Security builder & leader

How to Suck at Information Security - A Cheat Sheet

A tongue-in-cheek collection of common security mistakes to avoid: deploying products without tuning them, treating all assets with equal rigor regardless of risk, locking down infrastructure so tightly that work becomes difficult, and assuming compliance equals security.

How to Suck at Information Security - A Cheat Sheet - illustration

This cheat sheet presents common information security mistakes, so you can avoid making them. Yeah, the idea is that you should do the opposite of what it says below. To print, use the one-page PDF version; you can also edit the Word version for you own needs.

Security Policy and Compliance

Security Tools

Risk Management

Security Practices

Password Management

More Security Mistakes

Post-Scriptum

Special thanks for feedback and contributions from SANS Internet Storm Center handlers. This cheat sheet is distributed according to the Creative Commons v3 “Attribution” License. File version 1.4.

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →