This week's episode of CISO/Security Vendor Relationship PodcastThe "Do What We Tell You" Technique Isn't Working
This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our guest is Michelle Valdez, CISO, OneMain Financial. All three of us discussed:
Care more about users. We spend far too much effort trying to communicate the importance of security and getting people to care about it, that we lose sight of the need to secure users and data. What if we cared more about users and understood why they don't embrace security as much as they should? How can we sympathize with what they're doing so that we can work security into their flow, rather than getting them to operate into security's flow?
Minimize the surprises before you accept a job. You're not going to know everything about the security environment you inherit even if you ask all the right questions. But, first do ask questions. Don't leave it up to surprise when you arrive. And when they don't know the answers, their response as to how those answers will be found will be very telling as to how disastrous the situation may be.
Should you split the CISO's responsibilities? Our guest splits her responsibilities with another security leader. She handles the people and process, and her counterpart handles the technology. The CISO's job is overwhelming and with a clear division of labor this could make the tantamount job more manageable.
Read more: https://cisoseries.com/the-do-what-we-tell-you-technique-isnt-working/
Tags 🏷
#cybersecurity #cso #ciso #infosec #hacker #itriskmanagement #ciberseguranca #cyberattacks #threats #malware #cibercrime #exploit #hackers #hacker #breach #mitreatt&ck #pentesting #cloudsecurity #cyberwar #datasecurity #ethicalhacking #hacking #cloud #informationsecurity #securitymanagement #infosec #ransomware #datasecurity #cisoseries

Comentários
Postar um comentário