Go offline with the Player FM app!
Why CISO’s Fail: Some Practical Lessons for the Future - Barak Engel - CSP #173
Manage episode 416960619 series 2921188
Security is both overcooked and underdeveloped at the same time, and we keep doubling down on insanity. Our own community is at great fault for pushing fear and ignoring service, leading to consistent, negative experiences for all other stakeholders in the organization - and ultimately the CISOs themselves. "Do more cyber" never had, does not, and never will lead to better outcomes, yet this is all everyone is talking about. The trifecta of fear (we fear it, we don't understand it, we know we must have it) is used effectively by vendors to drive an ever-increasing wedge into IT budgets, even as the actual utilization ratio of security tools is precipitously low (my estimate is 5%). Frustration abounds, the CISO job is a revolving door, and nobody's happy. Now the regulators are getting involved in all the wrong ways (see the recent SEC action against Tim Brown) - and it's entirely our fault.
This segment is sponsored by Spirion. Visit https://cisostoriespodcast.com/spirion to learn more about them!
Visit https://cisostoriespodcast.com for all the latest episodes!
Show Notes: https://cisostoriespodcast.com/csp-173
214 episodes
Manage episode 416960619 series 2921188
Security is both overcooked and underdeveloped at the same time, and we keep doubling down on insanity. Our own community is at great fault for pushing fear and ignoring service, leading to consistent, negative experiences for all other stakeholders in the organization - and ultimately the CISOs themselves. "Do more cyber" never had, does not, and never will lead to better outcomes, yet this is all everyone is talking about. The trifecta of fear (we fear it, we don't understand it, we know we must have it) is used effectively by vendors to drive an ever-increasing wedge into IT budgets, even as the actual utilization ratio of security tools is precipitously low (my estimate is 5%). Frustration abounds, the CISO job is a revolving door, and nobody's happy. Now the regulators are getting involved in all the wrong ways (see the recent SEC action against Tim Brown) - and it's entirely our fault.
This segment is sponsored by Spirion. Visit https://cisostoriespodcast.com/spirion to learn more about them!
Visit https://cisostoriespodcast.com for all the latest episodes!
Show Notes: https://cisostoriespodcast.com/csp-173
214 episodes
All episodes
×
1 Mapping the Modern Attack Surface: Fintech’s Evolving Risk Frontier - Erika Dean - CSP #212 30:47

1 Maximizing Cyber Liability Insurance: Risk, Relationships & Renewal Strategies - Mandy Andress - CSP #211 33:42

1 Breach by the Dozen: Incident Response Lessons from the Field - Mike Miller - CSP #210 31:29

1 AI Governance: Navigating Risks, Frameworks, and the Future - Rock Lambros - CSP #209 29:25

1 Privacy Under Siege: Navigating Data Theft and the BadBox Threat - Gavin Reid - CSP #208 27:56

1 Cloud Security in Higher Education: Balancing Trust and Risk - Sheena Thomas - CSP #207 29:22

1 Cybersecurity in the Cloud: Lessons for Businesses and Beyond - Melina Scotto - CSP #206 34:09

1 Cloud Security for SMBs: Strategies, Risks, and Resources - Adam John - CSP #205 32:58

1 Cloud Security at Risk: Tackling Misconfigurations Head-On - Nadia Mazzarolo - CSP #204 23:36

1 Cloud Security: Lessons Learned and Applied to Emerging Tech - Bertrum Carroll - CSP #203 28:15

1 Identity Challenges in Manufacturing - Tammy Klotz - CSP #202 32:00

1 Identity Security: Navigating the New Normal with Dr. Sean Murphy - Sean Murphy - CSP #201 34:15

1 Identity Security Training: How important is it? - Eric Belardo - CSP #200 30:31

1 Have you ever had a pen tester own your network? - Julian Austin - CSP #199 28:51

1 How important is your relationship with your tool vendors? - Jacob Lorz - CSP #198 28:38
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.