Nice quote on security governance of AI

August 20, 2024

Came across this gem from LinkedIn Learning course by Lyron Andrews.

AI doesn't correct poor governance it simply accelerates existing behavior

Read More

Analogy for Generative AI vs Discriminative AI

August 20, 2024

I've recently been studying ISO/IEC 42001:2023 and came across a great LinkedIn Learning course by Lyron Andrews.

Among the many noteworthy points, Lyron summed the differences well between "Generative AI" learning models and "Discriminative AI" models:

A helpful analogy is that a generative . . .

Read More

OWASP Cheat Sheet Series

May 22, 2024

I stumbled across this amidst some prior training and thought I'd pass it along. OWASP has a fantastic collection of AppSec cheat sheets here.

A zip archive of all the cheat sheets is available for download here.

Read More

Security Certification Roadmap

December 14, 2023

Wow! Check out this awesome cybersecurity security infographic by Paul Jerimy. Original source here.

Silvrback blog image

Read More

Microsoft Storm-0558 Attack Analysis

September 30, 2023

I meant to post this earlier but got distracted by a few other things. Yay for busy life, right?

Earlier this month Microsoft concluded their investigation of the recent Storm-0558 email compromise/attack and the results are... fascinating. I highly recommend checking out the blog post when you get a chance. It's available here. . . .

Read More

[SC-100] Conditional access "what if" tool

More security controls in the market need a feature like this.

August 16, 2023

I'm digging the "What If" tool in Azure Conditional Access component. The idea is simple: as you're building policies, you can throw various scenarios at the policy engine to understand what the heck it'll do.

This gives admins the opportunity to observe effects and perhaps test variations of authentication use . . .

Read More

[SC-100] Sensitive Operations Report Workbook

August 16, 2023

Just a friendly reminder that the Microsoft sensitive operations report workbook exists and can be super helpful.

For those unfamiliar, it's an Azure Monitor workbook designed to capture activities/events that could be critical or impactful for Azure AD. Examples include:

  • Modified application and service . . .

Read More

Archive
   Subscribe by email and never miss a post.

This update link alerts you to new Silvrback admin blog posts. A green bubble beside the link indicates a new post. Click the link to the admin blog and the bubble disappears.

Got It!