Article

The OS doesn't make you secure, you do: Sami Laiho on the Mac-vs-Windows myth

Published on
September 11th, 2026
NIC 2026 SPEAKER SERIES "5 questions with"
Ahead of NIC 2026, we're sitting down with some of the practitioners leading sessions this October, the same five questions, put to people who spend their working lives in the trenches rather than on a stage. Second up: Sami Laiho, Senior Technical Fellow and MVP at Adminize.com, and one of the most established voices in Windows security.

What do you believe that most of your peers would disagree with?

Whether Macs are actually more secure than Windows. Most people still assume they are, and that Windows is the dangerous platform you have to lock down hard. I disagree. A properly configured and managed Windows computer can be extremely secure. The real question was never which OS you use, it's how well you understand it, configure it, manage privileges, patch it, and actually use the security capabilities already built in.

What do teams still accept as normal, even though it creates unnecessary risk?

Letting Entra ID and Azure admin portals be accessed from any computer. We've spent decades learning that privileged administration belongs on dedicated, trusted devices, yet cloud administration keeps getting an exception. Your Global Admins shouldn't be managing your cloud environment from the same machine they use for email, Teams, and everyday browsing. Use a dedicated Privileged Access Workstation. That's not a new idea just because the servers moved to the cloud.

When did something last go wrong that genuinely surprised you, and what changed afterwards?

A ransomware attack on a single computer, about two years ago. Our defenses worked, the attack was contained, so technically it was a successful demonstration of the architecture. What surprised me was how the attacker got there: the computer was sitting in a part of the network we didn't properly know about, because of a gap in our device inventory. Afterwards, I fixed the inventory, and this time we included physical network connections too, including underground cabling we didn't even know existed.

What is one thing someone can change on Monday morning without waiting for a project, budget, or permission?

Stop using an administrator account as your everyday login. You don't need a new product, a six-month project, or a bigger budget, just create a separate account for admin tasks and use your normal account without admin rights day to day. It's one of the oldest security recommendations in Windows, and still one of the most important. If your everyday account is an administrator, every app you run and every mistake you make starts from a far more privileged position than it needs to.

What will people experience at NIC that they cannot get from a blog post or webinar?

Networking is probably the most important asset you can have in a modern IT environment. And no, I don't mean TCP/IP, I mean people. Nobody can know everything anymore, the technology is too broad and changes too fast. What you can do is get to know people who know the things you don't. At NIC, you meet those people, ask them questions, challenge their ideas, share experiences, and build relationships that help you long after the conference itself is over.

Catch Sami live on the security track: 60 Life Hacks of Windows in 60 Minutes on Wednesday at 10:00am, and Cyber Security: State of the Union 2026 on Thursday at 3:40pm, both in Room 1.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.