04-07-20 - Let's Ask CISOs If They're Concerned About Data Security

Let's Ask CISOs If They're Concerned About Data Security

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

Let's Ask CISOs If They're Concerned About Data Security

Let's Ask CISOs If They're Concerned About Data Security

is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our sponsored guest is Steve Zalewski, deputy CISO, Levi Strauss & Co. The three of us discussed:

Avoid cybersplaining

. As a play on the term of mansplaining, cybersplaining is when a security salesperson tries to explain basic InfoSec to a cybersecurity expert. Far too many sales pitches begin with a question that really defines the CISO's job: "Are you concerned with hackers accessing your networks?"

Businesses are conflicted with data privacy.

Years ago the public wasn't so concerned about data privacy. Now, it's of utmost concern. Even so, businesses have been thriving on analyzing and collecting our data. Often they collect data just because they know they can. Given current public pressure and regulations companies have to rethink that decision.

Third party risk is an ongoing risk.

 So much of business relies on working with third parties. How you initially trust them is one big issue, but the much bigger issue is how do you verify company security policies. It creates a big brand management risk.

Service level agreements (SLAs) on data confidence vs. uptime?

Most SLAs are focused on uptime and speed of delivering tech support. But what do SLAs offer when it comes to the measurements of data confidence? Servers that are up yet have bad or misappropriated data all of a sudden becomes a core security issue.

Special thanks to this week's podcast sponsor, DivvyCloud.

DivvyCloud provides continuous security and compliance across all CSPs and containers, including AWS, GCP, Azure, Ailibaba, and Kubernetes, providing a comprehensive view of what’s in your cloud, along with the tools and automation you need to manage it today, tomorrow, and into the future as your business grows and changes.

Olivia Rose, former CISO, Mailchimp

[4-17-20] Hacking Zero Trust - CISO Series Video Chat

Please join us on April 17th, 2020 at 10 AM Pacific for the triumphant return of the CISO Series Video Chats, "Hacking Zero Trust: An hour of critical thinking on what it means to always verify access to people, data, and networks.”Joining moderator me, David Spark, producer, CISO Series, will be:Allan Alford, co-host, Defense in Depth. Anthony James, vp of product marketing, Infoblox.

    If you’ve never been a part of one of our CISO Series Video Chats, please join. While I have two fantastic experts to lead our discussion, ANYONE can and should participate in just the chat room, or live on video as a part of our discussion. I know you’ve all had plenty of time in front of the webcam, so join our unique conversation where we ENCOURAGE and even applaud bad ideas because they often lead to great ideas. We want you to be a part of some serious out of the box thinking (and fun) on this subject.Huge thanks to Infoblox for sponsoring this video chat.

    What Makes Cybertech in Tel Aviv So Unique

    https://cisoseries.com/what-makes-cybertech-in-tel-aviv-so-unique/

    Youth and energy is what makes Cybertech so different than major trade shows like Black Hat and RSA, said Roger Hale, former CISO in residence, YL Ventures, in our conversation at Cybertech 2020 in Tel Aviv.

    The two of us chatted about how this conference is so unique and different than other security shows.

    Yaron Levi, CISO, Blue Cross Blue Shield Kansas City on cybersecurity's vital business role

    SUBSCRIBE TO BOTH PODCASTS

    Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

    If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.