The New CISO

How Do You Measure the Success of Your Cybersecurity Program?


Listen Later

Taking The Jump From Consulting & Advice To A Younger Self

With consulting you have the opportunity to work with multiple large companies, which can be an attractive aspect of the job. Working with multiple companies on that scale can introduce you to the latest technology and how it works differently for different companies. That being said, if you want to build a team from the ground up a transition from consulting might be best for you. Also if you’re looking to partner, or gain any ownership in a company, consulting may not be your best bet. Develop relationships while in the consulting position to really feel out where you want to be, and then you’ll already be a familiar face when you’re looking to be hired on at a company.  Participating in networking groups is a great way to meet peers and other relevant connections you may want to utilize in the future. Just making sure that you are prioritizing your time and energy effectively can keep burnout at bay as well, focus on what you really want to achieve and walk down that path. Making these connections and being empathetic about others positions can really help advance your career, try to put yourself in others’ shoes when making these connections. 

 

Tying Success To Business Risk

Being able to make an impact with the way you communicate requires empathy. To be an effective communicator you must be able to put yourself in the position of the other higher executives including CEOs, CFOs, and other critical positions. If you cannot relay information to them in a format they relate to, the problem could be a crisis just by the loss of time on trying to communicate.  For some businesses security has always been a priority, yet for many other depending on the industry, security is only now coming to the forefront as a priority. Security teams need support, investment, and visibility. That is where those communication skills come in, present the value of the security team to other executives in a way the will relate to. 

 

Beyond Compliance

Having up-to-date certifications and technology will only work in your favor as a security team, but you cannot stop there, certifications alone will not stop negative issues from arising. There needs to be both efficiency and maturity working in tandem. There is compliance, which offers your team a framework to then build upon to meet your specific needs. Compliance does not guarantee that your company is 100% protected against negative events; it is a critical element, although not the only element. Identify what the real risk factors are within your company and view security as an ongoing process. Educate the executive leadership on the independent testing results and findings and how your team has shifted to deal with these real risk factors that are beyond compliance. Being a new and effective CISO means not only being technical, but also in-tune with the current needs of the industry by communicating in an empathetic way.

 

Resources:

Steve Moore: Linkedin

Marzena Fuller: Linkedin

Exabeam: Website

CISCO: Website

...more
View all episodesView all episodes
Download on the App Store

The New CISOBy Steve Moore

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

39 ratings


More shows like The New CISO

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,001 Listeners

Risky Business by Patrick Gray

Risky Business

373 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

637 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

370 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

Click Here by Recorded Future News

Click Here

417 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Life of a CISO with Dr. Eric Cole by Dr. Eric Cole

Life of a CISO with Dr. Eric Cole

33 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

133 Listeners

CISO Tradecraft® by G Mark Hardy & Ross Young

CISO Tradecraft®

48 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

Bulletproof Cyber by Dr. Eric Cole

Bulletproof Cyber

9 Listeners