Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 5 Top Pieces Of Advice For CISOs
Articles

5 Top Pieces Of Advice For CISOs

ISBuzz TeamBy ISBuzz TeamJune 20, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The cyber security market is overwhelmed by buzzwords. Artificial intelligence, machine learning, blockchain – all this attacks CISOs from every possible angle, from webinars and conferences to the media. Most vendors fall into the trends, forgetting about customer needs for the sake of a technology race. Unfortunately, the main problems for CISOs still lie within the borders of security basics.

New technologies will never bring any value to your company, unless you get your basic security right. While attackers and threats get more sophisticated, the level of security awareness at the board level often leaves much to be desired.

Here are five recommendations that you, as a CISO, can take advantage of to get maximum return on your cyber security efforts.

[su_youtube url=”https://www.youtube.com/watch?v=nE1XIQTIIKM&feature=youtu.be”]

1: Know your assets

Before you start making strategic security plans, it is very important to find out what IT assets and data you have, where they are located and how critical they are. This may sound like obvious advice, but in fact, not every company can handle this task. The research carried out by Kenna Security showed that most companies spend up to 15 hours per week, using more than 15 different tools, but are still able to discover only 60%-70% of the assets.

Lack of visibility prevents organizations from setting the right goals, which means they fail even before they start. The main challenge here is to discover the maximum number of assets within the minimum period of time. There is no one-size-fits-all solution yet, but it may lie somewhere in between an automated data discovery solution enforced with recon techniques (used by hackers to discover subdomains, resources and properties) and hiring a full-time employee responsible for the process.

2: Develop cloud security skills

As more organizations migrate to the cloud, data security becomes a pressing issue. Cloud security is not easy, but possible to achieve, and needs a holistic approach for success. Start with major decision makers and bring key stakeholders, including CISO, InfoSec and application teams together into one agile group. This will greatly contribute to developing a cloud security strategy and improve cooperation.

The next step involves a mix of new and old technologies. Combine network penetration testing, dynamic application security testing, automated patch management, vulnerability assessment with UEBA and SIEM solutions for cloud services, and cloud access security brokers (CASB). In addition to that, leverage security services offered by cloud providers. This combination of management decisions and technical expertise will greatly add to your security efforts.

3: Focus on identity not perimeter

Gradually network perimeter security disappears, clearing the way to an identity perimeter concept. Your employees can now work remotely from home or business trips, so your security measures should be adapted accordingly. Set protection of user identity as your ultimate goal and develop a security strategy to support it. Start with multi-factor authentication (MFA) that will allow you to minimize risks of account hijacking, especially in case of phishing attacks, and with CASB to intercept and monitor data traffic between your network and cloud platform if you use cloud services. Finally, raise security awareness among employees. Thus, everyone will understand their personal responsibility for data security in the company.

4: Speak the language of C-levels

Lack of budget has always been an ever-present issue for IT. However, CISOs could have been more successful if they understood that their board of directors speaks the language of money. If you want to convince the C-suite to increase your funds, get ready to talk about business benefits and financial risks. When getting ready for your speech, make sure you can evaluate and explain the following measurements:

  • Baseline: How much money you can you afford to lose and what breach probability is acceptable for your company?
  • Situation 1: You have made zero investments. How much money will the company lose in case of a breach? What is the likelihood of a breach in this case?
  • Situation 2: You have made investments. How much money will the company lose in case of a breach? What is the likelihood of a breach in this case?

Before the meeting, calculate the cost of risk reduction measures and be ready to explain in detail how the security team will spend it. Consider a risk assessment solution to articulate a clear plan.

In addition to talking about negative outcomes, support your statement with business benefits. Think strategically and explain how business can leverage technology. For example, if internal business processes become more efficient, cycle times will be lower, and business will gain more opportunities for innovation. In turn, the satisfaction rate of customers and stakeholders will rise, and transparent processes will simplify proof of compliance. Overall, the company will reduce costs and increase revenue and profitability.

5: Make compliance your BFF

Become a friend with all compliance standards your company is subject to. Even if you fall under GDPR compliance, which terrifies companies worldwide, instead of panicking or resisting changes, consider which benefits the GDPR will bring to the business. By following the guidelines, you will dramatically improve security and operations and get impressive perks: advanced data strategies, better privacy policy management, increased KPIs for data security and privacy, increased customer trust and new business opportunities to name a few.

Get the compliance department, if there is one, on your side. Compliance requires teamwork, so IT security teams can achieve more ambitious goals if they work together.

In conclusion

To survive in 2018 and beyond, CISOs should be aware of security and business risks, be able to prioritize security efforts, and do not hesitate to talk money and argue your position. Accept that there is no single technology solution to address all threats and solve all issues at once. You will never be 100% secured, but you can make your company a tough nut to crack.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Cloud Security Controls Explained: A Definitive Guide

March 19, 20269 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}