersecurity I just posted the first 3 new videos. Share and Enjoy! MarkonCyber.com
110
Mark Simos @markasimos.bsky.social · 04/09/2026
◾ AI-Driven Attacks and Software Exploitation (Mythos, MDASH and More) ◾ AI and Zero Trust ◾ Speaking to the Board about Security ◾ DevSecOps and Zero Trust ◾ Making Decisions using CRQ: Applying the Open FAIR™ Methodology to Zero Trust Implementation
000
Mark Simos @markasimos.bsky.social · 04/09/2026
◾ Who are They, and Why are They Attacking Us?: Building Realistic Requirements for Security with the Security Matrix Standard ◾ Building Security into your Organization: Security Principles for Architecture and the Zero Trust Commandments
100
Mark Simos @markasimos.bsky.social · 04/09/2026
Sessions include: ◾ A Unified Set of Standards for Security: Security and Zero Trust Body of Knowledge ◾ Security is EVERYONE’S Job: The Security Roles and Glossary Standard
100
Mark Simos @markasimos.bsky.social · 04/09/2026
I am really looking forward to talking about this work and how you can use it with the other folks who have been doing a lot of work to shape this with their experience including Hasan Yasar Nikhil Kumar Tony Carrato and John Linford
100
Mark Simos @markasimos.bsky.social · 04/09/2026
Hey all, I recorded a short video with a preview of the sessions and standards we will talking about at the FREE Security Forum event in Arlington, VA (near Washington DC) meet.opengroup.org/event/cbab26... Registration closes September 7 Would love to see you there!
100
Mark Simos @markasimos.bsky.social · 03/09/2026
This event is: ◾ Coming soon - Registration closes September 7 ◾ FREE - No charge, but only 75 seats available and they are filling up ◾ Vendor-neutral (not focused on Microsoft or any other security vendor)
000
Mark Simos @markasimos.bsky.social · 03/09/2026
Come hear the authors in speak in person (and ask them questions) on the upcoming Security Matrix standard. We will be live at the upcoming Security Forum event in Washington DC on September 15-17. (technically Arlington, VA) Agenda & register here - meet.opengroup.org/event/cbab26...
100
Mark Simos @markasimos.bsky.social · 01/09/2026
This is the inaugural Security Forum event with 2 days of interactive presentations from the authors of the standards (including myself) who are turning our scars and experience into scalable solutions. The 3rd day is for open group members to continue working on these standards
000
Mark Simos @markasimos.bsky.social · 01/09/2026
If you are in the Washington DC area, you are invited to a free vendor-neutral event focused on the toughest cybersecurity challenges Sep 15-17 aka.ms/TOGevent I would love to see you all there!
100
Mark Simos @markasimos.bsky.social · 30/08/2026
Our eternal goal as defenders is to find the cheapest and easiest defenses that add cost, difficulty, uncertainty so we can slow them down and on a good day - stop them entirely. Learn and think about what they require to succeed, what they prefer, and how to disrupt those.
000
Mark Simos @markasimos.bsky.social · 30/08/2026
2. They have some sort of plan or operating model to get benefit from a successful attack 3. They have to navigate a journey to do this and prefer the cheapest, easiest, and most reliable way to get the job done
100
Mark Simos @markasimos.bsky.social · 30/08/2026
We must take them time to learn about and understand them, their motivations, and their methods. Regardless of their use of AI, old skool attacks, social/phishing, etc. there are truths that don't change: 1. They want access to your goodies (business assets) for some reason
100
Mark Simos @markasimos.bsky.social · 30/08/2026
One of the things its easy to forget about cybersecurity is that our adversaries are creative and intelligent humans with goals, talents, preferences, limitations, blind spots, etc. just like us.
100
Mark Simos @markasimos.bsky.social · 23/08/2026
I am going to be talking on just about every aspect of security in person over 2 days at the free security forum event from The Open Group You can register for FREE for this Washington DC event here: meet.opengroup.org/event/cbab26... Would love to see you there!
◾ A Unified Set of Standards for Security: Security and Zero Trust Body of Knowledge
◾ Security is EVERYONE’S Job: The Security Roles and Glossary Standard
◾ Who are They, and Why are They Attacking Us?: Building Realistic Requirements for Security with the Security Matrix Standard
◾ Building Security into your Organization: Security Principles for Architecture and the Zero Trust Commandments
◾ AI-Driven Attacks and Software Exploitation (Mythos, MDASH and More)
◾ AI and Zero Trust
◾ Speaking to the Board about Security
◾ DevSecOps and Zero Trust
◾ Making Decisions using CRQ: Applying the Open FAIR™ Methodology to Zero Trust Implementation
000
Mark Simos @markasimos.bsky.social · 20/08/2026
New headshot! Who dis? Time catches up with us all. I didn't quite realize how old my headshot was (circa 2012) until I calculated that one of my teenage kids wasn't even born when my last headshot was taken. 😂
011
Mark Simos @markasimos.bsky.social · 20/08/2026
𝗪𝗵𝗲𝗻 - Sep. 15-17, 2026 𝗪𝗵𝗲𝗿𝗲 - SEI Carnegie Mellon University - 4301 Wilson Boulevard, Suite 200 - Arlington, Virginia 22203, USA
000
Mark Simos @markasimos.bsky.social · 20/08/2026
This work fixes fundamental root causes of cybersecurity that still plague us in today's age of AI (and will also directly cover AI security of course 😊). Nothing is sacred and no problems without solutions (even if the solutions are hard). It will be a blast! Looking forward to seeing you there!
110
Mark Simos @markasimos.bsky.social · 20/08/2026
Join me in person for a full-day vendor-neutral FREE security event! We are holding the inaugural Security Forum event in Arlington, VA to share the work we are doing at The Open Group. You can access the agenda and register here: meet.opengroup.org/event/cbab26...
meet.opengroup.org
Home - The Open Group Security Forum
Join us at The Open Group events covering topics from Enterprise Architecture, AI, Digital Transformation, Open Standards, Cybersecurity, and more. Register Today!
131
Mark Simos @markasimos.bsky.social · 19/08/2026
(free registration required, but no paywall and no advertising)
000
Mark Simos @markasimos.bsky.social · 19/08/2026
Think of this as the 'checklist' of criteria that board members should be using to examine the program with their expertise and experience. This also serves as a north star for the organization's management to focus on across business, technology, and security teams.
100
Mark Simos @markasimos.bsky.social · 19/08/2026
What should a board be looking for in their oversight of security management? What does good look like? The Open Group provides a standard definition as part of the accountabilities of board members - see Part 3.1 of publications.opengroup.org/s252
100
Mark Simos @markasimos.bsky.social · 15/08/2026
(Admittedly its easier to convince an airline pilot who would be part of a crash vs. convincing people about a more abstract business loss from security incident, even when they own it.) End 🧵
000
Mark Simos @markasimos.bsky.social · 15/08/2026
This is a good model for an empowered decision makers in the business that manage the balance between productivity/revenue/mission (on time departures, getting people where they need to go, etc.) and safety/security of people and assets.
100