How to Present Cyber Security Risk to Senior Leadership | SANS Webcast

  Рет қаралды 88,128

SANS Institute

SANS Institute

Күн бұрын

Пікірлер: 31
@claudiamanta1943
@claudiamanta1943 5 ай бұрын
45:20 Listen. You seem to be a decent man and a very good teacher, however… If their stupid incompetence affects me, I can’t be chilled about it, can I? If I were just an external consultant, it would be probably easier. But if my job in that company is at risk and/or if my data is at risk because an idiot up there can’t be bothered…Huston, we have a big problem. And, by the way, this typical Western type of mentality is one of the main causes for the demise of the West.
@NickPellegrene
@NickPellegrene 3 жыл бұрын
Great information shared! This aligns to our experiences and challenges as well. I began listening in the background as I worked but wound up completely focused on your presentation. I'll need to watch a second time to sketch out some notes to help us remember and action on what you highlighted.
@clausjespersen1073
@clausjespersen1073 Жыл бұрын
⁰⁰⁰⁰
@lawrencem3678
@lawrencem3678 2 жыл бұрын
Great presentation by James. However, as security practitioners, isn't it our job to sell security to stakeholders. Security is already a cost center so in most cases, we need to convince management to allocate resources to it, buy in into our strategy which is all about selling. Am i missing something? If we dont sell, arent we just pushing reports, a bit of effort to sell and reverting to not my problem?
@basictalent1
@basictalent1 2 жыл бұрын
Security is already sold to senior management by nature of regulations, fines or worst case imprisonments. If a company already has a IS policy mandate, we have to simply present them of what we are doing today to protect their assets and what we aren’t doing at all from a policy and industry frameworks point of view. Present them the threat and consequences for not getting it done. Show some security index, be prepared to share the cost of not doing vs. doing, so they cam make informed decisions of allocating resources.
@santibanks
@santibanks Жыл бұрын
@@basictalent1 That might be true on paper, but not all fields are regulated and smaller business can sometimes be exempt from certain regulations (like in the EU, If your company falls within one of the designated branches but has less than 10m revenue and/or less than 50 employees, you are still exempted from the NIS directive). I'm of the opinion that security is sold to a senior management when it actively engages with the topic. Just having a policy because everybody has one is not my definition of a management sold on security. A large part of the job as a practitioner in every rank (security engineer, information security officer, ciso, whatever) is creating awareness and educating people. So security is sold to management when it is a point on the agenda and decisions are actively and consciously being made (and that can include the decision to find other things higher priority than working on security). Because it is a human tendency to prioritise instant gratification on tangible things, security does need to be sold on a continuous basis. Now I do agree that you simply have to present what it is the company is doing and is not doing, what this means for their business in a fairly and accurate way (or at least as accurate as the information you have allows you for). And what the consequences for not getting it done can be within the context of the risk appetite. But management needs to understand that they are responsible for security, you are just the messenger and facilitator. Depending on the maturity of your management in question, you need to educate them and "sell security". It is up to management to make the calls and sign off on things. As a practitioner that is what you have to live with.
@IdentityMaxxstl
@IdentityMaxxstl 3 жыл бұрын
very informative and a fairly deep dive. Appreciate it.
@rmcgraw7943
@rmcgraw7943 9 ай бұрын
Whenever I see a girl making video at the gym, I take my phone and take pictures of them when they are in unflattering positions, which makes them go crazy! They come and start at me, and I simply reply, “If you are going to record me in a public gym and put me in your video, then I’m gonna do the same thing to you, and I’ll be the editor of my video.”
@wawood059
@wawood059 10 ай бұрын
Great presentation but I would argue that you miss a couple key process elements upfront: 1) documenting/deriving the systems architecture, and 2) determining critical assets. Also, I think the BIA process should be brought forward to help prioritize system protection requirements.
@dawoodessop6936
@dawoodessop6936 2 ай бұрын
Incredible
@sid294
@sid294 4 жыл бұрын
great video, very informative!
@Happy2bAmerican
@Happy2bAmerican 2 жыл бұрын
Great presentation, valuable information, and amazing speaker! 👏 seriously, your voice and performance is remarkable! Thank you! 😊
@jayasundaram8743
@jayasundaram8743 Жыл бұрын
Excellent presentation, drawing a line between Consulting and Senior Management is a great point myself to remember all ways.
@throughjoshuaseyes4453
@throughjoshuaseyes4453 2 жыл бұрын
Can you share please an internal report for the Risks to include the points you mentioned in the video :) Like a structure
@nikklasnachton5865
@nikklasnachton5865 4 жыл бұрын
Love this so much
@WeekendMuse
@WeekendMuse Жыл бұрын
Excellent and helpful presentation. The bits in red are the golden nuggets.
@joelmoo-young3529
@joelmoo-young3529 3 жыл бұрын
At 6:32, the SANS webcast at www.sans.org/webcasts/influencing-effectively-communicating-ceos-boards-directors-103927/ that was presented on 18 April 2017 by Alan Paller and John Pescatore is entitled "Influencing and Effectively Communicating to CEOs and Boards of Directors."
@throughjoshuaseyes4453
@throughjoshuaseyes4453 2 жыл бұрын
A very good instructor wow :) Very clear explanation
@strolle28
@strolle28 2 жыл бұрын
This was a AWESOME presentation! The content and delivery was focused and effective! Thank you!
@arsalananwar3397
@arsalananwar3397 2 жыл бұрын
yes This was a AWESOME presentation!
@user-hv9pt7em2u
@user-hv9pt7em2u 2 жыл бұрын
VERY well presented, excellent content.
@lmodje
@lmodje 3 жыл бұрын
I enjoyed this. Thanks a lot
@j.vinson9093
@j.vinson9093 2 жыл бұрын
Great job James!!
@shajikurian2938
@shajikurian2938 4 жыл бұрын
Good stuff
@mohdamrirazlan7879
@mohdamrirazlan7879 4 жыл бұрын
Good point!
@clausjespersen1073
@clausjespersen1073 Жыл бұрын
Ååååååååå1
@michaeljearfed5913
@michaeljearfed5913 3 жыл бұрын
Beastly work you have here
@GOTHAM21
@GOTHAM21 2 жыл бұрын
You guys need better microphones.
@cybersecstudy9871
@cybersecstudy9871 2 жыл бұрын
I’m sorry but I have to disagree with his definition of risk and his entire methodology! If you have threats but no vulnerabilities for the threats to expose… you don’t have a risk and you don’t need to implement controls!
@ralph17p
@ralph17p 2 жыл бұрын
Well done on totally missing the point. The video is about talking to senior leadership. You can stroke yourself all you like to the industry definitions of risk in your technical team meetings, but when you have 10 minutes with the board, if you waste 5 minutes explaining the threat * vulnerability * asset value formulas or whatever - game over. You've lost. You'll have bored them to death and they'll get their cyber security advice from their CEO buddies on the golf course based on what that guy's company is doing.
Top Five Trends in CISO Leadership
1:01:51
SANS Institute
Рет қаралды 1,7 М.
Understanding Cybersecurity Risk Management
34:55
SANS Security Awareness
Рет қаралды 61 М.
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26
когда не обедаешь в школе // EVA mash
00:57
EVA mash
Рет қаралды 3,6 МЛН
Help Me Celebrate! 😍🙏
00:35
Alan Chikin Chow
Рет қаралды 49 МЛН
Cyber Risk Management: Essentials for the Practical CISO
1:01:10
SANS Institute
Рет қаралды 3,6 М.
BEING A CISO
30:34
Dr Eric Cole
Рет қаралды 1,5 М.
How to Perform Effective OT Cyber Security Risk Assessments
30:36
SANS ICS Security
Рет қаралды 10 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
Cyber Security vs Frameworks
30:17
Dr Eric Cole
Рет қаралды 1,8 М.
How To Understand and Manage Cyber Risk
42:59
Gerald Auger, PhD - Simply Cyber
Рет қаралды 1,6 М.
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26