Great information shared! This aligns to our experiences and challenges as well. I began listening in the background as I worked but wound up completely focused on your presentation. I'll need to watch a second time to sketch out some notes to help us remember and action on what you highlighted.
@clausjespersen10732 жыл бұрын
⁰⁰⁰⁰
@WeekendMuse2 жыл бұрын
Excellent and helpful presentation. The bits in red are the golden nuggets.
@jayasundaram8743 Жыл бұрын
Excellent presentation, drawing a line between Consulting and Senior Management is a great point myself to remember all ways.
@IdentityMaxxstl3 жыл бұрын
very informative and a fairly deep dive. Appreciate it.
@strolle283 жыл бұрын
This was a AWESOME presentation! The content and delivery was focused and effective! Thank you!
@user-hv9pt7em2u2 жыл бұрын
VERY well presented, excellent content.
@j.vinson90932 жыл бұрын
Great job James!!
@lawrencem36783 жыл бұрын
Great presentation by James. However, as security practitioners, isn't it our job to sell security to stakeholders. Security is already a cost center so in most cases, we need to convince management to allocate resources to it, buy in into our strategy which is all about selling. Am i missing something? If we dont sell, arent we just pushing reports, a bit of effort to sell and reverting to not my problem?
@basictalent12 жыл бұрын
Security is already sold to senior management by nature of regulations, fines or worst case imprisonments. If a company already has a IS policy mandate, we have to simply present them of what we are doing today to protect their assets and what we aren’t doing at all from a policy and industry frameworks point of view. Present them the threat and consequences for not getting it done. Show some security index, be prepared to share the cost of not doing vs. doing, so they cam make informed decisions of allocating resources.
@santibanks Жыл бұрын
@@basictalent1 That might be true on paper, but not all fields are regulated and smaller business can sometimes be exempt from certain regulations (like in the EU, If your company falls within one of the designated branches but has less than 10m revenue and/or less than 50 employees, you are still exempted from the NIS directive). I'm of the opinion that security is sold to a senior management when it actively engages with the topic. Just having a policy because everybody has one is not my definition of a management sold on security. A large part of the job as a practitioner in every rank (security engineer, information security officer, ciso, whatever) is creating awareness and educating people. So security is sold to management when it is a point on the agenda and decisions are actively and consciously being made (and that can include the decision to find other things higher priority than working on security). Because it is a human tendency to prioritise instant gratification on tangible things, security does need to be sold on a continuous basis. Now I do agree that you simply have to present what it is the company is doing and is not doing, what this means for their business in a fairly and accurate way (or at least as accurate as the information you have allows you for). And what the consequences for not getting it done can be within the context of the risk appetite. But management needs to understand that they are responsible for security, you are just the messenger and facilitator. Depending on the maturity of your management in question, you need to educate them and "sell security". It is up to management to make the calls and sign off on things. As a practitioner that is what you have to live with.
@Happy2bAmerican2 жыл бұрын
Great presentation, valuable information, and amazing speaker! 👏 seriously, your voice and performance is remarkable! Thank you! 😊
@throughjoshuaseyes44532 жыл бұрын
A very good instructor wow :) Very clear explanation
@arsalananwar33972 жыл бұрын
yes This was a AWESOME presentation!
@sid2944 жыл бұрын
great video, very informative!
@lmodje3 жыл бұрын
I enjoyed this. Thanks a lot
@nikklasnachton58654 жыл бұрын
Love this so much
@throughjoshuaseyes44532 жыл бұрын
Can you share please an internal report for the Risks to include the points you mentioned in the video :) Like a structure
@wawood059 Жыл бұрын
Great presentation but I would argue that you miss a couple key process elements upfront: 1) documenting/deriving the systems architecture, and 2) determining critical assets. Also, I think the BIA process should be brought forward to help prioritize system protection requirements.
@dawoodessop69365 ай бұрын
Incredible
@shajikurian29384 жыл бұрын
Good stuff
@mohdamrirazlan78794 жыл бұрын
Good point!
@michaeljearfed59134 жыл бұрын
Beastly work you have here
@rmcgraw7943 Жыл бұрын
Whenever I see a girl making video at the gym, I take my phone and take pictures of them when they are in unflattering positions, which makes them go crazy! They come and start at me, and I simply reply, “If you are going to record me in a public gym and put me in your video, then I’m gonna do the same thing to you, and I’ll be the editor of my video.”
@cybersecstudy98713 жыл бұрын
I’m sorry but I have to disagree with his definition of risk and his entire methodology! If you have threats but no vulnerabilities for the threats to expose… you don’t have a risk and you don’t need to implement controls!
@ralph17p3 жыл бұрын
Well done on totally missing the point. The video is about talking to senior leadership. You can stroke yourself all you like to the industry definitions of risk in your technical team meetings, but when you have 10 minutes with the board, if you waste 5 minutes explaining the threat * vulnerability * asset value formulas or whatever - game over. You've lost. You'll have bored them to death and they'll get their cyber security advice from their CEO buddies on the golf course based on what that guy's company is doing.
@Jimi-HendrixJr2 ай бұрын
I agree with you here. As soon as he focused on threats not vulnerability I stopped watching. Threat without a vulnerability there is no risk plain and simple.
@clausjespersen10732 жыл бұрын
Ååååååååå1
@GOTHAM212 жыл бұрын
You guys need better microphones.
@Jimi-HendrixJr2 ай бұрын
Absolute garbage. I expect better than this from SANS.
@joelmoo-young35293 жыл бұрын
At 6:32, the SANS webcast at www.sans.org/webcasts/influencing-effectively-communicating-ceos-boards-directors-103927/ that was presented on 18 April 2017 by Alan Paller and John Pescatore is entitled "Influencing and Effectively Communicating to CEOs and Boards of Directors."
@claudiamanta19438 ай бұрын
45:20 Listen. You seem to be a decent man and a very good teacher, however… If their stupid incompetence affects me, I can’t be chilled about it, can I? If I were just an external consultant, it would be probably easier. But if my job in that company is at risk and/or if my data is at risk because an idiot up there can’t be bothered…Huston, we have a big problem. And, by the way, this typical Western type of mentality is one of the main causes for the demise of the West.