Insight #1
Spray and pray: That’s the modus operandi behind the latest successful attack against Microsoft, which resulted in compromise of the company’s email systems. The attackers reportedly got in through an old testing environment, which seemingly had no multi-factor authentication (MFA) stopping them.
Lesson learned: Just because it’s not a production system doesn't mean it can't be used as an avenue to get into your production systems. Threat models? MFA? It all matters.
Insight #2
I really love the idea of a civilian cybersecurity reserve. As time goes on, it will be increasingly important to have technical backup for cyber warfare.
Insight #3
Application Security (AppSec) is a persona. Where does this persona best fit in your organization? Is it an AppSec team, QA, Dev, IT, Compliance, or somewhere else? One of the coolest parts about AppSec is it can fit where you need it to in your org.