02-11-20 - Empowered! Working Together to Pile on the Cyber Guilt

Empowered! Working Together to Pile on the Cyber Guilt

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

Empowered! Working Together to Pile on the Cyber Guilt

 features my co-host Mike Johnson and our guest Chris Hatter, CISO, Nielsen. The three of us discussed:

Shaming vendors into better security.

Single Sign On (SSO) has been a boon to simplicity and security, but many security vendors are charging a huge premium for that capability. Rob Chahin's leading the cause to expose those companies that demand exorbitant rates for SSO privilege. Chahin argues that SSO needs to be ubiquitous and it's not going to get there if vendors keep charging such a significant premium for an easy add-on.

Why you should and shouldn't be concerned with 5G.

While creating protections against insecure networks is not new, 5G introduces a paradigm we haven't seen on earlier networks. There are geopolitical issues given that China's Huawei has such a significant head start and advantage on network construction. In addition, the sheer crush of devices that are going to come online and the data being collected will be many fold what we've previously seen. 

Replacing risk with uncertainty.

We talk a lot about the need to calculate risk. But there are many times you simply don't know even where to begin because the risk parameters are so uncertain. Simon Goldsmith of adidas recommended replacing those real unknowns with uncertainty. There is risk you calculate, and then there's the uncertainty. The goal is to make that uncertainty pool as small as possible. 

Mike Johnson on the hackneyed image of the hacker in the hoodie

THREE LIVE SHOWS in SF, NYC, and Boston

If you live in any of these cities, please come on out to see and participate in a live audience recording. Here's the info:Sunday, 2/23/20 in San Francisco at BsidesSF - 3:30 PMMike Johnson and I welcome Olivia Rose, CISO, Mailchimp for a recording in a movie theater during BsidesSF. You must purchase a ticket to BsidesSF and then register for our session.Tuesday, 3/3/20 in New York City at Rise-NYC - 5:30 PMJoining me will be guest co-host JJ Agha, vp, head of InfoSec, WeWork along with a special guest. This will be done in conjunction with NY Information Security Meetup Group that has over 5,000+ members. Small fee to attend since space is limited. REGISTER.Thursday, 3/5/20 in Boston at athenahealth - 6:00 PMMy special guest cohost will be Taylor Lehmann, CISO, athenahealth, and our guest will be Marnie Wilking, global head of security & technology risk management at Wayfair. REGISTER.

Michael Piacente, Hitch Partners on what a CISO can show after a breach

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.