Jack Cable

@jackhcable.bsky.social

CEO & Co-founder at Corridor. Previously: Senior Technical Advisor at CISA, TechCongress in the Senate, Krebs Stamos Group, CISA, Defense Digital Service, and Stanford.

New from Jen Easterly and me: as threats to our critical infrastructure increase, U.S. policymakers need to defend + strengthen the role of security research. This is personal for me, having received legal threats for good-faith security research. www.lawfaremedia.org/article/adva...

Advancing Secure by Design through Security Research

It is essential for U.S. policymakers to actively protect and promote the role of security research within an open and transparent ecosystem.

lawfaremedia.org

📢 Excited to share that I started a new company, Corridor, with Ashwin Ramaswami! Corridor is the AI-powered secure by design platform – and we're backed by @stamos.org, Chris Krebs, Christina Cacioppo, @alip.bsky.social at Neo, and Sarah Guo at Conviction. forms.gle/3LsFxtNqzok2...

Corridor Waitlist

Interested in learning more about Corridor? Fill out this form to join our waitlist. By submitting this form, you opt in to receiving emails from Corridor.

forms.gle

After two incredible years, today is my last day at CISA. Immensely grateful to have been able to drive CISA's work on Secure by Design, spurring commitments from 250 software manufacturers and publishing guidance with over a dozen int'l partners. My exit interview: cyberscoop.com/jack-cable-c...

A CISA secure-by-design guru makes the case for the future of the initiative

The initiative had led to tangible changes, Jack Cable said upon his exit from the agency as senior technical adviser.

cyberscoop.com

🔒 New from CISA, some tips on protecting your communications in light of compromises of telecom infrastructure. Includes: 1. Use only end-to-end encrypted messaging apps such as Signal. 2. Enable FIDO auth (security keys or passkeys) wherever possible. 3. Do not use a personal VPN.

Bild

ICYMI: CISA published the Product Security Bad Practices for public comment, due Dec 16. Included in the bad practices: development of new products in memory unsafe language, inclusion of user input in SQL queries/OS commands, default passwords, and more. www.cisa.gov/resources-to...

Product Security Bad Practices | CISA

This voluntary guidance provides an overview of product security bad practices that are deemed exceptionally risky, particularly for software manufacturers who produce software used in service of crit...

cisa.gov

Great joining @rosenzweigp.bsky.social on the Lawfare Podcast! Tune in for some holiday listening to hear from Lauren Zabierek, Bob Lord and me on CISA's path forward on Secure by Design. www.lawfaremedia.org/article/the-...

The Lawfare Podcast: Three CISA Senior Advisers on Secure by Design

What is Security by Design?

lawfaremedia.org

Lawfare@lawfaremedia.org · 3y ago

On today's Lawfare Podcast, @rosenzweigp.bsky.social sat down with three Senior Advisers to CISA — Lauren Zabierek, @jackhcable.bsky.social, and Bob Lord — to talk about their efforts to define a Secure by Design standard, as part of Lawfare’s Security by Design project.

Have thoughts on Secure by Design? Yesterday, CISA announced a Request for Information on Secure by Design. Have thoughts on eliminating classes of vulns, security education for developers, economics, AI, OT, and more? Check it out and respond (by Feb 20): www.federalregister.gov/documents/20...

Request for Information on “Shifting the Balance of Cybersecurity Risk: Principles and Approaches ...

CISA requests input from all interested parties on the white paper ``Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software.''

federalregister.gov