Evaluating the CvCISO Program--Midway Point

Evaluating the CvCISO Program--Midway Point

A couple of months ago, I posted I was planning to evaluate SecurityStudio 's CvCISO program. We have reached the halfway point, a good time to provide an update. I must profess up front, though, that because of workload and scheduling conflicts, I have not been able to attend all of the classes. However, I have reviewed the videos (they are recorded) and/or slide decks as well as completed the homework and quizzes, all in the learning portal.

The first half of the course is all about learning. The goal is to level-set everyone so all have the same baseline knowledge. It remined me of prepping for the CISSP nearly 20 years ago, including revisiting cryptography, my nemesis. This aspect of the course is challenging and interesting. This is not simply a "throw facts at you to memorize" strategy. Each topic is covered extensively, and discussion is encouraged. Real-world examples are presented, as are reference items that the student is encouraged not only to review but also consider using in their virtual CISO practice. Some items I would have presented differently, or left out, or added, but all of that is minor and would be nit-picking. Overall, the topics covered and their presentation are solid.

Yet the first half of the 10-week, 60-hour course isn't just about baseline technical and risk management knowledge. We covered items specific to the virtual CISO world, such as customer relations and what exactly a virtual CISO does. The latter is important, perhaps more so today, in an environment where the term "vCISO" has become quite diluted. Understanding the vCISO role is critical to being a vCISO. I've noted before that not all CISOs can be virtual CISOs; the skillsets have much overlap but there are differences.

I think one of my favorite aspects of this experience is the community that is growing from this class. Leveraging Discord also helps to create interactions. This is important in the development of the virtual CISO as none of us operate in a vacuum. The more resources we can ping, the better we are serving our clients. After all, service is the end goal. The whole reason for the CvCISO program is not to add yet another certification to an already saturated field, but rather to solve a problem. That problem is SMB security, which I write and talk about extensively (for example, check out my 2024 BSides Nashville presentation on this topic).

All in all, my view at the halfway point is the CvCISO program hits on all cylinders, exceeding my expectations (and I set the bar high internally). The second half, as I understand, will be more about applying knowledge. Unless the situation warrants otherwise, my next update will be at the end of this phase (and the course) and before taking the CvCISO exam. See you in five weeks!


Susan Richards

Do you know where your data is? Retain your sanity and save $$ by improving data security | HITRUST User Group leader | Securi-TEA party maven

10 个月

I was just thinking earlier today that I had not seen an update on the course in a while. Great milestone to accomplish and summarize your journey so far. Thanks for keeping us informed along the way and good luck on the second half.

John Martin

Cyber Imagineer | Problem Solver | Senior Risk Analyst | Navy Veteran | Coach | Humanist

10 个月

Really appreciate your insights on this course Greg! I'm keen to take this on to expand my own skillset but wanted to be sure that it was fully fleshed out. From your analysis, it sounds like a good investment in time and money.

Chris Rule

Cybersecurity Cowboy | CETL | CvCISO | CCRE | WyTEL President | Consultant | Father | Husband | Servant

10 个月

I got more out of the second half. The first part was a great review and accentuated some of my weaknesses, but I definitely liked the second part more. I'm enjoying your reviews.

要查看或添加评论,请登录

Greg Schaffer的更多文章

  • Finish

    Finish

    Cold. Wet.

    1 条评论
  • Evaluating the CvCISO Program - Final Analysis

    Evaluating the CvCISO Program - Final Analysis

    In the beginning of March I wrote about evaluating the SecurityStudio CvCISO program. We have a serious problem in our…

    9 条评论
  • Good Risk, Bad Risk

    Good Risk, Bad Risk

    Recently I conducted a LinkedIn survey asking if all risk is bad. The results didn't surprise me on the surface, and…

  • Do Entry-Level Cybersecurity Jobs Exist?

    Do Entry-Level Cybersecurity Jobs Exist?

    Last week I asked the question in a LinkedIn poll "Do cybersecurity entry-level jobs exist?" My view, as I expressed in…

    14 条评论
  • It's My Mother's Fault

    It's My Mother's Fault

    My father left my mother for another woman when I was three and a half. At 33, with only a high school education…

    9 条评论
  • Beginning the CvCISO Program

    Beginning the CvCISO Program

    Second in a series relaying my experience as a long-time CISO/vCISO evaluating the CvCISO program. I just completed…

    1 条评论
  • To Use or Not to Use a Custom Email Domain

    To Use or Not to Use a Custom Email Domain

    A few weeks ago I received an unsolicited email to help enhance my Search Engine Optimization (SEO) for one of my web…

    20 条评论
  • We Are Failing With SMB Information Security

    We Are Failing With SMB Information Security

    According to the U.S.

    8 条评论
  • Evaluating the CvCISO Program

    Evaluating the CvCISO Program

    I remember when the CvCISO program was announced by SecurityStudio a few years ago. I am skeptical of certifications in…

    19 条评论
  • I'm a Small Business Owner. Wow.

    I'm a Small Business Owner. Wow.

    Five years ago I was leading the information security program for a community institution (financial services speak for…

    10 条评论

社区洞察

其他会员也浏览了