Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Popping the Information Security Bubble
Articles

Popping the Information Security Bubble

ISBuzz TeamBy ISBuzz TeamAugust 26, 2014Updated:April 30, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Are you living in a bubble?

Now you’re thinking “Bubble?  You what…”

Let me explain. My experience is that a lot of the time we security types – yes, you and me – don’t actually know what the rest of the departments within the business actually do on a day-to-day basis. We know they exist and what their purpose is, but we don’t appreciate their pain points. We’ve all heard, way too many times, the quotation from Sun Tzu’s “The Art of War”: “If you know the enemy and know yourself, you need not fear the results of a hundred battles.”

I would argue that a lot of us don’t know our own organisation as well as we should, let alone the enemy.

Click here: to discover 5 reasons why we see security awareness training programs fail

If we consider a typical enterprise organisation, it will have departments such as HR, legal, sales, PR, marketing, accounts, IT and many others. These all have their own objectives, their own stresses and strains and targets to meet. Essentially they are in their own little bubble trying to do the best they can with what they have, and more often than not information security is the last thing on their minds. However, it is our job to help elevate their understanding of what we do and, most importantly, how we can help them to work more securely.

So if we are all in our own little bubbles, how can information security departments be effective for their businesses?  As far as I’m concerned, if you work in this field and you don’t step out of your bubble from time to time, you won’t be effective in the least. (When I talk about effectiveness, I mean helping to create a positive and lasting change, that is,  building a strong and permanent culture of security within your organisation.)

Yes, you may review third parties, you may assess project risks, you may get involved with pen tests and attend to incidents, but do you use these experiences to move towards building a more security-conscious work force? I guess that most of you do not. In truth, I don’t think most security departments are actually all that effective. They exist to serve compliance or some other tick-box exercise. It’s a case of “We do our jobs, and then we go home”. There’s nothing wrong with that if all we are interested in is hanging onto our jobs, but if we actually want to be effective, I mean if we want to change behaviour, then we need to change the way we approach our work or else we’ll keep going round in circles forever.

(Maybe, though, we don’t really want to change anything and deep down we think, “What difference does it make to me, ah none really….” Cynical? Or just a little too near the truth?)

In fact, effectiveness isn’t all that difficult. It means occasionally stepping out of your bubble and making an effort to appreciate the needs and wants of the business you work for. You need to listen, learn and adapt to what the business actually does on a daily basis. If you can do that, you can then begin to see new ways of working together with your colleagues, understand their difficulties, foresee problems looming ahead and do something to prevent them from happening.

Here’s a few bubble-destroying suggestions. You might have thought of some of these practices already, but if not, why not try them and see what they do for your effectiveness within your organisation?

–     Create a brand for your information security team or department. Be creative, ask the marketing and PR teams for a little help.

–     You should be seen and known outside your own immediate circle. When was the last time you stood up to give an information security briefing to the organization? When was the last time you actually walked around to different teams just to introduce yourself and have a little chat? Little chats can open doors to really worthwhile exchanges of information. Never think of a little chat as mere gossip or a waste of time.

–     Have a mission statement. Look at the corporate mission statement and align yours to that. You could even come up with a snappy slogan. Whatever it is, it will make you more approachable, and approachability is the first step towards increasing your effectiveness within your organisation.

To conclude, I would argue that if you’re a CISO/CSO/Head of Information Security or whatever senior security position you hold, building security culture should be your strategy.

So, don’t float – stand up and pop your bubble.

By Mo Amin, Information Security Consultant, The Roer Group

mo_aminBio: Mo Amin is a London based information security consultant. He is currently working with The Roer Group on the Security Culture Framework ) and the associated training at learn.roer.com. He can be found on Twitter @infosecmo and also attempts to maintain his personal blog at http://www.moamin.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}