Thanks Derek, always a good idea to look at why we do the cool stuff, as well as how.

I frequently find that lots of people in my org know about how, but are unsure as to why, so I have a security awareness presentation that tries to help fill in this gap, it specifically goes from global threat situation through GRC and threat models to testing controls and incident response. Shamelessly based on talks by Kelly Shortridge - cheers Kelly :)

