NDC Melbourne 2023
Understanding the Cyber Security Acronym Soup + Avoiding DNS Pain
Understanding the Cyber Security Acronym Soup
Over the last several decades, international standards bodies and governments have developed an acronym soup of cyber security standards. We commonly hear: SOC ISO/IEC, PCIE, ESTI, CIS, IRAP, ISPC; but how much do we really understand the goals, purposes and impacts on these standards?
Avoiding DNS Pain
In every organisation DNS is a critical system, but it rarely gets the attention that it deserves. We rely on DNS for the smooth operation of our businesses; if your customers can’t reach your website or email you, then your business is effectively cut-off.
Linux.conf.au 2022
Avoiding DNS Pain
In every organisation DNS is a critical system, but it rarely gets the attention that it deserves. We rely on DNS for the smooth operation of our businesses; if your customers can’t reach your website or email you, then your business is effectively cut-off. Organisations will keep disaster recovery plans and business continuity procedures for their corporate websites, mail servers and internal systems; but how many of these plans and procedures include DNS?
Linux.conf.au 2021
Sacrebleu - PowerShell on Linux!
Microsoft open-sourced PowerShell in 2016, and debuted a cross-platform interaction supporting Linux and MacOS. Since then, thousands have contributed to the PowerShell project, with the community growing exponentially. Linux users now outpace other platforms in downloading PowerShell modules and scripts from the PowerShell Gallery. With PowerShell 7.1, the community and Microsoft have delivered more features and bug fixes than ever before. In this session, we will work through some of the new features and improvements included in this release.
NDC Sydney 2020
Using GraphQL as a Secure Innovation Boundary and data-driven culture driver
In this presentation, we will describe how we went about pitching, prototyping, launching and operating Purple Graph. We will cover the learnings we've had along the way (technical and non-technical) and talk about the cultural change that we are starting to drive using this technology.
Zendesk Webinar
Expert Insights: Vital Tips To Boost Employees’ Efficiency and Wellbeing
In these unpredictable times, learn why employee wellbeing matters more than ever, and how you can boost your team’s efficiency and engagement with tech.
Microsoft 365 May
Panel: Career changers - the ideas, suggestions and people who influenced your career
Panel of industry professionals discuss the pivotal moments in their career including ideas, suggestions, advice and people that changed their career trajectory.
Microsoft Ignite The Tour Sydney
Bank Grade Security
Banks and financial services providers love to make some big claims when it comes to the security of their products and networks. The truth is, the phrase "bank grade security" has become an oxymoron. Many institutions have failed to implement basic security controls, least to keep ahead of security curve. Yet we continue to place considerable trust in them, and put up with security controls that are counter-productive, all to maintain the theatre of security.
Melbourne Cloud and Datacenter Meetup
Bank Grade Security
Banks and financial services providers love to make some big claims when it comes to the security of their products and networks. The truth is, the phrase "bank grade security" has become an oxymoron. Many institutions have failed to implement basic security controls, least to keep ahead of security curve. Yet we continue to place considerable trust in them, and put up with security controls that are counter-productive, all to maintain the theatre of security.
NDC Sydney 2019
Bank Grade Security
Banks and financial services providers love to make some big claims when it comes to the security of their products and networks. The truth is, the phrase "bank grade security" has become an oxymoron. Many institutions have failed to implement basic security controls, least to keep ahead of security curve. Yet we continue to place considerable trust in them, and put up with security controls that are counter-productive, all to maintain the theatre of security.
DDD Sydney 2019
Bank Grade Security
Banks and financial services providers love to make some big claims when it comes to the security of their products and networks. The truth is, the phrase "bank grade security" has become an oxymoron. Many institutions have failed to implement basic security controls, least to keep ahead of security curve. Yet we continue to place considerable trust in them, and put up with security controls that are counter-productive, all to maintain the theatre of security.
DDD Melbourne 2019
Bank Grade Security
Banks and financial services providers love to make some big claims when it comes to the security of their products and networks. The truth is, the phrase "bank grade security" has become an oxymoron. Many institutions have failed to implement basic security controls, least to keep ahead of security curve. Yet we continue to place considerable trust in them, and put up with security controls that are counter-productive, all to maintain the theatre of security.
Global Azure Bootcamp 2019
The Boring Security Talk
Troy Hunt and Scott Helme have spoken about all the exciting security things, so let’s talk about the boring bits! When we think about application and infrastructure security, we often think about the big shiny things and forget the boring bits. In this talk, we’ll look at the security of our package dependencies, CI/CD tools, how we send email and even resolve hostnames. Over the last few months, hackers have managed to inject cryptocurrency miners into all these places. Security incidents in these components might not result in an entry in Have I Been Pwned?, but they'll result in a bad day.
Click on the title for more informaiton.
CrikeyCon VI
The Boring Security Talk
Troy Hunt and Scott Helme have spoken about all the exciting security things, so let’s talk about the boring bits! When we think about application and infrastructure security, we often think about the big shiny things and forget the boring bits. In this talk, we’ll look at the security of our package dependencies, CI/CD tools, how we send email and even resolve hostnames. Over the last few months, hackers have managed to inject cryptocurrency miners into all these places. Security incidents in these components might not result in an entry in Have I Been Pwned?, but they'll result in a bad day.
Click on the title for more informaiton.
Melbourne Cloud and Datacenter Meetup
The Boring Security Talk
Troy Hunt and Scott Helme have spoken about all the exciting security things, so let’s talk about the boring bits! When we think about application and infrastructure security, we often think about the big shiny things and forget the boring bits. In this talk, we’ll look at the security of our package dependencies, CI/CD tools, how we send email and even resolve hostnames. Over the last few months, hackers have managed to inject cryptocurrency miners into all these places. Security incidents in these components might not result in an entry in Have I Been Pwned?, but they'll result in a bad day.
Click on the title for more informaiton.
NDC Sydney 2018
The Boring Security Talk
Troy Hunt and Scott Helme have spoken about all the exciting security things, so let’s talk about the boring bits! When we think about application and infrastructure security, we often think about the big shiny things and forget the boring bits. In this talk, we’ll look at the security of our package dependencies, CI/CD tools, how we send email and even resolve hostnames. Over the last few months, hackers have managed to inject cryptocurrency miners into all these places. Security incidents in these components might not result in an entry in Have I Been Pwned?, but they'll result in a bad day.
Click on the title for more informaiton.
DDD Melbourne
The Boring Security Talk
Troy Hunt and Scott Helme have spoken about all the exciting security things, so let’s talk about the boring bits! When we think about application and infrastructure security, we often think about the big shiny things and forget the boring bits. In this talk, we’ll look at the security of our package dependencies, CI/CD tools, how we send email and even resolve hostnames. Over the last few months, hackers have managed to inject cryptocurrency miners into all these places. Security incidents in these components might not result in an entry in Have I Been Pwned?, but they'll result in a bad day.
Click on the title for more informaiton.
Global Azure Bootcamp 2018
Secure Azure Deployment Patterns
Microsoft has provided an almost unlimited number of ways for you to securely deploy Azure resources; but people continue to make simple mistakes. In 2017 many organisations had breaches due to poor cloud deployment practices.
Click title for more information.
Readify Back2Base Victoria
Secure Azure Deployment Patterns
Microsoft has provided an almost unlimited number of ways for you to securely deploy Azure resources; but people continue to make simple mistakes. In 2017 many organisations had breaches due to poor cloud deployment practices.
Click title for more information.
Melbourne Microsoft Cloud and Datacenter Meetup
Ransomware 0, Admins 1
Ransomware made headlines in 2017, with attacks shutting down the UK's NHS and costing Maersk shipping over $300m in lost revenue. Ransomware is a massive business for cybercriminals, driving the cost of bitcoin from $1200 to over $7000 per coin. We often see ransomware as some unbeatable force, however with some common sense controls and simple tricks, the damage can be reduced or even stopped. Join Kieran to learn some simple, free steps you can do to stop ransomware in its tracks.
Click on the title for more information.
Readify Graduate Training Program
Developer Security
Internal training program for Readify Graduate Developers.
Co-presented with Vatsalya Goel.
Topics include:
* Case studies of real life security incidents.
* OWASP Top 10.
* Secure Azure Deployments
Click on the title for more information.
Microsoft Tech Summit - Sydney
DevSecOps in 10 minutes!
DevSecOps, or SecDevOps has the ambitious goal of integrating development, security and operations teams together, encouraging faster decision making and reducing issue resolution times. This session will cover the current state of DevOps, how DevSecOps can help, integration pathways between teams and how to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrating security into our infrastructure and software deployment processes.
Click on the title for more information.
Microsoft Tech Summit - Sydney
DevSecOps in 10 minutes!
DevSecOps, or SecDevOps has the ambitious goal of integrating development, security and operations teams together, encouraging faster decision making and reducing issue resolution times. This session will cover the current state of DevOps, how DevSecOps can help, integration pathways between teams and how to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrating security into our infrastructure and software deployment processes.
Click on the title for more information.
Experts Live Australia
Ransomware 0, Admins 1
The truth is that money can’t buy security just as it cannot buy happiness. Ransomware has become a cybercriminal’s most profitable enterprise, and something that IT professionals and even the general public now fear. Ransomware is actually pretty simple and unsophisticated code, and at times the damage can stopped with some simple tricks. Best of all, these are FREE!
Click on the title for more information.
CrikeyCon 2017
Introducing DevSecOps
DevSecOps, or SecDevOps has the ambitious goal of integrating development, security and operations teams together, encouraging faster decision making and reducing issue resolution times. This session will cover the current state of DevOps, how DevSecOps can help, integration pathways between teams and how to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrating security into our infrastructure and software deployment processes.
Click on the title for more information.
Infrastructure Saturday 2017
Level Up to DevSecOps
DevSecOps, or SecDevOps has the ambitious goal of integrating development, security and operations teams together, encouraging faster decision making and reducing issue resolution times. This session will cover the current state of DevOps, how DevSecOps can help, integration pathways between teams and how to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrating security into our infrastructure and software deployment processes.
Evolving your Automation with Hybrid Workers
Azure Automation wants you to automate everything, everywhere. Hybrid Workers allow Azure Automation to reach new places within your infrastructure, allowing for more automation and less complexity. This session covers the basics of Hybrid Workers before looking at balancing workloads, managing resource dependencies, integrating with web hooks and monitoring job execution. The is a great session for anyone who is automating infrastructure or cloud resources.
Click on the title for more information.
Microsoft Ignite Australia 2017
DevSecOps in 10 minutes!
DevSecOps, or SecDevOps has the ambitious goal of integrating development, security and operations teams together, encouraging faster decision making and reducing issue resolution times. This session will cover the current state of DevOps, how DevSecOps can help, integration pathways between teams and how to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrating security into our infrastructure and software deployment processes.
Click on the title for more information.
Readify WA Back 2 Base
PowerShell 101
Internal PowerShell training seminar delivered as Readify Queensland's Back2Base for May 2016.
Topics covered included, PowerShell basics, operators, getting and writing help, working with the pipeline, loops, filtering, sorting, CMDLets, modules, manifests, parameters, recommended structures, guidelines and gotchas.
Click on the title for more information.
Readify Dev Breakfast WA
Level up to DevSecOps
The IT industry has experienced rapid change and consolidation. The introduction of Cloud, Agile, DevOps and shortages in skilled staff have created immense pressure on enterprise IT teams. Organisations are concerned about the costs of data breaches, and need to act to ensure they do not become the next Yahoo, OPM or Target.
DevSecOps (or SecDevOps) integrates development, security and operations teams together to encourage faster decision making and reduce issue resolution times.
This session will cover the current state of DevOps, and how DevSecOps can help integrate pathways between teams to reduce fear, uncertainty and doubt. We will look at how to move to security as code, and integrate security into our infrastructure and software deployment processes.
Click on the title for more information.
Melbourne Microsoft Cloud and Datacenter Meetup
Evolving your Automation with Hybrid Workers
Azure Automation wants you to automate everything, everywhere. Hybrid Workers allow Azure Automation to reach new places within your infrastructure, allowing for more automation and less complexity. This session covers the basics of Hybrid Workers before looking at balancing workloads, managing resource dependencies, integrating with web hooks and monitoring job execution. The is a great session for anyone who is automating infrastructure or cloud resources.
Click on the title for more information.
Readify Queensland Back 2 Base
PowerShell 101
Topics covered included, PowerShell basics, operators, getting and writing help, working with the pipeline, loops, filtering, sorting, CMDLets, modules, manifests, parameters, recommended structures, guidelines and gotchas.
Click on the title for more information.