How to Prepare for a CISO Interview | CISO Interview Questions

  Рет қаралды 16,133

Dr Eric Cole

Dr Eric Cole

Күн бұрын

Пікірлер: 20
@call_me_tia7994
@call_me_tia7994 2 жыл бұрын
Just started discovering your channel and I love it! It’s a huge help to prepare for the future CISO position! Thank you Eric! I totally support your message about business enabling and that so few people do understand it. As a consultant I‘ve met a lot of CISOs and they seldom cared about the business. As you said: they had a checklist of “bad things” and never cared about the context. It was much easier to say no because of security.
@sabotagehase8073
@sabotagehase8073 2 жыл бұрын
This man is pure gold. I absolutely love it and get my further education next year.
@user-ro2kr1dk8u
@user-ro2kr1dk8u 9 ай бұрын
Thank you Eric! Not my first CISO gig but I’ve always rolled up to CTO and could get away with tech jargon. Had an interview today with a CFO and thanks to this, I CRUSHED it! Have a couple more interviews to go but this method absolutely works!!!!
@kappatoflash
@kappatoflash Жыл бұрын
This is the best channel on KZbin. I wished I have found it a long time ago. Thank you Dr. Eric!
@narendra7338
@narendra7338 Жыл бұрын
This is absolute gold. Thanks so much Eric for such valuable insights. Excellent material🙏
@TeamSmithLI
@TeamSmithLI 3 жыл бұрын
Excellent info; great job representing Strong Island!
@DrEricCole
@DrEricCole 3 жыл бұрын
Thanks Marc! Glad you enjoyed!
@TheThirdDictor
@TheThirdDictor 3 жыл бұрын
Great video, but Eric, I think times have changed about the "not a lot of people with the experience" part. There are thousands upon thousands of security professionals out there at the senior manager and director levels, who are looking to step up into the CISO role. Your analogy is spot on about "Can you fly that plane?" And just like in aviation where EVERYTHING is based on "how many hours do you have flying that plane already?", so it is for a CISO role. If a person doesn't have at least 15 years of experience in infosec, including progressive roles up from analyst, through engineer, through manager, through director? You really don't have a shot at becoming a CISO. Why would you? Why would I trust my company's existence to somebody who has not shown a history of getting it done at very senior levels before?
@DrEricCole
@DrEricCole 3 жыл бұрын
Remember a world class CISO has world-class security engineers that report to them. You don't need to be a world-class security engineer to be a CISO. And here's the big problem. If you do something for 12 to 15 years, you are really, really good at it. You are so good at it. That's ingrained in what you do. And it is habits that are very difficult if impossible to break. So if you've been doing security analysts and engineers for 12 to 15 years, that's what you know, that's what you love. That's your comfort zone. So most not all, but most people that have security engineers for 12 - 15 years make terrible CISOs because they go in and continue to be a world-class security engineer. Now, is it possible for you to break the habit? Is it possible for you to become strategic and trust your team and not yourself as the world-class expert? Yes, but it's really, really difficult to do, to be a world-class CISO. You are so good at it. That's ingrained in what you do. And it is habits that are very difficult if impossible to break. So if you've been doing security analysts and engineers for 12 to 15 years, that's what you know, that's what you love. That's your comfort zone. So most not all, but most people that have security engineers for 12, 15 years make terrible CISOs because they go in and continue to be a world-class security engineer. Now, is it possible for you to break the habit? Is it possible for you to become strategic and trust your team and not yourself as the world-class expert? Yes, but it's really, really difficult to do, to be a world-class CSO. You need to speak business, but you don't need to be the business expert. That's the CEO, that's the COO, they're the business experts. You just need to speak the language to translate cyber into business terms, and if you're a CISO, you need to speak security, technical language, but you're not the expert. You need to rely on your team to do that. You're going to have a world-class team around you. So typically the best CISOs out there are the ones that have three to five years experience in security. They have some exposure to business and they're comfortable in both. They haven't built bad habits in either, and they can very flexibly go back and forth between those two roles.
@anthonyharmon9265
@anthonyharmon9265 Жыл бұрын
Boy are you mistaken...I have never met a CIO, CTO or CISO that spent 15 years in the trenches....ever. Most have an elementary education about IT....if anything they know more about leadership, strategy and business acumen. Your way of thinking is inaccurate and outdated 😂
@TheThirdDictor
@TheThirdDictor Жыл бұрын
You have now, @anthonyharmon9265. CISO here. 12 years doing helpdesk, network admin, and network engineering, then over to audit and security ops, then security consulting. I've worked with plenty of CTO/CIO/CISO who have spent a TON of time doing dev, operations, even hardware design. I have NEVER met a CTO with an "elementary knowledge" of IT....every one I have ever worked with has a deep knowledge of dev or cloud. My "way of thinking" is what got ME in the C-suite, as well as many others I know. One of us is wrong about what C-suite tech folks know, and I don't think it the one of us actually IN the C-suite (me).@@anthonyharmon9265
@Vic-dl7wq
@Vic-dl7wq 3 жыл бұрын
Great content Dr. Cole! I've heard you talk about assessing the impact to the business multiple times. It sounds like primarily from a financial perspective. I would love to hear you go deeper on assessing impact on a podcast. I have been looking into CIS RAM which talks about the impact to mission, objectives, and obligations. I know different frameworks use different languages to think about these things. I would love to hear more about how you think about this. Thanks!
@DrEricCole
@DrEricCole 3 жыл бұрын
So to me, when it comes to these risk assessment models, I like to keep them simple. Now, if you're doing it correctly, there's two things. First, everything from a business standpoint is ultimately going to come down to the monetary impact of the business. Even nonprofits make money and even government organizations have to justify their budget. So ultimately everything in business is going to come down to money. So when we look at things like reputation, guess what, why are we concerned about reputational impact? Because it will hurt the brand. It will hurt customers. It will hurt referrals, which ultimately hurts the revenue for the company or the dollars. So all of these other things that would talking about when you're talking about, objectives and obligations and mission, and all of those things are ultimately important because the mission objectives and reputation of the organization is ultimately, what's going to allow your brand. So ultimately all risk is calculated with dollars, because guess what? That's the ultimate language of business. If you go in to your CEO or executives and you say, well, there's risk that could hurt us. Our objective, Eric had hurt our mission or could hurt our reputation. Ultimately, what they want to know is what is going to be that impact in dollars and cents. If I, you go in and say, Oh, we're going to impact our mission. It's going to be really, really bad. Well, what does really bad mean? Well, it's going to cause us to lose $20 million. Okay? Notice it ultimately comes down to dollars. So that that's one thing to remember as being a world-class chief information security officer, that the language you speak, you're a translator later, you speak tactical for the security team and you speak business for the executive team.
@Vic-dl7wq
@Vic-dl7wq 3 жыл бұрын
Great advice Dr. Cole - makes sense, thank you!
@Theicebergx
@Theicebergx 3 жыл бұрын
Great show Dr. Cole
@DrEricCole
@DrEricCole 3 жыл бұрын
Thanks for tuning in weekly Theicebergx!
@benjrix1
@benjrix1 3 жыл бұрын
nice show
@DrEricCole
@DrEricCole 3 жыл бұрын
Thanks Benjamin :)
@anfalshaikh6148
@anfalshaikh6148 3 жыл бұрын
Hi Eric , i want to enroll your ciso certification and need you know about the course .. trying to reach you but no luck could you please share the details with me
@ayoubmchaar
@ayoubmchaar Жыл бұрын
What a wonderful channel 🫡🫡🫡 You are talking gold and sharing both information and Mindset. Very helpful thanks a lot
Get ready for the CISO Interview - Series 1
20:45
Prabh Nair
Рет қаралды 4,2 М.
Turn Off the Vacum And Sit Back and Laugh 🤣
00:34
SKITSFUL
Рет қаралды 9 МЛН
How many people are in the changing room? #devil #lilith #funny #shorts
00:39
When Cucumbers Meet PVC Pipe The Results Are Wild! 🤭
00:44
Crafty Buddy
Рет қаралды 62 МЛН
10 Things You Should Avoid Revealing In A Job Interview - Interview Tips
12:35
A Life After Layoff
Рет қаралды 1,4 МЛН
How do you show up as a CISO?
26:13
Dr Eric Cole
Рет қаралды 859
Ask the CISO #5: Shamla Naidoo, Global CISO at IBM
17:35
Cybercrime Magazine
Рет қаралды 4,7 М.
6 Questions Every CISO Should Know How to Answer
32:07
CyberGRX
Рет қаралды 767
CISO Conversations - Managing Risk
10:46
Cisco
Рет қаралды 1,8 М.
CISO Interview Tips - Homework Before Attending Interview
14:45
Prabh Nair
Рет қаралды 4,1 М.
5 Quick And Easy Ways To Impress Your Interviewer!
9:19
Don Georgevich
Рет қаралды 26 М.
Becoming a Virtual CISO: Everything you need to know
32:42
Dr Eric Cole
Рет қаралды 6 М.
Turn Off the Vacum And Sit Back and Laugh 🤣
00:34
SKITSFUL
Рет қаралды 9 МЛН