- CISO Series Newsletter
- Posts
- [02-28-23] _Saying_ “We’re 100% Secure” Is Not the Problem
[02-28-23] _Saying_ “We’re 100% Secure” Is Not the Problem
_Saying_ “We’re 100% Secure” Is Not the Problem
CISO Series Podcast
_Saying_ “We’re 100% Secure” Is Not the Problem
It's pretty darn easy to just utter the words "we're 100% secure." Pulling that off seems universally impossible, but some organizations are adamant about certain types of safety so they aim for 100%.This week’s episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our sponsored guest is Yoav Regev, CEO, Sentra. Here’s what we discussed:A successful security program is built on relationships and measuring success. A relationship is iterative and so is building trust. “Part of building and maintaining those relationships is being able to show how the program is going and the impact to the company,” said Johnson. That impact should be how security is bringing resilience to the organization, added Regev.How do you shake up your viewpoint periodically to see your environment differently? It’s hard to see emerging threats if you’re looking at your total working and personal environments the same way. Attackers are always looking for new ways to infiltrate. And that’s probably in the places you don’t normally look. Mike has the benefit of being on the CISO Series Podcast regularly that he gets to hear varied viewpoints from our guests (BTW, listeners get that benefit as well). Yoav suggests talking to people on the front lines who are seeing issues every day. They’ll tell you want they’re seeing new in their environments.We live in a data-centric world, let’s shift our security to support that. The cloud is very data-centric. Its features make it very attractive to users who want to create, move, and share data. Yoav’s company, Sentra, is focused on understanding, tracking, managing, and securing all that wonderful behavior of cloud data.Why are security professionals convinced we can’t make a system 100% secure and usable? Ian Heggie said it can’t be because technology needs to be programmed and used by fallible humans, who are often connected to the Internet. And Mike Johnson said he doesn’t even know what 100% security means. “Generally, you measure point in time,” said Johnson. “But environments are constantly changing, so there will likely be drift you have to deal with. I like the idea of talking about verifiable security, where you are able to always know the state of security of a system.”Listen to the full episode on your favorite podcast app, or over on our blog where you can read the entire transcript. If you haven’t subscribed to CISO Series Podcast via your favorite podcast app, please go ahead and do so now.
Thanks to our podcast sponsor, Sentra
What I love about cybersecurity...
"It's endless, unlimited, and it's always changing. It's the core and the basics for the digital world we live in today. It's amazing." - Yoav Regev, CEO, Sentra
Listen to full episode of
How Can We Improve the Cyber Sales Cycle?
"You know, vendors are a key part of our security ecosystem and the vitriol I see spewed in their direction isn't always warranted. But to David's point, I'm at a stage where I make decisions for 2024 in 2022, and by the time I'm ready to buy something, I initiate the conversations myself. Imagine a plumber contacting you out of the blue and asking if you want to have your toilet replaced. The stars may align and one day the answer may be yes, but most of the time the answer's no. And that's what sales is like today and we need to fix that." - Jerich Beason, commercial CISO, Capital One
Listen to full episode of
Subscribe to our newsletters on LinkedIn!
We've got our bi-weekly and daily Cyber Security Headlines newsletters available right here on LinkedIn. Go ahead and subscribe to one or both!
CISO Series Newsletter - Twice every week
Cyber Security Headlines Newsletter - Every weekday
Cyber Security Headlines - Week in Review
Make sure you
to join the LIVE "Week In Review" this Friday for
Cyber Security Headlines
with CISO Series reporter Richard Stroffolino. We do it this and every Friday at 3:30 PM ET/12:30 PM PT for a short 20-minute discussion of the week's cyber news. Our guest will be Nick Vigier, CISO, Talend.
Thanks to our Cyber Security Headlines sponsor, Conveyor
Thank you!
Thank you for supporting CISO Series and all our programming
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing in social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.