Andy Ellis Profile Banner
Andy Ellis Profile
Andy Ellis

@csoandy

Followers
19,217
Following
817
Media
5,775
Statuses
80,916

Jew. Partner, @YLVentures . Author, 1% Leadership. Hall of Fame CSO, Board Director, Investor, Leadership Coach.

Boston/Tel Aviv
Joined February 2009
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@csoandy
Andy Ellis
6 years
We often tell stories from the point of view of the hero. But heroes don't notice everything; examining a story from the point of view of the villain can be informative. Let's look at Harry Potter. 1/20
Tweet media one
15
49
262
@csoandy
Andy Ellis
8 months
Ugh, wonder what Mini was thinking with this design.
320
283
5K
@csoandy
Andy Ellis
10 years
“Your microwave needs an Internet connection.” “Why?” “To get patches so it isn’t vulnerable to network attacks. And DST.”
26
637
677
@csoandy
Andy Ellis
9 years
There goes a binary palindrome year (11111011111), exchanged for a sorted binary year (11111100000).
17
911
672
@csoandy
Andy Ellis
5 years
I’m a big fan of @ringel ’s 15 minute rule: when you get stuck, spend 15 minutes documenting what you know, what you need to know, and use that to ask for help. Sometimes, at minute 14, you answer your own question. But if not, your question is clear.
11
220
492
@csoandy
Andy Ellis
4 years
Employees don’t get paid if they don’t click links from Payroll. Employees are subjective to disciplinary action if they don’t click links from HR. Employees are fired if they don’t click links from the ticketing system. Tell me how you’re training them not to click links.
@ryanaraine
Ryan Naraine
4 years
"I don’t care how many times you train people from not clicking on those unsolicited emails, people do. When you get to the nation-state advanced persistent level, sometimes those emails can be really well-crafted where it’s not an unreasonable thing for somebody to click on."
3
7
60
15
110
407
@csoandy
Andy Ellis
4 years
Remember how when the NFL peanut gallery would argue about whether Brady or Manning was the greater QB, as peers who came in at about the same time? Peyton just got selected to the Hall of Fame. Tomorrow, Tom is starting in his TENTH Super Bowl. Good times.
7
54
398
@csoandy
Andy Ellis
4 years
@iamchrisscott @LawyerLiz I wonder if that was a stock answer she gave, and now it’s March 31st…. “How many books do I have to write now?
1
0
380
@csoandy
Andy Ellis
6 months
@BriannaWu @TaliaKhan_MIT Welcome to another day that starts with ‘Yom’. In every generation it is this way for Jews: literally half of our holidays are observances of that time somebody tried to kill all of us, and it always starts with the slander.
36
11
370
@csoandy
Andy Ellis
8 months
76
14
343
@csoandy
Andy Ellis
5 years
@Dustinkcouch @LadyLovesTaft That’s just because Dumbledore spent Books 1-5 stalling for time.
@csoandy
Andy Ellis
6 years
We often tell stories from the point of view of the hero. But heroes don't notice everything; examining a story from the point of view of the villain can be informative. Let's look at Harry Potter. 1/20
Tweet media one
15
49
262
4
25
301
@csoandy
Andy Ellis
4 years
It’s been an excellent twenty-plus years at @Akamai , but eventually all paths diverge.  In March, I’ll be leaving.  Before I announce what I’m doing next, I just wanted to take a look at my last 20 years. (1/)
66
27
297
@csoandy
Andy Ellis
3 years
@SwiftOnSecurity Any sufficiently complex system is indistinguishable from a simple system to the casual observer.
10
46
233
@csoandy
Andy Ellis
5 years
Today officially wraps up my 19th year at @Akamai . Tomorrow, I start year 20!
24
2
216
@csoandy
Andy Ellis
8 years
All 3 kids in the house got @MartysaurusRex #HugFootballMarty pillows, which means 3 heart surgery patients at @BostonChildrens also get em.
2
14
188
@csoandy
Andy Ellis
5 years
First: kudos to @Cloudflare for transparency here and throughout their incident. Next: some thoughts on safety in distributed systems like this. (I don’t know how CF does it, so don’t take this as criticism of their practices, merely some musings from similar experiences) 1/
@mjos_crypto
mjos\dwez
5 years
so that cloudflare outage was a caused by a single regex rule deployed globally in one go🤦‍♂️
Tweet media one
55
830
2K
6
62
197
@csoandy
Andy Ellis
8 months
@kurtopsahl Ah, now I get it.
3
1
191
@csoandy
Andy Ellis
5 months
@CampusJewHate @Columbia A searchable database, maybe integrated with a course calendar, would be an awesome output.
7
3
180
@csoandy
Andy Ellis
3 years
Twenty years. You are not forgotten, Danny.
Tweet media one
6
9
175
@csoandy
Andy Ellis
8 years
What if the lottery is merely a government-run test to find precognitives?
7
59
161
@csoandy
Andy Ellis
6 years
Found some ⁦ @Patriots ⁩ fans in Buffalo.
Tweet media one
3
1
162
@csoandy
Andy Ellis
10 months
@DrEliDavid I hate to quibble, but in Brachos 44A, the Talmud subtweets Jesus, commenting that the fruit of the Genosar is very sweet, but not at all filling, and should be taken with a grain of salt.
6
5
136
@csoandy
Andy Ellis
4 years
Me: Why do people who hate the Patriots waste their energy watching them just to taunt? Also me: stays up late to watch the Steelers lose. 🍿🍿🍿
6
9
147
@csoandy
Andy Ellis
6 years
From a prep call for a conference today: “The two people you never want to have ask to speak with you: @taviso and @briankrebs .” Although, if necessary, I’d rather hear from them than not.
5
15
146
@csoandy
Andy Ellis
8 years
I’m increasingly convinced the Twitter 140 character limit is doing more to eliminate the double space after a period than anything else.
6
35
136
@csoandy
Andy Ellis
4 years
@FitzyGFY It’s one of the three classic blunders. Fighting a land war in Asia, going up against a Sicilian when death is on the line, and giving Brady the ball with the season on the line.
3
21
133
@csoandy
Andy Ellis
11 years
This is what happens when the about-to-be-8yo asks @gisellis for a @stampylongnose cake. (In progress) http://t.co/obDUuVIMNj
Tweet media one
20
26
119
@csoandy
Andy Ellis
3 years
Did you realize the ~40% of cyber security vendors' EULAs forbid even publishing a review about them? We've been so busy arguing about "responsible" disclosure for vulnerabilities, that we've been ignoring the basics around vendor transparency.
Tweet media one
6
35
123
@csoandy
Andy Ellis
5 months
@swagitda_ I am tempted to come sit in your hotel lobby and wait for a repeat offense.
5
2
127
@csoandy
Andy Ellis
3 years
Wakes up. Checks Twitter. Sees some Internet issue. “Not my problem anymore.” Goes back to bed.
5
2
115
@csoandy
Andy Ellis
6 years
Really good write up by @hacks4pancakes on the intersection of IOT, home renting (and leasing at scale), physical security, and information security.
3
59
111
@csoandy
Andy Ellis
9 months
@Devon_Eriksen_ It wasn’t just the takedown (which was excellent), it was also the beauty of the English language in your hand.
4
0
109
@csoandy
Andy Ellis
4 years
Thought: humans learn best by being conscious of being wrong. In environments where it’s unsafe to be wrong, humans tell themselves (and others) stories about how they were really right all along — which negates any learning value. And they were still wrong.
4
25
101
@csoandy
Andy Ellis
6 months
@BriannaWu @TaliaKhan_MIT We have no other choice: we live like this, we celebrate our joys, or we let those who hate us destroy us. But when we’ve spoken up in progressive spaces, we get mobbed & unpersoned. So many Jews have had to lock up their voice to support others.
6
4
96
@csoandy
Andy Ellis
8 months
@TheMossadIL I like this, but it’s not in my size.
Tweet media one
20
1
89
@csoandy
Andy Ellis
4 years
Received CoViD jab. Have not developed mutant powers. Do not appear to be a 5G hotspot. Highly disappointed in the hype.
8
4
93
@csoandy
Andy Ellis
6 years
@HNYNUT_BERRIOS Assuming you thrive, it gives you a built in “BERR10S” brand.
4
4
84
@csoandy
Andy Ellis
7 months
@StandUp2JewHate Why is he being called to Torah at that hour? Or are we trying to mislead those who call in threats?
10
0
81
@csoandy
Andy Ellis
5 years
@BritishArmy @USArmy @USArmyEurope @BritishArmyUSA Your tea is just fine, with a little Boston salt water added to it! But blood is thicker than that.
0
0
65
@csoandy
Andy Ellis
6 years
First, you really want to have a good target body to jump into. Ideally, they're part of the Peverell clan, which has a long history of access to cool powers, and maybe you can get some. 11/20
Tweet media one
1
6
78
@csoandy
Andy Ellis
6 years
With apologies to @jk_rowling , for using her characters to illustrate this point: Rarely is someone the villain in the story they tell. Usually, that's because they aren't a villain. But Albus Dumbledore and Ritual of Immortality? He’s the villain. 20/20
Tweet media one
4
10
82
@csoandy
Andy Ellis
5 years
We’ve pulled all of our non-product-marketing content @Akamai out into its own site (), if you’re interested in it. No regwall.
3
41
80
@csoandy
Andy Ellis
6 years
How quickly can one change one’s name? Asking for a friend...
@JetBlue
JetBlue
6 years
If your first name starts with P-A-T and you’re flying into or out of BOS or ATL today, this one’s on us! We’re crediting the base fare of your flight to your JetBlue Travel Bank. Check your email for details. #JetBlueOfficialAirline
98
350
1K
3
4
70
@csoandy
Andy Ellis
6 years
One path to immortality is life extension, like with the philosopher's stone. Problem? You still age. After a while, you're spending all your time fighting with Medicare Part B billing. 3/20
Tweet media one
2
4
72
@csoandy
Andy Ellis
1 year
Your annual pre-RSAC pro tip. Take care of your wellness, it’s the greatest asset you control.
Tweet media one
4
6
76
@csoandy
Andy Ellis
6 years
Inspired by PechaKucha, here is my attempt at telling a story -- The Villain's Quest in Harry Potter -- via Twitter. 20 "slides", one every 20 seconds. For good or ill, it'll be over soon. 0/20
4
20
71
@csoandy
Andy Ellis
5 months
@MikeReiss @ESPNStatsInfo Well, that’s a low bar to over-achieve.
1
0
73
@csoandy
Andy Ellis
4 years
I’m not sure who needs to hear this, but: You are more awesome than others know or give you credit for. One day, they’ll find out.
2
12
75
@csoandy
Andy Ellis
1 year
@USConst_Amend_I My contrarian take is that there are 6, not 5; that the anti-establishment right is distinct from the free exercise right.
11
2
70
@csoandy
Andy Ellis
5 months
It's worth remembering that not only are we not yet back to where we were in 1939, but the global genocide against Jews wasn't orchestrated by just the Nazis in Europe, but a lot of Arab nations also participated in wiping out their Jewish populations.
@IsraelWarRoom
Israel War Room
5 months
Ahead of Holocaust Remembrance Day in 2024, there are 15.7 million Jews worldwide. That's still lower than the global Jewish population in 1939, before the Holocaust wiped out more than 1/3 of the world's Jews. That's what actual genocide looks like.
81
401
1K
3
23
69
@csoandy
Andy Ellis
11 months
@amyalkon Technically, Gaza is riddled with bomb shelters, underground, under hospitals … but only Hamas gets to use them.
0
11
67
@csoandy
Andy Ellis
4 years
@diannaESPN @minakimes @MikeReiss @soldernate Well, if you’re going to go there...
Tweet media one
1
0
62
@csoandy
Andy Ellis
4 years
Ask everyone in the company two questions: * What’s the most useless security practice we have? * What the most glaring hole in our security near you? You probably now know more than your predecessor. Go.
@varcharr
casey
4 years
New CISOs, ISOs, and other security leads can often find themselves accidentally in this critical role. What are the first steps a security officer should do when taking over the protection and security of an infrastructure (system, network, etc)?
59
31
148
1
11
66
@csoandy
Andy Ellis
3 years
Born in CA. Moved to MA. Led a Boston organization to dominance. Married Gisele. I’ve been one step ahead of @TomBrady my entire career. And now, one more time…
16
3
65
@csoandy
Andy Ellis
8 years
@SwiftOnSecurity “no one will ever use this that way” is the source of more disasters….
2
15
62
@csoandy
Andy Ellis
5 months
@swagitda_ Dang it! I left that outfit at home! Next year we can coordinate.
1
0
66
@csoandy
Andy Ellis
8 years
Found @MartysaurusRex at the @ImaginationAgcy booth! May he have one more slice of cake!
Tweet media one
0
3
60
@csoandy
Andy Ellis
6 years
I promise not to reference Sun Tzu or Clausewitz in my #RSAC talk on Tuesday (“Humans are Awesome (at Risk Management)”).
6
6
61
@csoandy
Andy Ellis
7 years
You know, I’ve long been an advocate of eliminating passwords altogether, but I didn’t quite mean it this way.
0
14
64
@csoandy
Andy Ellis
5 years
I survived. I think the nurses are happy to be rid of their chatty & inquisitive patient. 😹😹😹
Tweet media one
12
0
62
@csoandy
Andy Ellis
5 months
@swagitda_ Although this is SF. I might be able to source something.
3
0
62
@csoandy
Andy Ellis
7 years
@brandincooks glad you’re well enough to tweet! May the One who brings healing grace you with a speedy and full recovery. #NotDone
2
0
60
@csoandy
Andy Ellis
4 years
Kind of weird to not be a CSO. (No, I’m not changing my handle)
9
0
62
@csoandy
Andy Ellis
2 years
I love it when stores have the Rosh Hashanah candy next to the Sukkot candy, even if they flipped them left/right. (Cc @JewWhoHasItAll )
Tweet media one
3
3
58
@csoandy
Andy Ellis
6 years
And security folks wonder why marketing has a love/hate relationship with us.
@chiefmartec
Scott Brinker
6 years
I swear, @marketoonist is killing me softly with his song. #MarTech
Tweet media one
8
142
388
4
14
59
@csoandy
Andy Ellis
1 year
@Seinpeaks @boblord Thanks for sharing those twin peeks.
1
1
59
@csoandy
Andy Ellis
7 years
Not at all sketchy.
Tweet media one
7
16
57
@csoandy
Andy Ellis
4 years
@SwiftOnSecurity Look, this is my basement. I’m not judging.
Tweet media one
4
2
58
@csoandy
Andy Ellis
8 months
@kurtopsahl Not even sure how that’d work “differently” in the UK.
8
0
57
@csoandy
Andy Ellis
5 years
Last week, I got to fly in the Chiefs’ equipment. This week, I’m flying with a much better package…. (cc @MikeReiss )
Tweet media one
3
1
57
@csoandy
Andy Ellis
6 years
Today marks 18 years at @Akamai . Today included: ☑️ Fly to/from DC ☑️ Keynote ☑️ Sales support ☑️ Compliance ☑️ Incident mgmt ☑️ Press ☑️ Finance ☑️ Plan a Lewin Lecture ☑️ See my team handle even more Like most days, full of diverse work, and great coworkers.
5
2
56
@csoandy
Andy Ellis
8 years
Sounds like a Distributed DM Denial of Service on @SwiftOnSecurity . Our first ever DDDoSoSoS.
@SwiftOnSecurity
SwiftOnSecurity
8 years
HELP: I can't work with Twitter DMs anymore at my scale. Are there good 3rd-party, high-volume tools you recommend? Outlook interface?
27
11
50
1
4
53
@csoandy
Andy Ellis
5 months
@SwiftOnSecurity This is what a world with Clippy looks like.
1
0
55
@csoandy
Andy Ellis
4 years
My first day of unemployment involved 4 meetings/events and 3 calls. I might be doing this wrong.
4
0
56
@csoandy
Andy Ellis
3 years
In before everyone else: Happy half century to me!
26
0
55
@csoandy
Andy Ellis
5 years
May your light never be extinguished by fear or hate.
Tweet media one
1
10
55
@csoandy
Andy Ellis
6 years
@SwiftOnSecurity Arguably, machine decision-making will be about distancing humans from hard choices, so we can nebulously blame the system* for bad outcomes. * or whichever outgroup the mob dislikes this week,
1
11
52
@csoandy
Andy Ellis
6 years
@its_a_lisa @bcrypt Indeed! Usually works well:
1
9
53
@csoandy
Andy Ellis
6 years
@SwiftOnSecurity This reminds me of the old X-NSA-Keywords header people would put into SMTP headers.
3
3
52
@csoandy
Andy Ellis
1 year
Well, I’ve got the @McCourtyTwins jersey half-autographed. @devinmccourty left a little bit of room for you, @JasonMcCourty
Tweet media one
0
1
51
@csoandy
Andy Ellis
8 months
@da_allgeier The US doesn’t *require* this level of failure.
4
1
51
@csoandy
Andy Ellis
6 years
Another challenge with body-hopping is that the other body probably has a soul in it, that doesn't want to leave. So you have to share. And sharing isn't caring. 6/20
Tweet media one
1
2
46
@csoandy
Andy Ellis
6 years
30 ways to shoot yourself in the foot: how not to approach a CISO (25 is my pet peeve).
11
20
51
@csoandy
Andy Ellis
5 years
Every so often, a cold-emailer gets my vendor rebuf () and sends me back a snippy argument. I’m not sure they realize the brand damage they cause.
11
10
52
@csoandy
Andy Ellis
2 years
@SwiftOnSecurity Stop paraphrasing my book before people get a chance to read it!
Tweet media one
2
9
50
@csoandy
Andy Ellis
4 years
I’ll also have to write some new keynote material before all the conferences start back up.  “One Score of CSO Years Ago...” has a nice ring to it as a topic, I think ;). (14/FIN (for now))
10
1
51
@csoandy
Andy Ellis
6 years
You know what I’d prefer before autonomous vehicles? Intelligent traffic lights with that full sensor suite, acting to reduce congestion.
7
5
49
@csoandy
Andy Ellis
2 years
@JewWhoHasItAll Yes! Especially if it’s leftover candy from the Chaggim, but even if not, it’s covered by the gleanings rule from Ruth. Of course, it’s always better if both sides are anonymous, so wearing a masked costume offers dignity to them.
0
3
49
@csoandy
Andy Ellis
6 years
The horcrux downside, of course, is that you never know who is going to fall prey to it. You might end up having to go through puberty again, which probably isn't high on a wizard's wish list. 9/20
Tweet media one
1
2
44
@csoandy
Andy Ellis
5 months
@shaunmmaguire @AvivaKlompas In fairness, she’s not exactly wrong: the pro-genocide Jews are the ones in the encampment, calling for their own genocide. It’s the rest of us who are anti-genocide.
20
1
46
@csoandy
Andy Ellis
5 months
@Devon_Eriksen_ “The law may be an ass, but this law is a bikini model's ass” is a beautiful piece of writing.
0
0
50
@csoandy
Andy Ellis
4 years
I’m excited to announce that I’ve joined @ylventures as an Operating Partner.  Together, we’ll continue to accelerate the cybersecurity startup pipeline, from seed to lead, and continue to protect a better Internet.
14
1
48
@csoandy
Andy Ellis
6 years
@jk_rowling If you would like to see the prose of this story of the villainy of Albus Dumbledore, there is prose at for your further reading pleasure. 21/20
2
1
47
@csoandy
Andy Ellis
7 years
A backup @Patriots QB is now a starter, drives downfield in OT, and Vinatieri kicks a game-winning FG? Is Destiny just copying old stories?
1
29
46
@csoandy
Andy Ellis
6 years
And since Death wants you back, you have to do unpleasant things to stay alive. Like kill unicorns. And not the Silicon Valley unicorns, those awesome ones that wander in the forest. 7/20
Tweet media one
1
2
42
@csoandy
Andy Ellis
9 months
@Devon_Eriksen_ I think you can safely say you did your marketing job with a banger of a tweet today.
1
0
48
@csoandy
Andy Ellis
4 years
If someone trusts you enough to let you see their work-in-progress, don’t critique it as if it were done. And don’t give obvious advice about their next step; you’re not their supervisor.
3
10
47
@csoandy
Andy Ellis
1 year
It’s here!
Tweet media one
13
4
48
@csoandy
Andy Ellis
6 years
What does the villain want in Harry Potter? Immortality! It's easy to say, "Power," but the power that matters to the villain is not dying, and everything else will flow from that. 2/20
Tweet media one
2
2
40
@csoandy
Andy Ellis
4 years
We built a world-class Information Security team.  Nearly a hundred professionals, who govern risk, safety, intelligence, and compliance across our business.  Over 40% of whom are women. (11/)
2
1
46