Author Archives: Rafeeq Rehman

About Rafeeq Rehman

Consultant, Author, Researcher.

Verizon Data Breach Digest – A Must-Read for CISOs

Data Breach Digest is the latest report from Verizon RISK team. This is the same Verizon team that publishes Verizon Data Breach Investigations Report or more commonly known as DBIR. The main idea behind the Data Breach Digest is to … Continue reading

Posted in InfoSec | Comments Off on Verizon Data Breach Digest – A Must-Read for CISOs

A Three-Step Approach to Build IoT Business for Manufacturers

Manufacturers have been building products (or things) for a very long time. A major shift is in the competitive landscape is about making these products or things “smart”. Now, people not only need a light bulb, but they want a … Continue reading

Posted in IoT | Tagged , | Comments Off on A Three-Step Approach to Build IoT Business for Manufacturers

Internet of Things (IoT) and Why It Matters Now

IoT is all about connecting devices and machines to the Internet who can talk to each other, collect and share data, analyze the data, and bring business value out of data analytics. A fair argument is that we have been … Continue reading

Posted in InfoSec | Tagged , , | Comments Off on Internet of Things (IoT) and Why It Matters Now

How to separate learning myths from reality | McKinsey & Company

How brain works? can we learn after childhood? What is our mental capacity? What are the myths and what is reality? This article from McKinsey & Company sheds some light on these questions. “Misconceptions about the brain are embedded in … Continue reading

Posted in Leadership | Comments Off on How to separate learning myths from reality | McKinsey & Company

SDN Impact on Information Security

Software Defined Networking or SDN brings a paradigm shift and new promises about how networks are designed and operated. The biggest change is separating the control plane from the data forwarding plane, which, in the current network paradigm are tied … Continue reading

Posted in InfoSec | Tagged | Comments Off on SDN Impact on Information Security

The Latest 2015 CISO Mind Map is here!

Note: There is an updated CISO Mind Map for 2018 on this URL As the InfoSec landscape changes constantly, so do the responsibilities of a CISO. Virtual Security Appliances are becoming more common in the Cloud environment. Similarly IoT and … Continue reading

Posted in cisomindmap, InfoSec | Tagged , , , | Comments Off on The Latest 2015 CISO Mind Map is here!

A Quick Overview of Verizon 2015 DBIR – DBIR15

The Verizon 2015 DBIR just released today, and as someone said. It is “the best” DBIR ever. The report provides a number of important findings and new data analysis especially around the cost of data breaches. The report contains analysis … Continue reading

Posted in InfoSec | Tagged , , , | Comments Off on A Quick Overview of Verizon 2015 DBIR – DBIR15

A take on information security reports

There are almost as many information security reports out there as the number of security vendors. Keeping up to date about these reports could be a challenge and sometimes these reports may become an information overload for security professionals. Verizon … Continue reading

Posted in InfoSec | Tagged , , | Comments Off on A take on information security reports

Using SWOT Analysis to Create InfoSec Strategy

SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis is an industry standard way of analyzing current situation (marketing, business strategy, risk assessment, etc). In many cases, SWOT analysis provides foundation for creating business strategy. Following is a short description of how we … Continue reading

Posted in InfoSec, Leadership | Tagged , , | Comments Off on Using SWOT Analysis to Create InfoSec Strategy

The Bare Minimum Business Terminology Every InfoSec Professional Must Know

The role of CISO, and other InfoSec professionals, has morphed into a critical business function. One should expect getting involved in “business” discussion often, and at higher levels. Understanding and speaking business language is more important than ever for success … Continue reading

Posted in InfoSec, Leadership | Tagged , | Comments Off on The Bare Minimum Business Terminology Every InfoSec Professional Must Know