Baby Steps

In security we often want to boil the ocean!

Rebuilding a roof is a series of small steps. Each one significant and built upon on the other.

First the rafters, eaves, and fascia.

Then the plywood and flashing.

Afterwards paper and then finally the shingles.

Each one building on the other.

Each one insignificant alone, but fundamental together.

Putting together an Information Security Program is the same way.


Find your unknown unknowns.

Stop the bleeding.

Put together a plan.

Start healing and building.

Revisit plan often, execute, iterate.

Moral of the Story

Rome was not built in a day.

Slow and steady wins the race.

Little streams make big rivers.

You get the picture :).

