Unwitting snake oil?
"the right beer now" (TM)

Unwitting snake oil?

I spend a lot of time thinking about how to spend company resources of money and time as a CISO. I’d even go so far as to say that crafting efficient spend to maximize risk mitigated for the lowest price point is the CISO’s core job function.

So I was delighted to discover this 2008 research paper called “The Market for Silver Bullets” (H/T Ross Haleliuk).

Very little has changed since Ian Grigg wrote this paper almost twenty years ago. There are so many quotable quotes in this paper I feel like a preacher man underlining the entire Bible while writing a sermon.

How much is a security vendor worth to your employer, anyway?

Read More: https://ninja.cybercybercybercyber.ninja/p/unwitting-snake-oil

Zsolt N.

CEO at R6 Security | Pioneering Adaptive Cloud Security | Innovator in Kubernetes & AI Orchestration Solutions

1 周

Sun Tzu: "The best security is the kind you don’t notice—until you don’t have it. And by then, it’s too late" :) On a serious note, this ROI calculation is so 20th century... we have not attacks models where the variables are not that easy to figure out clearly.

回复
Max I.

Global CISO at Bitpanda | One of Germany's Top CISOs | Keynote Speaker | Security Advocate & Ambassador

8 个月

As always a very good read. And I couldn’t agree more on the Security ROI metric.

要查看或添加评论,请登录

J.M. P.的更多文章

  • "IT" is Dead

    "IT" is Dead

    Now it's mostly Security It is now possible to build a company without an IT team. Anyone under 40 can set up a laptop…

    2 条评论
  • Bottom-up Security Doesn't Work

    Bottom-up Security Doesn't Work

    Choosing not to govern is still a governance choice Barn-raising is an effective way to build software, especially open…

  • If Education is the Solution to Your Security Problem, Then You've Already Failed

    If Education is the Solution to Your Security Problem, Then You've Already Failed

    A new scientific study confirms what has been obvious to me for years in the trenches: Security awareness training is…

    8 条评论
  • SOC 2 in Crypto is Pointless

    SOC 2 in Crypto is Pointless

    Legal Risk and Security Risk Are Not The Same I find it astonishing that in the year 2024 I have to say this out loud…

  • Make Sure We Never Get Hacked (How not to measure a CISO's job performance)

    Make Sure We Never Get Hacked (How not to measure a CISO's job performance)

    An innocent approach to measuring the performance of the security job function would be to measure the number or…

  • CISOs Need to Speak the Language of Business

    CISOs Need to Speak the Language of Business

    I was chatting with a security vendor I won’t name, and their CEO told me during the call, “Wow, it’s so refreshing to…

    1 条评论
  • The CISO as Chief Cyber Risk Officer

    The CISO as Chief Cyber Risk Officer

    I’ve been meeting a lot more CROs in industry lately, and for some companies centralizing all risk management in one…

    2 条评论
  • Bottom-up Security Doesn't Work

    Bottom-up Security Doesn't Work

    Choosing not to govern is still a governance choice Barn-raising is an effective way to build software, especially open…

  • The North Korean Love Triangle

    The North Korean Love Triangle

    What happens when you combine market competition with warfare? Crypto companies are trapped in the North Korean Love…

  • Web3 Security: Brittle or Resilient?

    Web3 Security: Brittle or Resilient?

    Outside of crypto, your tech startup’s primary competition comes from other companies—established players you want to…

社区洞察

其他会员也浏览了