Opens profile photo
Follow
Click to Follow spgedwards
Simon PG Edwards
@spgedwards
CEO, SE Labs () 👉 linkedin.com/in/spgedwards/ (while Twitter faces an uncertain future)
WriterLondonspgedwards.comJoined September 2011

Simon PG Edwards’s Tweets

Feels like Elon Musk laid me off too, and I don't even work for Twitter Social media takes time & effort. For what reward? Staying in touch with: ◇ Friends ◇ Colleagues ◇ Interested strangers I'm not joining another platform. Find me here: linkedin.com/in/spgedwards/ 😘
No one is immune from mental health issues We might not notice them until things have gone too far Pay attention, ignore stigma, be kind to yourself Also, eat, exercise and TALK. (I have no problem with two of things things...)
Quote Tweet
Mental health challenges (S2E6) Including: 🔸 Effects of lockdown 🔸 3 mental health essentials 🔸 Self help vs. support + #SecurityLifeHack! blog.selabs.uk/2022/10/cyber- ft. @VrcWhfc (@teameleos) @Luis_Corrons @MarcBriggs20 #cybersecurity #podcast
Image
2
New type of ransomware report - coming tomorrow! 📄🙀 We copied how loads of different ransomware gangs operate And not just malware. Full network penetrations too Very exciting!
Quote Tweet
And 8 months later we have a report! 🔹 300 different ransomware attacks 🔹 Full network penetration using ransomware gang tactics Deep, direct ransomware testing, as you've never seen it! Coming 25 Oct 2022 (1337 UTC +1) blog.selabs.uk/?utm_source=tw #ransomware #TestLikeHackers
Extremely proud of our team of advanced hacking testers, who learned how to be just like real-world ransomware gangsters... 😇 And stayed legit! We #TestLikeHackers to make our #cybersecurity test results realistic and useful!
Quote Tweet
And 8 months later we have a report! 🔹 300 different ransomware attacks 🔹 Full network penetration using ransomware gang tactics Deep, direct ransomware testing, as you've never seen it! Coming 25 Oct 2022 (1337 UTC +1) blog.selabs.uk/?utm_source=tw #ransomware #TestLikeHackers
1
Even strong passwords can be cracked. Here's what it looks like when a bad guy gets into your Microsoft account. Use extra (free) security to avoid this. cc:
Quote Tweet
💥 Hacked! That's what you get when you don't use an app as well as a password: 1. Unsuccessful sign-in - Russia (Monday) 😢 2. As above 3. Unusual activity - Hungary (Wed) 🥳 4. Warning email from Microsoft (3 hours later) Solution: a) Enable #2FA b) Change password
Image
1
Worried about keeping your WiFi etc on 24h/day? Worst-case daily costs* Laptop (50W): 40p £146/year WiFi router (30W): 24p £87/year Need to cut costs? Cheaper slower broadband deal can save ~£60-120/year * If devices working 100% & power costs 34p/kWh -UK price cap 2022
1
In some ways mobile devices make it easier for attackers. It's harder for us users to check where links go before clicking them.* But in this case our iPhone would have saved us 😅 * Just don't click links in emails to reduce this risk!
Quote Tweet
Phishing attack failing on mobile... This targeted phishing email works as designed on a desktop computer, but fails hard on an iPhone #email #cybersecurity #phishing
phishing attack failing on mobile
1
This came through email security filters today: Hello simon, Your password for {my legit email address} is due to expire in less than 24 hours Date: Tuesday, October 4, 2022 Please click below to continue with the same password [Keep Same Access] < not Microsoft 🙄
Image
Testing security products is such an important activity that testers need to be responsible and: 1. Explain what they plan to do 2. Follow their plan, without deviating 3. Be prepared to prove that they didn't deviate It's why we follows the AMTSO testing Standard
@SELABSUK @AMTSO
1
Getting too big for your boots can be fatal! 🤿 "Experts are human: they can miss things and they make mistakes We cannot leave it to the novice to speak up and wave the red flag We need to encourage a culture of openness and learning in organisations"
1995 - 1st publishing job £11.5K, no job description which became moving boxes, making tea* and opening mail so I got to read my confidential references when they came in Start of a weird career... *The big boss made tea so I focussed on stocking the fax machine
Image
1
5
🪦 Anti-virus (AV) is not dead. 🦖>🤖 AV isn't just AV anymore. 👨‍👩‍👧 Even consumer products can detect some advanced threats. But you can't just install and forget it. It might spot threats quietly (logs) 🕵🏽‍♂️
Quote Tweet
This. We constantly hear "AV is useless" but my experience is the same. Nearly every incident I deal with has an overlooked AV alert early on. It won't stop ninja APT but it nearly always sees them. twitter.com/cyb3rops/statu…
Finally!
Quote Tweet
It's the one you've been waiting years for! Targeted attacks take on 5 well-known EDR products from: 🔸 BlackBerry Cylance 🔸 Broadcom 🔸 CrowdStrike 🔸 Kaspersky 🔸 (Another of the biggest) vs. 🔹 Wizard Spider 🔹 Lazarus Group 🔹 Operation Wocao blog.selabs.uk/2022/07/endpoi
Image
This is the result of over 6 years of work! We had to build a reputation strong enough so the security industry would trust us to do a great job. Finally, with the expert leadership of our CTO , we have a public report comparing Cylance, CrowdStrike and others!
Quote Tweet
Tomorrow: a brand new test report For years you've asked us to compare EDR products This is THE first detailed, full attack chain report of top-tier EDR products Make sure to follow us to get the earliest update! #enterprise #endpoint #EDR #testlikehackers
Image
5
Jeff Bezos' wife MacKenzie Scott has determined that I qualify for special financial support! Awesome. I'll be writing to her via Dr Ngalagu46's Gmail account ASAP 💰💰💰
Image
Security test reports are only useful if you trust the testers But how do they test? What are their motivations and biases? Learn how (some) testers and security companies work together. Or against each other! Guests include real hackers, gov-backed testers + more
Quote Tweet
Testing like hackers (S2E3) Plus! 🔸 How to choose a good test report 🔸 Bullet-proof your email 🔸 #SecurityLifeHack blog.selabs.uk/2022/07/decode #cybersecurity #podcast ft. @frankduff @michaelsentonas @sigurdurarnar @dcuthbert
DE:CODED cyber security podcast
Date: 2nd July 22 Notice of FTC Settlement - 2019 Data Breach "Before November 2019, CafePress didn't have reasonable practices to keep your information safe" The following may have been stolen: EVERYTHING* (* I paraphrase for brevity) #securitybreach due to #poorsecurity
Image
Hackers sometimes spy on your email using forwarding rules They can see your messages even if you change your password Check your rules regularly. For most people there shouldn't be any in place Disable any you don't recognise This easy 4-step checklist works for Gmail
Check Gmail forwarding rules