CISO Alignment and Week in Review
E.B. Spoke | Week In Review

CISO Alignment and Week in Review

We're halfway through #cybersecurityawarenessmonth - and I hope everyone is more familiar with the four focus areas of updating software, having strong passwords, enabling multifactor authentication (MFA), and recognizing and reporting phishing.

TLDR? Where should the CISO be in a modern organization? A recap on my interviewing tips. A leadership thought. A cybersecurity awareness catch-up. And a post-note on acronyms (TLDR- Too Long Didn't Read).

Organizing Security for Success

Cybersecurity awareness doesn't limit itself to these four areas. Another key topic is how your organization is organized to focus on cybersecurity. Having an individual or team designated to cybersecurity is a key requirement, by insurance, auditors, and most regulatory frameworks. In this Forbes article, we even see the Securities and Exchange Commission (SEC) may require this expertise on the boards of publicly traded company.

I recently polled* a group of cybersecurity professionals on where they see the Chief Information Security Officer (CISO) reporting in the organization. Why does this matter, you might wonder? The short answer is it (1) vests the correct authority and power in the role to make the correct decisions for the company without inappropriate influence and (2) demonstrates the seriousness the organization places on cybersecurity.

A graph showing "Where should the CISO be organizationally aligned in 2023"? - On the Board (23%), Reports to the Board (24%), Reports to the CEO (34%), Reports to the CIO/CTO/CxO (18%).

The majority of votes were in favor of reporting to the CEO. Of interest though, 50% of overall votes were split almost evenly between being on the Board (as the SEC may require) or at least Reports to the Board.

This shift could also be influenced by the former Uber CISO's recent conviction last week. The conviction was related to the cover-up, but it was alleged the CEO at the time was also in the loop. CISOs having independence from even the CEO can be natural extension of how to mitigate this risk.

Regardless of how your company organizes - it's critical you define a role with enough authority and autonomy to investigate, report, and remediate cybersecurity incidents.

* The poll was in a private LinkedIn group, so you may not have access.

Week in Review

In case you missed it (ICYMI) - I talked about a few different topics this week. Since many people are still on the job hunt, I shared a few interviewing tips from my experience as a hiring manager and as an interviewee all those years ago. A few leadership thoughts cross my keyboard as well. And of course, I shared my daily cybersecurity awareness tidbit.

Check the posts out if you're interested and missed them!

Interviewing Tips

#ebspoke_careers

Good luck this next week on your interviews. And if you're a cloud professional, .net or front-end developer, and want to work with me (or Improving), send me a message!

For the leaders...

#ebspoke_leadership

A quick reflection on permission-based leadership, versus letting your team have some authority and autonomy to be creative.

Cybersecurity is Always Important

#ebspoke_cybersecurity

Thank you!

A big shoutout to everyone engaging with conversations on LinkedIn. I love hearing your thoughts and opinions on all the important topics.

Lyndsee Nielson had a great thread about using acronyms in your posting. I did today, but also spelled them out first. We get caught up in jargon so often, we risk losing people who aren't our core audience. So always be conscious of jargon and acronyms. Check out her post and the conversation here.

For more of my past posts, check out:

#ebspoke_grc

#ebspoke_sharing

And of course, subscribe to my weekly newsletter, and follow/subscribe to my profile to not miss anything during the week!

要查看或添加评论,请登录

Erik Boemanns的更多文章

  • Great Events, Past and Future

    Great Events, Past and Future

    Thank you again for everyone who has been able to make it out to one of the two cybersecurity community events hosted…

    4 条评论
  • How Does Your Garden Grow?

    How Does Your Garden Grow?

    Spring is upon us in the northern hemisphere, and if you're inclined to garden, you may have begun by now. Furrowing…

    1 条评论
  • The Energy of Youth, the Wisdom of Age

    The Energy of Youth, the Wisdom of Age

    As I spent some time building out a new product (see Atlanta Tech Events below), I realized how I had much more energy…

    2 条评论
  • Encouraging Entrepreneurship

    Encouraging Entrepreneurship

    Yesterday I had the opportunity to be a judge for TiE Atlanta's TiE University College Entrepreneurship program. The…

    3 条评论
  • Let's Connect IRL*

    Let's Connect IRL*

    Got FOMO for the upcoming event in Chamblee on Tuesday? IDK if you do, but I do hope to see you there! Seriously…

  • Gray Stone and Mortar

    Gray Stone and Mortar

    I attended Oglethorpe University to finish my bachelor's degree, after earning an associate degree from Young Harris…

  • A Big Competition?

    A Big Competition?

    Many of you won't see my newsletter when it lands in your inbox this evening. I hear there's something on TV right now…

    1 条评论
  • Happy Groundhog Day!

    Happy Groundhog Day!

    Groundhog Day - the day where a small ground rodent predicts the weather for us. Today's prediction? Six more weeks of…

    2 条评论
  • Together, Better

    Together, Better

    Whether building a new business, protecting it from cyber threats, looking for a job, or just keeping up with…

    3 条评论
  • Service.

    Service.

    Service to company. Service to community.

    7 条评论

社区洞察

其他会员也浏览了