Cosive hires ex-Deloitte Prescott Pym as Principal Consultant

Cosive hires ex-Deloitte Prescott Pym as Principal Consultant
December 3, 2024

Security operations and cyber threat intelligence firm Cosive has appointed Prescott Pym as a Principal Security Consultant.

Based in Canberra, Prescott will be responsible for growing Cosive's professional services client base and helping drive the go-to-market strategy for its SaaS offerings, including CloudMISP, MalwareZoo, and Antifraud.

Prescott brings over 25 years of experience running Security Operations Centres (SOCs) globally and recently helped lead the national threat intelligence sharing program in Australia.

Prior to joining Cosive, Prescott was a Principal Consultant for Cyber Security at Deloitte Australia, where he worked on large-scale, nationally significant cyber projects.

He has also served as a global leader in Verizon’s Managed Security Services and has played pivotal roles in establishing Security Operations Centres in Australia, India, Japan, Germany, Switzerland, and the USA.

“With his extensive background in cyber threat intelligence and security operations, Prescott brings a wealth of expertise to guide our strategic initiatives," said Cosive Managing Director Terry MacDonald.

"We are very pleased to have him join the team as he will bring tremendous value to our customers and support our ongoing regional growth."

Meanwhile, Prescott said he has known Cosive’s senior management team for "many years".

"The cyber industry across Australia is quite interlinked, so you don't have to go far to find where Cosive has had an impact," he added.

"I'm really passionate about how communities help people and organisations grow and create something special that can't be done in isolation. I've seen Cosive work actively in this space, sharing knowledge at conferences, demonstrating best practices in their work, and supporting broader communities for the greater good. I'm really excited about what the future might hold as we collaborate together with our customers."

Follow Prescott Pym on LinkedIn | Follow Cosive on LinkedIn

February 21, 2024

Getting More Out of MISP and Microsoft Sentinel

Typically, SecOps analysts will have many daily routines, one of which will be to check their favourite Threat Intelligence Platforms, read the latest threats and note down any that are worthy of attention. Next, they’ll add those threats to the their central log analysis and alerting platform (e.g. Microsoft Sentinel) as something to look for. Depending on how many feeds analysts are watching and how active the bad actors are, this can be a very time consuming process. Granted, an important one, but still time consuming. Wouldn't it be nice if we could save the planet one tree at a time by doing away with all the post-it notes with one-off IP addresses and domain names? Could we get MISP and Microsoft Sentinel to talk directly without wasting analyst time?

February 21, 2024

Episode #003: Securing REST API Endpoints (or How to Avoid Another Optus) with James Cooper

Unless you have been living in a cave on Mars with your eyes shut and your fingers in your ears for the past few weeks, you have probably heard something about a data breach at Australian telecommunications giant Optus.As security mistakes go, the vulnerability reported to have enabled the attack leans toward the more embarrassing side of the scale. If reports are true, Optus has effectively exposed customer data on an endpoint available to the entire internet.While it is plausible that a developer will forget to (re)secure an endpoint once they finish their development work, there are multiple practical steps you can take to catch or mitigate the problem.