THOUGHT LEADERSHIP: 5 Lessons From The Breach We Didn't Have

Share

From the LinkedIn of Brad Thornwell-Pierce, CISSP, CISM, CRISC, CISA, CCSP, CEH, Sec+, and recent recipient of the "Cyber Visionary Under 50" award from a publication he had not previously heard of.


5 Lessons From The Breach We Didn't Have

This week, our organization successfully prevented a breach. You didn't hear about it — because it didn't happen. That's the point.

Here are 5 things every CISO can learn from the incident that wasn't:

  1. Culture is everything. I have spent 18 months building a culture of security. Last week, that culture paid dividends. Specifically, my IT team patched a server.
  2. The board needs to hear from us. I briefed the board on the non-incident. They were impressed by my proactivity. One member asked what a "server" is. I said it doesn't matter.
  3. Zero Trust is a journey, not a destination. We are 14% of the way there, according to a maturity model I commissioned from a consulting firm whose name I am still learning to pronounce.
  4. Invest in your people. I have invested $4.7M in tooling this year. My people, specifically, will receive a pizza party in Q4 pending CFO approval.
  5. Lead from the front. I led this initiative from the front. Specifically, the front of the building, where my office is. The IT team led from the data center, which is in the back.

A breach we didn't have is still a win we can claim.

CyberSecurity #Leadership #ZeroTrust #ThoughtLeadership #CISO #BradGetsIt

Read more

Cybersecurity Industry Marks 15 Consecutive Years Of Demanding More Cybersecurity Professionals, Asks For 16th

Filed by Cybersecurity Smith ALEXANDRIA, VA. — The International Information System Security Certification Consortium, known as ISC2, released its annual Cybersecurity Workforce Study this fall, marking the fifteenth consecutive year in which the cybersecurity industry has called for an immediate and substantial increase in the number of cybersecurity professionals. ISC2 is