14Ian Coldwater

“What hackers do isn’t magic; it’s logic, and it can be taught and learned from.”

Closeup image of the DevSecOps engineer "Ian Coldwater."

Twitter: @IanColdwater

Ian Coldwater is a DevSecOps engineer turned red teamer who specializes in containers and cloud infrastructure. She has spoken about Kubernetes security at conferences including DerbyCon, O’Reilly Velocity, and SANS SecDevOps Summit. In her spare time, she likes to go on cross-country road trips, participate in capture-the-flag competitions, and eat a lot of pie.

If there is one myth that you could debunk in cybersecurity, what would it be?

People think hackers are wizards, and we don’t do a lot to debunk that. I like shiny zero-days as much as the next hacker, but the dull truth is that most cybersecurity breaches stem from far less sexy causes, such as misconfigurations, logic failures, and defaults that never got changed.

It’s not as much fun to talk about the basics over and over, but scaring people doesn’t help them fix problems. What hackers do isn’t magic; it’s logic, and it can be taught and learned from.

What is one of the biggest bang-for-the-buck actions that an organization can take to improve its cybersecurity posture?

I think one of the biggest bang-for-the-buck actions an organization can undertake is to threat model well. Organizations that know what they’re trying to protect and whom they’re trying to protect it from are more likely to ...

Get Tribe of Hackers now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.