06-02-20 - Facebook Personality Quiz Asks, "What's Your Favorite Password?"

Facebook Personality Quiz Asks, "What's Your Favorite Password?"

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

Facebook Personality Quiz Asks, "What's Your Favorite Password?"

Facebook Personality Quiz Asks, "What's Your Favorite Password?"

is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our guest is Lakshmi Hanspal, global CISO, Box. All three of us discussed:

Alert fatigue isn't just about managing outputs.

What you put into the system can create unnecessary and unwarranted alerts. If you want to manage alert fatigue, you have to manage your inputs and outputs on an ongoing basis. The problem can get better, but it's incumbent on you to determine what does and doesn't matter.

For security training to work, it must be memorable.

Scaring people into being secure may provide a short-term fix, but it won't in the long term. You have to instill new behaviors and memories. Security training with humor has that ability. We often want to repeat jokes. We don't want to repeat things that made us scared.

We're enemy #2.

Given the trend of breaches and where we're most susceptible, our ability to make mistakes and not configure our clouds properly have made us the second biggest threat after black hat hackers. Look within your own organization to how you're creating your own vulnerabilities. 

Special thanks to this week's podcast sponsor, CyberArk.

CyberArk

At

, we believe that sharing insights and guidance across the CISO community will help strengthen security strategies and lead to better-protected organizations. CyberArk is committed to the continued exploration of topics that matter most to CISOs related to improving and integrating privileged access controls.

Mike Johnson on the importance of asset discovery

CISO/Security Vendor Relationship Podcast turns TWO

Yesterday marked the two-year anniversary of the CISO/Security Vendor Relationship Podcast with me and Mike Johnson. It's been a ton of fun, and we're so thrilled that so many of you have been so responsive to our editorial. So much of our content comes directly from you.If you're eager to hear the story of how the series and both podcasts started, it's all detailed here with me, Mike, and Allan. If you want to see how far we've come, listen to our very first episode with guest and good friend, Dwayne Melancon.

This FRIDAY! [6-5-20] CISO Series Video Chat: Hacking the Risk Decision Making Process

Join us next Friday, June 5th, 2020 at 10 AM Pacific/1 PM Eastern for "Hacking the Risk Decision Making Process: An hour of critical thinking on how we look at risk from all areas of the business".I'll be there leading the discussion with Tony Sager, senior vp and chief evangelist, Center for Internet Security and Marnie Wilking, global head of security & technology risk management at Wayfair.REGISTER.Plus, register for our future events:6-12-19: Hacking Rogue IT6-19-20: Hacking API Security

Allan Alford on why prevention-only security will ultimately fail

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.