I have some sympathy for the @Okta corporate comms team. After all, the @awscloud PR playbook isn't really an option for them.
But perhaps mine will be? A thread.
I paid @acvisneski (my crisis comms consultant) to prepare a handbook for what to do in the event of an actual crisis. Chapter 1 may be of some interest: "Don't stick your dick in a pie." Let's read it together, much like I read my children bedtime stories.
And see, this is why she's the expert and not me; I've already run afoul of Step 1, "Don't refer to a crisis as sticking your dick in a pie."
Oops. So far, so good for you though.
Step 2: If you *do* find your dick stuck in a pie, apologize.
If it's not your pie, go directly to Step 4.
Step 3: If it is your pie, take responsibility and explain how you're going to remove your dick and make things right.
This is where you folks kinda dropped the ball. You've gotta own the pie and the dick here!
Step 4 is ideally a step you won't need to take. Because honestly? Don't be trash!
Chapter 2 "Don't bare your butt to a bear" and Chapter 3 "So you fucked around and found out" are available upon request. Hope this helps!
• • •
Missing some Tweet in this thread? You can try to
force a refresh
And now, a live Zoom meeting where @okta's CISO Ray Bradbury talks about the breach.
"It's an embarrassment for myself and the entire Okta team." He's so incensed that he misuses the reflexive pronoun!
Taking pains to point out that Sitel is an external contractor. "It's not entirely our fault because we outsource dealing with our customers because we don't want to do it ourselves" isn't the strong statement it was workshopped as.
"We knew we were breached back in January but didn't think to check what the attacker may have done with that access" is how I read this. And reader, this is not a good interpretation.
How is it that I, a Cloud Economist whose secrets are arguably some of the most boring in the world, have a better comms plan in the event of breach than a bona fide security company?
Honestly, @awscloud giving self-taught learners free sandbox AWS accounts that are heavily restricted is a great thing for most people.
In my case it's like strapping raw meat to your chest right before you climb into the zoo enclosure to fuck around with the tigers.
Don't worry, if I run the AWS training and certification team's AWS bill into the stratosphere they can either ask for a concession from @awssupport or else engage The @DuckbillGroup for help!
"You know we monitor these for misuse, right?"
"Your version of 'misuse' is calibrated towards 'I use the account to mine cryptocurrency,' not 'I'm gaining nothing, but running up the AWS billing score.'"