logo

NJP

Friday Fast Fifteen | Conversations in Security Operations

Import · Dec 06, 2021 · video

hello everyone welcome to the friday fast 15 the snack size show where we tackle big tech topics in under 15 minutes current events keep security operations top of mind these days thankfully caitlyn frank our director of marketing joined me for a conversation about our new cyber security ebook today called managing cyber risk conversations with executive stakeholders welcome to the show caitlyn thanks for having me kim caitlyn here at cross fuse we talk security operations a lot why does this topic need to remain top of mind for both practitioners and business leaders i mean that's a great question and probably one that explains why i as a marketing leader am here talking about cyber security and it's because it's a topic that really cannot be ignored by anybody in in at any levels of a company but especially those in a leadership position um i mean you you look at what happened just in the last week or two there's been several security breaches one being the the very infamous now paseo hack which some are saying is the most substantial security breach ever um and and what we've learned from that is it's you know these kinds of things don't just impact giant organizations they have you know they can have a very substantial downstream impact as well it's not only the you know you as an organization that are that are at risk but the organizations you serve and the customers that they serve so um you know it's it's increasingly top of mind you know he the kasaya hack alone or you know notwithstanding the cassia hack he looked back over the last year um throughout the whole you know response to the kovid pandemic as organizations were shifting to a remote workforce how do you balance the need to enable your employees to work collaboratively and effectively and yet keep your organization you know secure um so it's it's it's a conversation that spans any role everybody relies on it to do their work um and it's something that you know if you as a leader what you know whether you're you know a manager or just a team leader or an executive you need to be aware of what's at stake and what the what the risk is what the level of risk is and just be more educated about you know how you might address some of these things and what are some of the options so it's it's it's you know there's so much there it's very new it's very evolving and um it's something that's it's not going away anytime soon exactly so caitlin what are the conversations that are happening at that executive level i i mean there's a lot um but i think you know what what business leaders need to ask each other and not just the the chief information security officer or the cio or you know the the person that's on paper in charge of it but um everybody needs to be asking what what are we doing to keep our organization secure um that seems like an obvious one and the follow-up to that is what are our vendors and our partners doing to keep themselves secure because you know if a lot of times if they go down we're going down with them you know so many you know the way businesses work today you you rely on so many partners nobody's nobody's kind of working in their own anymore so you rely on others other organizations to help you do the things that you do on a day-to-day basis and so if if any one of those pillars drops you know you could be putting your own business at risk so it's asking a much broader question of you know not only internal processes and internal technologies that you're putting in place but what are you asking of your key partners and your key vendors because that risk fundamentally changes you know what what we have what we ask of our partners and what expectations we set of our partners and as um cyber security people and leaders go through these exercises what are the challenges to reaching alignment you know it it's often really just a lack of understanding um you know this stuff is really changing so rapidly and it's evolving so rapidly um it's definitely not covered in your standard mba programs that you know so many of today's execs have come out of um you know if you you mentioned the the the ebook that we put out recently and if you look at that you'll see a quote from a gartner study from last year that found the top three reasons why enterprise-sized organizations take a reactive approach to cyber threats is first of all lack of understanding of the magnitude of the risk and consequences number two is the assumption that risk is an i.t problem and not a business problem and number three is the notion that attacks are something to be dealt with once they've already happened like oh there's nothing you could possibly do to prepare so we might as well just wait until something happens and then deal with it later um that's you know if you if you go into it with that mindset the amount of risk that you could find yourself in is is probably pretty staggering so the important thing is and you know obviously i'm you know as a marketing person i'm not a cyber security expert by any stretch of the imagination but as somebody that's you know often a part of these conversations at a leadership level it's something you need to get used to talking about and used to asking the right questions and you know taking a stance of of you know always learning and figuring out how to educate yourself on these topics because that's the only way that you as a team can make informed quality decisions for your business exactly it's all about teamwork so caitlyn we've talked about why security operations should be top of mind for everyone and we've discussed the conversations that need to happen to ensure strategic alignment with business objectives and we've highlighted some challenges that teams run into do you have any final thoughts for our audience today um really just you know expanding on my last thought the responsibility for a company's security operations it's it doesn't live with just the cso or with just the it executive um more and more those people in those roles need to take on that role of being educators and learn how to inform and recommend action um because with that that's that's how you get the buy-in and that's how you get accountability across the board there needs to be a common understanding of the risks of what's at stake um and that's how you can have those more informed conversations you can get more diverse perspectives and figure out where to you know where to balance that you know if you're if you're talking about a spectrum of you know a fully locked down organization versus one that's fully exposed you know very it's very unlikely that anybody's going to be on those extreme ends but knowing where to put that you know point in somewhere in the middle that's that's a conversation that needs to happen with you know leaders from every function um and so just knowing how to be that sort of support role that educator role and knowing how to guide those conversations and and facilitate those discussions that might be uncomfortable to have but you need to have them in order to you know know what you're dealing with well caitlyn this has been a pleasure it is so interesting to hear a business leader's perspective on cyber security issues thank you for helping with this project today absolutely happy to help and again there's you know a lot more that is expert written in our ebook so encourage anybody who's listening and watching to go check that out thank you everyone for joining us today this has been the friday fast 15 conversations and security operations with our director of marketing caitlyn frank if you'd like to learn more reach out at let's talk crossfuse.com and for more snack size conversations subscribe to the fridayfast15 on apple podcast spotify or youtube [Applause]

View original source

https://www.youtube.com/watch?v=bAiJRBsuIuc