Beginning the CvCISO Program

Beginning the CvCISO Program

Second in a series relaying my experience as a long-time CISO/vCISO evaluating the CvCISO program.

I just completed, along with 30 or so others, the first of 30 classes in the SecurityStudio CvCISO program. I have opted to devote the time to participating in the entirety of the program to evaluate how effective it is in addressing one aspect of SMB needs. More about that in my first article in this series at https://www.dhirubhai.net/pulse/evaluating-cvciso-program-greg-schaffer-cd0ye/,

FRSecure and SecurityStudio CEO Evan Francen began in a manner different from any other course I've taken, that I can recall, and it was quite refreshing and enlightening. He discussed the purpose, the "why" of the CvCISO program. While some of this he and I covered in a recent episode of The Virtual CISO Moment (check it out at https://www.youtube.com/live/6lvvNFdjigA?si=jJkp6DyGJFZiOlQO), he emphasized that two main drivers are that organizations need good leadership and those who are vCISOs want to be good vCISOs.

He projects the kind of authenticity that makes you like him almost instantly, so when he emphasizes his guiding principle of "Mission Before Money", you don't feel like you're being sold a line - you believe it. His reasoning is if you focus on the mission, you'll make money, but if you focus on the money, you won't make the mission. This is a refreshing take not just in information security but for life in general. How many times in a day are we all exposed to "me first", entitlement situations?

Another thing he constantly emphasized during the two hour initial class is the importance of community. He noted - and I agree - that there is a vast underserved need for quality virtual CISOs - businesses need the leadership. Because of that, it's not about competition, but rather collaboration. Together we are better positioned to solving the problem of SMB security. Fostering community is an important aspect of that.

From there he outlined the course syllabus. Having been a practicing virtual CISO for seven years and a CISO for 10 years before that, I mostly agreed with not only the topics but the order of presentation. If the course delivers on the subject material, I can see that all would be well positioned with the skills necessary to be an effective vCISO - one that helps, not hinders business.

But what of experience? The CvCISO program recognizes that a 60 hour course alone is not enough to jump in and start providing virtual CISO services for SMBs. There are levels based on prior experience and takes into account an apprenticeship arrangement of sorts. I'm not yet sold on this being an effective ramp up for those to be effective vCISOs, but that's because of my background. I have always held to the belief that one must have been a CISO prior to serving as a vCISO, because you're not selling a product - you're selling your deep experience.

I am of course keeping an open mind. If any program can take someone from the beginning to being a practicing, effective vCISO, this one is probably as well designed as can be. The next 29 sessions are going to be quite interesting, I'm sure.


Timothy Hoffard

Certified vCISO/IT Security & Governance

11 个月

Great recap article Greg Schaffer I look forward to hearing more about your learning journey! (And Evaluation)

要查看或添加评论,请登录

Greg Schaffer的更多文章

  • Finish

    Finish

    Cold. Wet.

    1 条评论
  • Evaluating the CvCISO Program - Final Analysis

    Evaluating the CvCISO Program - Final Analysis

    In the beginning of March I wrote about evaluating the SecurityStudio CvCISO program. We have a serious problem in our…

    9 条评论
  • Good Risk, Bad Risk

    Good Risk, Bad Risk

    Recently I conducted a LinkedIn survey asking if all risk is bad. The results didn't surprise me on the surface, and…

  • Do Entry-Level Cybersecurity Jobs Exist?

    Do Entry-Level Cybersecurity Jobs Exist?

    Last week I asked the question in a LinkedIn poll "Do cybersecurity entry-level jobs exist?" My view, as I expressed in…

    14 条评论
  • Evaluating the CvCISO Program--Midway Point

    Evaluating the CvCISO Program--Midway Point

    A couple of months ago, I posted I was planning to evaluate SecurityStudio's CvCISO program. We have reached the…

    5 条评论
  • It's My Mother's Fault

    It's My Mother's Fault

    My father left my mother for another woman when I was three and a half. At 33, with only a high school education…

    9 条评论
  • To Use or Not to Use a Custom Email Domain

    To Use or Not to Use a Custom Email Domain

    A few weeks ago I received an unsolicited email to help enhance my Search Engine Optimization (SEO) for one of my web…

    20 条评论
  • We Are Failing With SMB Information Security

    We Are Failing With SMB Information Security

    According to the U.S.

    8 条评论
  • Evaluating the CvCISO Program

    Evaluating the CvCISO Program

    I remember when the CvCISO program was announced by SecurityStudio a few years ago. I am skeptical of certifications in…

    19 条评论
  • I'm a Small Business Owner. Wow.

    I'm a Small Business Owner. Wow.

    Five years ago I was leading the information security program for a community institution (financial services speak for…

    10 条评论

社区洞察

其他会员也浏览了