Jess Figueras's Avatar

Jess Figueras

@jessfigueras.bsky.social

Cybersecurity, data, risk & governance, civil society. Co-founder of Cyber Governance for Boards(CxB). Other stuff. Also music-ing.

323 Followers  |  794 Following  |  198 Posts  |  Joined: 08.08.2023  |  2.0929

Latest posts by jessfigueras.bsky.social on Bluesky

Encountered quite a convincing scam tonight.

Nice Geordie lady called, apparently from my credit card company - flagging suspicious activity and asking me about transactions and logins that sounded off. Nice and detailed, professional tone. She read me the last 4 digits of my card number.

21.05.2025 21:08 β€” πŸ‘ 75    πŸ” 43    πŸ’¬ 13    πŸ“Œ 6

As if it's an official source which can be held accountable

18.05.2025 16:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Hell yeah!

17.05.2025 07:25 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Nice

16.05.2025 18:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I mean maybe the policy is about preparing kids to read increasingly miserable news headlines with equanimity. We could all do with a bit of that. Stiffen the upper lip as we pick up the morning Guardian or Telegraph.

16.05.2025 18:09 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If you see this, quote with the energy you bring to Bluesky

16.05.2025 17:43 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
EU ruling: tracking-based advertising by Google, Microsoft, Amazon, X, across Europe has no legal basis EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and ...

Big news this evening

This EU ruling has been 7 years in the making

www.iccl.ie/digital-data...

14.05.2025 18:55 β€” πŸ‘ 563    πŸ” 277    πŸ’¬ 15    πŸ“Œ 45
A large number of security alerts

A large number of security alerts

A really emotional and inspiring story of burnout and recovery from Andrew Barber. Jobs which look like this πŸ‘‡ 24x7 take a serious toll on cyber professionals. Our digital first responders should not need to be heroes and organisations must take care of them

#whitehallgovsec

15.05.2025 13:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Data Security and Protection Toolkit (DSPT) for Care Providers
What it is: A self-assessment tool mandated for all NHS partners, including adult social care providers. The ASC version is tailored to care provider's operational conditions and regulatory requirements. It is accompanied by the Better Security, Better Care programme

Data Security and Protection Toolkit (DSPT) for Care Providers What it is: A self-assessment tool mandated for all NHS partners, including adult social care providers. The ASC version is tailored to care provider's operational conditions and regulatory requirements. It is accompanied by the Better Security, Better Care programme

Cyber security of the social care sector was immature and unsophisticated until recently, says Michelle Corrigan. But the DSPT has changed that

#whitehallgovsec

15.05.2025 13:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Panel speakers listen to questions from the audience

Panel speakers listen to questions from the audience

Question from the audience: our CEO wants to know when cyber security will stop being a top red risk, given all our efforts to reduce the risk score. What do I say?

Answer: it will always be a top red risk. Tell your CEO to accept the new reality.

#whitehallgovsec

15.05.2025 13:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

As M&S approaches a month offline, business continuity is on everyone’s mind. David Leech says you need to define your MVP: Minimum Viable Company

#whitehallgovsec

15.05.2025 11:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

(Have just committed the conference chair’s cardinal sin by wrongly announcing lunch 1 hour early. The last morning speakers are now under extreme pressure to be even more compelling than lunch.)

#whitehallgovsec

15.05.2025 11:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
The threat to government security
National Audit Office
β€’ The size, age and diversity of government's digital estate makes it challenging to be cyber resilient
β€’ The threat is rapidly evolving and is the most sophisticated it has ever been
β€’ Cyber attacks routinely target government organisations and can have devastating effects on public services and people's lives

The threat to government security National Audit Office β€’ The size, age and diversity of government's digital estate makes it challenging to be cyber resilient β€’ The threat is rapidly evolving and is the most sophisticated it has ever been β€’ Cyber attacks routinely target government organisations and can have devastating effects on public services and people's lives

A pithy summary of the problem for government from Jonathan Pownall

#whitehallgovsec

15.05.2025 10:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

You’ve got to get your board on board, says Richard Pilkington. YES!!! This is the cyber governance structure at Clatterbridge Cancer Centre NHS trust.

#whitehallgovsec

15.05.2025 09:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Picture of Andrew Dillon

Picture of Andrew Dillon

More on risk prioritisation: Andrew Dillon says we shouldn’t treat users as alike when it comes to human risk. Different groups have different skills, roles, permissions etc.

Food for thought as most organisations roll out universal cyber awareness training!

#whitehallgovsec

15.05.2025 09:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Curious - how did the BBC verify that they were genuinely speaking with the criminal gang responsible?

Plus, I would not be making confident statements about someone’s English language proficiency based on a text conversation !

Reporting on stories like this is a minefield, IMHO

15.05.2025 09:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
The Problem:
Most organisations cannot accurately identify which suppliers pose the greatest risk and traditional assessments focus on tier-1 suppliers and procurement value.
IDENTIFY
The Solution:
β€’ A multi-dimensional risk profiling approach that considers:
β€’ Access to sensitive systems/data
β€’ Integration depth and privileges
β€’ Substitutability and concentration risk
β€’ Geographical/jurisdictional factors
How to begin? Start by mapping your suppliers against these four dimensions.

The Problem: Most organisations cannot accurately identify which suppliers pose the greatest risk and traditional assessments focus on tier-1 suppliers and procurement value. IDENTIFY The Solution: β€’ A multi-dimensional risk profiling approach that considers: β€’ Access to sensitive systems/data β€’ Integration depth and privileges β€’ Substitutability and concentration risk β€’ Geographical/jurisdictional factors How to begin? Start by mapping your suppliers against these four dimensions.

We should require higher levels of security assurance from higher risk suppliers, points out Andy Simpson. Unfortunately, procurement teams define high risk as β€˜large contract size’ rather than looking at what the supplier is actually doing!

#whitehallgovsec

15.05.2025 09:07 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Slide reads: β€œNORMALISATION OF DEVIANCE. Permeates into the organisation becoming acceptable to simply accept risk without knowing even what it is let alone effectively managing it”

Slide reads: β€œNORMALISATION OF DEVIANCE. Permeates into the organisation becoming acceptable to simply accept risk without knowing even what it is let alone effectively managing it”

Chairing #whitehallgovsec again today. Stuart Frost observes that organisations’ lack of action on supply chain security means we’ve accepted the risk without even knowing anything about it

15.05.2025 08:40 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Lol

12.05.2025 07:44 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Embrace it. It’s a socially sanctioned way for us to say that people who are older or younger than us are dreadful

07.05.2025 07:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

See you there!

06.05.2025 18:08 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Get off social media and do more of this sort of thing. The world would be a better place if we did

05.05.2025 10:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Yes. The weekend FT is also reaching new levels of silly. I suppose it’s all cope for the geopolitically-terrified.

26.04.2025 11:14 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I guess George Osborne’s experience with the β€˜pasty tax’ put politicians off … but I’m surprised by enduring lack of action on alcohol. Given public awareness of harms is growing, feels like the right time to tackle it

26.04.2025 08:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Movie you’ve watched more than six times using gifs. (β€œHard mode” no Star Wars, Star Trek, or LOTR).

26.04.2025 07:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Ohhh yes. I am still awaiting my opportunity to say β€œforgot to give you something…” to someone awful

26.04.2025 07:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Best film EVER

26.04.2025 07:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

The best thing I've seen all week

25.04.2025 13:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Sounds like a cheery read

25.03.2025 20:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
A three part cartoon. In the first part it shows a sad engineer looking at a big rubbish pile of tech complexity in the way of building apps

In the second part it has the title "What people think AI will do" with a Happy Non-Engineer on the left, a bubble with "AI!" then a rubbish pile titles "Hidden pile of complexity that no longer matters", then the Apps on the right again.

In the final part, titled "What is actually going to happen" is a sad engineer on the left. A new rubbish pile of complexity (AI pipelines, templates etc), then the AI bubble, then the old pile of complexity with two sadder engineers looking over it, then the apps on the far right

A three part cartoon. In the first part it shows a sad engineer looking at a big rubbish pile of tech complexity in the way of building apps In the second part it has the title "What people think AI will do" with a Happy Non-Engineer on the left, a bubble with "AI!" then a rubbish pile titles "Hidden pile of complexity that no longer matters", then the Apps on the right again. In the final part, titled "What is actually going to happen" is a sad engineer on the left. A new rubbish pile of complexity (AI pipelines, templates etc), then the AI bubble, then the old pile of complexity with two sadder engineers looking over it, then the apps on the far right

By @forrestbrazeal.bsky.social

18.03.2025 13:12 β€” πŸ‘ 16    πŸ” 5    πŸ’¬ 3    πŸ“Œ 0

@jessfigueras is following 20 prominent accounts