Andre Smith's Avatar

Andre Smith

@andresmith-sec.bsky.social

Hacking systems to stop hackers, before they strike. 25 years experience in cybersecurity. CEO & Director of Technology for AMEOT. Real proactive security is detection-less. www.ameot.com

21 Followers  |  19 Following  |  59 Posts  |  Joined: 14.11.2024  |  1.6951

Latest posts by andresmith-sec.bsky.social on Bluesky

Nice. Yes, AI can be a bit funny like that.

06.05.2025 18:45 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The cover invokes so many questions. It definitely beckons the inquisitive reader.

07.01.2025 14:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Speed is greatโ€”until it skips security. Fast deployments often skip critical security steps. Is your rush to innovate opening the door for attackers? Are you trading safety for speed?

11.12.2024 21:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

High cost โ‰  high tech. The most expensive tools often rely on old tech with new marketing. Expensive โ‰  innovative. Are you paying for innovation or legacy systems in disguise? Know your tools, not just your brands.

11.12.2024 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Detection tools miss the unknown. How are you defending the future? Detection tools only recognize known patternsโ€”zero-days go undetected. Are you stuck reacting with yesterday's threat intelligence? Get Proactive.

11.12.2024 17:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Costly detection based tools still cry wolf. Are your teams chasing noise? False positives still plague even the priciest tools, draining your teamโ€™s time and energy. False positives = wasted time. Are you paying more for more alerts? Are your most expensive tools solving or creating problems?

11.12.2024 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

AI + humans = success. Are you underestimating the human element? Automation supports humans, it doesnโ€™t replace them. No one wants to rely on a company that is more robotic than human. Don't trade talent for tools it creates gaps in your operations and defenses.

10.12.2024 21:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

ML โ‰  magic. Machine learning models rely on quality data. Are you feeding your tools the data they need? Are you maintaining your tools or leaving them blind? ML needs data, not assumptions, how well-fed is your model?

10.12.2024 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Are you trusting AI without understanding its foundation? Big data alone โ‰  smart decisions any more than more data (quality excluded) โ‰  better results. Are your tools making you safer or are they just busy massaging heaps of less than useful data?

10.12.2024 17:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Are you ready for the unknown? Detection based tools are designed to find the known threats, unknown threats are often blind spots. What about threats your tools canโ€™t see? Get Proactive! Detection only works after the fact.

10.12.2024 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A bigger budget, alone, doesnโ€™t stop breachesโ€”it just makes failure more costly. Are you focusing on the price of your tools or creating an effective strategy? Are you investing for bragging rights or to solve the right problems? Seek results!

09.12.2024 21:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Proactive โ‰  reactive. Detection tools only react after a threat is presentโ€”AI doesnโ€™t make them proactive. Are you confusing speed with prevention? AI speeds reaction, but it canโ€™t prevent presence. Is your AI-driven tool just faster at playing catch-up? AI โ‰  proactive.

09.12.2024 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

High cost โ‰  high security and expensive tools โ‰  foolproof security. Every year we spend more, only to have the rate of successful attacks rise. Results should overshadow price tag, otherwise, your just buying great branding, which also โ‰  great security. Seek results!

09.12.2024 17:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Because that would be badโ€ฆright?

08.12.2024 23:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISOs arenโ€™t there to clean up breachesโ€”theyโ€™re there to stop them before they happen. Are you treating security as an afterthought? #CyberSecurity #ProactiveDefense

07.12.2024 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISOs drive business strategy, not just IT. Are you underestimating their authority by treating cybersecurity as an IT issue instead of a business priority? #Leadership #CyberSecurity #Strategy #RiskManagement

06.12.2024 21:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISO life = strategy+ risk management, not โ€œhackers vs. CISOs.โ€ A CISOโ€™s day isnโ€™t Hollywood-style hacking. Are you glamorizing the grind while ignoring its complexity? #CyberSecurity #Leadership

06.12.2024 19:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is very interesting. When I first read your post I thought it was a new cybersecurity issue, but it seems more like a securities issue based on concise terminology. We donโ€™t spotlight the AI and ML in our solution because it is reactive and we focus more on promoting our proactive tools.

06.12.2024 18:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Key risk trends for Directors and Officers in 2025: โ€˜AI washingโ€™ is an emerging risk: resilienceforward.com/key-risk-tre...

#RiskManagement

06.12.2024 16:47 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Compliance is the floor, not the ceiling. CISOs are there to protect your business, not just check boxes. Compliance โ‰  security. Are you focused on protection or just policies? #CyberSecurity
#Compliance #Leadership

06.12.2024 17:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISOs worry just as much about insider threats, supply chain risks, and human error. External attackers arenโ€™t the only threat. Does your CISO have full visibility? #CyberSecurity #RiskManagement #Leadership

06.12.2024 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISOs guide the organization, however, security is everyoneโ€™s job. Although the responsibility is shared, the CISO gets all the blame. Are you helping or blaming? #CyberSecurity #Board #TeamWork

05.12.2024 21:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISOs arenโ€™t magicians. Expecting a CISO to secure your organization with an inadequate budget is like asking for a skyscraper on a shedโ€™s budget. CISOs need resources, not miracles. #SmartSpending #Cybersecurity #Budget

05.12.2024 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

CISO = tech + strategy + leadershipโ€”itโ€™s aligning security strategy with business goals. A CISOโ€™s role isnโ€™t just tech. Are you underestimating their value? Or do you see their impact on your organizationโ€™s future? #Leadership #CyberSecurity #CISO .

05.12.2024 17:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is a baseline problem that can be solved by training and better lines of communications. How many times do we see companies shotgunning communications via email without notice or follow up, it desensitizes the employees to validating the messaging they receive due to email fatigue.

05.12.2024 16:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Novel phishing campaign uses corrupted Word documents to evade security A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but...

A new phishing campaign discovered by malware hunting firm Any.Run utilizes intentionally corrupted Word documents as attachments in emails that pretend to be from payroll and human resources departments.
www.bleepingcomputer.com/news/securit...

02.12.2024 19:20 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
The UK is 'widely' underestimating online threats from hostile states and criminals, cyber security chief warns The NCSC's incident management team was required to provide support in response to 430 cyber attacks over the past year - up from 371 in 2023.

This is so true. Most companies don't have an understanding of what risks are out there or they think it will never happen to them. Business leaders need to be looking at these risks and taking steps to be more secure.

news.sky.com/story/the-uk...

#infosec #cybersecurity #informationsecurity

03.12.2024 06:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Have I Been Pwned: Check if your email has been compromised in a data breach Have I Been Pwned allows you to search across multiple data breaches to see if your email address or phone number has been compromised.

It's really worth doing a review of your personal online accounts on a regular basis. Have check of the email address you use on haveibeenpwned.com, check for new security settings that you might want to enable. One little tweak might just prevent an account being compromised.

#cyberawareness

03.12.2024 07:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@andresmith-sec is following 18 prominent accounts