Daniel Kennedy's Avatar

Daniel Kennedy

@danielkennedy74.bsky.social

Application Development, Application Security VP, FinCo CISO now industry analyst. Spend my days talking to CISOs. Tweets and opinions are my own, a10wn. http://www.praetorianprefect.com https://blog.451alliance.com/author/dkennedy/

204 Followers  |  132 Following  |  33 Posts  |  Joined: 20.11.2024  |  1.5688

Latest posts by danielkennedy74.bsky.social on Bluesky

Post image

Use of GenAI security solutions has spiked, continued uptake projected: blog.451alliance.com/use-of-genai...

22.07.2025 15:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Turns out it’s not the company clothing store…

29.06.2025 01:09 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Webinar Recap: Reimagining Application Security Posture Management In a timely discussion hosted by S&P Global Market Intelligence, Principal Research Analyst Daniel Kennedy sat down with Idan Plotnik (Founder of Apiiro) and Jason Espone (Global Head of Application S...

apiiro.com/blog/webinar...

13.05.2025 03:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
AI Delivers AppSec Gains, but Ransomware Overconfidence Persists Cybersecurity leaders are embracing generative AI for its practical value in security operations and application security. But as ransomware tactics evolve, S&P's

I had the opportunity again this year at #RSAC to discuss my latest end user security research with @mathewjschwartz.bsky.social at the ISMG studio.

Full interview: www.databreachtoday.com/ai-delivers-...

05.05.2025 16:18 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
RSA Conference Preview
YouTube video by S&P Global Market Intelligence RSA Conference Preview

#RSAC 2025 - www.youtube.com/watch?v=F7GX...

03.05.2025 00:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Thank you to all who joined our 451 #RSAC breakfast this year, it was great catching up, however briefly.

30.04.2025 19:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

As the RSA Conference kicks off this week, listen to our conference preview on the Next in Tech podcast: www.spglobal.com/market-intel... #rsac2025

28.04.2025 14:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I recently had the opportunity to sit down with a couple of folks who have spent significant time working out real world challenges in enterprise application security programs, catch the replay here: event.on24.com/wcc/r/490723...

22.04.2025 00:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Security talent gap cannot be expressed in job numbers alone The 451 Alliance shares key findings from a recent information security study. The topic? Organizational behavior.

How important are information security certifications?

Almost half (47%) of respondents to our recent survey note certifications are very important, and they require job candidates to have them. Another 43% note they are somewhat important - blog.451alliance.com/security-tal...

28.03.2025 19:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Meta just fired about 20 employees for leaks The Facebook parent company fired the workers for sharing confidential information

From an old hand, step 1 in the 'finding leakers' handbook is...don't announce you're looking for or have found leakers. I know you think it has a deterrence effect, it doesn't. You want folks to make mistakes and leave bread trails, not get better at leaking information.

qz.com/meta-fires-2...

01.03.2025 17:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
a man in a black shirt and tie is writing on a notebook with a pen . ALT: a man in a black shirt and tie is writing on a notebook with a pen .

Let's see, from what I'm reading you're making some demands here, somewhat impolitely, I just need to check a couple things...

- Yup, not in my chain of command, ok, next thing...

- You don't add value, either now or project to in the future...

And there you go, right on the 'pay no mind' list.

28.02.2025 21:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"We have a new guideline in place, if you could just sign the form..."

Gotcha, well I apologize, I have a process where I'm not allowed to 'just sign' anything I don't understand or agree with or that lacks the force of law, you understand, can't be upsetting the folks upstairs here at Kennedy Inc.

11.02.2025 18:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cybersecurity expertise gaps: More than meets the eye | TechTarget What 10 years of market research data reveals about past improvements in SecOps practices and how to tackle gaps in cybersecurity expertise.

"SecOps managers said they were aware of but unable to investigate 43% of alerts they received through security operations center (SOC) tools.It's a number that has remained consistent over the years..."

www.techtarget.com/searchitoper...

24.01.2025 16:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

TikTok replaced Vine, and if it’s banned something will replace it (YouTube shorts and Instagram reels among the options). All of these β€˜it will be healthy’ takes…20 million kids aren’t going to walk outside and rub their eyes in the sun, and then β€˜play until the street lights come on’.

16.01.2025 02:00 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Preview
Explosive use of GenAI in 2023 results in need to secure it What's in store for 2024? The 451 Alliance asks security professionals about their planned spending for the new year.

Explosive use of GenAI in 2023 results in predictable need to secure it - blog.451alliance.com/explosive-us...

13.01.2025 19:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Multicloud multiplies the pain for information security - 451 Alliance The 451 Alliance explores the evolution of cloud security practices in organizations and key pain points identified in securing the cloud.

Multicloud multiplies the pain for information security - blog.451alliance.com/multicloud-m...

06.01.2025 14:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Ransomware Defender Risk: 'Overconfidence' in Security Tools Are your defenses against ransomware good enough to survive contact with the enemy? Don't be so sure. A new study from market researcher 451 Research finds that "overconfidence in security tooling rem...

"indicating the importance of a resilience-based strategy focusing on backup technologies such as immutable storage" www.databreachtoday.com/blogs/ransom...

18.12.2024 14:24 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Don’t celebrate #ransomware’s decline just yet - blog.451alliance.com/dont-celebra...

16.12.2024 16:07 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
The arc of SecOps is long, but bends toward improvement S&P Global Market Intelligence principal research analyst Daniel Kennedy discusses what the results of his Voice of the Enterprise research project dating back to 2015 reveal about the notion of a...

I had the opportunity to sit down with Beth Pariseau on her podcast for a wide ranging discussion on the notion of a cybersecurity skills shortage & the effects of the Crowdstrike outage on a long-running debate about platforms vs best-of-breed: www.podbean.com/media/share/...

12.12.2024 18:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Exploring the shifts in attitudes around 'coordinated disclosure': www.veracode.com/sites/defaul...

10.12.2024 19:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Managing privileged identities remains a headache for organizations’ security leaders β€” it is the top-cited pain point in identity management (36%). blog.451alliance.com/privileged-i...

09.12.2024 17:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
App Sec and the shift to DevSecOps with 451 Research and GitLab
YouTube video by GitLab App Sec and the shift to DevSecOps with 451 Research and GitLab

App Sec and the shift to DevSecOps, a conversation with GitLab: www.youtube.com/watch?v=LFtW...

06.12.2024 18:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
[Ep. 152] Cyber Insurance | Next in Tech
YouTube video by S&P Global Market Intelligence [Ep. 152] Cyber Insurance | Next in Tech

A discussion on cyber insurance with Eric Hanselman, @scott-crawford.bsky.social and Tom Mason on the 'Next in Tech' podcast: www.youtube.com/watch?v=keg8...

05.12.2024 18:40 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Lol, whatever it takes...

04.12.2024 18:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Security pros see potential in AI-augmented fixes for security flaws As generative AI is increasinglyΒ applied toΒ information security, a key emerging use case emerges. The 451 Alliance shares key findings.

While much has been said about GenAI’s potential to enhance developer productivity by generating usable code in integrated development environments, automating code patches for security vulnerabilities may enable similar efficiency gains in application security. blog.451alliance.com/security-pro...

04.12.2024 02:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Enterprises and the Multi-Cloud of Madness.mp4 This is "Enterprises and the Multi-Cloud of Madness.mp4" by Fastly on Vimeo, the home for high quality videos and the people who love them.

The challenges in securing the 'multicloud of madness', a panel discussion with CISOs Mike Johnson and Lora Vaughn: vimeo.com/759687623

02.12.2024 21:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

β€œShould I engage a MSSP or bring security in-house?”

You should reject the premise of the question, as that is not how the majority of managed security services relationships are set up, as an β€˜either-or’.

27.11.2024 22:52 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Open Source Security Risk - Managing the Threat in Mergers & Acquisitions | Black Duck
YouTube video by Black Duck Open Source Security Risk - Managing the Threat in Mergers & Acquisitions | Black Duck

Discussing the prevalence of open source in applications today and what risks that poses in the realm of Mergers & Acquisitions (M&A) - www.youtube.com/watch?v=JrJv...

26.11.2024 20:15 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Cyber insurance remains a sought after risk transference strategy for enterprise security leaders, but the market for acquiring insurance remains complex to navigate. Most of that complexity is due to the shift and growth in ransomware... blog.451alliance.com/cyber-insura...

26.11.2024 04:17 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Organizational Dynamics of Information Security Positioning Information Security within the enterprise presents its own set of challenges. Our recent survey data from hundreds of senior security and IT leaders like you uncovered a number of systemi...

'Organizational dynamics in information security': www.brighttalk.com/webcast/1315...

22.11.2024 16:29 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@danielkennedy74 is following 20 prominent accounts