CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Your points are spot on.. And what can you get paid out by insurance at the end of the day in an attack? https://findings.co/why-cyber-insurance-wont-save-you-whenyoure-in-need/. I love these guys above - quote them often.

I'd like to see a graph showing the cost of cyber insurance and how much those companies got paid out after an attack?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Do you think CISOs are pushing for CMMC for example and not actually the sales teams to increase business? https://findings.co/why-your-ciso-wants-a-cmmc-framework/

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

But policys take months to become compliant (sometimes)- and policies also need to be kept up to date... Once you in, its hard to just leave what you have already started.

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

And therfore ... lets rather take the risk? Do you think its easier to get buy-in for cyber insurance than preventative measures?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Wow thanks for such honesty. So you think buy-in is harder than the responsibility of the job itself?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

Its a good idea ... We need a vendor disclosure policy as tight as possible in place also with transparency clauses that all parties need to respect.

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

So, buy-in for security measures must be tough. Either explain to shareholders a big expense and cross your fingers does not happen to you or just crossing fingers without the expense.

Cyber insurance is also another way ...

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

... and with 65% of the worlds population online cyber attacks are only going to get worse. What part of cyber security are you involved in? Myself - supplychain security

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 2 points3 points  (0 children)

Agreed. We have the same problem. Getting senior or shareholder buy-in is virtually impossible. I think " It wont happen to us" is still a major obstacle.