Brett Winterford

Brett Winterford
Senior Director, Cybersecurity Strategy

Brett Winterford is the Senior Director of Cybersecurity Strategy at Okta. He advises policy makers, business leaders and fellow security professionals on evolving threats and opportunities to improve their security posture.Prior to Okta, Brett held a senior leadership role at Symantec, and helmed security management, research and education at Commonwealth Bank.He’s best known for his work as a security journalist. In 2020, he was the founding editor of the Srsly Risky Biz newsletter, a companion to the Risky Business podcast, providing the cybersecurity, policy, defense and intelligence communities with a weekly brief of the news that shapes cyber policy.

Prior to working as a security practitioner, Brett was the editor-in-chief of ITnews Australia and has contributed extensively to ZDNet, the Australian Financial Review and the Sydney Morning Herald.

Brett Winterford

Protection, without perimeters

Given the premise that “identity is the new perimeter”, we’re often asked about the role network attributes should play in restricting access to applications, servers and data. Can we, and should we, for example, deny access requests originating in high-risk countries or countries involved in conflict? The reality is that network context still matters. We can take into account the identity of the network and location our users are authenticating from. If a customer determines that there are...

Brett Winterford

We (still) need to talk about RDP

Quarter by quarter, for three years now, abuse of Remote Desktop Protocol (RDP) has been the most common root cause of all ransomware events. It’s no surprise why RDP makes for an attractive target: RDP is the primary vehicle for remote access to Windows servers and is used for administrative functions. It’s the most commonly listed method of remote access sold by initial access brokers. According to some 2019 research [pdf] by Sophos, an open RDP port gets its first connection request...

Brett Winterford

Just how risky is legacy authentication?

Does your organization still allow users to authenticate to Office 365 or other Microsoft services using only a username and password? If you do, you’re 53x more likely to be targeted in credential-based attacks. (No, not 53% more likely. It’s 53 times more likely). Many organizations (at least one in ten Microsoft customers, as of October 2021) still allow access to the M365 cloud using what Microsoft calls “Legacy Authentication”. In these requests, the client forwards the username and...