Security News

Move fast, break security: Why CISOs must push back against Agile IT
2021-12-16 08:30

The Vectra Masked CISO series gives security leaders a place to expose the biggest issues in security and advise peers on how to overcome them. As the Agile dogma continues to spread, it's our job as dispassionate security leaders to push back.

It’s about the survival of the fittest – CISOs must be brave enough to throw away their security playbook, or suffer the consequences
2021-11-25 17:00

This holds true as attackers become more organised - constantly tweaking threat vectors, studying widely-used security playbooks, or testing their attacks against ancient security tools like IDPS. By relying on signatures to detect known threats and following the same old approaches, you're always going to be caught out by modern attackers, who already have the tools to bypass these dated defenses. I still see 90% of CISOs today are "Playing it safe", clinging to old playbooks and legacy tools like IDPS. Perhaps it ticks a box for them by filling a control gap, or maybe the board is tired of security asking for new products, or these tools are just seen as "Tried and tested." The inconvenient truth is that we can't sit on our laurels in security, or we'll be completely exposed to attacks like Sunburst and Colonial Pipeline.

CISOs missing major holidays due to work demands
2021-11-24 05:30

Two in five Chief Information Security Officers have missed holidays like Thanksgiving due to work demands, a Tessian report reveals. In addition to missing national holidays, the report reveals that CISOs work, on average, 11 more hours than they're contracted to each week while one in 10 works 20 to 24 hours extra a week.

Does your company employ a CISO? Many are operating without security leadership
2021-11-23 05:30

45% of companies do not employ a Chief Information Security Officer, a Navisite research found. Of this group, 58% think their company should hire a CISO. Only 40% of respondents stated their cybersecurity strategy was developed by a CISO or member of the security team, with 60% relying on other parts of their organization, including IT, executive leadership and compliance.

Most CIOs and CISOs underestimate the risk of an OT breach
2021-11-10 05:30

The research also uncovered that organizations underestimate the risk of a cyberattack, with 73% of CIOs and CISOs "Highly confident" their organizations will not suffer an OT breach in the next year. 83% also said they had at least one OT security breach in the prior 36 months.

A ransomware reality check for CISOs
2021-11-03 07:00

While cyber insurance is an effective risk transference mechanism, don't confuse it with having a plan. Boards and C-suites understand and commonly factor in a variety of business risks, including market risk, supply chain risk, and liquidity risk, yet many don't understand industrial cyber risk.

Advice from a young, female CISO: Key lessons learned
2021-11-02 06:00

In this interview with Help Net Security, she talks about her take on the CISO role and offers advice for those who aspire to fulfill it one day. The company then created the first Information Security Officer role, which I stepped into to work on building out a security-first approach.

The CISO’s guide to third-party security management
2021-10-28 02:30

Managing the security of your third parties is crucial, but security assessments are riddled with problems, including a lack of context, scalability and relevance. In this comprehensive guide, we provide the direction you need to make your organization's third-party security program efficient and scalable.

The CISO’s guide  to choosing an automated security questionnaire platform
2021-10-26 07:55

In this day and age of cyber risk and data privacy regulations, automated third-party questionnaires are a must. Organizations can no longer simply hire vendors without proof of a strong cyber posture, and a comprehensive questionnaire can demonstrate that vendors' internal security policies are up to par.

The CISO’s guide to evaluating third-party security platforms
2021-10-19 08:52

A comprehensive third-party security program can align your vendor's security with your internal security controls and risk appetite. The right third-party security management platform can be a smart way to get your program off the ground or automate the one you already have in place.