Today Cyber Security plays a paramount role in global security. On this blog, the CEO of Paramount Defenses shares rare insights on issues related to Cyber Security, including Privileged Access, Organizational Cyber Security, Foundational Security, Windows Security, Active Directory Security, Insider Threats and other topics.


October 28, 2018

Happy Birthday, Bill Gates!

Dear Bill,

Here's wishing you Sir, likely the most successful and influential person of not just our time, but of all time, a very Happy B'day!

Photo source and attirbution: https://mobile.twitter.com/BillGates/photo

Most of the world knows you as the Founder of Microsoft, a great philanthropist, and the world's wealthiest* person.


Based on my personal experience, I however know you to be someone who truly exemplifies the very words I strive to live by, and ideally, that we should all strive to live by, because in the grand scheme of things, we are all here for relatively little time.


Deep Gratitude for Mr. Gates

If I may, I'd like to share from my personal experience, a very small example of Mr. Gates thoughtfulness, humility and kindness.

One day back in 2004, when I was a Microsoft employee, I got a call from the Reception of Building 33, the Executive Building at Microsoft, and I was asked to come and pick something up - when I reached there, the kind lady at the reception gave me a package and said that "Bill left this for you, as he's unfortunately out of town today," and in it was a note written by Bill himself - "To Sanjay, Happy Birthday, Bill Gates" ( here.) (BTW, this is not customary at all at Microsoft; in fact, it was an absolute rarity.)

I couldn't believe it. Bill Gates, our CEO, and the world's most successful and wealthiest person, made and took the time to wish me Happy B'day, and since he was going to be out of town, he was thoughtful enough to have it be given to me on my b'day!

Since that day, for the last fourteen years I've been working tirelessly to be able to express my profound respect and gratitude to Mr. Gates, and it is for the first time, that I feel I've done my bit to be able to thank him, not just in words, but in global IMPACT.


Mr. Gates, it is your greatness, kindness and humility that inspired me to conquer proverbial mountains as I persevered against all odds to ultimately build and deliver a paramount capability needed to secure and defend the very foundation of cyber security of and across Microsoft's global organizational customer base i.e. your one little act of kindness, led to and inspired THIS.



Birthday Wishes

Mr. Gates, today, you're wished profound joy and excellent health, but above all, you're wished that which is a rarity today, and that which sometimes even all the money in the world can't buy - True Peace of Mind and Happiness in the Simplest of Things!


BillG, I thank you for the incredible human being you are, and wish you a truly wonderful year ahead.

Namaste,
Sanjay.


PS: I occasionally come across monetarily wealthy people, you know, little multi-millionaires and billionaires, and some of them exude such arrogance, that I feel like telling them that there are people out there (e.g. you) who could buy all their wealth out a hundred times over, so how about a little humility?! :-) In stark contrast, I visited the Gates Foundation website today, and it was so incredibly refreshing to see it unequivocally communicate that All Lives Have Equal Value!  You Sir, command my respect.

October 27, 2018

Words I Live By

Folks,

Today, I just wanted to take a moment to share with you the words I live by -


No matter who we are, we should always strive to be ...

Sincerely,
Sanjay.

October 26, 2018

What Lies at the Foundation of Organizational Cyber Security Worldwide?

Folks,

In days to come, I'm going to answer both, the most important, and the second most important question in all of Cyber Security

Today though, I just wanted to ask a simple (rhetorical) cyber security question, so that CEOs, CIOs, CISOs and IT Directors at organizations worldwide realize just what lies at the very foundation of the cyber security of their multi-billion $ organizations.

Microsoft Active Directory

Today, at the very foundation of organizational cyber security worldwide, lie their foundational Active Directory deployments.

Consequently, it logically follows that all organizations that operate on Microsoft Active Directory are only as secure as are their foundational Active Directory deployments. After all, no matter how tall, every skyscraper is only as strong as its foundation.

In days to come, I'll share with you just how secure foundational Active Directory deployments are worldwide today - right here.

Best wishes,
Sanjay

October 13, 2018

A Very Simple Trillion $ Cyber Security Multiple-Choice Question

Folks,

In days to come, I'll be helping organizations worldwide understand what constitutes a privileged user in Active Directory, how to correctly audit privileged access in Active Directory, and what the world's most important Active Directory security capability is.

Today though, I just wanted to ask a very simple and elemental cyber security multiple-choice question, so here it is -


Q. What are the minimum Active Directory Security Permissions that a perpetrator needs to be able to successfully run Mimikatz DCSync against an organization's foundational Active Directory deployment?

Is it -
A. The "Get Replication Changes" Extended Right 
B. The "Get Replication Changes All" Extended Right 
C. Both A and B above 
D. Something else

I already know the answer to this simple question. I'm only asking because I believe that today every Domain Admin and every CISO at every organization that operates on Active Directory MUST know the answer to this question, and here's why.

You may be surprised if I were to share with you just how many Domain Admins and CISOs (at so many of the world's most prominent organizations) don't know even seem to know what Mimikatz DCSync is, let alone knowing the answer!

If you know the answer to this question, and care to share, please feel free to share it by leaving a comment below.

Best wishes,
Sanjay.