08-06-19 - Improve Security By Hiring People Who Know Everything

Improve Security By Hiring People Who Know Everything

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

Improve Security By Hiring People Who Know Everything

CISO/Security Vendor Relationship Podcast: Improve Your Security Posture By Hiring People Who Know Everything

was recorded in front of a live audience at ADAPT's CISO Edge conference in Sydney, Australia. This special episode was co-hosted by Liam Connolly, CISO of Seek. Along with our two guests, Matt Boon, director of strategic research for ADAPT, and our sponsored guest John Karabin, vp, cybersecurity for Dimension Data, the four of us discussed:

Really talented cybersecurity people actually don't know everything.

We discussed a far-reaching job posting asking for a cyber professional with subject matter expertise across 12 different disciplines. This unreasonable request will turn off what could potentially be your best candidate. Be wary of those who

do

respond. They're probably lying.

(left to right) David Spark, producer, CISO Series, Liam Connolly, CISO, Seek, and Matt Boon, director of strategic research, ADAPT.

If you offer everything, don't lead with that.

A listener from Fortinet questioned how he should approach a CISO when his company offers such a broad portfolio, of which many of the products are commoditized. Best course of action is to ignore your portfolio for a moment and do whatever you can to understand the customer. Over time, as you build a relationship with a customer, you'll probably be able to sell more products from your portfolio.

Please, please, please do not try to be funny in an introductory email to a cybersecurity professional.

We understand that with blind email communications you're trying to set yourself apart from the pack. An Open Mic Night Comedy email is not a good place to start. This misguided approach preys on the recipient to be so humored by your comment that they'll be compelled to take a meeting with you. If you have any evidence of that ever happening from an initial email, let me know. We've yet to see it happen.

Special thanks to this week's CISO/Security Vendor Relationship Podcast sponsors, Dimension Data/NTT and ADAPT.

Dimension Data/NTT

By 1 October 2019, all 28 NTT companies, including Dimension Data, will be branded as NTT. Together we enable the connected future. Visit NTT at hello.global.ntt.

ADAPT

ADAPT’s mission is to equip IT executives with the knowledge, relationships, inspiration and tools needed to gain competitive advantage. ADAPT’s membership platform provides business leaders with fact-based insights, actionable patterns of success and the collective experience of 3,000 peers to improve strategic IT, security, and business decisions. Visit ADAPT for more.

Mike Johnson on the failure of the "listen to me" style of cyber education

The entire CISO Series crew is at Black Hat 2019

Tuesday, August 6th - Security Bsides

I'll be there recording questions and "What's Worse?!" scenarios for upcoming podcast episodes. If you see me, have one locked and loaded.

Wednesday, August 7th - Black Hat

I'll be asking attendees questions for my "man on the street" videos. If you see me and my cameraman, stop by. I may have a question for you.

Thursday, August 8th - Black Hat

Mike Johnson and I will be recording an episode of the

CISO/Security Vendor Relationship Podcast

 in ExtraHop's booth (#822) on August 8th at 12 PM. Our sponsored guest will be Tom Stitt, ExtraHop's senior director, product marketing - security.

Allan Alford on not necessarily needing to stay up to date on the latest vulnerabilities

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.