After years of breaches, stolen data, CIO/CISO resignations and huge impacts to business reputation, it’s time for the industry to rethink its approach to network security.
After years of breaches, stolen data, CIO/CISO resignations and huge impacts to business reputation, it’s time for the industry to rethink its approach to network security.
Last month I had the honor to speak at the Security 500 conference in front of a large room of senior security leaders. My own personal take-away from the event is that no matter how long you’ve been in this industry there is always something new to learn.
The year 2018 is coming to a close, and that means many of you may soon consider a move from one employer to another. The question is whether it will be a voluntary change or a shift due to circumstances beyond your control.
There was a time when the corporate security team was responsible for setting the policies for overall security within an organization including digital. Today, those responsibilities are likely to be separated between a Chief Security Officer (CSO) and a Chief Information Security Officer (CISO). This brings into play the views, opinions, needs and requirements of both the CSO and the CISO and the potential conflict that may ensue.
The threats that face the United States today are the same threats that we faced on 9/11,” says Michael McGarrity, Assistant Director for the Counterterrorism Division of the FBI.
Successful strategists in the security arena face the same kind of tactical issues as football coaches. Attackers are skillful, resourceful and motivated success. Football coaches can’t deploy a “one-size-fits-all” strategy, and neither can security leaders. On a macro level, this is called “Risk-Based Security.”