07-21-20 - How Will the Candidate Respond to "What's Worse?!"

How Will the Candidate Respond to "What's Worse?!"

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

How Will the Candidate Respond to "What's Worse?!"

How Will the Candidate Respond to "What's Worse?!"

is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our sponsored guest is Elliot Lewis, CEO, Keyavi Data. All three of us discussed:

Answers to "What's Worse?!" scenarios will show how a candidate can rationalize risk decisions.

Security is based on weighing pros and cons and making a decision that's best for the business. Sometimes you're faced with two horrible options, like what we present in the "What's Worse?!" game. The right answer is the one that delivers the best business rationale.

Sell security innovation not FUD (fear, uncertainty, and doubt).

CISOs don't respond well to scare tactics. In fact, they're well aware of their problems. What they need from security vendors are innovative approaches to solving their problems. Don't let security problems dictate security policy. Instead, the marketing message should be towards a business innovation plan that drives IT strategy. 

We've heard the "at rest" and "in transit" story of encryption.

We want to hear the "in use" story. How are companies truly taking advantage of the encryption tool? What happens after it's deployed? How is it used? What's the business context of how it's being used?

Special thanks to this week's podcast sponsor, Keyavi Data.

Keyavi Data

Now you can share data without ever losing control of it. Our advanced architecture makes data self-protecting, intelligent and self-aware – wherever it goes, no matter who has it. Our .SAFE patented multi-key technology enables data to evaluate its own safety conditions, including geo-sensing, recipient authentication, and policy changes from its owner. Contact Keyavi Data today and see for yourself.

Shawn Bowen, CISO, Restaurant Brands International on security theater

This Friday [7-24-20] We're Hacking Automation

Join us for Friday, July 24th, 2020 at 10 AM Pacific/1 PM Eastern for

"Hacking Automation: An hour of critical thinking on when and where to computerize”.

I'll be leading this discussion with Eoin Keary, CEO, edgescan and Jimmy Sanders, head of information security, Netflix DVD. 

Plus, immediately after the video chat (11:00 AM PT/2:00 PM ET) we'll rollover to the CISO Series Friday Meetup. Each participant will be randomly matched up in impromptu 1-on-1 five-minute conversations with fellow cybersecurity professionals. Link to do that will be made available during the video chat.

Huge thanks to our sponsor

.

API Security and Business Logic – Seeing the Forest as Well as the Trees

API Security and Business Logic – Seeing the Forest as Well as the Trees

CISO Series reporter, Steve Prentice, has an excellent piece about how API security shouldn't be seen as blocking and tackling, but rather an intrinsic part of overall business logic. Securing APIs is its own separate discipline. If you try to implement traditional security methods on this ever growing complicated process, you're going to find yourself overwhelmed very quickly. Understand connections and data flows and how that pertains to your business and you'll have a lot more success with API security.

Salt Security

Salt Security protects the APIs at the core of SaaS, web, and mobile applications. By using patented behavioral protection Salt Security automatically and continuously discovers and learns the granular behavior of each unique API and stops attacks. In 2020 Salt Security was named a Gartner Cool Vendor in API Strategy.

Allan Alford on centralizing API logic

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.