Security News

Download: CISO’s guide to choosing an automated security questionnaire platform
2022-04-26 06:27

Failing to adequately screen suppliers' security can lead to data breaches, which can shut down operations, damage customer trust and incur hefty regulatory penalties. An automated security questionnaire platform can vastly accelerate and scale the vendor security evaluation process.

Testing, testing, testing: Why Red Teaming is a must for every CISO
2022-04-05 07:15

It is vital that every CISO can offer a clear picture of how their security is really holding up against the latest tactics, techniques, and procedures. A red team exercise may not even need to exploit any technology-related vulnerability; rather, testers can rely on social engineering, phishing, or identifying shadow IT as an entry point.

The CISO as brand enabler, customer advocate, and product visionary
2022-04-04 06:00

Where should the CISO report for maximum effect? How does the CISO gain that valuable seat at the executive table, and a regularly scheduled time slot every quarter in front of the board? Is it possible that broad technical competency may be superior to deep technical expertise for this C-level role? And if you are the CISO who thought you signed up for an IT-centric, inward-facing role, I have a few nation-state and cybercriminal actors to introduce to you. It's clear that your organization's brand is as much an asset as the devices and networks that the CISO is charged with protecting - in fact, the brand may be your organization's largest single asset.

What CISOs can do to be most effective in their roles
2022-03-24 13:03

Ben Smith, Field Chief Technology Officer at NetWitness spoke to the obstacles faced by those in the CISO role today along with what can be done to improve organizations safety and while remaining compliant with the new reporting regulations put into law. "A lot of the CISO's day job revolves around technology, whether it's defensive technology or in some cases, offensive technology. One of the big challenges I think a lot of CSOs have today is where should that role be set in the organizations."

CISOs face 'perfect storm' of ransomware and state-supported cybercrime
2022-03-18 13:14

With not just ransomware gangs raiding network after network, but nation states consciously turning a blind eye to it, today's chief information security officers are caught in a "Perfect storm," says Cybereason CSO Sam Curry. "One of the values that we [CISOs] give an organization is to start thinking about what is that next level? What are they going to pivot to next?".

Is a focus on tech skills for CISOs holding us back in the boardroom?
2022-02-17 07:30

CISOs report to CEOs, CIOs, CTOs and more, and the skills needed depend on the nature of the business and who they report to. Reporting lines do not dictate power or the value of a role, but when most CISOs are still reporting to a technical leader - this limits the ability to be strategic and dilutes value.

The CISO’s guide to evaluating third-party security platforms
2022-01-17 04:00

A comprehensive third-party security program can align your vendor's security with your internal security controls and risk appetite. The right third-party security management platform can be a smart way to get your program off the ground or automate the one you already have in place.

The rise of the CISO: The escalation in cyberattacks makes this role increasingly important
2022-01-10 23:29

The CISO role has taken on greater prominence at a time when cyberattacks have become relentless and increasingly sophisticated, and millions of people continue to work from home. "As cybercrime continues to increase and companies face monetary losses or damages, the role of the CISO and security overall or critical to business success."

The CISO’s guide to third-party security management
2022-01-05 03:30

Managing the security of your third parties is crucial, but security assessments are riddled with problems, including a lack of context, scalability and relevance. In this comprehensive guide, we provide the direction you need to make your organization's third-party security program efficient and scalable.

A CISO’s guide to discussing cybersecurity with the board
2022-01-03 06:00

To get the assets needed for CISOs to properly do their jobs, business leaders need to invest time, attention, and money in cybersecurity. Here are helpful ways that CISOs can discuss cybersecurity with their C-suite and board members.