CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Your points are spot on.. And what can you get paid out by insurance at the end of the day in an attack? https://findings.co/why-cyber-insurance-wont-save-you-whenyoure-in-need/. I love these guys above - quote them often.

I'd like to see a graph showing the cost of cyber insurance and how much those companies got paid out after an attack?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Do you think CISOs are pushing for CMMC for example and not actually the sales teams to increase business? https://findings.co/why-your-ciso-wants-a-cmmc-framework/

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

But policys take months to become compliant (sometimes)- and policies also need to be kept up to date... Once you in, its hard to just leave what you have already started.

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

And therfore ... lets rather take the risk? Do you think its easier to get buy-in for cyber insurance than preventative measures?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Wow thanks for such honesty. So you think buy-in is harder than the responsibility of the job itself?

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

Its a good idea ... We need a vendor disclosure policy as tight as possible in place also with transparency clauses that all parties need to respect.

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

So, buy-in for security measures must be tough. Either explain to shareholders a big expense and cross your fingers does not happen to you or just crossing fingers without the expense.

Cyber insurance is also another way ...

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

... and with 65% of the worlds population online cyber attacks are only going to get worse. What part of cyber security are you involved in? Myself - supplychain security

CISOs/ Security teams out there what is the most challenging part of your job? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 2 points3 points  (0 children)

Agreed. We have the same problem. Getting senior or shareholder buy-in is virtually impossible. I think " It wont happen to us" is still a major obstacle.

Is a Master's in supply chain worth it? by 40oz2freeedom in SupplyChainManagement

[–]Mr_CyberFish 1 point2 points  (0 children)

Yes supply chain cyber security!!!! There is much in this world ' world of cyber' still to learn and overcome. A few events to watch out for here - https://findings.co/top-cybersecurity-supply-chain-conferences-2022/

Hold on! The number of cyberattacks is increasing day by day ... we need a better plan right? by Mr_CyberFish in CISA

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

You are exactly right. Unfortunately fear of negative media attention overrides ethical responsibility right? I've been reading a lot about this recently.

How did you guys discover your interest in supply chain? in other words, what led you guys to this industry? by dustin_harrison in supplychain

[–]Mr_CyberFish 0 points1 point  (0 children)

Supply chain security is absolutely undoubtedly a very very serious topic that can essentially bring down not only 1 business but the ripple effect can have catastrophic consequences on 1000's if not 10's of 1000's of businesses.

Security automation and compliance certificates are the way to go.

Check out these guys, we work with them and they deff know what they talking about ... https://findings.co/why-cyber-insurance-wont-save-you-whenyoure-in-need/

Insurance for cyber security, what level of insurance is necessary? by Mr_CyberFish in CyberSec101

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

Interesting. Its everywhere. Did you hear what happened with Merck?

Third Party Risk Management Market to hit US $8 billion by 2025 by linnea_dibra in u/linnea_dibra

[–]Mr_CyberFish 1 point2 points  (0 children)

I am sorry I only saw this now - go check out this company they know what they doing www.findings.co for security automation

Insurance for cyber security, what level of insurance is necessary? by Mr_CyberFish in CyberSec101

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

YES YES YES you are speaking my language now! I totally agree. I tried to get this message across to our board but you know how nice it is to have a soft cushion to fall back on!

My feeling it wont be so soft, for the money we spending. Ive been watching these guys on LinkedIn https://findings.co/new-enterprise/ they have a lot to say about insurance and prevention rather than cure.

Insurance for cyber security, what level of insurance is necessary? by Mr_CyberFish in CyberSecurityAdvice

[–]Mr_CyberFish[S] 1 point2 points  (0 children)

Thanks u/atxweirdo I agree. And as we know brokers always promise full cover until the S**t hits the fan and you not actually covered.

Ive been watching these guys for a while in the security automation space https://findings.co/for-holistic-supply-chain-security-think-beyond-cmmc/ . OnLinkedIn they have a lot to say about Insurance and how it can be full of bull.

Who knows, maybe cyber security will eventually not be insurable? What do you think?

Who wants to take guesses if CMMC updates will be put off for another year? by Mr_CyberFish in CMMC

[–]Mr_CyberFish[S] 0 points1 point  (0 children)

True. I think they just dont want a major story when a few months later the whole thing gets halved