How do you survive as a CISO?

preview_player
Показать описание
This episode is about how to survive and keep your job as a CISO. There has never been a greater demand for CISOs and V-CISOs, but at the same time, because many executives have never hired a CISO before, they don’t completely understand what it means to be a successful CISO. Therefore, you may be at risk for being fired even though you are doing a good job. The biggest conversation to have with an executive early on in your tenure in the company is to explain that you cannot have 100% security with any functionality. If executives don’t understand this, you may get fired when there is a breach, even though a breach is inevitable. Second, you must understand the goal of cybersecurity. It’s not to prevent all attacks, it’s to detect and control attacks. The third is to go over the benefits and risks of action or inaction. Finally, when presenting the threats and risks, you must explain both sides of the equation, give options, and do not get emotional. If you can do these things, you can expect to have a highly-paid, long, and successful career as a CISO.

📖 [ORDER] Cyber Crisis Book
How to Protect your Business from Real Threats in the Virtual World

🔑 [FREE MASTERCLASS]
Discover How You Can Advance Your Career Through Cybersecurity

Show notes:
0:35 When COVID hit, organizations went into survival mode
2:14 There wasn’t as much focus on security when offices were shut down
3:04 Top Gun
3:58 “Engage!”
5:20 Good news/bad news
6:41 More good news/bad news
8:03 Companies aren’t necessarily looking for experienced cybersecurity veterans
8:36 Why my CISO certification is what you need now
10:30 I challenge you…
11:40 How do you survive as a CISO?
12:41 You must have a business discussion with executives to make sure you’re on the same page
13:49 You will never be 100% secure, and execs need to know that
16:10 You have two options
17:50 You will have a breach
18:49 The second conversation: what is the goal of cybersecurity.
19:25 Are you 100% healthy and never need to do anything?
21:11 Our goal in health is not to never get sick
22:01 Third conversation: the benefit and the risk
22:58 What if the system gets breached?
24:46 The risk
26:12 Always present both sides of the equation, the options, & do not get emotional
29:03 Option B

About Dr Eric Cole
Eric Cole, PhD, is an industry-recognized security expert with over 20 years of hands-on experience in consulting, training, and public speaking. As the founder and CEO of Secure Anchor Consulting, Dr. Cole focuses on helping customers prevent security breaches, detect network intrusions, and respond to advanced threats. In addition, he is a sought-after expert witness and a 2014 inductee to the InfoSecurity Hall of Fame.

#LifeOfaCISO #Cybersecurity #Careerpath
Рекомендации по теме
Комментарии
Автор

Great show as always. Looking to become a CISO one day.

Dbollin
Автор

Fantastic episode - I think people may not realize the work involved in arriving at the summary concerning risk reduction (currently 85%, want to spend $300k to reduce risk to 25% - if not invested, it will cost $4M). That takes time, work, research, and investigation. I don't see a lot of organizations in my experience putting that level of thought into it. But you are right - once you have that story, an exec will listen.

sscheuri
Автор

Hi sir
I am Mohamed Faroz From India
Now I am doing Bachelor in BCA ( Bachelor of computer applications)
I need want to become Chief information security officer (CISO)
Sir
I want study post graduate in Canada
What are the skills need for CISO?
What are the certifications need for CISO ?

mohamedfaroz.s