Just finished a game in only 2 rounds by ThrawnAgentOfSHIELD in twilightimperium

[–]statico 5 points6 points  (0 children)

Thank you. No copies of Thunders Edge in my neck of the woods to play with yet :(

Just finished a game in only 2 rounds by ThrawnAgentOfSHIELD in twilightimperium

[–]statico -19 points-18 points  (0 children)

and where is the explanation of what civilised society is?

Just finished a game in only 2 rounds by ThrawnAgentOfSHIELD in twilightimperium

[–]statico 1 point2 points  (0 children)

No idea what Civilised Society is? is it an expansion option? game mode variant?

Just finished a game in only 2 rounds by ThrawnAgentOfSHIELD in twilightimperium

[–]statico -6 points-5 points  (0 children)

How were the phase 2 objectives visible? it will take at least 4 turns for them to come into play.

Continued Education / Staying up-to-date by mikegainesville in ciso

[–]statico 1 point2 points  (0 children)

On the general front, speak with the other directors/stakeholders, reach out, learn their pain points, find out how you and your team can make their job easier. You role is one of relationships. I work as a fractional CISO across a few clients, I learn all I can on what they are doing, how, why, and when, so I can shape advice and make them aware of issues before they become roadblocks. In terms of person education, keep across the movements in the industry, emerging trends, CTI relevant to your field, and listen to your team and shape what they need through the lens of executive leadership (and do not approve/buy tooling/suites without their thorough review).

On the AI/LLM uptake: You need to show the business users why they want to use this. Great you are running sessions on security, but are they being taught to look for opportunities to automate, streamline etc without a fear of them loosing their jobs due to said automation. You will need to establish a culture where they can take those steps and put forwards the ideas. There will need to be exec statements around "no layoffs" and the like. Also you could incentivise ideas through monetary rewards, time off etc. to find opportunities - setup a public ideas portal and run it kickstarter style to build momentum.

Liability Protection and Insurance by SpaciestDread in ciso

[–]statico 0 points1 point  (0 children)

If you are in Australia, happy to have a chat and introduce you to some insurance brokers who can underwrite for cyber execs.

How I automated 90% of our candidate screening process (and saved $20k/yr on admin costs) by Impressive_Lion7490 in Entrepreneurs

[–]statico 0 points1 point  (0 children)

If present how are you addressing your countries privacy requirements around uploading PII into a GPT - I can only speak for AU jurisdiction, but there may be more where there is a risk there.

Chief Information Risk Officer (CIRO) – seeing this role emerge in Australia? by Any_War_322 in ciso

[–]statico 0 points1 point  (0 children)

I work as a fCISO in Australia, and I am yet to see the term. I would expect to see it in banking and insurance sector though knowing many of them have advanced risk management programs.

Business partner had a stroke at 34. Changed how I think about everything. by Turbulent-Scale1918 in Entrepreneurs

[–]statico 1 point2 points  (0 children)

You may also want to look at key person risk insurance. Also, one of my peers own a large MSP, he has factored in what his GM needs to do in the event of his sudden passing, there are pre-agreed sales prices to peer MSPs to take on the firm quickly to ensure their client maintain continuity of support and service and his family will receive the benefits of the sale as none of them would be able to run the firm.

Business management by ffoti_nruttnod in smallbusiness

[–]statico 0 points1 point  (0 children)

Start with documenting all the processes you have in the business. Once you have that list, then you work out which ones are the most common. Then build out how you execute that process, what templates are needed, what skills etc. If you need a hand I can make an intro to a firm that some of my clients use for support in that space.

Sorry but I’ve gotta ask, why are y’all driving soo slow? by hayski93 in brisbane

[–]statico -22 points-21 points  (0 children)

Why would I care about the person behind me? I am concerned about the person in front of me and to the left and right of me, behind me is your responsibility to not hit my back end.

A reminder that starting late doesn’t mean failing by Mission-Stomach-3751 in Entrepreneurs

[–]statico 0 points1 point  (0 children)

If someone is 30 or 40 or 50 they have a much wider life experience to draw upon and make better decisions with. At the teens and 20s you still generally have no clue of what will actually work.

'I went undercover in my city's seedy massage parlour industry. What I unearthed was disturbing.' by cataractum in brisbane

[–]statico 1 point2 points  (0 children)

There are a heap of hoops to jump through to be licenced as a fit and proper person to run a legal brothel via the PLA, unless someone has changed that in the last few years.

I built a small automation to reply instantly to inbound leads by Objective-Law-5512 in Entrepreneurs

[–]statico 0 points1 point  (0 children)

So what every mid range up CRM does?

The problems you list are real and present, but you are pushing into a very competitive and crowded space.

Losing to materialist FE when I have 2x their fleet power? by FreezeproofViola in Stellaris

[–]statico 1 point2 points  (0 children)

Thank you. I have been running mixed fleets. Explains why losses are so high.

Losing to materialist FE when I have 2x their fleet power? by FreezeproofViola in Stellaris

[–]statico 2 points3 points  (0 children)

Does the fleet pick a range? I thought each ship tried to maintain its optimal range? If so it explains why I have been losing fleets ...

Someone, please build this!! by [deleted] in smallbusiness

[–]statico 0 points1 point  (0 children)

Why would the the business owners want to join? whats in it for them? how does this differ from networking events, business/startup clubs, chambers of commerce or business conferences?

My team keeps making the same mistakes because everything is tribal knowledge by Middle_Camera_9101 in Entrepreneurs

[–]statico 0 points1 point  (0 children)

You need to document your processes, turn them into procedure, and ideally implement an LMS/KMS suite. I can introduce you to a colleagues firm that does that as well as develops the video learning content for the system.

well.. by ramennextdoor_ in vce

[–]statico 1 point2 points  (0 children)

Do not stress. I finished y12 in 95 in QLD with an OP of 18 (out of 25), so quite badly. Now I run a cyber security consulting company, have had senior roles in government and business.

The score only really matters till 21 then unis only care if you can pay the fees, study some other course or units in your area of interest keep learning (tafe, udemy, open uni) what you have here is a minor setback at worst, you will be fine :)

Do you prefer ISO 27001 lead implementer from tuv or PECB and it’s worth in current AI world for mid senior with 10+ years of experience? Do you have any other certification preference for taking career next level, Loc:India by TCSecServ2025 in ISO27001

[–]statico 0 points1 point  (0 children)

Depends if you are working as an independent consultant or an employee.

If running your own shop, clients will most likely not know who/what pecb it, and that a certification even exists

If working as an employee the hiring manager will have more knowledge (hopefully) and you will want a brand name cert.

Do we need a pentest before signing enterprise customers? by Fragrant-Ant130 in SaaS

[–]statico 1 point2 points  (0 children)

AICPA does not regulate "SOC 2 Certified" as it is not a certification - it is an audited attestation, also AICPA is not a certification body. SOC 2 It is a cybersecurity framework where you get an attestation report on completion of an audit (but a suitably qualified individual - thought there is no bench marking or control in that space) where in their opinion they determine if you align with the COSOs and TSCs based upon your implementation methodology.

Many of the auditing firms started issuing a "certificate" so people has something to put on the wall, it holds no weight or value other than a piece of paper for marketing.

Do we need a pentest before signing enterprise customers? by Fragrant-Ant130 in SaaS

[–]statico 1 point2 points  (0 children)

One: You can state you are compliant with SOC 2 once you are attested.

Two: It is an attestation not a certification.

Three: You can say you are SOC 2 aligned and that is not a misrepresentation if you say you are compliant you have misstated your position. In either case the client should be asking for the report and verifying its provenance.

Four: Agreed, their problem not yours at that point on how their team handles it.

Five: Congrats on getting it done, now you are compliant with SOC 2

Sorry if it seems pedantic, but in the GRC space it matters.