Sign in to view Tanya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tanya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Greater Victoria Metropolitan Area
Sign in to view Tanya’s full profile
Tanya can introduce you to 1 people at Grafos AI
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
58K followers
500+ connections
Sign in to view Tanya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tanya
Tanya can introduce you to 1 people at Grafos AI
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tanya
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tanya’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Services
Articles by Tanya
-
#SplunkConf23: Keynote Lessons
#SplunkConf23: Keynote Lessons
Hey there, fellow InfoSec-ers and IT professionals! How's it going? So, I recently (virtually) attended SplunkCon23…
3
-
Consulting on Canada’s Approach to Cyber SecurityJul 18, 2022
Consulting on Canada’s Approach to Cyber Security
You may not be aware but Canada’s Public Safety department put out a call to Canadian Citizens (sorry brilliant people…
168
8 Comments -
I want to talk about Log4jDec 14, 2021
I want to talk about Log4j
Lots of people are talking about how Log4J affects servers, but if you subscribe to this newsletter, you probably want…
111
5 Comments -
Application Security 101 Course Now Available for Pre-RegistrationApr 17, 2020
Application Security 101 Course Now Available for Pre-Registration
Our first course from SheHacksPurple.dev is now available for pre-registration, 'Application Security 101'.
79
-
#CyberMentoringMondayMar 4, 2019
#CyberMentoringMonday
Some people have been asking me online how to be a good mentor. Here are some thoughts for all of you.
87
16 Comments -
Promoting Yourself on Social MediaNov 1, 2018
Promoting Yourself on Social Media
As originally published on my blog, SheHacksPurple. Many people who are aspiring to become a public speaker ask me how…
56
9 Comments -
Pushing Left, Like a Boss: Part 4 — Secure CodingOct 25, 2018
Pushing Left, Like a Boss: Part 4 — Secure Coding
As originally published on my blog, SheHacksPurple. In the previous article in this series we discussed secure design…
38
2 Comments -
Pushing Left, Like a Boss: Part 3— Secure DesignOct 22, 2018
Pushing Left, Like a Boss: Part 3— Secure Design
As originally published on my blog, SheHacksPurple. In the previous article in this series we discussed security…
41
1 Comment -
Pushing Left, Like a Boss: Part 2 — Security RequirementsOct 9, 2018
Pushing Left, Like a Boss: Part 2 — Security Requirements
As originally published on my blog, SheHacksPurple. In the previous article in this series we discussed why ensuring…
43
1 Comment -
Practice Makes Perfect: Comments on Public SpeakingOct 5, 2018
Practice Makes Perfect: Comments on Public Speaking
As originally published on my blog, SheHacksPurple. Many people ask me about how to become a better speaker.
12
1 Comment
Activity
58K followers
-
Tanya Janca shared thisToday I used my tractor to move a lot of heavy rocks. All by myself! 💪 #infosecgardening
-
Tanya Janca shared thisIn this video I cover 5 top API Security Best Practices, taken from chapter 5 of my book, "Alice and Bob Learn Secure Coding". 3 minutes! https://twp.ai/4htjsm
-
Tanya Janca shared thisIt's good to be home. #infosecgardening There's a bee taking a nap in this flower. Maybe he has jet lag too? 😉
-
Tanya Janca shared this🚨 New blog post! **The Psychology of Bad Code – Part 7: "It Worked Last Time"** One of the most dangerous phrases in software development is: > "It worked last time." https://twp.ai/4hshvb 1/2 When something succeeds once, our brains are wired to assume it will keep succeeding, even when the situation has changed completely. It's a useful shortcut... until it isn't. If you've ever heard (or said 😅) "We've always done it this way," this one's for you. https://twp.ai/IlsRVn 2/2
-
Tanya Janca shared thisInsecure defaults are sneaky because they do not feel like bad decisions. They feel like “I’m busy, this worked before, ship it!” And that, my friends, is how the haunted config file gets passed down through generations. Watch or download on any podcast platform: https://twp.ai/4hsf7l #episode8
-
Tanya Janca shared thisOctober (Security Awareness Month) will be here before we know it, and my calendar is officially open for bookings! If you're looking for engaging security content that software developers will actually enjoy, I'd love to help. tanya AT shehackspurple DOT ca 1/4 I offer virtual keynotes, workshops, lunch-and-learns, and Security Champion Program sessions on topics including: 🤖 AI Security & Secure AI Development 🔐 Secure Coding 🎯 Threat Modeling 📦 Software Supply Chain Security 🛡️ OWASP Top 10 & Application Security tanya AT shehackspurple DOT ca 2/4 Whether you have a team of 20 or 2,000, I can deliver live virtual sessions anywhere in the world. If you're planning your October Security Awareness Month activities, now is the perfect time to reserve your date before my calendar fills up. 3/4 📩 Send me a message or visit shehackspurple.ca to learn more about training, workshops, and speaking opportunities. tanya AT shehackspurple DOT ca #SecurityAwarenessMonth #AppSec #SecureCoding #ThreatModeling #AISecurity #CyberSecurity 4/4
-
Tanya Janca shared thisJoin us for #OpenHack Cowichan Valley Sept 16th, at the Craig Street in Duncan, BC! https://twp.ai/4hu5jH
-
Tanya Janca reposted thisTanya Janca reposted this🚨 OWASP 2026 Board Elections are here! Do you have ideas, experience, and a passion for helping shape the future of the OWASP community? 🌎🔐 Three seats on the OWASP Global Board of Directors are up for election, and nominations are now open! 🎯 Want to stand for the Board? Eligible OWASP members can self-nominate by August 31, 2026. https://lnkd.in/gNv38cvj 🗳️ Want to participate without running? You can help shape the election by contributing to the candidate interview questions and, as an eligible member, casting your vote this autumn. https://lnkd.in/g7qKFFrR 📅 Key dates • August 31: Candidate nominations close • September 30 – November 1: Eligible members must maintain membership to vote • October 15: Voting ballots are sent to eligible members Whether you’re ready to lead, keen to contribute, or simply want your voice heard, this is your opportunity to get involved. 🙌 👉 Learn more and view the full election timeline: https://lnkd.in/g_5G-mXb #OWASP #OWASP2026 #AppSec#CyberSecurity #ApplicationSecurity #Leadership hashtag#Community #BoardElections#opensource
-
Tanya Janca shared thisHave you heard of #InfoSecGardening? 🌱🌻 It’s for ANYONE in cybersecurity (or IT!) to share photos of what you’re growing -> flowers, veggies, herbs, houseplants, gardens… whatever brings you joy. 💜 Think of it as a #TimeCleanse: a chance to step away from the screens, calm your brain, get your hands in the dirt, and reconnect with something real. It’s also a lovely way for our community to share a bit of joy with each other. 💚 So please: show me what you’re growing! I genuinely want to see it. 🌿🌸🍅
-
Tanya Janca liked thisTanya Janca liked thisI’m hiring a Director, Application and Product Security at Grainger! I’m looking for a security leader who genuinely understands the software engineer’s perspective, the pressure to deliver and the tradeoffs involved in building and operating products at scale. This leader will need to set strategy, drive execution, build strong partnerships, and help teams manage risk without creating unnecessary friction. If you can speak both security and software engineering, we’d like to hear from you! Interested, or know someone who may be a strong fit? Please take a look and share: https://lnkd.in/gkGw7NKz #Hiring #ApplicationSecurity #ProductSecurity #SoftwareEngineering #Cybersecurity #Grainger
Experience & Education
-
She Hacks Purple Consulting Inc.
****** ****** *******
-
******
******** ***** ******
-
********
******** ***** ******
-
********* ******* ** ******* **** *** **********
******** *********** ********** ********* ******* undefined
-
-
******** *********
****** ********** ***** ****** ***** **** ***** ****** ** * ****** ******** ***
-
View Tanya’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Volunteer Experience
-
OWASP Ottawa Chapter Leader
OWASP
- 4 years 2 months
Science and Technology
I started as the chapter coordinator, forging a partnership with the Public Library, then I organized interactive evens such as our annual Capture the Flag (CTF), trivia night and debates, which lead to my launching the Mentoring Program (pairing junior and aspiring AppSec enthusiasts with senior and experienced professional career guides). I started doing serious diversity-oriented recruitment our chapter, and became the second leader of our chapter. I also assist in speaker and topic…
I started as the chapter coordinator, forging a partnership with the Public Library, then I organized interactive evens such as our annual Capture the Flag (CTF), trivia night and debates, which lead to my launching the Mentoring Program (pairing junior and aspiring AppSec enthusiasts with senior and experienced professional career guides). I started doing serious diversity-oriented recruitment our chapter, and became the second leader of our chapter. I also assist in speaker and topic selection (malware, reverse engineering, social engineering, zero-day/vulnerability hunting, secure code review, PenTesting, hacking, etc), and sometimes I even am the speaker.
-
DevSlop Project Leader
OWASP Foundation
- 4 years 6 months
Science and Technology
Lead the "Patty the Pipeline" module, created a 9 product deep DevSecOps pipeline, created countless videos and hosted even more live streams of coding and bug fixing. Also, created the team website.
-
Co-Founder and Victoria Chapter Leader
WoSEC
- 2 years 2 months
Science and Technology
Along with Donna Hogan, Duhah, Judy Ngure and several other amazing women I founded WoSEC: Women of Security. I started the original chapter in Ottawa, Canada with Donna Hogan, and worked with many others to open chapters world-wide. Our goal is to create a community of women that helps each other success, flourish and have fun in our industry! I currently lead the Victoria, BC chapter with my co-leader Vane Makori.
-
Cyber Security Content Advisor
ICTC-CTIC
- Present 8 years 1 month
Education
I help add 'cyber' to high school curriculum in Canada.
Languages
-
French
Professional working proficiency
-
English
Native or bilingual proficiency
Organizations
-
Forte Group
-
- PresentNon-profit for women CEOs, CISOs and Startup Founders
-
OWASP
Chapter Coordinator
-
Recommendations received
5 people have recommended Tanya
Join now to viewView Tanya’s full profile
-
See who you know in common
-
Get introduced
-
Contact Tanya directly
Other similar profiles
-
Charlie Zappien
Charlie Zappien
Westmount Solutions, Inc.
2K followersGreater Montreal Metropolitan Area -
Adrian Moise
Adrian Moise
Aequilibrium Software Inc.
9K followersGreater Vancouver Metropolitan Area -
Nathalie Lussier
Nathalie Lussier
Waykeeper Farm & Nerdery
4K followersGreater St-Catharines-Niagara Metropolitan Area
Explore more posts
-
Ryan Zorn
CyberAGroup • 310 followers
Loblaw Breach - Ransom Paid? CyberAGroup assesses that a ransom was likely paid in the Loblaw breach, primarily because the threat actors voluntarily removed their post on the morning of the deadline. In typical data ransom scenarios, attackers don’t simply disappear when a deadline passes; they usually escalate by doubling their demands, even when bluffing, or by leaking more data to maintain leverage. Having worked on similar cases, we have found that hackers generally only back down once they’ve been compensated. Given that they probably paid a ransom, the incident is certainly more than a "low-level data breach." It is also being reported that Loblaw has engaged outside cybersecurity firms to conduct a forensic audit and determine the full extent of the intrusion. At the time of this post, Loblaw is sticking to its guns; its original notification from March 10 remains and has not been updated. Just because Loblaw paid a ransom doesn't mean your personal information is safe, especially in this case. Trusting in the "honor" and good faith of cybercriminals to actually delete data is a gamble at best. With respect to "branded" ransom groups like PLAY, SHINYHUNTERS, or COINBASE CARTEL, a victim’s only hope is that these groups won't dump, resell, or re-ransom the data in order to protect their reputations so that future victims will pay up. In this incident, involving a single username created specifically for this ransom (not publicly identified with any of the known groups), there is no reputational damage if the attackers turn around and sells the data to other bad actors or simply dumps it on the dark web in the future. Payment doesn't equal real protection. It may only prevent Loblaw from dealing with immediate consequences, with the company hoping that when your data does eventually surface, they won't be blamed. So, what now? We should expect to know exactly what personal data is out there and could resurface. Unfortunately, we don't know of a case where a company provided its customers with the real full details, even when they know exactly what was leaked. The sad reality is that companies will often tell customers it was a "low-level" leak and hope everyone forgets about it. While those companies go back to business as usual, the data lives on to be exploited by the burgeoning industry of fraudsters, extortionists, and data brokers.
8
-
NEL PROFESSIONAL
803 followers
External Attack Surface Signals, $Calgary Organizations At NEL Professional, we analyzed the publicly visible cyber posture of several large Calgary organizations. Common exposure signals included: • Missing SPF / DMARC email authentication • Publicly listable cloud storage buckets • Missing Content Security Policy headers • Lack of CAA DNS certificate controls • Large public subdomain attack surfaces These are not breaches but they represent the same signals attackers use during reconnaissance. Cybersecurity begins with understanding what the internet already reveals about your infrastructure. 🌐 https://lnkd.in/gaTS-QQi #CyberSecurity #AttackSurfaceManagement #NIST #ISO27001 #SOC2
2
-
Techsek Inc.
144 followers
Cyber Update for SMEs 1,400 MongoDB Servers at Risk Thousands of databases remain exposed online due to weak or missing access controls, making data wipes and ransom demands easy for attackers. Dozens of SMEs across Quebec have already been impacted often without realizing their systems were publicly accessible in the first place. This highlights a simple but critical reality: without basic security hardening, asset visibility, and continuous monitoring, cloud environments remain an easy target. Misconfigurations , not sophisticated exploits , continue to be one of the leading causes of data exposure for growing businesses. Unsure if your systems are properly secured? Techsek works as a long-term partner to help SMEs reduce risk and build resilient IT environments. 📩 info@techsek.ca #CyberSecurity #SMEs #Canada #Quebec #CloudSecurity #DataProtection #MongoDB #ITSecurity #DigitalRisk #BusinessContinuity
2
-
Digital Governance Standards Institute | Institut des normes de gouvernance numérique
2K followers
The Digital Governance Standards Institute is pleased to announce the reaffirmation of the National Standard of Canada CAN/DGSI 100-4, Data Governance – Part 4: Scalable Remote Access Infrastructure. CAN/DGSI 100-4 provides a comprehensive set of requirements and guidance to help organizations: ➡️Mitigate security risks related to remote access ➡️ Support rapid scaling of remote access technologies ➡️ Protect organizational networks from unsecured endpoint devices ➡️ Maintain robust compliance monitoring and auditability ➡️ Implement zero-trust and least-privilege access controls ➡️ Ensure secure onboarding and offboarding of workers It also offers guidance to organizations responding to sudden or unplanned shifts to remote work, ensuring that remote access environments remain secure, manageable, and aligned with best practices in data governance. Access the reaffirmed standard here: https://lnkd.in/d5Nadjq2
11
-
Alberta Risk and Security Services
742 followers
The CIRA 2025 Cyber Security Survey - https://lnkd.in/gBHtYUmg ⚠️ The Current Threat Reality: Canadian organizations face an aggressive threat landscape where cyber attacks and data breaches are common. 43% of Canadian organizations reported being targeted in a cyber attack in the last 12 months. A similar share, 42%, experienced a breach of customer or employee data. 🤖 The Intensifying Danger: New, sophisticated threats powered by generative AI are raising major concerns among decision-makers. 70% of cybersecurity decision-makers are worried about: Improved phishing emails and texts: 61% AI-powered cyber attacks: 54% 🍁 A Call for Canadian Solutions: Data Sovereignty: Cited as the single most important consideration when selecting third-party cybersecurity vendors: 69% 82% say that a vendor’s country of origin is now more important than it was 12 months ago. Partner with a made-in-Canada consultancy, message us here on LinkedIn, or email us: Arssinc@gmail.com
3
1 Comment -
InnovLead Inc
132 followers
New cyber threats demand immediate patching. Gunra ransomware-as-a-service makes sophisticated attacks dangerously accessible. Concurrently, an actively exploited Microsoft Windows zero-day, CVE-2026-68820, grants SYSTEM privileges without user interaction, as CISA confirms. This means your Canadian business cannot afford to delay. Patching critical vulnerabilities, especially those listed in CISA's Known Exploited Vulnerabilities Catalog, is not optional; it is a rapid-response imperative. Microsoft addressed 421 CVEs in its August 2026 security updates, per SecurityWeek. This constant threat volume proves reactive defense is a losing game. How quickly can your team deploy critical patches when a zero-day is announced? #Cybersecurity #RiskManagement #InnovLead
-
Shahzad Mustafa
Indusflow Systems Inc. • 2K followers
The City of Hamilton has spent over $18 million dollars and will continue to spend $400K per month until November 2026 to rebuild their systems after a ransomware attack. See article in comments section. Reading this article, I’m shaking my head at the vulnerabilities the city’s IT leadership tolerated leading up to this attack. Root cause? Multi-factor authentication was not enabled for many departments. Why? Because many users resisted the inconvenience of having to manage MFA. The only reason the city decided to re-ignite their MFA rollout was because their insurance company was demanding it. Unfortunately, a ransomware gang got to them first. This is serious incompetence that has wasted millions of dollars of taxpayers’ money. There is no doubt rolling out MFA in large enterprises with diverse workstyles can be challenging. In our experience in healthcare, we take the following approach to ensuring everyone is using MFA: 1. For remote users, enforce MFA, no questions. 2. For office-only users, use conditional policies to not enforce a double login when working within the office. This makes life easier for internal, high-trust users. 3. For users that don’t have company-issued mobile phones or those with shared accounts, use a physical token technology such as Yubikeys. These are USB keys that users will plug into the computer to provide a second authentication. MFA is cybersecurity 101. There is NO excuse to ignore it. #cybersecurity
24
4 Comments -
Bil Harmer, CISSP, CISM, CIPP
Supabase • 11K followers
If you don’t think you need to be able to tell a story in this business you’ve never dealt with a breach, a customer or a board. They all involve telling a story effectively and each one is different. Learning to present is a key part of any job but it is critical to cyber. Story telling is one of the most effective methods to get your point across and make it stick.
13
1 Comment -
Francois Guay
CCN Intelligence • 35K followers
Why the new Canadian Cybersecurity Network newsletter is a must read with content from Rafael Arturo Ramírez, J.Paul Haynes, P.Eng., Femi Ogunji, CISSP, CISM, CCSP, Cary Johnson, Junior Williams and more. Expert insights from within the newsletter “Make no mistake there is no option for cybersecurity practitioners as you must fully embrace these technologies or you will fall behind” — eSentire Threat Response Unit insight on AI in security - J Paul Haynes “AI agents make work run faster including mistakes if your processes are messy” — Enterprise Architect on autonomous AI risks - Junior Williams “Awareness platforms aren’t the problem measurement is” — Founder, Phishbusters on cyber awareness program gaps - Cary Johnson “The perimeter did not fail because technology was weak but because human trust remains the most exploitable attack surface in any organization” - Femi Ogunji “Successful Canadian cybersecurity companies create a flywheel producing new founders investors and the next generation of innovation” - Richard Stiennon “Israel Singapore and Estonia prove that cybersecurity leadership is not accidental It is designed Canada has not yet designed for scale or urgency” - Francois Guay “Communities forged in pressure respond faster think clearer and recover stronger” - Rafael Arturo Ramirez View it here - https://lnkd.in/eemuiPQd
10
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More