How to Tell If Your CISO Sucks At Their Job
This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our guest is Lee Parrish, CISO, Hertz. All three of us discussed:
How to handle a CISO who is more self-interested in their industry status than securing the company. We have talked about our distaste of the security industry lauding praise on industry rock stars. One listener feared their CISO may be spending more time focusing on the 'visionary' prize rather than what needs to be done, the boring security basics. If your CISO is doing this, maybe steer them to the CIS Top 20 and, if you can, show them one or two new innovative ways to tackle these old problems.
Security can understand the business by inviting themselves into the business.This means do your best to understand the most minor details and all positions at a company. If you see how all roles are interacting with technology, you'll better understand how security can fit into their day-to-day workflow.
When there's redundancy in tools, a third one could enter to replace both.Whenever there's an overlap in tools, which can often happen after a merger, it's a chance to reexamine the tools you have. The factors to consider are the effectiveness of the tools, the cost, and how well they integrate with other tools. It's also a time to look at a new vendor that could possibly displace the two incumbents.
Read more: https://cisoseries.com/how-to-tell-if-your-ciso-sucks-at-their-job/
Tags 🏷
#cybersecurity #cso #ciso #infosec #hacker #itriskmanagement #ciberseguranca #cyberattacks #threats #malware #cibercrime #exploit #hackers #hacker #breach #mitreatt&ck #pentesting #cloudsecurity #cyberwar #datasecurity #ethicalhacking #hacking #cloud #informationsecurity #securitymanagement #infosec #ransomware #datasecurity #cisoseries
This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our guest is Lee Parrish, CISO, Hertz. All three of us discussed:
How to handle a CISO who is more self-interested in their industry status than securing the company. We have talked about our distaste of the security industry lauding praise on industry rock stars. One listener feared their CISO may be spending more time focusing on the 'visionary' prize rather than what needs to be done, the boring security basics. If your CISO is doing this, maybe steer them to the CIS Top 20 and, if you can, show them one or two new innovative ways to tackle these old problems.
Security can understand the business by inviting themselves into the business.This means do your best to understand the most minor details and all positions at a company. If you see how all roles are interacting with technology, you'll better understand how security can fit into their day-to-day workflow.
When there's redundancy in tools, a third one could enter to replace both.Whenever there's an overlap in tools, which can often happen after a merger, it's a chance to reexamine the tools you have. The factors to consider are the effectiveness of the tools, the cost, and how well they integrate with other tools. It's also a time to look at a new vendor that could possibly displace the two incumbents.
Read more: https://cisoseries.com/how-to-tell-if-your-ciso-sucks-at-their-job/
Tags 🏷
#cybersecurity #cso #ciso #infosec #hacker #itriskmanagement #ciberseguranca #cyberattacks #threats #malware #cibercrime #exploit #hackers #hacker #breach #mitreatt&ck #pentesting #cloudsecurity #cyberwar #datasecurity #ethicalhacking #hacking #cloud #informationsecurity #securitymanagement #infosec #ransomware #datasecurity #cisoseries

Comentários
Postar um comentário