Frank McGovern Profile Banner
Frank McGovern Profile
Frank McGovern

@FrankMcG

16,151
Followers
247
Following
3,117
Media
24,317
Statuses

Cybersecurity @ Fortune 100’s ● @BlueTeamCon Founder ● @MARFORCYBER Cyber Auxiliarist ● Former USMC Intel ● Auto Enthusiast ● Real Estate Owner ● Rucker

Chicago, IL
Joined May 2017
Don't wanna be here? Send us removal request.
Pinned Tweet
@FrankMcG
Frank McGovern
10 months
Impersonation is going to run rampant with all this social media fracturing. This is my validation post. I am only on the following: - Twitter: @FrankMcG - LinkedIn: /in/frankmcgovern/ - Mastodon: frankmcg @infosec .exchange - Discord: frankmcg - Reddit: u/FrankMcG
1
0
21
@FrankMcG
Frank McGovern
4 years
He is in several high-risk groups — elderly, obese, low-income.
1K
20K
199K
@FrankMcG
Frank McGovern
3 years
Me after seeing there’s a lambda version now
Tweet media one
97
2K
13K
@FrankMcG
Frank McGovern
2 years
“Hey remember those roles we didn’t let you hire for? I secured funding.”
Tweet media one
81
927
6K
@FrankMcG
Frank McGovern
2 years
I’m seeing people publicly share the name and social media links of the compromised #Okta user. Don’t do this. Don’t even look at their LinkedIn. Don’t say their name. Don’t even approach the topic. This could happen to any one of us; the actual user is irrelevant. Be better.
28
472
3K
@FrankMcG
Frank McGovern
3 months
What happens to Linux when Linus dies? Serious question. Should this be on a risk register?
@testaccountoki
not a sloth
3 months
linus still going hard
Tweet media one
170
880
10K
87
129
2K
@FrankMcG
Frank McGovern
2 years
My biggest IT advice is to have the SMALLEST Oracle footprint you can possibly have at all times.
78
145
2K
@FrankMcG
Frank McGovern
2 years
The Microsoft Cybersecurity Reference Architecture.
Tweet media one
34
464
2K
@FrankMcG
Frank McGovern
4 years
For those not in the know, that’s 3 tours to Iraq with a combat action ribbon and TWO Purple Hearts.
Tweet media one
19
325
2K
@FrankMcG
Frank McGovern
1 month
Wait, really? 😂😂😂 “Though it seemed completely automated, Just Walk Out relied on more than 1,000 people in India watching and labeling videos to ensure accurate checkouts” The true AI. Now I want to know how many people are behind the scenes responding in @ChatGPTapp .
@Gizmodo
Gizmodo
1 month
Amazon Reportedly Ditches 'Just Walk Out' Checkouts at Its Grocery Stores
Tweet media one
27
63
173
26
290
2K
@FrankMcG
Frank McGovern
4 years
Elite hacks, ladies and gentlemen. I think I have to sell my car now. I didn’t know this was a thing. I’m scared.
Tweet media one
114
354
2K
@FrankMcG
Frank McGovern
5 months
Have any of you with unlimited PTO really tried to test it out? I’m talking take like every Friday or every other Friday off for a whole year. Implement the 4-day work week yourself.
111
51
2K
@FrankMcG
Frank McGovern
3 years
Hi, I’m Frank. I’m the sole Cybersecurity Architect for a Fortune 100 org. I barely know code. I barely know scripting. I barely know containers. I barely know forensics. I’ve never popped a shell. You’ll be OK. I depend on coworkers & other SME’s to fill me in while I learn.
@sherrod_im
Sherrod DeGrippo
3 years
A lot of debate about if you need to know how to code to be in security. Is the dev community having a debate about how you need to know security to be a real dev?
93
41
473
55
189
1K
@FrankMcG
Frank McGovern
4 years
What the hell happened to this tweet. I don’t need money, but others do. Please consider donating to good causes like @HackersHealth . Also: - Enable MFA on your accounts - Use a password manager - Run Windows Updates - Uninstall Adobe Flash
19
65
1K
@FrankMcG
Frank McGovern
4 years
When someone says they’re an expert in cybersecurity, remember this.
Tweet media one
31
390
1K
@FrankMcG
Frank McGovern
3 years
Tweet media one
11
189
1K
@FrankMcG
Frank McGovern
3 years
Documentation will save your ass. Do it.
36
211
1K
@FrankMcG
Frank McGovern
2 years
Anyone else notice this trend of not putting dates on blogs or articles? It drives me insane. I need to know how old your content is.
66
56
1K
@FrankMcG
Frank McGovern
2 years
There are three main things you should never be cheap on: - Tires - Mattress - Desk Chair
104
71
1K
@FrankMcG
Frank McGovern
4 years
TODAY is the day that @BarackObama will follow me.
35
32
1K
@FrankMcG
Frank McGovern
2 years
@trek Because you’ve been on the sales side for so long that you’re starting to believe that a vendor can truly solve every use case and problem and will give you exclusive white glove service at all times.
12
19
1K
@FrankMcG
Frank McGovern
3 years
If you think $500k is good CISO pay, wait until you learn the AMEX CISO makes $8mil/yr.
41
97
984
@FrankMcG
Frank McGovern
2 months
Excel runs our entire financial industry globally. This is table stakes.
@arstechnica
Ars Technica
2 months
Formula 1 chief appalled to find team using Excel to manage 20,000 car parts
431
944
8K
18
184
927
@FrankMcG
Frank McGovern
3 years
Man, this Cybersecurity Awareness Month is even more lit than ever. We’re only 6 days in!
18
142
896
@FrankMcG
Frank McGovern
2 years
Kali Linux creators ( @offsectraining ) announce free cyber security sessions (PEN-200) delivered live on Twitch. Two 60-minute sessions every week for 25 weeks, starting on 22 June 2022. Every Wednesday and Friday between 17:00 and 18:00 (BST).
14
305
882
@FrankMcG
Frank McGovern
3 years
Everything is easy to a third party consultant that has never worked first party in Cybersecurity.
20
103
879
@FrankMcG
Frank McGovern
2 years
ServiceNow. They offer you basically nothing for millions but then you have to go build it all yourself with millions more. It’s like if you asked me to build cybersecurity policies for your org and I just went and purchased Microsoft Word and installed it and said “done”.
63
95
838
@FrankMcG
Frank McGovern
3 months
The dissolution of VMware will be the single largest catalyst of shifting to the cloud that we’ll ever see.
49
50
830
@FrankMcG
Frank McGovern
2 years
Raspberry Pi’s are $160+ now???!!!
129
45
768
@FrankMcG
Frank McGovern
5 months
Fun fact: Many of the sites don’t actually do anything regardless of what you click. Some don’t store cookies, some store even if you click deny, some don’t do at all what you customize. It’s all made up and the points don’t matter.
@ChristianSelig
Christian Selig
5 months
I will never forgive the EU for making me click Accept Cookies 492,345 times per month
152
781
10K
17
130
762
@FrankMcG
Frank McGovern
3 years
SANS is now approaching $7,500 a class?? Jeeze, they are loving to milk the industry. I remember when it was still in the $3k-$5k range and even that was crazy. Where is the competition?
109
58
725
@FrankMcG
Frank McGovern
1 year
Tweet media one
44
48
711
@FrankMcG
Frank McGovern
3 years
Just a reminder. You will probably never see me refer to myself as an expert. I just work in cybersecurity. Remember that this field has all of these verticals and I doubt anyone on the planet knows all of them. I can speak to a lot of these, but there is so much I don’t know.
@FrankMcG
Frank McGovern
4 years
When someone says they’re an expert in cybersecurity, remember this.
Tweet media one
31
390
1K
32
103
641
@FrankMcG
Frank McGovern
2 years
Vendors, Please STOP putting security advisories behind logins. Do not use security alerts as a way to get members to sign up so you can farm leads.
26
113
627
@FrankMcG
Frank McGovern
6 months
SEC is charging SolarWinds CISO for their breach due to hiding and inaccurately painting their security posture picture. I probably know a few “people-leader CISO’s” that probably fall into this. Be warned. Know what you’re doing or let someone else lead.
30
177
629
@FrankMcG
Frank McGovern
2 years
I went to Iraq twice. I’ve had friends I know die for the USA. I’ve taken life for the USA. I love fireworks. Usually buy them annually. I honestly find this 4th of July with zero excitement and no enjoyment. This is not the country I went to the Marines for. It’s all a lie.
42
39
593
@FrankMcG
Frank McGovern
3 months
We banned Wireshark at my last company for any non-IT personnel and it was mostly my decision. AMA
104
30
603
@FrankMcG
Frank McGovern
4 years
I was awarded my CISSP certification today. It’s official.
59
5
594
@FrankMcG
Frank McGovern
2 years
Microsoft Teams users: They have enabled a new feature starting TODAY that accounts not managed by an org can be messaged and those accounts can also message your org. 🚨It is enabled by DEFAULT.🚨 You likely do not want at least the checkbox enabled.
Tweet media one
34
258
591
@FrankMcG
Frank McGovern
1 year
Splunk and Sentinel costs. 🤯 How do you actually justify ROI? There’s no way. I knew they were decently expensive, but like I thought maybe 30% of where it is. This market needs a hella correction. Have gotten way too greedy.
84
39
575
@FrankMcG
Frank McGovern
2 years
#Okta : 1. Share the information internally. 2. Collect and retain related logs. 3. Hunt logs for bad. 4. Rotate Okta privileged passwords. 5. Move on unless Okta reaches out to you that you are involved. Adjust DFIR to their context. That’s about all you can do right now.
8
159
568
@FrankMcG
Frank McGovern
1 year
People like to make fun of the @USCG and as a former Marine, I get asked often “who’s the toughest branch?” My answer is always “the USCG” without delay. Why? Because they fly INTO storms and hurricanes and then JUMP INTO THEM. Would you? I’m good on land with my rifle.
33
55
564
@FrankMcG
Frank McGovern
3 years
Print this out and hang it up.
Tweet media one
11
161
552
@FrankMcG
Frank McGovern
1 year
Anyone else not touched ChatGPT at all?
107
8
530
@FrankMcG
Frank McGovern
5 years
Put all your passwords in a password manager and put that master password in your will. Help your survivors by making it easy for them. Don’t forget your digital surface when it comes to death.
27
113
531
@FrankMcG
Frank McGovern
4 years
Many blogs tell you about what Microsoft E5 gets you (which is a lot), but none really write about “I bought Microsoft E5, where do I start?” I wrote a blog that outlines how you should implement the Microsoft E5 stack in a planned approach.
31
160
519
@FrankMcG
Frank McGovern
3 years
OnlyFans CEO learning about his own website on Friday.
10
133
501
@FrankMcG
Frank McGovern
9 days
AWS Monthly Budget 💰Revenue: $10,000 Lambda: ~$2,300 Load Balancing: $750 Firewall-as-a-Service: $1,600 S3 PUT Requests: $732,943 VPN: $163 Someone who is good at the cloud, please help, my resources are starving.
10
31
512
@FrankMcG
Frank McGovern
1 year
People will stan a CEO billionaire that is PUBLICLY SHITTING on his own team but then call out employees for responding to that PUBLIC SHITTING in a defensive way. Amazing. If my manager publicly shit on my work on here, you’re god damn right I would yeet my job into space.
15
89
494
@FrankMcG
Frank McGovern
1 year
@SwiftOnSecurity Welcome to every main tech company in existence right now. Never look at the financials. You’ll realize we have a long way to go down because it’s all made up and the points don’t matter. Companies evaluated as “worth” billions of dollars and have only lost money.
10
20
477
@FrankMcG
Frank McGovern
1 year
Going to write a blog on what a Cybersecurity Architect is and does day-to-day. Anything specific you’d like to see or learn? If you’re an architect, any areas I should make sure I cover?
97
34
483
@FrankMcG
Frank McGovern
3 years
As former military intel, I only have a few easy things to say: - China is not going to go to war with us. - Russia is not and cannot go to war with us. - North Korea can’t go to war with us. - Iran can’t go to war with us. It’s all fear-mongering to keep you busy. /TED Talk
27
63
465
@FrankMcG
Frank McGovern
2 years
I have confirmed that you don’t need to know code to learn about and remediate the Log4j vulnerability.
24
26
450
@FrankMcG
Frank McGovern
3 years
I’m just waiting for when ransomware starts changing data as it decrypts for you. Ransomware is the tip of the iceberg. How many have you fully solved data integrity protections? I’ll wait while you lie. Much greater risks and concerns. What do you do if your data is all muddy?
44
74
442
@FrankMcG
Frank McGovern
2 years
Today I slept to 10am, laid in bed on my phone doing nothing of value, then fell back asleep until 2pm. Got up and watched two episodes of Seinfeld while eating cereal. Then, fell asleep on the couch for 2 hours. About to eat dinner and then play WoW for ~5 hours. Bomb ass day.
27
4
450
@FrankMcG
Frank McGovern
2 years
Please stop being the person that joins the meeting at the 5-minute reminder message so that it tells everyone the meeting is started and they feel pressured to join early.
79
34
441
@FrankMcG
Frank McGovern
5 months
Fun fact. You can wash a properly seasoned cast iron in soap and water. Way too many people do not know this. It’s a myth that it can never touch soap and water.
@HeroDividend
Dividend Hero
5 months
My grandma always makes me do the dishes after Christmas eve lunch She will be so happy to see that I cleaned her dirty old pan
Tweet media one
1K
337
13K
41
17
445
@FrankMcG
Frank McGovern
2 years
I’m in a meeting with 10 people and 5 of them are named Michael. We’ll see how this goes.
100
10
432
@FrankMcG
Frank McGovern
2 years
“Infosec is a cost center/drain on expenses.” I’m tired of hearing this about any services group. Drop an infantryman in a combat zone and remove pay, food, supply, intelligence, and communication and let me know how he does. This is old guard thinking and it’s growing tiring.
47
46
428
@FrankMcG
Frank McGovern
4 years
When discussing going to a 4-day work week, please stop saying 4x10’s. The real path is to a 4-day work week with 8-hours a day still. The 40 hours a week is an arbitrary number and with technology isn’t necessary anymore. The goal is 4x8. Nothing less.
24
72
426
@FrankMcG
Frank McGovern
4 years
Second order of business now that I’m not working for anyone: ✅ Fuck you Kevin Mitnick and your sock account of the name Garth Richards that you used to try and get me fired in 2019 for calling you out as the charlatan you are.
20
25
424
@FrankMcG
Frank McGovern
4 years
Please present PowerPoint in presentation mode. Not in the editor and clicking through slides. That’s the whole point of the product.
34
33
396
@FrankMcG
Frank McGovern
1 year
Security! Secure…eye…tee
15
53
396
@FrankMcG
Frank McGovern
7 months
Please. Stop. Emailing. Personal. Information. When applying for a mortgage. When applying for an auto loan. When looking to retain a lawyer. When signing up for new credit. Please, please, please. Demand a secure upload site. Don’t use them if they don’t have one. It’s 2023.
28
79
389
@FrankMcG
Frank McGovern
5 years
Did you know the Windows Store in Windows 10 allows anything to be installed? Did you know that it installs differently than running an executable so it most likely is circumventing your application whitelisting product? Control via Intune or GPO or applocker.
22
108
371
@FrankMcG
Frank McGovern
2 years
Resources for Log4j vuln. Reply here with more. - Overview by @LunaSecIO : - Vulnerable Hashes by @mubix : - IP’s Exploiting by @GreyNoiseIO : - Detection Rules by @cyb3rops :
14
170
372
@FrankMcG
Frank McGovern
5 months
I'm creating an email security product called Void that automatically deletes every inbound email permanently. Will be able to claim and guarantee ZERO PHISHING within seconds after deployment. I’m seeking investors at this time.
50
32
365
@FrankMcG
Frank McGovern
1 year
20 years from now, the only people who will remember that you worked late are your kids. (Source: u/salingungatha on reddit)
6
74
352
@FrankMcG
Frank McGovern
2 years
Please, for the love of god, stop using debit cards day-to-day. Literally do not use them unless it’s an absolute last resort and you do a forensics analysis for 30mins on the machine you’re putting it into. You have 0 protection if the money goes. Stop. Using. Debit. Cards.
57
44
352
@FrankMcG
Frank McGovern
3 years
Executives and Directors: “Microsoft E5 is ridiculous with price and we can’t put all our eggs in one basket. Way too risky. Why is every feature in E5?!? I’m not paying for that.” Also, them: “ServiceNow is sweet! We can do it all in one! Millions you say? Awesome! Buy it!”
19
38
353
@FrankMcG
Frank McGovern
4 years
This is legit legit
Tweet media one
48
3
344
@FrankMcG
Frank McGovern
4 years
Those of you on @MicrosoftTeams , you actually can upload custom backgrounds. Coworker discovered this fun nugget. Go to ‘%APPDATA%\Roaming\Microsoft\Teams\Backgrounds\Uploads’ Once uploaded, will appear as an option in the list. Have fun!
13
102
347
@FrankMcG
Frank McGovern
1 year
Amazing.
Tweet media one
13
47
338
@FrankMcG
Frank McGovern
11 months
Whelp, it was a fun run. See you later, @Reddit . I have ZERO interest in using your official app. I’ll also start my transition removing myself as head mod a top 1% subreddit with 760k+ subscribers. End of an era. Digg > Reddit > ???
Tweet media one
24
19
336
@FrankMcG
Frank McGovern
5 years
We need more CTF’s that promote teaching and sharing. I want to see a CTF that awards points when you help someone else catch a flag.
26
56
335
@FrankMcG
Frank McGovern
2 years
If you’re active on Twitter and work at a company doing infosec, I recommend you mix up what technologies you post about. It’s very easy to determine what tech stack is at a company by scraping what vulns and complaints you make. Throw in other products you don’t use sometimes.
41
32
334
@FrankMcG
Frank McGovern
6 years
HEY YOU. Yeah. You. Scrolling through your feed. Drink some water. @defcon #defcon #HackerSummerCamp
10
71
319
@FrankMcG
Frank McGovern
4 years
Solving an IT problem for now without fixing the root cause.
Tweet media one
20
99
320
@FrankMcG
Frank McGovern
1 year
Be careful of your kids becoming hackers! Know what to look for.
Tweet media one
88
66
316
@FrankMcG
Frank McGovern
3 years
In my opinion, Cybersecurity has only been “mainstream” for barely over a decade. Due to that, I’d argue no one is an expert at it. So if you have imposter syndrome, realize no one truly knows what they’re doing because this is all brand new and wildly advancing.
22
43
308
@FrankMcG
Frank McGovern
1 month
I see WAY too many people working through lunch because “I need to get stuff done” or “I didn’t get enough done yesterday”. Please, stop. The work doesn’t end. It always exists. It’ll wait for you. You are also a human and need fuel. Take 👏🏼 your 👏🏼 breaks.
14
41
312
@FrankMcG
Frank McGovern
3 years
In your 5-year org roadmap for Cybersecurity, you should have a full year where no new tools are onboarded. Work on finishing those tools implemented to 90% and understand what your capability is. You likely don’t need a new tool for a gap.
16
40
305
@FrankMcG
Frank McGovern
2 years
People live in their limited scope and forget that cybersecurity is more than engineers, SOC, and hackers. GRC, for example, is a great area where someone can excel and do it only from 9-5 and be here for the paycheck. E.g., someone doing third-party risk assessments full-time.
15
38
304
@FrankMcG
Frank McGovern
10 months
Aren’t most of these people “new”? This is a really bad way to start out your career. If anyone’s creating a list of names, I’ll take it. I’ll make sure men like this never work for companies I’m a part of. Fucking respect others.
@shenetworks
shenetworks
10 months
“She’s dumb as fuck, she might be the horny one tho” “Should send her to jerry” “The babies would be a sight to see” “She’s at least physically attractive” “I wouldn’t kick her out of bed if she kept her mouth shut” From BowTiedCybers discord server Should I continue?
Tweet media one
Tweet media two
130
111
913
18
26
305
@FrankMcG
Frank McGovern
3 years
What’s life as a Cybersecurity Architect at a Fortune 100? Today is 8am to 2pm with 0 breaks. That was 9 different meetings. I then get 2-2:20pm to hopefully eat. Then 2:30 to 4:30pm is 4 more meetings. Tomorrow is 8am to 6pm and 13 meetings. Only 1 hour of breaks in that.
67
28
294
@FrankMcG
Frank McGovern
4 years
Ever wondered “what Azure AD role do I actually need to give someone to complete their task?” or “what role should someone be able to PIM/JIT to for their work?” This Microsoft Docs page shows you the least privileged role to complete a task in Azure AD.
6
104
296
@FrankMcG
Frank McGovern
3 years
I don’t know who needs to hear this, but for 99.9999999999% of you reading this, the government and intelligence agencies do not care about you.
37
22
291
@FrankMcG
Frank McGovern
3 years
What are your thoughts on a CISO not being technical? It’s ok if your answer is “it depends,” but if so, what does it depend on? For example, what if your CISO has never deployed a server in the cloud or can’t build a script or has never configured a rule on a firewall.
246
35
291
@FrankMcG
Frank McGovern
3 years
Consultants, have you ever turned down work for a company because you just didn’t like the company or what they do as a business?
121
7
286
@FrankMcG
Frank McGovern
1 year
Oracle has made a change to licensing. Shocking, right? For Oracle Java now, you must license for ALL users in the environment if you have ONE instance of it. It’s no longer to only license the server/CPU counts. I cannot emphasize enough to rid of it.
28
97
289
@FrankMcG
Frank McGovern
4 years
Here is v2.0. Credit goes to Henry Jiang. Ref:
Tweet media one
8
81
280
@FrankMcG
Frank McGovern
3 years
I’m going to make a business one day and employees will only work 4 days a week and less than 8 hours a day and they’ll still be compensated the same and have all the benefits. And I’m going to steal all your best employees because of it. Good luck.
20
16
278
@FrankMcG
Frank McGovern
2 years
Tweet media one
14
46
276
@FrankMcG
Frank McGovern
5 years
The great @ATT tried rolling out their fake 5G to the Chicagoland area today. It proceeded to completely brick phones so bad that you can’t even connect to WiFi. If you have AT&T, disable LTE to fix. Expected fix time for area isn’t until 8pm.
13
111
261
@FrankMcG
Frank McGovern
2 years
Identity is slept on. Cybersecurity Engineers will eventually be saturated and many can do it with ease. Identity is much harder and requires deeply understanding the root of trust and AAA. Not many getting into it, so it will be more highly sought after eventually. $$$$
19
27
273
@FrankMcG
Frank McGovern
7 months
Tweet media one
70
2
272
@FrankMcG
Frank McGovern
1 year
I have 0 interest in ever going to an office again for more than 2 days/week. That’s the opposite way I want my life to exist and go for a work/life balance. My entire days are ruined now when I go the office. I lose 2 hours of sleep, I lose more evening time, & tasks build up.
22
12
270
@FrankMcG
Frank McGovern
3 years
Too many of the same people invited to events or once someone is twitter “famous” enough. Start paying attention to people with only 50 or 500 or 2,000 followers. Someone’s opinion isn’t valid once they hit a certain threshold and the large follower accounts are doing fine.
7
36
265
@FrankMcG
Frank McGovern
2 years
Netflix is going to kill themselves with cracking down on “shared accounts.” There is no legitimate way to get it right. The algorithm will have so many false-positives. People with multiple homes. People that travel. People that use at work and home. Military.
35
16
266