The Good, the Bad, and the Ugly

The Good, the Bad, and the Ugly


How to Be a Good Compliance Leader in the Age of Threat-Informed Defence

Compliance is essential for any organisation that wants to operate legally and ethically. It is the responsibility of compliance leaders to ensure that their organisations comply with all applicable laws and regulations. However, not all compliance leaders are created equal. There are good compliance leaders, bad compliance leaders, and everything in between.

The Good

Good compliance leaders are proactive and take ownership of the entire compliance process. They set clear expectations, make sure everyone on the team understands their role, and foster a sense of accountability. They also see the bigger picture and understand the importance of compliance for the long-term success of the organisation.

Good compliance leaders are also good communicators who can explain complex compliance concepts in plain language. They are also able to build relationships with key stakeholders and get buy-in for compliance initiatives.

In the age of threat-informed defence, good compliance leaders also understand the importance of cybersecurity. They work with the security team to identify the organisation's most critical assets and determine the threats that those assets face.

They help to develop and implement security controls that are tailored to the specific threats that the organisation faces. They communicate the threat landscape to the organisation and ensure that everyone is aware of the risks. They monitor and evaluate the effectiveness of security controls to ensure that they are effective in mitigating threats.

The Bad

Bad compliance leaders are reactive and make excuses. They blame others for problems, and they are not willing to take responsibility for their own actions. They also dwell on the past and what could have been done differently, instead of focusing on the future and how to improve.

Bad compliance leaders also think in terms of the next audit and focus on tasks and evidence, rather than on the overall risk picture. They are more concerned with checking boxes than with actually understanding and mitigating risk.

Bad compliance leaders also talk about compliance in technical terms that most people don't understand. They make compliance seem like a complex and daunting task, and they don't do enough to engage and motivate others to take ownership of compliance.

The Ugly

The ugly compliance leaders are the ones who actively harm their organisations.


They may knowingly violate laws and regulations, or they may turn a blind eye to non-compliance. They may also use their position to enrich themselves or their friends. Ugly compliance leaders can be a danger to any organisation.?

How to Be a Good Compliance Leader

If you want to be a good compliance leader, there are a few things you can do:

  • Be proactive and take ownership of the entire compliance process.
  • Set clear expectations and make sure everyone on the team understands their role.
  • Foster a sense of accountability.
  • See the bigger picture and understand the importance of compliance for the long-term success of the organisation.
  • Be a good communicator and be able to explain complex compliance concepts in plain language.
  • Build relationships with key stakeholders and get buy-in for compliance initiatives.
  • Be ethical and uphold the highest standards of conduct.
  • Understand the threat landscape and how it impacts your organisation's compliance risks.
  • Work with the security team to develop and implement security controls that are tailored to the specific threats that your organisation faces.
  • Communicate the threat landscape to the organisation and ensure that everyone is aware of the risks.
  • Monitor and evaluate the effectiveness of the security controls to ensure that they are effective in mitigating the threats.

If you can do these things, you will be well on your way to becoming a good compliance leader in the age of threat-informed defence.


Inspired by the recent work of anecdotes


_______________________________________________

Enjoy reading this edition?

Consider subscribing to the Bright Insights Newsletter for weekly cybersecurity updates and insights:?

https://www.dhirubhai.net/build-relation/newsletter-follow?entityUrn=6978673051278135296??

Paul Briault

Business Development and Sales Leader | Relationship Leader | Board Advisor | Entrepreneur | NED

1 年

Great article Murray. Keep them coming.

回复
Chris McClellan

Entrepreneur, Founder & Business Strategist 9 X Founder & CEO with 7-9 figure Exits Investor & Advisor Acquisitions, Scale-up & Exits Impact, Tech, AI, Health-tech & Property

1 年

I'm sure you have no ugly compliance leaders reading this. They're definitely in the minority.

回复

要查看或添加评论,请登录

Murray Pearce的更多文章

  • From Doubt to Evidence: The Case for Threat-Informed Defense

    From Doubt to Evidence: The Case for Threat-Informed Defense

    For years, cybersecurity strategies have centered on the mantra: patch vulnerabilities, eliminate weaknesses, and keep…

  • When Seeing Isn’t Believing: Deepfakes in Cybercrime

    When Seeing Isn’t Believing: Deepfakes in Cybercrime

    Let’s delve into a potent force getting out of hand: deepfake technology. At first a novelty for entertainment…

  • Content Filtering: Not To Be Underestimated!

    Content Filtering: Not To Be Underestimated!

    You know that saying, not all heroes wear capes? Well, it’s true. Often, the people who help us the most are the same…

    3 条评论
  • The Sherlock Holmes of Cybersecurity

    The Sherlock Holmes of Cybersecurity

    Ransomware Profiling Ever considered yourself as a modern-day cybersecurity Sherlock Holmes, solving the ever-evolving…

    3 条评论
  • Unmasking Compliance Horrors: Data Quality Nightmare

    Unmasking Compliance Horrors: Data Quality Nightmare

    Whilst Halloween has been and gone, and the world takes off its eerie costumes, a different kind of nightmare still…

  • Strengthening your Cybersecurity Strategy

    Strengthening your Cybersecurity Strategy

    To ensure the effectiveness of your security controls, continuous validation is key. Continuous validation of your…

    2 条评论
  • A Gift to Security Leaders - Positive Intelligence

    A Gift to Security Leaders - Positive Intelligence

    Cybersecurity isn't just about technology; it's about people. As a security leader, your ability to engage with…

    3 条评论
  • Navigating the Uncharted Waters of Cloud Security

    Navigating the Uncharted Waters of Cloud Security

    The rapid migration to the cloud has left many organisations sailing blindly without a clear strategy to validate their…

    1 条评论
  • Stop trying to Boil the Ocean

    Stop trying to Boil the Ocean

    Staying informed about threats is essential. However, just because a threat makes headlines doesn't necessarily mean…

    3 条评论
  • A Marathon, Not a Sprint

    A Marathon, Not a Sprint

    You’ve heard the saying before, but never has it been more accurate than when threat defence is in the picture. When it…

    5 条评论

社区洞察

其他会员也浏览了